Common Vulnerabilities and Exposures (CVE) stories - Page 13
Trend Micro helps uncover critical file sharing Samba bug
Thu, 10th Feb 2022
#
cybersecurity
#
trend micro
#
cyber attacks
Trend Micro discovers critical vulnerability in Samba file sharing protocol, advises urgent patching for affected organisations.
Supply chain vulnerability identified in SAP transport system
Fri, 21st Jan 2022
#
supply chain
#
software development
#
sap
Supply chain attacks on SAP software distribution process allow internal attackers to intervene undetected, says SecurityBridge. A patch has been released.
WordPress vulnerabilities more than doubled in 2021
Thu, 13th Jan 2022
#
risk & compliance
#
cybersecurity
#
wordpress
WordPress vulnerabilities have more than doubled in 2021, with 77% of them being exploitable, according to Risk Based Security.
Ransom DDoS attacks surged in final quarter of 2021 - report
Wed, 12th Jan 2022
#
ddos
#
cybersecurity
#
botnet
Ransom DDoS attacks increased by 29% YoY and 175% QoQ in the last quarter 2021, according to new research from Cloudfare.
Critical Microsoft Office patch exploited by new malware
Fri, 24th Dec 2021
#
malware
#
firewalls
#
network infrastructure
Sophos has released details of a novel exploit that bypasses a patch for a critical vulnerability affecting the Microsoft Office file format.
Security flaw identified in smartphone chip used in Android devices
Fri, 26th Nov 2021
#
semiconductors
#
technology gifts
#
mediatek
Flaws in smartphone chip used in 37% of world's smartphones could enable eavesdropping or hiding malicious code, says Check Point Research.
Vulnerability in Cisco security devices could cause firewalls to fail
Wed, 24th Nov 2021
#
pam
#
ndr
#
cybersecurity
Vulnerability in Cisco ASA and Cisco FTD firewalls discovered by Positive Technologies researcher, could lead to denial of service. Install updates.
New Microsoft Defender vulnerability should concern every enterprise - expert
Mon, 15th Nov 2021
#
cybersecurity
#
microsoft
#
security vulnerabilities
Microsoft Defender vulnerability poses significant threat, warns Virsec. With 55 vulnerabilities in total, it is deemed the most concerning by experts.
ExtraHop launches decryption support for Microsoft to halt advanced attacks
Tue, 9th Nov 2021
#
advanced persistent threat protection
#
microsoft
#
extrahop
ExtraHop has expanded decryption support for Microsoft authentication and application protocols, providing high fidelity detection of malicious activity.
BlackBerry and Okta partner to deliver seamless identity and access capabilities
Tue, 9th Nov 2021
#
malware
#
supply chain
#
edr
BlackBerry has announced a new technology integration between Okta's Identity Cloud and BlackBerry Spark unified endpoint management.
Imperva launches free security assessment service for Amazon RDS
Fri, 29th Oct 2021
#
cloud security
#
breach prevention
#
amazon
Imperva launches free cloud data security assessment for Amazon RDS databases, allowing teams to quickly identify compliance issues.
ATM vulnerabilities open door for attacks - report
Thu, 28th Oct 2021
#
breach prevention
#
cybersecurity
#
security breaches
Vulnerabilities in Wincor Cineo ATMs allow attackers to bypass encryption and make cash withdrawals, according to researchers.
MysterySnail: Kaspersky finds zero-day exploit for Windows OS
Thu, 14th Oct 2021
#
cybersecurity
#
microsoft
#
windows
Kaspersky uncovers zero-day exploit for Windows OS, used in attacks by IronHusky group. Patched by Microsoft on October 12.
BlackBerry and Deloitte join forces to secure IoT software supply chains
Tue, 12th Oct 2021
#
supply chain
#
cybersecurity
#
deloitte
The partnership will address the increasing complexity and growing cybersecurity threats among multi-tiered software supply chains.
90% of malware arriving over encrypted connections, Microsoft threats persist in popularity
Tue, 5th Oct 2021
#
malware
#
firewalls
#
network infrastructure
Over 90% of malware arrived through encrypted connections in Q2 2021, highlighting the need for strong endpoint protection, says WatchGuard.
New cyber-criminal group discovered targeting government servers, fuel, energy and aviation companies
Fri, 1st Oct 2021
#
datacentre infrastructure
#
cybersecurity
#
cybercrime
Researchers have identified a new, previously unknown group that has systematically attacked Russia's fuel and energy complex and its aviation industry.
Security experts weigh in on Microsoft Azure security holes
Wed, 22nd Sep 2021
#
public cloud
#
open source
#
cybersecurity
The vulnerabilities currently putting Azure customers at risk are just the latest in a staggering number of crippling threats in internet software.
HackerOne unveils sweeping product expansion, including vulnerability ranking table
Tue, 21st Sep 2021
#
cybersecurity
#
hacking
#
cybersafety
HackerOne introduces new features for its security intelligence services, including a worldwide top 10 ranking table and CVE Exploitation Index.
Microsoft Azure alert for authentication bypass vulnerability in Linux products
Fri, 17th Sep 2021
#
firewalls
#
network infrastructure
#
network security
A patch is currently available for this vulnerability, however many sysadmins are potentially unaware they have the OMI product installed and are at risk.
.
Patch management, robust password policies vital in reducing risk of cyberattacks
Fri, 17th Sep 2021
#
kaspersky
#
passwords
#
patching
More than half of cyberattacks start with password brute force and vulnerability exploitation, according to new research by Kaspersky.