CISA Releases Decision Tree Model to Help Companies Prioritize Vulnerability Patching

The US Cybersecurity and Infrastructure Security Agency (CISA) on Thursday announced the release of a Stakeholder-Specific Vulnerability Categorization (SSVC) guide that can help organizations prioritize vulnerability patching using a decision tree mod… Continue reading CISA Releases Decision Tree Model to Help Companies Prioritize Vulnerability Patching

ABB Oil and Gas Flow Computer Hack Can Prevent Utilities From Billing Customers

Oil and gas flow computers and remote controllers made by Swiss industrial technology firm ABB are affected by a serious vulnerability that could allow hackers to cause disruptions and prevent utilities from billing their customers, according to indust… Continue reading ABB Oil and Gas Flow Computer Hack Can Prevent Utilities From Billing Customers

Microsoft Patches MotW Zero-Day Exploited for Malware Delivery

Microsoft’s latest Patch Tuesday updates address six zero-day vulnerabilities, including one related to the Mark-of-the-Web (MotW) security feature that has been exploited by cybercriminals to deliver malware.
read more Continue reading Microsoft Patches MotW Zero-Day Exploited for Malware Delivery

Google Reveals Spyware Vendor’s Use of Samsung Phone Zero-Day Exploits

Google Project Zero has disclosed the details of three Samsung phone vulnerabilities that have been exploited by a spyware vendor since when they still had a zero-day status.
read more Continue reading Google Reveals Spyware Vendor’s Use of Samsung Phone Zero-Day Exploits