Windows 10 Installer
27
Dec
2022

Trojanized Windows 10 Installer Used in Cyberattacks Against Ukrainian Government Entities

Government entities in Ukraine have been breached as part of a new campaign that leveraged trojanized versions of Windows 10…

BetMGM
27
Dec
2022

Leading sports betting firm BetMGM discloses data breach

Leading sports betting company BetMGM disclosed a data breach after a threat actor stole personal information belonging to an undisclosed…

Go SAML library vulnerable to authentication bypass
27
Dec
2022

Go SAML library vulnerable to authentication bypass

An attacker could masquerade as an authenticated user without presenting credentials An open source Go implementation of the SAML protocol…

27
Dec
2022

Apple Expands End-to-End Encryption to iCloud Backups

Apple announced today that it is launching expanded end-to-end encryption protections in its iCloud service. The company already offers the…

Hackers Deploy New Information Stealer
27
Dec
2022

Hackers Deploy New Information Stealer Malware

Researchers at Phylum recently discovered that hackers had been injecting information stealer malware into Python developers’ machines in order to…

27
Dec
2022

Samba Issues Security Updates to Patch Multiple High-Severity Vulnerabilities

Samba has released software updates to remediate multiple vulnerabilities that, if successfully exploited, could allow an attacker to take control…

27
Dec
2022

Apple Kills Its Plan to Scan Your Photos for CSAM. Here’s What’s Next

In August 2021, Apple announced a plan to scan photos that users stored in iCloud for child sexual abuse material…

AttackIQ Named Winner of Virtually Testing Foundation’s Most Engaged Community Partner Award
27
Dec
2022

AttackIQ Named Winner of Virtually Testing Foundation’s Most Engaged Community Partner Award

[ This article was originally published here ] SANTA CLARA, Calif.–()–®, the leading independent vendor of Breach and Attack Simulation…

27
Dec
2022

Modern technology and cyber recovery will intersect in the next generation of attacks

As technology continues to evolve for business and personal use, cybercriminals are also leveraging innovation in the next generation of…

gmail Client-Side Encryption
27
Dec
2022

Google Takes Gmail Security to the Next Level with Client-Side Encryption

Dec 18, 2022Ravie LakshmananEncryption / Email Security Google on Friday announced that its client-side encryption for Gmail is in beta…

Ghost CMS logo over a ghostly figure
27
Dec
2022

Ghost CMS vulnerable to critical authentication bypass flaw

A critical vulnerability in the Ghost CMS newsletter subscription system could allow external users to create newsletters or modify existing…

Deserialized web security roundup - Algolia API key leak, GitHub CVE reporting, scoring CVSS scores
27
Dec
2022

Deserialized web security roundup: Algolia API key leak, GitHub CVE reporting, scoring CVSS scores

Adam Bannister 02 December 2022 at 17:19 UTC Updated: 19 December 2022 at 17:12 UTC Your fortnightly rundown of AppSec…