News
-
"GitHub Patches Critical Vulnerability in Enterprise Server"Code hosting platform GitHub has recently released patches for a critical severity vulnerability in the GitHub Enterprise Server that could lead to unauthorized access to affected instances.
-
"Critical Vulnerability Patched in 101 Releases of WordPress Plugin Jetpack"Automattic recently announced patches for 101 versions of the popular WordPress security plugin Jetpack to resolve a critical severity vulnerability introduced in 2016.
-
"Splunk Enterprise Update Patches Remote Code Execution Vulnerabilities"Splunk recently announced fixes for 11 vulnerabilities in Splunk Enterprise, two of which are high-severity bugs leading to remote code execution on Windows systems.
-
"Skills Shortages Now a Top-Two Security Risk for SMBs"According to a new study by Sophos, a shortage of cybersecurity expertise and capacity in global SMBs is fueling talent burnout and creating new opportunities for threat actors.
-
"Eight Million Users Install 200+ Malicious Apps from Google Play"Between June 2023 and April 2024, security researchers at Zscaler discovered over 200 malicious apps on Google Play, which is nominally a safer platform for Android downloads than third-party app stores.
-
"Supply Chain Attacks Can Exploit Entry Points in Python, npm, and Open Source Ecosystems"Researchers at Checkmarx have discovered that threat actors could abuse entry points across PyPI, npm, Ruby Gems, and other programming ecosystems to stage software supply chain attacks.
-
"Georgia Tech's New Tool Can Detect Malware on Android Phones"Researchers at the Georgia Institute of Technology (Georgia Tech) have developed a new tool named "Detector of Victim-specific Accessibility" (DVa) to check for malware on Android phones.
-
"Juniper Networks Patches Dozens of Vulnerabilities"Juniper Networks has recently released patches for dozens of vulnerabilities in its Junos OS and Junos OS Evolved network operating systems, including multiple flaws in several third-party software components.
-
"Gryphon Healthcare, Tri-City Medical Center Disclose Significant Data Breaches"Gryphon Healthcare and Tri-City Medical Center recently disclosed separate data breaches in which the personal information of more than 500,000 individuals was stolen.
-
"OpenAI Confirms Threat Actors Use ChatGPT to Write Malware"OpenAI disrupted over 20 malicious cyber operations involving ChatGPT, its Artificial Intelligence (AI)-driven chatbot. Threat actors have used ChatGPT to develop malware, evade detection, and more.
-
"US DOD Tightens Cybersecurity Standards for Defense Contractors"The finalization of the latest version of the Cybersecurity Maturity Model Certification (CMMC) program empowers US Department of Defense (DOD) officials to better assess cybersecurity measures implemented by defense contractors.
-
"Cyber Insurer Says Ransomware Attacks Drove a Spike in Claim Sizes"The cyber insurance provider Coalition reported that its customers made fewer claims in the first half of 2024 than in the same period in 2023, but their average loss increased by 14 percent to $122,000.