A researcher has gone public with details about a recently resolved flaw in Acronis cloud management console
28
Dec
2022

CSS injection flaw patched in Acronis cloud management console

CSRF attacks could be triggered to access and exfiltrate information A security researcher has disclosed a CSS injection flaw in…

A security researcher earned a bug bounty payout for a Google Pixel lock screen bypass vulnerability
28
Dec
2022

Google Pixel screen-lock hack earns researcher $70k

John Leyden 10 November 2022 at 16:14 UTC Updated: 11 November 2022 at 11:23 UTC Android security pwned by PUK…

Malicious Excel Add-ins
28
Dec
2022

APT Hackers Turn to Malicious Excel Add-ins as Initial Intrusion Vector

Dec 28, 2022Ravie LakshmananMalware / Windows Security Microsoft’s decision to block Visual Basic for Applications (VBA) macros by default for…

Researchers discovered a series of web security flaws in the REST API of popular web hosting admin tool Plesk
28
Dec
2022

CSRF in Plesk API enabled server takeover

Ben Dickson 11 November 2022 at 11:31 UTC Updated: 11 November 2022 at 16:51 UTC Bugs in programming interfaces of…

Google wants its Gmail users to take these security steps in 2023
28
Dec
2022

Google wants its Gmail users to take these security steps in 2023

Google, the much-used search engine across the world, has disclosed some security steps to its Gmail users to stay cyber…

Prototype pollution project yields another Parse Server RCE
28
Dec
2022

Prototype pollution project yields another Parse Server RCE

Adam Bannister 11 November 2022 at 15:37 UTC Updated: 02 December 2022 at 11:49 UTC Bug emerges from ambition to…

Black Basta Ransomware hits two electric utilities in America
28
Dec
2022

Black Basta Ransomware hits two electric utilities in America

Black Basta Ransomware Group has reportedly hit two electric utilities in North America in October this year and the attack…

Linux Kernel Use-After-Free RCE
28
Dec
2022

Linux Kernel Use-After-Free RCE Vulnerability

An emergency security patch was released by Linux recently to fix a kernel-level security critical severity vulnerability.  This vulnerability has…

rrr
28
Dec
2022

All Day DevOps: Third of Log4j downloads still pull vulnerable version despite threat of supply chain attacks

Adam Bannister 14 November 2022 at 16:16 UTC Updated: 24 November 2022 at 12:50 UTC AppSec engineer keynote says Log4j…

Ookla Commends the Communications Regulatory Authority of Qatar for Efforts to Help Improve User Experience During FIFA World Cup™
28
Dec
2022

Ookla Commends the Communications Regulatory Authority of Qatar for Efforts to Help Improve User Experience During FIFA World Cup™

[ This article was originally published here ] SEATTLE–()–®, an internationally recognized leader in network measurement and connectivity intelligence, commends…

28
Dec
2022

3 important changes in how data will be used and treated

Regula has presented their vision of the developments that will shape the industry’s landscape in 2023. Deepfakes, new cyber-hygiene norms,…

Mastodon users vulnerable to password-stealing attacks
28
Dec
2022

Mastodon users vulnerable to password-stealing attacks

Jessica Haworth 15 November 2022 at 15:39 UTC Updated: 15 November 2022 at 15:47 UTC Patched bug could have leaked…