Oddbean new post about | logout

Notes by ITSEC News | export

 July Windows Server updates break Remote Desktop connections - Microsoft has confirmed that July's security updates break remote desktop connections in ... https://www.bleepingcomputer.com/news/microsoft/july-windows-server-updates-break-remote-desktop-connections/ #microsoft 
 Cencora data breach exposes US patient info from 8 drug companies - Some of the largest drug companies in the world have disclosed data breaches due to a Feb... https://www.bleepingcomputer.com/news/security/cencora-data-breach-exposes-us-patient-info-from-8-drug-companies/ #healthcare #security 
 New ShrinkLocker ransomware uses BitLocker to encrypt your files - A new ransomware strain called ShrinkLocker creates a new boot partition to encrypt corpo... https://www.bleepingcomputer.com/news/security/new-shrinklocker-ransomware-uses-bitlocker-to-encrypt-your-files/ #microsoft #security 
 Almost all citizens of city of Eindhoven have their personal data exposed - A data breach involving the Dutch city of Eindhoven left the personal information related... https://www.bitdefender.com/blog/hotforsecurity/almost-all-citizens-of-city-of-eindhoven-have-their-personal-data-exposed/ #netherlands #databreach #guestblog #lawℴ #dataloss #privacy 
 Google fixes eighth actively exploited Chrome zero-day this year - Google has released a new emergency security update to address the eighth zero-day vulner... https://www.bleepingcomputer.com/news/security/google-fixes-eighth-actively-exploited-chrome-zero-day-this-year/ #security #google 
 Google fixes two Pixel zero-day flaws exploited by forensics firms - Google has fixed two Google Pixel zero-days exploited by forensic firms to unlock phones ... https://www.bleepingcomputer.com/news/security/google-fixes-two-pixel-zero-day-flaws-exploited-by-forensics-firms/ #security #google #mobile 
 Windows KB5035849 update failing to install with 0xd000034 errors - The KB5035849 cumulative update released during today's Patch Tuesday fails to install on... https://www.bleepingcomputer.com/news/microsoft/windows-kb5035849-update-failing-to-install-with-0xd000034-errors/ #microsoft 
 Brave: Sharp increase in installs after iOS DMA update in EU - Brave has seen a sharp increase in users installing its privacy-focused Brave Browser on ... https://www.bleepingcomputer.com/news/technology/brave-sharp-increase-in-installs-after-ios-dma-update-in-eu/ #technology #software 
 Stanford: Data of 27,000 people stolen in September ransomware attack - Stanford University says the personal information of 27,000 individuals was stolen in a r... https://www.bleepingcomputer.com/news/security/stanford-data-of-27-000-people-stolen-in-september-ransomware-attack/ #security 
 Acer confirms Philippines employee data leaked on hacking forum - Acer Philippines confirmed that employee data was stolen in an attack on a third-party ve... https://www.bleepingcomputer.com/news/security/acer-confirms-philippines-employee-data-leaked-on-hacking-forum/ #security 
 Another Patch Tuesday with no zero-days, only two critical vulnerabilities disclosed by Microsoft - For the second month in 2024, there are no actively exploited vulnerabilities included in... https://blog.talosintelligence.com/microsoft-patch-tuesday-march-2024/ #patchtuesday 
 Windows 11 KB5035853 update released, here's what's new - Microsoft has released the KB5035853 cumulative update for Windows 11 23H3 and 22H2, with... https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5035853-update-released-heres-whats-new/ #microsoft #software 
 Windows 10 KB5035845 update released with 9 new changes, fixes - Microsoft has released the KB5035845 cumulative update for Windows 10 21H2 and Windows 10... https://www.bleepingcomputer.com/news/microsoft/windows-10-kb5035845-update-released-with-9-new-changes-fixes/ #microsoft 
 Microsoft March 2024 Patch Tuesday fixes 60 flaws, 18 RCE bugs - Today is Microsoft's March 2024 Patch Tuesday, and security updates have been released fo... https://www.bleepingcomputer.com/news/microsoft/microsoft-march-2024-patch-tuesday-fixes-60-flaws-18-rce-bugs/ #microsoft #security 
 Tor’s new WebTunnel bridges mimic HTTPS traffic to evade censorship - The Tor Project officially introduced WebTunnel, a new bridge type specifically designed ... https://www.bleepingcomputer.com/news/security/tors-new-webtunnel-bridges-mimic-https-traffic-to-evade-censorship/ #security 
