-
"Google Shells Out $600,000 for OSS-Fuzz Project Integrations"Google recently announced an extension to its OSS-Fuzz rewards program, an initiative meant to reward contributors for integrating projects into OSS-Fuzz. Launched in 2016, OSS-Fuzz is intended to help identify vulnerabilities in open source…
-
"HPE, NetApp Warn of Critical Open-Source Bug"Hewlett Packard Enterprise (HPE) has issued an alert regarding its OneView infrastructure management platform, warning of a use-after-free vulnerability that enables remote attackers to execute arbitrary code on targeted systems, leak data, and more. The…
-
"Experts Warn of Two Flaws in Popular Open-Source Software ImageMagick"Researchers at Metabase Q found two security flaws in the open-source image manipulation software ImageMagick that could lead to information exposure or a Denial-of-Service (DoS) condition. ImageMagick is a free, open-source software suite for displaying…
-
"Scammers Managed to Slip Crypto Apps Onto Apple, Google App Stores"According to a new report by Sophos, scammers were able to get two fraudulent apps onto both Google's Play Store and Apple's App Store, allowing them to persuade users into making fake cryptocurrency investments. Sophos researchers found Ace Pro and…
-
"Number of New Common Vulnerabilities and Exposures (CVEs) Expected to Increase in 2023"The cyber insurance company Coalition predicts that in 2023, there will be more than 1,900 new Common Vulnerabilities and Exposures (CVEs) every month, including 270 high-severity and 155 critical-severity vulnerabilities, a 13 percent rise from 2022.…
-
"Andersen Corporation Leaks Customer Home Photos and Addresses"The Cybernews research team found an unprotected Azure storage blob holding around one million files belonging to Renewal by Andersen, a subsidiary of the international Andersen Corporation, on January 18, 2023. Andersen Corporation is the largest maker…
-
"Experts Warn of 'Ice Breaker' Cyberattacks Targeting Gaming and Gambling Industry"Since at least September 2022, a new attack campaign has been targeting the gaming and gambling industries. The cybersecurity firm Security Joes is monitoring the activity cluster named "Ice Breaker," saying that the attacks use social engineering…
-
HoTSoS 2023: Registration Open March 7th!HoTSoS 2023: Registration Open March 7th! The Hot Topics in the Science of Security (HoTSoS) Symposium is a research event centered on the Science of Security, which aims to address the fundamental problems of security in a principled manner.…
-
"New HeadCrab Malware Infects 1,200 Redis Servers to Mine Monero"Since September 2021, new stealthy malware dubbed HeadCrab has infected over 1,000 vulnerable Redis servers in order to form a botnet that mines the Monero cryptocurrency. The malware, discovered by Aqua Security researchers, has infected at least 1,200…
-
"Vulnerability in Cisco Industrial Appliances Is a Potential Nightmare"Some of Cisco's industrial routers, gateways, and enterprise wireless access points were discovered to contain a high-severity vulnerability, tracked as CVE-2023-20076. This now-patched vulnerability could be used to inject malicious code that cannot be…
-
"Lazarus Group Rises Again, to Gather Intelligence on Energy, Healthcare Firms"The North Korean Lazarus Group launched a cyberattack campaign against medical research and energy organizations for espionage purposes. The attribution was made by threat intelligence analysts at WithSecure, who uncovered the campaign while…
-
"City of London on High Alert After Ransomware Attack"A suspected ransomware attack on a key supplier of trading software to the City of London this week appears to have disrupted activity in the derivatives market. Ion Cleared Derivatives released a brief statement on Tuesday saying that it…
News