Category: Uncategorized
-
GitHub Paid Out $1.5 Million in Bug Bounties in 2022 Ionut Arghire
GitHub says it paid out more than $1.5 million in bug bounties for 364 vulnerabilities in 2022, reaching a total of nearly $4 million since 2016. The post GitHub Paid Out $1.5 Million in Bug Bounties in 2022 appeared first on SecurityWeek. Read More
-

Guide: How Google Workspace-based Organizations can leverage Chrome to improve Security [email protected] (The Hacker News)
More and more organizations are choosing Google Workspace as their default employee toolset of choice. But despite the productivity advantages, this organizational action also incurs a new security debt. Security teams now have to find a way to adjust their security architecture to this new cloud workload. Some teams may rely on their existing network…
-

Google Introduces First Quantum Resilient FIDO2 Security Key [email protected] (The Hacker News)
Google on Tuesday announced the first quantum resilient FIDO2 security key implementation as part of its OpenSK security keys initiative. “This open-source hardware optimized implementation uses a novel ECC/Dilithium hybrid signature schema that benefits from the security of ECC against standard attacks and Dilithium’s resilience against quantum attacks,” Elie Bursztein and Fabian Kaczmarczyck Read More
-

Critical Security Flaws Affect Ivanti Avalanche, Threatening 30,000 Organizations [email protected] (The Hacker News)
Multiple critical security flaws have been reported in Ivanti Avalanche, an enterprise mobile device management solution that’s used by 30,000 organizations. The vulnerabilities, collectively tracked as CVE-2023-32560 (CVSS score: 9.8), are stack-based buffer overflows in Ivanti Avalanche WLAvanacheServer.exe v6.4.0.0. Cybersecurity company Tenable said the shortcomings are the result of bufferRead More
-
Chrome 116 Patches 26 Vulnerabilities Ionut Arghire
Google has released Chrome 116 with patches for 26 vulnerabilities and plans to ship weekly security updates for the popular web browser. The post Chrome 116 Patches 26 Vulnerabilities appeared first on SecurityWeek. Read More
-
Top 12 risk management skills and why you need them
Post ContentRead More
-

Nearly 2,000 Citrix NetScaler Instances Hacked via Critical Vulnerability [email protected] (The Hacker News)
Nearly 2,000 Citrix NetScaler instances have been compromised with a backdoor by weaponizing a recently disclosed critical security vulnerability as part of a large-scale attack. “An adversary appears to have exploited CVE-2023-3519 in an automated fashion, placing web shells on vulnerable NetScalers to gain persistent access,” NCC Group said in an advisory released Tuesday. “The adversary canRead…
-

Cybercriminals Abusing Cloudflare R2 for Hosting Phishing Pages, Experts Warn [email protected] (The Hacker News)
Threat actors’ use of Cloudflare R2 to host phishing pages has witnessed a 61-fold increase over the past six months. “The majority of the phishing campaigns target Microsoft login credentials, although there are some pages targeting Adobe, Dropbox, and other cloud apps,” Netskope security researcher Jan Michael said. Cloudflare R2, analogous to Amazon Web Service S3,…
-

Multiple Flaws Found in ScrutisWeb Software Exposes ATMs to Remote Hacking [email protected] (The Hacker News)
Four security vulnerabilities in the ScrutisWeb ATM fleet monitoring software made by Iagona could be exploited to remotely break into ATMs, upload arbitrary files, and even reboot the terminals. The shortcomings were discovered by the Synack Red Team (SRT) following a client engagement. The issues have been addressed in ScrutisWeb version 2.1.38. “Successful exploitation of theseRead More
-
Top Routinely Exploited Vulnerabilities 2022
The joint cybersecurity advisory provides details on the Common Vulnerabilities and Exposures (CVEs) routinely and frequently exploited by malicious cyber actors in 2022. According to the report, malicious cyber actors exploited older software vulnerabilities more frequently than recently disclosed vulnerabilities and targeted unpatched, internet-facing systems.Read More