 Google paid $10 million in bug bounty rewards last year - Google awarded $10 million to 632 researchers from 68 countries in 2023 for finding and r... https://www.bleepingcomputer.com/news/google/google-paid-10-million-in-bug-bounty-rewards-last-year/ #security #google 
 Over 12 million auth secrets and keys leaked on GitHub in 2023 - GitHub users accidentally exposed 12.8 million authentication and sensitive secrets in ov... https://www.bleepingcomputer.com/news/security/over-12-million-auth-secrets-and-keys-leaked-on-github-in-2023/ #security 
 ISACA Joins Forces with Erasmus+ for SHE@CYBER Project - ISACA has announced its participation in the Erasmus+ program’s SHE@CYBER project. This i... https://www.itsecurityguru.org/2024/03/12/isaca-joins-forces-with-erasmus-for-shecyber-project/?utm_source=rss&utm_medium=rss&utm_campaign=isaca-joins-forces-with-erasmus-for-shecyber-project #thegurucyberallyance 
 #MIWIC2024: Blessing Usoro, Cyber for Schoolgirls - Organised by Eskenzi PR in media partnership with the IT Security Guru, the Most Inspirin... https://www.itsecurityguru.org/2024/03/12/miwic2024-blessing-usoro-cyber-for-schoolgirls/?utm_source=rss&utm_medium=rss&utm_campaign=miwic2024-blessing-usoro-cyber-for-schoolgirls #mostinspiringwomenincyber #miwic2024 
 Alert: FBI Warns Of BlackCat Ransomware Healthcare Attack - In recent months, a concerning trend has emerged within the healthcare sector: the resurg... https://tech-wreckblog.blogspot.com/2024/03/alert-fbi-warns-of-blackcat-ransomware.html 
 Windows 10 KB5034843 update released with 9 new changes, fixes - Microsoft has released the optional KB5034843 Preview cumulative update for Windows 10 22... https://www.bleepingcomputer.com/news/microsoft/windows-10-kb5034843-update-released-with-9-new-changes-fixes/ #microsoft 
 News alert: Kovrr report reveals exposure and cost of material cyber threats — across industries - Tel Aviv, Israel, Oct. 5, 2023 —  Kovrr, the leading global provider of cyber risk... https://www.lastwatchdog.com/news-alert-kovrr-report-reveals-exposure-and-cost-of-material-cyber-threats-across-industries/ #uncategorized 
 Unlock the Secrets of Employee Training for Phishing Emails: 2023 Guide - Introduction In today’s digital landscape, the significance of employee training for phis... https://tech-wreckblog.blogspot.com/2023/10/unlock-secrets-of-employee-training-for.html 
 D.C. Board of Elections confirms voter data stolen in site hack - The District of Columbia Board of Elections (DCBOE) is currently probing a data leak invo... https://www.bleepingcomputer.com/news/security/dc-board-of-elections-confirms-voter-data-stolen-in-site-hack/ #security 
 Blackbaud agrees to $49.5 million settlement for ransomware data breach - Cloud computing provider Blackbaud reached a $49.5 million agreement with attorneys gener... https://www.bleepingcomputer.com/news/security/blackbaud-agrees-to-495-million-settlement-for-ransomware-data-breach/ #security 
 FTC warns of ‘staggering’ losses to social media scams since 2021 - The Federal Trade Commission says Americans have lost at least $2.7 billion to social med... https://www.bleepingcomputer.com/news/security/ftc-warns-of-staggering-losses-to-social-media-scams-since-2021/ #security 
 Genetics firm 23andMe says user data stolen in credential stuffing attack - 23andMe has confirmed to BleepingComputer that it is aware of user data from its platform... https://www.bleepingcomputer.com/news/security/genetics-firm-23andme-says-user-data-stolen-in-credential-stuffing-attack/ #healthcare #security 
 Revealed! The top 10 cybersecurity misconfigurations, as determined by CISA and the NSA - A joint advisory from the United States's National Security Agency (NSA) and Cybersecurit... https://www.tripwire.com/state-of-security/revealed-top-10-cybersecurity-misconfigurations-determined-cisa-and-nsa #securitythreats #guestblog #cisa #nsa 
 MGM Resorts ransomware attack led to $100 million loss, data theft - MGM Resorts reveals that last month's cyberattack cost the company $100 million and allow... https://www.bleepingcomputer.com/news/security/mgm-resorts-ransomware-attack-led-to-100-million-loss-data-theft/ #security 
