Microsoft Plugs Gaping Hole in Azure Kubernetes Service Confidential Containers

Patch Tuesday: Microsoft warns that unauthenticated hackers can take complete control of Azure Kubernetes clusters.
The post Microsoft Plugs Gaping Hole in Azure Kubernetes Service Confidential Containers appeared first on SecurityWeek.
Continue reading Microsoft Plugs Gaping Hole in Azure Kubernetes Service Confidential Containers

Patch Tuesday: Code Execution Flaws in Multiple Adobe Software Products

Adobe calls attention to a pair of code execution bugs in Adobe Commerce and Magento Open Source, a product used to manage online stories.
The post Patch Tuesday: Code Execution Flaws in Multiple Adobe Software Products appeared first on SecurityWeek.
Continue reading Patch Tuesday: Code Execution Flaws in Multiple Adobe Software Products

Ivanti CEO Vows Cybersecurity Makeover After Zero-Day Blitz

Ivanti releases a carefully scripted YouTube video and an open letter from chief executive Jeff Abbott vowing to fix the entire security organization.
The post Ivanti CEO Vows Cybersecurity Makeover After Zero-Day Blitz appeared first on SecurityWeek.
Continue reading Ivanti CEO Vows Cybersecurity Makeover After Zero-Day Blitz

Microsoft’s Security Chickens Have Come Home to Roost

News analysis:  SecurityWeek editor-at-large Ryan Naraine reads the CSRB report on China’s audacious Microsoft’s Exchange Online hack and isn’t at all surprised by the findings.
The post Microsoft’s Security Chickens Have Come Home to Roost appea… Continue reading Microsoft’s Security Chickens Have Come Home to Roost

Veracode Buys Longbow Security for Automated Root Cause Analysis Tech

Veracode announces a deal to acquire Longbow Security, a Texas seed-stage startup working on automated root cause analysis technology.
The post Veracode Buys Longbow Security for Automated Root Cause Analysis Tech appeared first on SecurityWeek.
Continue reading Veracode Buys Longbow Security for Automated Root Cause Analysis Tech

Code Execution Flaws Haunt NVIDIA ChatRTX for Windows

Artificial intelligence computing giant NVIDIA patches flaws in ChatRTX for Windows and warns of code execution and data tampering risks.
The post Code Execution Flaws Haunt NVIDIA ChatRTX for Windows appeared first on SecurityWeek.
Continue reading Code Execution Flaws Haunt NVIDIA ChatRTX for Windows

Google Report: Despite Surge in Zero-Day Attacks, Exploit Mitigations Are Working

Despite a surge in zero-day attacks, data shows that security investments into OS and software exploit mitigations are forcing attackers to find new attack surfaces and bug patterns.
The post Google Report: Despite Surge in Zero-Day Attacks, Exploit Mi… Continue reading Google Report: Despite Surge in Zero-Day Attacks, Exploit Mitigations Are Working

Researchers Discover 40,000-Strong EOL Router, IoT Botnet 

Malware hunters sound an alarm after discovering a 40,000-strong botnet packed with end-of-life routers and IoT devices being used in cybercriminal activities.
The post Researchers Discover 40,000-Strong EOL Router, IoT Botnet  appeared first on Securi… Continue reading Researchers Discover 40,000-Strong EOL Router, IoT Botnet