This week’s cybersecurity landscape highlights how familiar systems can become powerful tools in the wrong hands. From zero-click smartphone exploits...
Version 3.0.7 of the popular OpenSSL cryptographic library is out, with fixes for CVE-2022-3602 and CVE-2022-3786, two high-severity buffer overflow vulnerabilities in the punycode decoder that...
Analysts at Orca Security have found a critical vulnerability affecting Azure Cosmos DB that allowed unauthenticated read and write access to containers. Named CosMiss, the security...
Users often create weak and easily guessed passwords they reuse across systems and websites. As a result, traditional passwords are often the weakest link in the...
Threat actors are using newly discovered spyware known as SandStrike and delivered via a malicious VPN application to target Android users. They focus on Persian-speaking practitioners...
The OpenSSL Project has patched two high-severity security flaws in its open-source cryptographic library used to encrypt communication channels and HTTPS connections. The vulnerabilities (CVE-2022-3602 and CVE-2022-3786) affect OpenSSL...
A set of four malicious applications currently available in Google Play, the official store for the Android system, are directing users sites that steal sensitive information...
Dropbox disclosed a security breach after threat actors stole 130 code repositories after gaining access to one of its GitHub accounts using employee credentials stolen in...
A Government Accountability Office report found that the Department of Veterans Affairs lacks sufficient data on its VET TEC pilot to “assess the effectiveness of the...
The agency has promised to measure the success of efforts to steer major software providers toward the inclusion of logging and other basic security features in...
The analyzed ransomware variants—from July to December 2021—amounted to millions of dollars in damages. A new analysis from the Department of Justice’s Financial Crimes Enforcement Network reveals that...
Recent Comments