 Expanding our exploit reward program to Chrome and Cloud - Stephen Roettger and Marios Pomonis, Google Software EngineersIn 2020, we launched a nove... http://security.googleblog.com/2023/10/expanding-our-exploit-reward-program-to.html 
 Lookout Named Mobile Security Solution of the Year by the CyberSecurity Breakthrough Awards Program - Yesterday, Lookout, Inc., the data-centric cloud security company, today announced that i... https://www.itsecurityguru.org/2023/10/06/lookout-named-mobile-security-solution-of-the-year-by-the-cybersecurity-breakthrough-awards-program/?utm_source=rss&utm_medium=rss&utm_campaign=lookout-named-mobile-security-solution-of-the-year-by-the-cybersecurity-breakthrough-awards-program #news 
 News alert: Massachusetts pumps $1.1 million into state college cybersecurity training programs - Worcester, Mass., Oct. 5, 2023 – Today, the Healey-Driscoll Administration kicked ... https://www.lastwatchdog.com/news-alert-massachusetts-pumps-1-1-million-into-state-college-cybersecurity-training-programs/ #uncategorized 
 MGM Resorts says ransomware attack cost $100 million, data stolen - MGM Resorts reveals that last month's cyberattack cost the company $100 million and allow... https://www.bleepingcomputer.com/news/security/mgm-resorts-says-ransomware-attack-cost-100-million-data-stolen/ #security 
 To Schnorr and beyond (Part 1) - Warning: extremely wonky cryptography post. Also, possibly stupid and bound for n... https://blog.cryptographyengineering.com/2023/10/06/to-schnorr-and-beyond-part-1/ #fundamentals 
 The state of open source software security: Changes in attack methods, policy and more - The post The state of open source software security: Changes in attack methods, ... https://tech-wreckblog.blogspot.com/2023/10/the-state-of-open-source-software.html 
 Breaking down barriers: Redefining the FedRAMP® journey for cloud service providers - Since the passing of the FedRAMP Authorization Act last December, inquiries about navigat... https://tech-wreckblog.blogspot.com/2023/10/breaking-down-barriers-redefining.html 
 Organized Retail Crime in Focus - Fighting ORC is possible, but without a holistic view and fully resourced corporate secur... https://tech-wreckblog.blogspot.com/2023/10/organized-retail-crime-in-focus.html 
 Unlocking MDM for Small Business: What you need to know - Introduction Navigating the maze of device management is a common challenge for small bus... https://tech-wreckblog.blogspot.com/2023/10/unlocking-mdm-for-small-business-what.html 
 Microsoft officially removes Cortana for Windows 11 Insiders - Microsoft finally removed the Cortana standalone app from Windows 11 in the latest previe... https://www.bleepingcomputer.com/news/microsoft/microsoft-officially-removes-cortana-for-windows-11-insiders/ #microsoft 
 Microsoft releases faster, new Teams app for Windows and Mac PCs - A new, faster, and completely redesigned Microsoft Teams application is generally availab... https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-faster-new-teams-app-for-windows-and-mac-pcs/ #microsoft 
 Exploits released for Linux flaw giving root on major distros - Proof-of-concept exploits have already surfaced online for a high-severity flaw in GNU C ... https://www.bleepingcomputer.com/news/security/exploits-released-for-linux-flaw-giving-root-on-major-distros/ #security 
 Exploit released for Linux flaw giving root on major distros - Proof-of-concept exploits have already surfaced online for a high-severity flaw in GNU C ... https://www.bleepingcomputer.com/news/security/exploit-released-for-linux-flaw-giving-root-on-major-distros/ #security 
 Is it bad to have a major security incident on your résumé? (Seriously I don’t know) - Welcome to this week’s edition of the Threat Source newsletter.It’s Cybersecurity Awarene... https://blog.talosintelligence.com/threat-source-newsletter-oct-5-2023/ #threatsourcenewsletter 
 5 Tips for Choosing the Best Proxy Service Provider - Selecting the appropriate proxy provider can frequently appear as a challenging endeavor.... https://www.itsecurityguru.org/2023/10/05/5-tips-for-choosing-the-best-proxy-service-provider/?utm_source=rss&utm_medium=rss&utm_campaign=5-tips-for-choosing-the-best-proxy-service-provider #insight 
