Security
Headlines
HeadlinesLatestCVEs

Source

DARKReading

Truebot Malware Variants Abound, According to CISA Advisory

US and Canadian government agencies find that new variants of the malware are increasingly being utilized.

DARKReading
#vulnerability#rce#perl#botnet
Spyware Gamed 1.5M Users of Google Play Store

Malware spoofed file management applications thanks to elevated permissions, enabling exfiltration of sensitive data with no user interaction, researchers find.

MOVEit Transfer Faces Another Critical Data-Theft Bug

Users need to patch the latest SQL injection vulnerability as soon as possible. Meanwhile, Cl0p's data extortion rampage gallops on.

Can Generative AI Be Trusted to Fix Your Code?

Not yet — but it can help make incremental progress in reducing vulnerability backlogs.

Startup Spotlight: Endor Labs Focuses on Reachability

The company, one of four finalists in Black Hat USA's 2023 startup competition, looks for the vulnerabilities an attacker could actually access.

StackRot Linux Kernel Bug Has Exploit Code on the Way

Linus Torvalds led a Linux kernel team in developing a set of patches for the privilege escalation flaw.

Patchless Cisco Flaw Breaks Cloud Encryption for ACI Traffic

Vulnerable Nexus 9000 Series Fabric Switches in ACI mode should be disabled, Cisco advises.

Shell Becomes Latest Cl0p MOVEit Victim

In another MOVEit attack, oil and gas giant Shell saw the release of the private information of its employees.

Privacy Woes Hold Up Global Instagram Threads Launch

Meta's answer to Twitter went live and quickly racked up millions of members — but the social media app's privacy practices are under the microscope.