Thousands of Industrial Systems Targeted With New ‘PseudoManuscrypt’ Spyware

Tens of thousands of devices around the world, including many industrial control systems (ICS) and government computers, have been targeted in what appears to be an espionage campaign that involves a new piece of malware dubbed PseudoManuscrypt, Kasper… Continue reading Thousands of Industrial Systems Targeted With New ‘PseudoManuscrypt’ Spyware

Log4Shell Tools and Resources for Defenders – Continuously Updated

The widely used Apache Log4j Java-based logging tool is affected by a critical remote code execution vulnerability that has been increasingly exploited by malicious actors, including to deliver various types of malware.
read more

Continue reading Log4Shell Tools and Resources for Defenders – Continuously Updated

Chrome 96 Update Patches Exploited Zero-Day Vulnerability

Google on Monday announced a Chrome 96 update that patches five vulnerabilities, including a zero-day that has been exploited in attacks.
The most severe of these vulnerabilities can be exploited to execute arbitrary code in the context of the browser…. Continue reading Chrome 96 Update Patches Exploited Zero-Day Vulnerability

CISA Expands ‘Must-Patch’ List With Log4j, FortiOS, Other Vulnerabilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added 13 new vulnerabilities to its list of security errors known to be exploited, including Apache Log4j and Fortinet FortiOS bugs that were disclosed last week.
read more

Continue reading CISA Expands ‘Must-Patch’ List With Log4j, FortiOS, Other Vulnerabilities