 NSA and CISA reveal top 10 cybersecurity misconfigurations - The National Security Agency (NSA) and the Cybersecurity and Infrastructure Security Agen... https://www.bleepingcomputer.com/news/security/nsa-and-cisa-reveal-top-10-cybersecurity-misconfigurations/ #security 
 Amazon to make MFA mandatory for 'root' AWS accounts by mid-2024 - Amazon will require all privileged AWS (Amazon Web Services) accounts to use multi-factor... https://www.bleepingcomputer.com/news/security/amazon-to-make-mfa-mandatory-for-root-aws-accounts-by-mid-2024/ #technology #security #cloud 
 Smashing Security podcast #342: Royal family attacked, keyless car theft, and a deepfake Tom Hanks - Is a deepfake Tom Hanks better than the real thing? Who has been attacking the British Ro... https://grahamcluley.com/smashing-security-podcast-342/ #smashingsecurity #denialofservice #vulnerability #instagram #deepfake #tomhanks #podcast #royalty #ddos #car 
 Microsoft releases new, faster Teams app for Windows and Mac PCs - A new, redesigned, and faster Microsoft Teams application is generally available for all ... https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-new-faster-teams-app-for-windows-and-mac-pcs/ #microsoft 
 SHARED INTEL Q&A: My thoughts and opinions about cyber threats — as discussed with OneRep - Editor’s note: I recently had the chance to participate in a discussion about the ... https://www.lastwatchdog.com/shared-intel-qa-my-thoughts-and-opinions-about-cyber-threats-as-discussed-with-onerep/ #fortechnologists #forconsumers #topstories #mytake #qa 
 Lyca Mobile investigates customer data leak after cyberattack - Lyca Mobile has released a statement about an unexpected disruption on its network caused... https://www.bleepingcomputer.com/news/security/lyca-mobile-investigates-customer-data-leak-after-cyberattack/ #security 
 Cybersecurity sector in drive to boost female tech talent - Cybersecurity giants BAE Systems, DarkTrace and GCHQ are on a mission to address the indu... https://www.itsecurityguru.org/2023/10/05/cybersecurity-sector-in-drive-to-boost-female-tech-talent/?utm_source=rss&utm_medium=rss&utm_campaign=cybersecurity-sector-in-drive-to-boost-female-tech-talent #news 
 JUMPSEC team inspires local primary school children to consider a future career in cyber-security - Acton-based cyber security company, JUMPSEC, recently visited a local primary school to s... https://www.itsecurityguru.org/2023/10/05/jumpsec-team-inspires-local-primary-school-children-to-consider-a-future-career-in-cyber-security/?utm_source=rss&utm_medium=rss&utm_campaign=jumpsec-team-inspires-local-primary-school-children-to-consider-a-future-career-in-cyber-security #news 
 Charting a Course to Zero Trust Maturity: 5 Steps to Securing User Access to Apps - When organizations started to embark on zero trust security back in 2020, i... https://duo.com/blog/charting-course-to-zero-trust-maturity #industrynews 
 Introducing Invariant Development as a Service - Understanding and rigorously testing system invariants are essential aspects of developin... https://blog.trailofbits.com/2023/10/05/introducing-invariant-development-as-a-service/ #uncategorized 
 Execution of Arbitrary JavaScript in Android Application - In this blog, we will learn about the possible ways to find cross-site scripting by abusi... https://tech-wreckblog.blogspot.com/2023/10/execution-of-arbitrary-javascript-in.html 
 CVE-2023-38545, A High Severity cURL and libcurl CVE, to be published on October 11th - New Information From Rezilion Research A high-severity cURL vulnerability (CVE-2023-38545... https://tech-wreckblog.blogspot.com/2023/10/cve-2023-38545-high-severity-curl-and.html 
 Qakbot-affiliated actors distribute Ransom Night malware despite infrastructure takedown - The threat actors behind the Qakbot malware have been conducting a campaign since ... https://blog.talosintelligence.com/qakbot-affiliated-actors-distribute-ransom/ #ransomware #securex #malware #qakbot 
 ‘No excuses – try harder’: Martha Lane Fox and lineup at DTX + UCX Europe challenges tech leaders to double-down on diversity and sustainability - Baroness Martha Lane Fox has launched a rallying cry for the tech world to invest in dive... https://www.itsecurityguru.org/2023/10/05/no-excuses-try-harder-martha-lane-fox-and-lineup-at-dtx-ucx-europe-challenges-tech-leaders-to-double-down-on-diversity-and-sustainability/?utm_source=rss&utm_medium=rss&utm_campaign=no-excuses-try-harder-martha-lan... 
