News
  • "Despite a Year of Warnings and Patching, Nearly 3 Out of 4 Organizations Still Vulnerable to Log4Shell"
    According to several security experts, the Log4Shell vulnerability will impact organizations for at least a decade. Those concerns appear to be justified, as a new report from Tenable finds that 72 percent of organizations are still vulnerable, even…
  • "JSON-Based SQL Injection Attacks Trigger Need to Update Web Application Firewalls"
    Security researchers have devised a generic SQL injection technique that circumvents multiple Web Application Firewalls (WAFs). WAF vendors have failed to add support for JSON inside SQL statements, allowing potential attackers to easily conceal their…
  • "Stolen Data of 3,000 Irish People Sold on Bot Markets, Study Claims"
    According to the cybersecurity firm NordVPN, at least 5 million people worldwide have had their online data stolen and sold on "bot markets." About 3,000 of those affected are from Ireland, while nearly 46,000 are from the UK. Bot markets are online…
  • "67 Percent of Companies Lose Business Deals Over Security Strategy Concerns"
    According to new LogRhythm research, 67 percent of respondents say their company has lost a business deal due to a customer's lack of trust in their security strategy. Dimensional Research conducted the survey of 1,175 security professionals and…
  • "Cisco Survey Reveals Increased Focus on Cybersecurity Resilience"
    According to a global survey of 4,700 Information Technology (IT) professionals conducted by Cisco, the most common types of incidents were network or data breaches (52 percent), followed by network or system outages (51 percent), ransomware events (47…
  • "Consumers Prioritize Mobile App Security Over Features"
    Researchers at Appdome unveiled the results of a global survey that shares the views of 25,000 consumers in 11 countries on mobile app use and consumer expectations of mobile app security.  The researchers found that more than half (53.5%) of…
  • "Endor Labs Unveils New Research on Impact of Open-Source Software on Supply Chain Security"
    Endor Labs published "The State Of Dependency Management," which provides insight into the widespread but often unmonitored use of existing open-source software in application development, as well as the risks associated with this common practice. The…
  • "Lighting Giant Acuity Brands Discloses Two Data Breaches"
    Lighting and building management giant Acuity Brands has recently publicly disclosed two data breaches it suffered in recent years, including one that may have involved ransomware.  The Atlanta, Georgia-based firm employs roughly 13,000 people and…
  • "Android App With Over 5M Downloads Leaked User Browsing History"
    According to the Cybernews research team, web Explorer - Fast Internet, an Android browsing app, left its Firebase instance open, exposing app and user data. Firebase is a mobile app development platform with numerous analytics, hosting, and real-time…
  • "Supply Chain Web Skimming Attacks Hit Dozens of Sites"
    Security researchers at Jscrambler had recently discovered that a web skimming campaign running for the past year has already compromised over 40 e-commerce sites.  The researchers revealed that "Group X," which exfiltrated card data to a server in…
  • "Google Unearths Internet Explorer Zero-Day Exploited by North Korean Hackers"
    Google's Threat Analysis Group (TAG) discovered a zero-day exploit for an Internet Explorer (IE) vulnerability that was used to target South Korean users. TAG made the discovery in October 2022 and found malware in documents emailed to targets. The…
  • "Apple to Roll Out New Set of Cybersecurity Features for Users"
    Apple has announced plans for new cybersecurity features aimed at helping users protect their data more effectively from hacking. The first feature Apple will include in the update is Advanced Data Protection, which will be made available through iCloud…