Security researchers have published technical details and proof-of-concept exploit code for CVE-2022-28219, a critical vulnerability in the Zoho ManageEngine ADAudit Plus tool for monitoring activities in...
Azure Active Directory (Azure AD) now allows admins to issue time-limited passcodes that can be used to register new passwordless authentication methods, during Windows onboarding, or to...
Microsoft is warning that toll fraud malware is one of the most prevalent threats on Android and that it is evolving with features that allow automatic...
https://player.vimeo.com/video/724851593?h=45f7d6f572&badge=0&autopause=0&player_id=0&app_id=58479&dnt=1 In this video for Help Net Security, Scott Sutherland, Senior Director, Adversary Simulation and Infrastructure Testing, NetSPI, discusses how, in order to stay ahead of malicious...
The XFiles info-stealer malware has added a delivery module that exploits CVE-2022-30190, aka Follina, for dropping the payload on target computers. The flaw, discovered as a...
American retailer Walmart has denied being hit with a ransomware attack by the Yanluowang gang after the hackers claimed to encrypt thousands of computers. In a...
https://player.vimeo.com/video/724772047?h=444cc56f8c&badge=0&autopause=0&player_id=0&app_id=58479&dnt=1 In 2021, the demand for data privacy jobs soared with no indication of slowing down and stemming from the proliferation of new government regulations and...
UPDATED OpenSea, the world’s largest non-fungible token (NFT) marketplace, has revealed that a rogue employee at a third-party vendor has shared its users email addresses with an...
A recent attack on a rare-earths processor shows a new facet of information warfare: weaponized NIMBYism. A Chinese disinformation effort against a Pentagon contractor building a...
Google Workspace (formerly G Suite) has been updated to notify admins of highly sensitive changes to configurations, including those made to single sign-on (SSO) profiles and...