 Exclusive Report: The Rise of Credit Union Brand Impersonations Online in 2023 - As a credit union member, I find myself thwarting inbound scam attempts far more o... https://tech-wreckblog.blogspot.com/2023/10/exclusive-report-rise-of-credit-union.html 
 STEPS FORWARD Q&A: Will ‘proactive security’ engender a shift to risk-based network protection? - Something simply must be done to slow, and ultimately reverse, attack surface expa... https://tech-wreckblog.blogspot.com/2023/10/steps-forward-q-will-proactive-security.html 
 STEPS FORWARD Q&A: Will ‘proactive security’ engender a shift to risk-based network protection? - Something simply must be done to slow, and ultimately reverse, attack surface expa... https://www.lastwatchdog.com/steps-forward-qa-will-proactive-security-engender-a-shift-to-risk-based-network-protection/ #fortechnologists #stepsforward #topstories #mytake 
 P@ssW0rdsR@N0T_FUN! - No matter how many letters, numbers, or special characters you give them an... https://duo.com/blog/passwords-r-not-fun #industrynews 
 Apple emergency update fixes new zero-day used to hack iPhones - Apple released emergency security updates to patch a new zero-day security flaw exploited... https://www.bleepingcomputer.com/news/apple/apple-emergency-update-fixes-new-zero-day-used-to-hack-iphones/ #security #apple 
 Your next online dating match might actually be ChatGPT - Ah, the world of online dating! Where else can you find a potential soulmate whil... https://tech-wreckblog.blogspot.com/2023/10/your-next-online-dating-match-might.html 
 Atlassian patches critical Confluence zero-day exploited in attacks - Australian software company Atlassian released emergency security updates to fix a maximu... https://www.bleepingcomputer.com/news/security/atlassian-patches-critical-confluence-zero-day-exploited-in-attacks/ #security 
 Researchers warn of 100,000 industrial control systems exposed online - About 100,000 industrial control systems (ICS) were found on the public web, exposed to a... https://www.bleepingcomputer.com/news/security/researchers-warn-of-100-000-industrial-control-systems-exposed-online/ #security 
 Top 3 Tips Learned from Getting Fairwinds Insights into AWS Marketplace - The AWS Marketplace has grown extensively over the years, and it has a significan... https://tech-wreckblog.blogspot.com/2023/10/top-3-tips-learned-from-getting.html 
 Cisco fixes hard-coded root credentials in Emergency Responder - Cisco released security updates to fix a Cisco Emergency Responder (CER) vulnerability th... https://www.bleepingcomputer.com/news/security/cisco-fixes-hard-coded-root-credentials-in-emergency-responder/ #security 
 Typosquatting campaign delivers r77 rootkit via npm - ReversingLabs researchers have identified a new, malicious supply chain attack af... https://tech-wreckblog.blogspot.com/2023/10/typosquatting-campaign-delivers-r77.html 
 Microsoft: Hackers target Azure cloud VMs via breached SQL servers - Hackers have been observed trying to breach cloud environments through Microsoft SQL Serv... https://www.bleepingcomputer.com/news/security/microsoft-hackers-target-azure-cloud-vms-via-breached-sql-servers/ #microsoft #security #cloud 
 The Crucial Difference Between Pre- and Post-Delivery Email Scanning - Some major cybersecurity vendors are demonstrating significant flaws because thei... https://tech-wreckblog.blogspot.com/2023/10/the-crucial-difference-between-pre-and.html 
 What is the dark web? - Most users interact with the internet through the web, and many of the threat actors we w... https://blog.talosintelligence.com/what-is-the-dark-web/ #theneedtoknow 
 Outpost24 Expands Leadership Team by Appointing New Chief Revenue Officer - Today, cyber risk management company Outpost24 have announced the appointment of Allan Ro... https://www.itsecurityguru.org/2023/10/04/outpost24-expands-leadership-team-by-appointing-new-chief-revenue-officer/?utm_source=rss&utm_medium=rss&utm_campaign=outpost24-expands-leadership-team-by-appointing-new-chief-revenue-officer #news 
 Episode 253: DevSecOps Worst Practices With Tanya Janca of We Hack Purple - Tanya Janca of the group We Hack Purple, talks with Security Ledger host Paul Robe... https://feeds.feedblitz.com/~/797526818/0/thesecurityledger~Episode-DevSecOps-Worst-Practices-With-Tanya-Janca-of-We-Hack-Purple/ #applicationdevelopment #applicationsecurity #penetrationtesting #hacks&hackers #wehackpurple #purpleteam #topstories #tanyajanca #devsecops #secdevops #spotlight #podcasts #software #podcast #devops 
