Security
Headlines
HeadlinesLatestCVEs

Source

DARKReading

50% of Servers Have Weak Security Long After Patches Are Released

Many servers remain vulnerable to high-severity flaws in Microsoft Exchange Server, VMware vCenter, Oracle WebLogic, and other popular products and services.

DARKReading
Salt Security Finds Widespread Elastic Stack API Security Vulnerability that Exposes Customer and System Data

New threat research from the Salt Labs Security research team details Elastic Stack injection exploit that can result in DoS attacks and cascading API threats

Dell Technologies Addresses Modern Support and Security

Services and security updates deliver customized IT support and secure PC experiences for work-from-anywhere employees.

1Password and Fastmail Partner to Boost Online Privacy

Allows users to securely generate unique email aliases, adding an extra layer of online privacy.

Cyberspace, Cybergames, and Cyberspies

How cyberspace has become a global cybergames stage, where all of us are actors.

Russian Officials Arrest Group-IB CEO, Accuse Him of Treason

Ilya Sachkov, founder and CEO of the massive cybersecurity firm, was arrested on treason charges and will be in custody for two months.

Why Should I Care About HTTP Request Smuggling?

HTTP request smuggling is a growing vulnerability, but you can manage the risk with proper server configuration.

DAST to the Future: Shifting the Modern AppSec Paradigm

NTT Application Security's Modern AppSec Framework takes a DAST-first approach to defend applications where breaches happen — in production.

Sneaky Android Trojan Siphons Millions Using Premium SMS

More than 200 applications on the Google Play store have, until recently, allowed cybercriminals to deliver malicious Web content to victims' phones, likely garnering tens of millions of dollars.

75K Email Inboxes Hit in New Credential Phishing Campaign

Attacker used a legitimate — but likely deprecated — domain to sneak malicious emails past security filters, vendor says.