Data breach and privacy incidents occur daily at organizations of all sizes. Just recently, hackers broke into a water treatment facility in Florida, gaining access to an...
Despite the vaccine rollout, it seems unlikely that things will ever return to the way they were before the pandemic. A recent PWC survey found that 78% of...
A software supply chain attack—such as the recent SolarWinds Orion attack—occurs when a cyber threat actor infiltrates a software vendor’s network and employs malicious code to...
A security incident at online marketplace Reverb has exposed the personal data of users. Reverb, which connects buyers and sellers of secondhand musical instruments, urged users to reset...
A newly developed plugin allows security analysts and researchers to interact with the Mitre ATT&CK framework without leaving their Visual Studio Code (VSCode) environments. VSCode-ATT&CK, an extension for...
Embedthis has patched a null byte injection vulnerability in GoAhead, the embedded web server deployed in hundreds of millions of devices. “A specially crafted URL with a %00 character embedded...
An XML External Entity (XXE) injection bug in WordPress could allow attackers to remotely steal a victim’s files, researchers have revealed. Security researchers at SonarSource who discovered the...
Kaspersky recently conducted a study based on anonymized OS metadata provided by consenting Kaspersky Security Network users. The survey found that almost one quarter (22%) of PC...
Microsoft Edge will automatically redirect users to a secure HTTPS connection when visiting websites using the HTTP protocol, starting with version 92, coming in late July. By...
Millions of email addresses collected by Emotet botnet for malware distribution campaigns have been shared by the Federal Bureau of Investigation (FBI) as part of the...