 Sony confirms data breach impacting thousands in the U.S. - Sony Interactive Entertainment (Sony) has notified current and former employees and their... https://www.bleepingcomputer.com/news/security/sony-confirms-data-breach-impacting-thousands-in-the-us/ #security 
 Keeper Security Becomes a CVE Numbering Authority - Today, password management company Keeper Security has announced that it has been authori... https://www.itsecurityguru.org/2023/10/04/keeper-security-becomes-a-cve-numbering-authority/?utm_source=rss&utm_medium=rss&utm_campaign=keeper-security-becomes-a-cve-numbering-authority #news 
 Safe, Secure, Anonymous, and Other Misleading Claims - Presently sponsored by: NTT’s Samurai XDR offers affordable enterprise-grade secur... https://www.troyhunt.com/safe-secure-anonymous-and-other-misleading-claims/ #security #privacy 
 Emergency alert on US phones and TVs today — Don’t worry, it’s just a test - The U.S. Federal Emergency Management Agency (FEMA) and the Federal Communications Commis... https://www.bleepingcomputer.com/news/technology/emergency-alert-on-us-phones-and-tvs-today-dont-worry-its-just-a-test/ #technology #government 
 New 'Looney Tunables' Linux bug gives root on major distros - A new Linux vulnerability known as 'Looney Tunables' enables local attackers to gain root... https://www.bleepingcomputer.com/news/security/new-looney-tunables-linux-bug-gives-root-on-major-distros/ #security #linux 
 Microsoft now lets you play a game during Windows 11 installs - Microsoft has introduced a new twist to the Windows 11 installation and update process, t... https://www.bleepingcomputer.com/news/microsoft/microsoft-now-lets-you-play-a-game-during-windows-11-installs/ #microsoft 
 Google to bolster phishing and malware delivery defenses in 2024 - Google will introduce new sender guidelines in February to bolster email security against... https://www.bleepingcomputer.com/news/security/google-to-bolster-phishing-and-malware-delivery-defenses-in-2024/ #security #google 
 Android October security update fixes zero-days exploited in attacks - Google has released the October 2023 security updates for Android, addressing 54 unique v... https://www.bleepingcomputer.com/news/security/android-october-security-update-fixes-zero-days-exploited-in-attacks/ #security #google #mobile 
 ShellTorch flaws expose AI servers to code execution attacks - A set of critical vulnerabilities dubbed 'ShellTorch' in the open-source TorchServe AI mo... https://www.bleepingcomputer.com/news/security/shelltorch-flaws-expose-ai-servers-to-code-execution-attacks/ #security 
 Qualcomm says hackers exploit 3 zero-days in its GPU, DSP drivers - Qualcomm is warning of three zero-day vulnerabilities in its GPU and Compute DSP drivers ... https://www.bleepingcomputer.com/news/security/qualcomm-says-hackers-exploit-3-zero-days-in-its-gpu-dsp-drivers/ #security #mobile 
 The State of Cybersecurity: Cyber skills gap leaves business vulnerable to attacks, new research reveals - ISACA, the leading global professional association helping individuals and organisations ... https://www.itsecurityguru.org/2023/10/03/the-state-of-cybersecurity-cyber-skills-gap-leaves-business-vulnerable-to-attacks-new-research-reveals/?utm_source=rss&utm_medium=rss&utm_campaign=the-state-of-cybersecurity-cyber-skills-gap-leaves-business-vulnerable-to-attacks-new-research-reveals 
 Microsoft Edge, Teams get fixes for zero-days in open-source libraries - Microsoft released emergency security updates for Edge, Teams, and Skype to patch two zer... https://www.bleepingcomputer.com/news/microsoft/microsoft-edge-teams-get-fixes-for-zero-days-in-open-source-libraries/ #microsoft #security 
 Modernizing Traditional Applications with Enhanced Security: Duo SSO, Third-Party SAML Libraries and OIDC - In today's digital landscape, security is constantly evolving and legacy ap... https://duo.com/blog/modernizing-traditional-applications-with-enhanced-security #product&engineering 
 Software Consumers Are Not Waiting For SBOMs - The post Software Consumers Are Not Waiting For SBOMs appeared first on CodeSecure.
