Sophos Patches Firewall Vulnerability
Sophos has released an update to address a critical authentication bypass vulnerability in its Firewall products. The flaw exists in the User Portal and Webadmin of the Sophos Firewall, and…
Sophos has released an update to address a critical authentication bypass vulnerability in its Firewall products. The flaw exists in the User Portal and Webadmin of the Sophos Firewall, and…
CISA has added 66 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber…
Google has issued an emergency security update for all Chrome users as it confirms that attackers are already exploiting a high severity zero-day vulnerability. The emergency update to version 99.0.4844.84 of…
A Chinese-speaking threat actor called Scarab has been linked to a custom backdoor dubbed HeaderTip as part of a campaign targeting Ukraine since Russia embarked on an invasion last month,…
ESET Research uncovers a sophisticated scheme that distributes trojanized Android and iOS apps posing as popular cryptocurrency wallets More https://www.welivesecurity.com/2022/03/24/crypto-malware-patched-wallets-targeting-android-ios-devices/
Researcher Jose Bertin has identified critical security vulnerabilities in a building controller made by Russian firm Tekon Avtomatika (Tekon.ru). Read more https://www.hackread.com/100-russian-building-controllers-can-be-remotely-hacked/
Chinese state-sponsored actors recently breached the networks of six state governments by exploiting a vulnerability in the U.S. Animal Health Emergency Reporting Diagnostic System. More https://www.wired.com/story/china-apt41-hacking-usaherds-log4j/
Researchers discovered a possible variant of the Spectre malware in Intel chips, pushing back an expected update to Linux. AMD products not appear to be affected at this time. More…
The Symantec Management Agent is susceptible to a privilege escalation vulnerability. A low privilege local account can be elevated to the SYSTEM level through registry manipulations. More information here https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/20366
Incorrect Permission Assignment for Critical Resource vulnerability in the crash handling component BDReinit.exe as used in Bitdefender Total Security, Internet Security, Antivirus Plus, Endpoint Security Tools for Windows allows a…