High-severity OpenSSL vulnerabilities fixed (CVE-2022-3602, CVE-2022-3786)

Version 3.0.7 of the popular OpenSSL cryptographic library is out, with fixes for CVE-2022-3602 and CVE-2022-3786, two high-severity buffer overflow vulnerabilities in the punycode decoder that could lead to crashes (i.e., denial of service) or potenti… Continue reading High-severity OpenSSL vulnerabilities fixed (CVE-2022-3602, CVE-2022-3786)

Assessing the state of the internet to make smart security decisions

The internet constantly changes as new technologies are developed, and vulnerabilities are discovered. At the same time, organizations expand their operations that interact with the Internet. In this Help Net Security video, Emily Austin, Security Data… Continue reading Assessing the state of the internet to make smart security decisions

Assessing the state of the internet to make smart security decisions

The internet constantly changes as new technologies are developed, and vulnerabilities are discovered. At the same time, organizations expand their operations that interact with the Internet. In this Help Net Security video, Emily Austin, Security Data… Continue reading Assessing the state of the internet to make smart security decisions

Organizations should fear misconfigurations more than vulnerabilities

Censys launched its State of the Internet Report, a holistic view into internet risks and organizations’ exposure to them. Through careful examination of which ports, services, and software are most prevalent on the internet and the systems and regions… Continue reading Organizations should fear misconfigurations more than vulnerabilities

Researchers uncover potential ransomware network with U.S. connections

Researchers at Censys found what appears to be a command and control network capable of launching attacks, including one host in Ohio.

The post Researchers uncover potential ransomware network with U.S. connections appeared first on CyberScoop.

Continue reading Researchers uncover potential ransomware network with U.S. connections

Censys raises $35 million to accelerate product development and sales operations

Censys announced it completed a $35 million Series B funding round led by Intel Capital. Previous investors including Google Ventures, Decibel and Greylock Partners also participated in the round. With this funding, Censys will continue to accelerate i… Continue reading Censys raises $35 million to accelerate product development and sales operations

US Govt’s secret terrorist watchlist with 2M records exposed online

By Waqas
The watchlist was exposed on a misconfigured server hosted on a Bahrain IP address instead of a US one.
This is a post from HackRead.com Read the original post: US Govt’s secret terrorist watchlist with 2M records exposed online
Continue reading US Govt’s secret terrorist watchlist with 2M records exposed online

SolarWinds patches zero-day exploited in the wild (CVE-2021-35211)

SolarWinds has released an emergency patch for CVE-2021-35211, a RCE vulnerability affecting its Serv-U Managed File Transfer and Serv-U Secure FTP that is currently being exploited in the wild. “Microsoft has provided evidence of limited, target… Continue reading SolarWinds patches zero-day exploited in the wild (CVE-2021-35211)

Healthcare industry at greatest risk of data breach

The healthcare industry has significantly more exposed attack surfaces than any other industry surveyed, according to Censys’s research findings of cloud risks and cloud maturity by industry, revealed at RSA Conference 2020. Leveraging the Censys… Continue reading Healthcare industry at greatest risk of data breach