Critical VMware Zero-Day Bug Allows Command Injection; Patch Pending

VMware explained it has no patch for a critical escalation-of-privileges bug that impacts both Windows and Linux operating systems and its Workspace One. Continue reading Critical VMware Zero-Day Bug Allows Command Injection; Patch Pending

Multiple Industrial Control System Vendors Warn of Critical Bugs

Four industrial control system vendors each announced vulnerabilities that ranged from critical to high-severity. Continue reading Multiple Industrial Control System Vendors Warn of Critical Bugs

Hacked Security Software Used in Novel South Korean Supply-Chain Attack

Lazarus Group is believed to be behind a spate of attacks that leverage stolen digital certificates tied to browser software that secures communication with government and financial websites in South Korea. Continue reading Hacked Security Software Used in Novel South Korean Supply-Chain Attack