Webex Monitors Microphone Even When Muted, Researchers Say

Cisco’s enterprise-facing Webex video conferencing and messaging utility monitors the microphone at all times, even when the user’s microphone is muted in the software, according to warning from a group of academic researchers.
read more

Continue reading Webex Monitors Microphone Even When Muted, Researchers Say

GitHub Warns of Private Repositories Downloaded Using Stolen OAuth Tokens

GitHub has sounded the alarm on a cyberattack that resulted in the private repositories of dozens of organizations being downloaded by an unauthorized party abusing stolen OAuth user tokens.
The incident was identified on April 12, when the code hostin… Continue reading GitHub Warns of Private Repositories Downloaded Using Stolen OAuth Tokens

Critical Code Execution Flaw Haunts VMware Cloud Director

Cloud computing and virtualization technology firm VMWare on Thursday rolled out patches for an extremely critical security flaw in the VMWare Cloud Director product, warning that unpatched systems are at risk of remote code execution attacks.
read mor… Continue reading Critical Code Execution Flaw Haunts VMware Cloud Director

Cloud Security Startup DoControl Raises $30 Million

Cloud data security startup DoControl has closed a $30 million Series B funding round that brings the total raised by the company to $43 million.
The financing round was led by Insight Partners, with additional investments from Cardumen Capital, CrowdS… Continue reading Cloud Security Startup DoControl Raises $30 Million

Adobe Patches Gaping Security Holes in Acrobat, Reader, Photoshop

Adobe’s security update engine revved into overdrive this month with the release of patches for at least 78 documented software vulnerabilities, some serious enough to expose corporate customers to remote code execution attacks.
read more

Continue reading Adobe Patches Gaping Security Holes in Acrobat, Reader, Photoshop

OpenSSH Moves to Prevent ‘Capture Now, Decrypt Later’ Attacks

OpenSSH has joined the high-stakes fight to protect data from quantum computers.
The latest version of the widely used encryption and connectivity tool has been fitted with new features to prevent “capture now, decrypt later” attacks linked to advancem… Continue reading OpenSSH Moves to Prevent ‘Capture Now, Decrypt Later’ Attacks

Thoma Bravo to Take SailPoint Private in $6.9B All-Cash Deal

Private equity firm Thoma Bravo’s deep push into the cybersecurity market continued Monday with the announcement of plans to spend $6.9 billion to acquire identity and access management powerhouse SailPoint.
read more

Continue reading Thoma Bravo to Take SailPoint Private in $6.9B All-Cash Deal

Nudge Security Bags $7M Seed Round

Nudge Security, an early stage startup promising to help organizations manage cybersecurity decisions, has banked a $7 million seed round.
read more

Continue reading Nudge Security Bags $7M Seed Round

Apple Leaves Big Sur, Catalina Exposed to Critical Flaws: Intego

Apple is being called to task for neglecting to patch two “actively exploited” zero-day vulnerabilities on older versions of its flagship macOS platform.
read more

Continue reading Apple Leaves Big Sur, Catalina Exposed to Critical Flaws: Intego

CashApp Says Ex-Employee Stole Customer Stock Trading Data

Financial services and stock trading platform CashApp on Tuesday fessed up to a data breach being blamed on a former employee who stole brokerage data, including portfolio values, from an unknown number of U.S. accounts.
read more

Continue reading CashApp Says Ex-Employee Stole Customer Stock Trading Data