Security

GUAC – A Google Open Source Project to secure software supply chain

Google launched the Graph for the Understanding Artifact Composition (GUAC) project, to secure the software supply chain. Google this week launched a…

3 years ago

BlueBleed: Microsoft confirmed data leak exposing customers’ info

Microsoft disclosed a data leak, sensitive data of some of its customers were exposed by a misconfigured Microsoft server accessible…

3 years ago

Internet disruptions observed as Russia targets critical infrastructure in Ukraine

While the Russian army is conducting coordinated missile and drone strikes in Ukraine experts observed Internet disruptions in the country.…

3 years ago

Brazilian police arrested a man suspected of being a member of LAPSUS$ gang

The Federal Police of Brazil arrested an individual who is suspected of being a member of the notorious LAPSUS$ extortionist…

3 years ago

Experts discovered millions of .git folders exposed to public

Nearly two million .git folders containing vital project information are exposed to the public, the Cybernews research team found. Original…

3 years ago

Text4Shell, a remote code execution bug in Apache Commons Text library

Researcher discovered a remote code execution vulnerability in the open-source Apache Commons Text library. GitHub's threat analyst Alvaro Munoz discovered a remote…

3 years ago

Researchers share of FabriXss bug impacting Azure Fabric Explorer

Cybersecurity researchers published technical details about a now-patched FabriXss flaw that impacts Azure Fabric Explorer. Orca Security researchers have released technical…

3 years ago

Microsoft Office 365 Message Encryption (OME) doesn’t ensure confidentiality

A bug in the message encryption mechanism used by Microsoft in Office 365 can allow to access the contents of the…

3 years ago

China-linked APT41 group targets Hong Kong with Spyder Loader

China-linked threat actors APT41 (a.k.a. Winnti) targeted organizations in Hong Kong, in some cases remaining undetected for a year. Symantec…

3 years ago

Over 17000 Fortinet devices exposed online are very likely vulnerable to CVE-2022-40684

Fortinet confirmed that many systems are still vulnerable to attacks exploiting the CVE-2022-40684 zero-day vulnerability. Fortinet is urging customers to address…

3 years ago

This website uses cookies.