Latest Cybersecurity News and Articles


How MDR Helps Solve the Cybersecurity Talent Gap

25 July 2023
How do you overcome today's talent gap in cybersecurity? This is a crucial issue — particularly when you find executive leadership or the board asking pointed questions about your security team's ability to defend the organization against new and current threats. This is why many security leaders find themselves turning to managed security services like MDR (managed detection and response),

Zenbleed: New Flaw in AMD Zen 2 Processors Puts Encryption Keys and Passwords at Risk

25 July 2023
A new security vulnerability has been discovered in AMD's Zen 2 architecture-based processors that could be exploited to extract sensitive data such as encryption keys and passwords. Discovered by Google Project Zero researcher Tavis Ormandy, the flaw – codenamed Zenbleed and tracked as CVE-2023-20593 (CVSS score: 6.5) – allows data exfiltration at the rate of 30 kb per core, per second. The

Onetrust Hauls in Another $150 Million on a $4.5 Billion Down Round Valuation

25 July 2023
The round was led by Generation Investment Management, which is former vice president Al Gore’s firm, with participation from existing investor Sands Capital. OneTrust CEO Kabir Barday says that the company has been executing since its last round.

Ivanti Patches Mobileiron Zero-Day Bug Exploited in Attacks

25 July 2023
The patches can be installed by upgrading to EPMM 11.8.1.1, 11.9.1.1, and 11.10.0.2. They also target unsupported and end-of-life software versions lower than 11.8.1.0 (e.g., 11.7.0.0, 11.5.0.0)

Apple Rolls Out Urgent Patches for Zero-Day Flaws Impacting iPhones, iPads and Macs

25 July 2023
Tracked as CVE-2023-38606, the shortcoming resides in the kernel and permits a malicious app to modify sensitive kernel state potentially. The company said it was addressed with improved state management.

Atlassian Releases Patches for Critical Flaws in Confluence and Bamboo

25 July 2023
Atlassian has released updates to address three security flaws impacting its Confluence Server, Data Center, and Bamboo Data Center products that, if successfully exploited, could result in remote code execution on susceptible systems. The list of the flaws is below - CVE-2023-22505 (CVSS score: 8.0) - RCE (Remote Code Execution) in Confluence Data Center and Server (Fixed in versions 8.3.2 and

Ivanti Releases Urgent Patch for EPMM Zero-Day Vulnerability Under Active Exploitation

24 July 2023
Ivanti is warning users to update their Endpoint Manager Mobile (EPMM) mobile device management software (formerly MobileIron Core) to the latest version that fixes an actively exploited zero-day vulnerability. Dubbed CVE-2023-35078, the issue has been described as a remote unauthenticated API access vulnerability that impacts currently supported version 11.4 releases 11.10, 11.9, and 11.8 as

Apple Rolls Out Urgent Patches for Zero-Day Flaws Impacting iPhones, iPads and Macs

24 July 2023
Apple has rolled out security updates to iOS, iPadOS, macOS, tvOS, watchOS, and Safari to address several security vulnerabilities, including one actively exploited zero-day bug in the wild. Tracked as CVE-2023-38606, the shortcoming resides in the kernel and permits a malicious app to modify sensitive kernel state potentially. The company said it was addressed with improved state management. "

70% financial services, insurance companies suffer API security delays

24 July 2023
A new report reveals nearly 70% of financial services and insurance companies have suffered rollout delays due to API security.

Atlassian Patches Remote Code Execution Vulnerabilities in Confluence, Bamboo

24 July 2023
The most severe of these issues, tracked as CVE-2023-22508 (CVSS score of 8.5), was introduced in Confluence version 7.4.0. The second bug, tracked as CVE-2023-22505 (CVSS score of 8.0), was introduced in Confluence version 8.0.0.

Lazarus Targets Windows IIS Web Servers for Malware Distribution

24 July 2023
ASEC discovered that the North Korean state-sponsored Lazarus APT group is attacking Windows Internet Information Service (IIS) web servers and using them to distribute malware. It is imperative for organizations to adopt stringent measures, including attack surface management, to identify exposed assets and continuously apply the latest security patches.

Over 20,000 Citrix Appliances Vulnerable to New Exploit

24 July 2023
A new exploit technique targeting a recent Citrix Application Delivery Controller (ADC) and Gateway vulnerability can be used against thousands of unpatched devices, cybersecurity firm Bishop Fox claims.

Home affairs cyber survey exposed personal data of participating firms

24 July 2023
Home affairs cyber survey exposed personal data of participating firms Minister admits leak of ‘sensitive’ information after research into the Optus and Medibank hacks was ‘deeply ironic’Get our morning and afternoon news emails, free app or daily news podcastThe home affairs department exposed the personal information of more than 50 small business survey participants who were sought for their views on cybersecurity, Guardian Australia can reveal.The names, business names, phone numbers and emails of the participants in the survey were published on the parliament website in response to a question on notice from May’s Budget estimates hearing. Continue reading...

Banking Sector Witnesses First-Ever OSS Supply Chain Attack

24 July 2023
For the first time, the banking sector has been explicitly targeted by two distinct Open-Source Software (OSS) supply chain attacks that enabled attackers to stealthily overlay the banking sites. Organizations must equip themselves with the best early threat alerting and sharing platforms that can enable them to promptly identify the risks and perform threat assessment in real-time.

Critical Zero-Days in Atera Windows Installers Expose Users to Privilege Escalation Attacks

24 July 2023
The flaws, discovered by Mandiant on February 28, have been assigned the identifiers CVE-2023-26077 and CVE-2023-26078, with the issues remediated in versions 1.8.3.7 and 1.8.4.9 released by Atera on April 17, and June 26, respectively.

Report: US and UK executives grapple with evolving data privacy laws

24 July 2023
As global data privacy compliance increases in scope and complexity, only about half of executives feel “very prepared” to meet regulatory requirements in the United States, United Kingdom and European Union. 

Norwegian Government Security and Service Organisation Hit by Cyberattack

24 July 2023
Twelve Norwegian government ministries have been hit by a cyberattack, the Norwegian government said on Monday, the latest attack to hit the public sector of Europe's largest gas supplier and NATO's northernmost member.

Critical Zero-Days in Atera Windows Installers Expose Users to Privilege Escalation Attacks

24 July 2023
Zero-day vulnerabilities in Windows Installers for the Atera remote monitoring and management software could act as a springboard to launch privilege escalation attacks. The flaws, discovered by Mandiant on February 28, 2023, have been assigned the identifiers CVE-2023-26077 and CVE-2023-26078, with the issues remediated in versions 1.8.3.7 and 1.8.4.9 released by Atera on April 17, 2023, and

New OpenSSH Vulnerability Exposes Linux Systems to Remote Command Injection

24 July 2023
Details have emerged about a now-patched flaw in OpenSSH that could be exploited to run arbitrary commands remotely. The vulnerability is being tracked under the CVE identifier CVE-2023-38408. It impacts all versions of OpenSSH before 9.3p2.

Google Messages Getting Cross-Platform End-to-End Encryption with MLS Protocol

24 July 2023
Google has announced that it intends to add support for Message Layer Security (MLS) to its Messages service for Android and open source implementation of the specification. "Most modern consumer messaging platforms (including Google Messages) support end-to-end encryption, but users today are limited to communicating with contacts who use the same platform," Giles Hogben, privacy engineering