π΄ What the AppSec Penetration Test Found π΄
π Read
via "Dark Reading: ".
New data drills down on the types of security misconfigurations and challenges dogging application developers.π Read
via "Dark Reading: ".
Dark Reading
What the AppSec Penetration Test Found
New data drills down on the types of security misconfigurations and challenges dogging application developers.
β Microsoft Patches A Pair of Zero-Days Under Active Attack β
π Read
via "Threatpost".
The software giant also addressed 15 critical flaws and advised on the recently disclosed Linux Kernel "SACK Panic" bug.π Read
via "Threatpost".
Threat Post
Microsoft Patches A Pair of Zero-Days Under Active Attack
The software giant also addressed 15 critical flaws and advised on the recently disclosed Linux Kernel "SACK Panic" bug.
ATENTIONβΌ New - CVE-2018-11427 (oncell_g3150-hspa-t_firmware, oncell_g3150-hspa_firmware)
π Read
via "National Vulnerability Database".
CSRF tokens are not used in the web application of Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior, which makes it possible to perform CSRF attacks on the device administrator.π Read
via "National Vulnerability Database".
π΄ Microsoft Patches Zero-Day Vulnerabilities Under Active Attack π΄
π Read
via "Dark Reading: ".
Microsoft issued fixes for 77 unique vulnerabilities this Patch Tuesday, including two zero-day privilege escalation vulnerabilities seen exploited in the wild.π Read
via "Dark Reading: ".
Dark Reading
Cyber Risk recent news | Dark Reading
Explore the latest news and expert commentary on Cyber Risk, brought to you by the editors of Dark Reading
π΄ Zoom Client for Mac Exposing Users to Serious Risks π΄
π Read
via "Dark Reading: ".
Videoconferencing software maker downplays risks and says mitigations are on the way.π Read
via "Dark Reading: ".
Dark Reading
Cyberattacks & Data Breaches recent news | Dark Reading
Explore the latest news and expert commentary on Cyberattacks & Data Breaches, brought to you by the editors of Dark Reading
π΄ Coast Guard Warns Shipping Firms of Maritime Cyberattacks π΄
π Read
via "Dark Reading: ".
A commercial vessel suffered a significant malware attack in February, prompting the US Coast Guard to issues an advisory to all shipping companies: Here be malware.π Read
via "Dark Reading: ".
Darkreading
Coast Guard Warns Shipping Firms of Maritime Cyberattacks
A commercial vessel suffered a significant malware attack in February, prompting the US Coast Guard to issues an advisory to all shipping companies: Here be malware.
π΄ Financial Impact of Cybercrime Exceeded $45B in 2018 π΄
π Read
via "Dark Reading: ".
Cybersecurity analysts explore a range of industry research to examine trends around cyber incidents and their financial impact.π Read
via "Dark Reading: ".
Dark Reading
Financial Impact of Cybercrime Exceeded $45B in 2018
Cybersecurity analysts explore a range of industry research to examine trends around cyber incidents and their financial impact.
π΄ Organizations Are Adapting Authentication for Cloud Applications π΄
π Read
via "Dark Reading: ".
Companies see the changing demands of cloud identity management but are mixed in their responses to those demands.π Read
via "Dark Reading: ".
Dark Reading
Organizations Are Adapting Authentication for Cloud Applications
Companies see the changing demands of cloud identity management but are mixed in their responses to those demands.
β Intel Patches High-Severity Flaw in Processor Diagnostic Tool β
π Read
via "Threatpost".
Intel issued patches for a high-severity flaw in its processor diagnostic tool as well as a fix for a medium-severity vulnerability in its data center SSD lineup.π Read
via "Threatpost".
Threat Post
Intel Patches High-Severity Flaw in Processor Diagnostic Tool
Intel issued patches for a high-severity flaw in its processor diagnostic tool as well as a fix for a medium-severity vulnerability in its data center SSD lineup.
