Critical Flaws in 3rd-Party Code Allow Takeover of Industrial Control Systems

Researchers warn of critical vulnerabilities in a third-party industrial component used by top ICS vendors like Rockwell Automation and Siemens. Continue reading Critical Flaws in 3rd-Party Code Allow Takeover of Industrial Control Systems

Critical Adobe Flaws Allow Attackers to Run JavaScript in Browsers

Five critical cross-site scripting flaws were fixed by Adobe in Experience Manager as part of its regularly scheduled patches. Continue reading Critical Adobe Flaws Allow Attackers to Run JavaScript in Browsers

Vulnerability Disclosure: Ethical Hackers Seek Best Practices

Cybersecurity researchers Brian Gorenc and Dustin Childs talk about the biggest vulnerability disclosure challenges in IoT and the industrial vertical. Continue reading Vulnerability Disclosure: Ethical Hackers Seek Best Practices

NSA Mass Surveillance Program Illegal, U.S. Court Rules

The NSA argued its mass surveillance program stopped terrorist attacks – but a new U.S. court ruling found that this is not, and may have even been unconstitutional. Continue reading NSA Mass Surveillance Program Illegal, U.S. Court Rules

U.S. Agencies Must Adopt Vulnerability-Disclosure Policies by March 2021

U.S. agencies must implement vulnerability-disclosure policies by March 2021, according to a new CISA mandate. Continue reading U.S. Agencies Must Adopt Vulnerability-Disclosure Policies by March 2021

Joker Spyware Plagues More Google Play Apps

The six malicious apps have been removed from Google Play, but could still threaten 200,000 installs. Continue reading Joker Spyware Plagues More Google Play Apps