A new executive order signed on Friday by U.S. President Donald Trump prohibits the acquisition of bulk-power system equipment that could contain intentional backdoors planted by foreign adversaries.
Hi, what are you looking for?
A new executive order signed on Friday by U.S. President Donald Trump prohibits the acquisition of bulk-power system equipment that could contain intentional backdoors planted by foreign adversaries.
High-severity vulnerabilities patched in the Ninja Forms and LearnPress WordPress plugins could be exploited to take over vulnerable sites, WordPress security company Defiant reports.
Over the past several days, hackers have exploited two recently disclosed Salt vulnerabilities to compromise the servers of LineageOS, Ghost and DigiCert.
A newly discovered piece of Android malware is targeting the users of close to 300 financial applications across the United States and Europe, Cybereason Nocturnus security researchers warn.
Oracle warned customers on Thursday that threat actors have been spotted attempting to exploit multiple recently patched vulnerabilities, including a critical WebLogic Server flaw tracked as CVE-2020-2883.
An alert the U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) published this week reiterates previously issued recommendations on how organizations should properly secure Microsoft Office 365 deployments.
Several vulnerabilities, most of which have been described as cross-site scripting (XSS) flaws, have been patched in WordPress this week with the release of version 5.4.1.
A memorandum sent by the United States Cybersecurity and Infrastructure Security Agency (CISA) to Chief Information Officers (CIOs) at federal agencies reminds them to use EINSTEIN 3 Accelerated (E3A)’s Domain Name System (DNS) sinkholing capability for DNS resolution.
A sophisticated phishing kit has been used by multiple cybercrime groups to target high-ranking employees in North America and other parts of the world, and researchers believe there are at least 150 victims.
Individuals and criminal organizations have taken immediate advantage of the COVID-19 pandemic to find new ways of making money, the European Union’s law enforcement agency said Thursday, citing a spike in counterfeiting and cybercrime.
Google said Thursday its task force devoted to fighting "bad" ads hawking bogus coronavirus cures, illegitimate unemployment benefits and overpriced medical supplies had blocked tens of millions of messages.
The European Union on Thursday accused unnamed parties of exploiting the coronavirus pandemic to launch cyberattacks on infrastructure and healthcare services.
American education technology company Chegg this week sent notifications to its employees to inform them of a data breach that occurred earlier this month.Based in Santa Clara, California, Chegg offers various student services, including digital and physical textbook rentals and online tutoring, and has more than three million subscribers.
Tel Aviv, Israel-based Secret Double Octopus has raised $15 million in a Series B funding round from Sony Financial Ventures, KDDI, and Global Brain as well as prior investors. The firm provides passwordless authentication for enterprises, and is eyeing the growing WFH market.
The number of attacks abusing the remote desktop protocol (RDP) to compromise corporate environments has increased significantly over the past couple of months, Kaspersky reports.
YARA 4.0.0 was released on Wednesday with some important new features and performance improvements.YARA is a highly popular open source tool designed to help researchers identify and classify malware samples. It has been described as “the pattern-matching swiss knife for malware researchers.”
Ransomware Capabilities Added to 'Lucy' Android MalwareA piece of Android ransomware uses a scareware tactic to extort money from victims: it asks them to provide their credit card information to pay a “fine,” Check Point reveals.
Google this week announced a new set of rules for its Chrome Web Store, meant to ensure that developers don’t spam users with extensions that have similar functionality.The Chrome Web Store has been available since 2011, offering a total of more than 200.000 browser extensions that allow users to easily customize their browsing experience in Chrome.
The Salt community has been aware of a critical vulnerability in Salt Master versions since late last week. It was informed that the vulnerability has a CVSS rating of 10.0, that Salt Masters should not be exposed to the internet, and that fixes would be released this week.
The actions of the hackers who recently targeted water facilities in Israel show their sophistication and prove that they knew exactly what they were doing, according to people with knowledge of the attacks.