Google addresses 2 actively exploited vulnerabilities in security update

Serbian security services exploited one of the actively exploited vulnerabilities to break into the phone of a youth activist in Serbia, according to Amnesty International.

The post Google addresses 2 actively exploited vulnerabilities in security update appeared first on CyberScoop.

Continue reading Google addresses 2 actively exploited vulnerabilities in security update

China-backed espionage group hits Ivanti customers again

UNC5221 has a knack for exploiting defects in Ivanti products. The group has exploited at least four vulnerabilities in the vendor’s products since 2023, according to Mandiant.

The post China-backed espionage group hits Ivanti customers again appeared first on CyberScoop.

Continue reading China-backed espionage group hits Ivanti customers again

Independent tests show why orgs should use third-party cloud security services

AWS, Microsoft Azure and Google Cloud Platform each scored 0% security effectiveness in CyberRatings.org’s evaluation of cloud network firewall vendors’ ability to prevent exploits and evasions.

The post Independent tests show why orgs should use third-party cloud security services appeared first on CyberScoop.

Continue reading Independent tests show why orgs should use third-party cloud security services

Apple issues fixes for vulnerabilities in both old and new OS versions

The company released a host of security patches Monday, including ones that address two zero-day vulnerabilities.

The post Apple issues fixes for vulnerabilities in both old and new OS versions appeared first on CyberScoop.

Continue reading Apple issues fixes for vulnerabilities in both old and new OS versions

Identity lapses ensnared organizations at scale in 2024

Cisco Talos observed identity-based attacks in 60% of the incidents it responded to last year.

The post Identity lapses ensnared organizations at scale in 2024 appeared first on CyberScoop.

Continue reading Identity lapses ensnared organizations at scale in 2024

The North Korea worker problem is bigger than you think

The yearslong scheme goes much deeper than contract work, extending to roles beyond traditional IT and sometimes granting the insider threat “keys to the kingdom,” DTEX President Mohan Koo said.

The post The North Korea worker problem is bigger than you think appeared first on CyberScoop.

Continue reading The North Korea worker problem is bigger than you think

Browser extension sales, updates pose hidden threat to enterprises

Some browser extension permissions are too broad, and owners can quickly repurpose pre-approved capabilities for malicious intent, a security researcher told CyberScoop.

The post Browser extension sales, updates pose hidden threat to enterprises appeared first on CyberScoop.

Continue reading Browser extension sales, updates pose hidden threat to enterprises

String of defects in popular Kubernetes component puts 40% of cloud environments at risk

Researchers aren’t aware of active exploitation in the wild, but they warn the risk for publicly exposed and unpatched Ingress Nginx controllers is extremely high.

The post String of defects in popular Kubernetes component puts 40% of cloud environments at risk appeared first on CyberScoop.

Continue reading String of defects in popular Kubernetes component puts 40% of cloud environments at risk

Researchers raise alarm about critical Next.js vulnerability

The software defect in the widely used open-source JavaScript framework allows attackers to bypass middleware-based authorization.

The post Researchers raise alarm about critical Next.js vulnerability appeared first on CyberScoop.

Continue reading Researchers raise alarm about critical Next.js vulnerability

Canadian citizen allegedly involved in Snowflake attacks consents to extradition to US

Connor Moucka, a 26-year-old arrested at the behest of U.S. authorities in October in Kitchener, Ontario, faces 20 federal charges.

The post Canadian citizen allegedly involved in Snowflake attacks consents to extradition to US appeared first on CyberScoop.

Continue reading Canadian citizen allegedly involved in Snowflake attacks consents to extradition to US