Category: Uncategorized
-

TETRA:BURST — 5 New Vulnerabilities Exposed in Widely Used Radio Communication System [email protected] (The Hacker News)
A set of five security vulnerabilities have been disclosed in the Terrestrial Trunked Radio (TETRA) standard for radio communication used widely by government entities and critical infrastructure sectors, including what’s believed to be an intentional backdoor that could have potentially exposed sensitive information. The issues, discovered by Midnight Blue in 2021 and held back until…
-

How MDR Helps Solve the Cybersecurity Talent Gap [email protected] (The Hacker News)
How do you overcome today’s talent gap in cybersecurity? This is a crucial issue — particularly when you find executive leadership or the board asking pointed questions about your security team’s ability to defend the organization against new and current threats. This is why many security leaders find themselves turning to managed security services like…
-

Zenbleed: New Flaw in AMD Zen 2 Processors Puts Encryption Keys and Passwords at Risk [email protected] (The Hacker News)
A new security vulnerability has been discovered in AMD’s Zen 2 architecture-based processors that could be exploited to extract sensitive data such as encryption keys and passwords. Discovered by Google Project Zero researcher Tavis Ormandy, the flaw – codenamed Zenbleed and tracked as CVE-2023-20593 (CVSS score: 6.5) – allows data exfiltration at the rate of 30 kb per core,…
-
Ivanti Zero-Day Vulnerability Exploited in Attack on Norwegian Government Eduard Kovacs
An Ivanti EPMM product zero-day vulnerability tracked as CVE-2023-35078 has been exploited in an attack aimed at the Norwegian government. The post Ivanti Zero-Day Vulnerability Exploited in Attack on Norwegian Government appeared first on SecurityWeek. Read More
-

Atlassian Releases Patches for Critical Flaws in Confluence and Bamboo [email protected] (The Hacker News)
Atlassian has released updates to address three security flaws impacting its Confluence Server, Data Center, and Bamboo Data Center products that, if successfully exploited, could result in remote code execution on susceptible systems. The list of the flaws is below – CVE-2023-22505 (CVSS score: 8.0) – RCE (Remote Code Execution) in Confluence Data Center and Server (Fixed in…
-

Ivanti Releases Urgent Patch for EPMM Zero-Day Vulnerability Under Active Exploitation [email protected] (The Hacker News)
Ivanti is warning users to update their Endpoint Manager Mobile (EPMM) mobile device management software (formerly MobileIron Core) to the latest version that fixes an actively exploited zero-day vulnerability. Dubbed CVE-2023-35078, the issue has been described as a remote unauthenticated API access vulnerability that impacts currently supported version 11.4 releases 11.10, 11.9, and 11.8 asRead More
-

Apple Rolls Out Urgent Patches for Zero-Day Flaws Impacting iPhones, iPads and Macs [email protected] (The Hacker News)
Apple has rolled out security updates to iOS, iPadOS, macOS, tvOS, watchOS, and Safari to address several security vulnerabilities, including one actively exploited zero-day bug in the wild. Tracked as CVE-2023-38606, the shortcoming resides in the kernel and permits a malicious app to modify sensitive kernel state potentially. The company said it was addressed with improved state management.…
-
Apple Patches Another Kernel Flaw Exploited in ‘Operation Triangulation’ Attacks Ryan Naraine
Apple patches another zero-day flaw used in the ‘Operation Triangulation’ exploit chain. iOS and macOS-powered devices are affected. The post Apple Patches Another Kernel Flaw Exploited in ‘Operation Triangulation’ Attacks appeared first on SecurityWeek. Read More
-
Nubeva’s Ransomware Key Interception and Decryption Technology Validated in Third-Party Lab Kevin Townsend
100% key capture rate and successful ransomware decryption shows progress in ransomware defense capabilities. The post Nubeva’s Ransomware Key Interception and Decryption Technology Validated in Third-Party Lab appeared first on SecurityWeek. Read More
-
Coveware: Rate of victims paying ransom continues to plummet
Post ContentRead More