β Instagram asks bullies, βAre you sure you want to say that?β β
π Read
via "Naked Security".
A new anti-bullying feature uses AI to recognize mean words in comments and warns users before they post them.π Read
via "Naked Security".
Naked Security
Instagram asks bullies, βAre you sure you want to say that?β
A new anti-bullying feature uses AI to recognize mean words in comments and warns users before they post them.
β Rogue Android apps ignore your permissions β
π Read
via "Naked Security".
New research has revealed that apps are snooping on data such as location and unique ID number - even when users haven't given permission.π Read
via "Naked Security".
Naked Security
Rogue Android apps ignore your permissions
New research has revealed that apps are snooping on data such as location and unique ID number β even when users havenβt given permission.
β Two zero days and 15 critical flaws fixed in Julyβs Patch Tuesday β
π Read
via "Naked Security".
Patch Tuesday July 2019 offers fixes for a total of 77 vulnerabilities, including 15 marked critical, rounded out by two zero-day flaws.π Read
via "Naked Security".
Sophos News
Naked Security β Sophos News
π Corporate users struggle to identify phishing attacks, other security threats π
π Read
via "Security on TechRepublic".
An audit of security awareness conducted by Proofpoint found that users on average answered 22% of security-related questions incorrectly.π Read
via "Security on TechRepublic".
TechRepublic
Corporate users struggle to identify phishing attacks, other security threats
An audit of security awareness conducted by Proofpoint found that users on average answered 22% of security-related questions incorrectly.
π΄ 10 Ways to Keep a Rogue RasPi From Wrecking Your Network π΄
π Read
via "Dark Reading: ".
A Raspberry Pi attached to the network at NASA JPL became the doorway for a massive intrusion and subsequent data loss. Here's how to keep the same thing from happening to your network.π Read
via "Dark Reading: ".
Dark Reading
10 Ways to Keep a Rogue RasPi From Wrecking Your Network
A Raspberry Pi attached to the network at NASA JPL became the doorway for a massive intrusion and subsequent data loss. Here's how to keep the same thing from happening to your network.
β Agent Smith Malware Infects 25M Android Phones to Push Rogue Ads β
π Read
via "Threatpost".
Researchers say malware infects phones in order to sneak ads on devices for profit.π Read
via "Threatpost".
Threat Post
Agent Smith Malware Infects 25M Android Phones to Push Rogue Ads
Researchers say malware infects phones in order to sneak ads on devices for profit.
π΄ 4 Reasons Why SOC Superstars Quit π΄
π Read
via "Dark Reading: ".
Security analysts know they are a hot commodity in the enviable position of writing their own ticket. Here's how to keep them engaged, challenged, and happy.π Read
via "Dark Reading: ".
Dark Reading
4 Reasons Why SOC Superstars Quit
Security analysts know they are a hot commodity in the enviable position of writing their own ticket. Here's how to keep them engaged, challenged, and happy.
ATENTIONβΌ New - CVE-2018-12626
π Read
via "National Vulnerability Database".
An issue was discovered in Eventum 3.5.0. /htdocs/popup.php has XSS via the cat parameter.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2018-12625
π Read
via "National Vulnerability Database".
An issue was discovered in Eventum 3.5.0. /htdocs/validate.php has XSS via the values parameter.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2018-12623
π Read
via "National Vulnerability Database".
An issue was discovered in Eventum 3.5.0. htdocs/switch.php has XSS via the current_page parameter.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2018-12622
π Read
via "National Vulnerability Database".
An issue was discovered in Eventum 3.5.0. htdocs/ajax/update.php has XSS via the field_name parameter.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2018-11423 (oncell_g3150-hspa-t_firmware, oncell_g3150-hspa_firmware)
π Read
via "National Vulnerability Database".
There is Memory corruption in the web interface Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior, different vulnerability than CVE-2018-11420.π Read
via "National Vulnerability Database".