The p... https://tech-wreckblog.blogspot.com/2023/10/software-consumers-are-not-waiting-for.html 
 Building a Career in Cyber Security: The Biggest Lie - TL;DR: Cybersecurity is a complex and challenging field, and it's important to have reali... https://tech-wreckblog.blogspot.com/2023/10/building-career-in-cyber-security.html 
 A Closer Look at Prospect Medical Holdings’ Ransomware Nightmare - Medical service providers have increasingly become prime targets f... https://tech-wreckblog.blogspot.com/2023/10/a-closer-look-at-prospect-medical.html 
 The CVE-2023-5217 Deja Vu – Another Actively Exploited Chrome Vulnerability Affecting a WebM Project Library (libvpx) - By Ofri Ouzan & Yotam Perkal, Rezilion Security Research On September 27th, 2023 Goog... https://tech-wreckblog.blogspot.com/2023/10/the-cve-2023-5217-deja-vu-another.html 
 Microsoft Defender no longer flags Tor Browser as malware - For Windows users who frequently use the TorBrowser, there's been a pressing concern. Rec... https://www.bleepingcomputer.com/news/security/microsoft-defender-no-longer-flags-tor-browser-as-malware/ #security #software 
 Exim patches three of six zero-day bugs disclosed last week - Exim developers have released patches for three of the zero-days disclosed last week thro... https://www.bleepingcomputer.com/news/security/exim-patches-three-of-six-zero-day-bugs-disclosed-last-week/ #security 
 New BunnyLoader threat emerges as a feature-rich malware-as-a-service - Security researchers discovered a new malware-as-a-service (MaaS) named 'BunnyLoader' adv... https://www.bleepingcomputer.com/news/security/new-bunnyloader-threat-emerges-as-a-feature-rich-malware-as-a-service/ #security 
 Ransomware gangs now exploiting critical TeamCity RCE flaw - Ransomware gangs are now targeting a recently patched critical vulnerability in JetBrains... https://www.bleepingcomputer.com/news/security/ransomware-gangs-now-exploiting-critical-teamcity-rce-flaw/ #security 
 Exploit available for critical WS_FTP bug exploited in attacks - Over the weekend, security researchers released a proof-of-concept (PoC) exploit for a ma... https://www.bleepingcomputer.com/news/security/exploit-available-for-critical-ws-ftp-bug-exploited-in-attacks/ #security 
 Arm warns of Mali GPU flaws likely exploited in targeted attacks - Arm in a security advisory today is warning of an actively exploited vulnerability affect... https://www.bleepingcomputer.com/news/security/arm-warns-of-mali-gpu-flaws-likely-exploited-in-targeted-attacks/ #security #mobile 
 GUEST ESSAY: Has shielding and blocking electromagnetic energy become the new normal? - Surrounded by the invisible hum of electromagnetic energy, we’ve harnessed its pow... https://www.lastwatchdog.com/guest-essay-has-shielding-and-blocking-electromagnetic-energy-become-the-new-normal/ #fortechnologists #guestblogpost #forconsumers #topstories 
 Motel One discloses data breach following ransomware attack - The Motel One Group has announced that it has been targeted by ransomware actors who mana... https://www.bleepingcomputer.com/news/security/motel-one-discloses-data-breach-following-ransomware-attack/ #security 
 FBI warns of surge in 'phantom hacker' scams impacting elderly - The FBI issued a public service announcement warning of a significant increase in 'phanto... https://www.bleepingcomputer.com/news/security/fbi-warns-of-surge-in-phantom-hacker-scams-impacting-elderly/ #security 
 GRC Automation: The Competitive Edge for Enterprises - Governance, risk, and compliance (GRC) form the pillars upon which organizations build th... https://tech-wreckblog.blogspot.com/2023/10/grc-automation-competitive-edge-for.html 
 A New Approach to Defending Network Infrastructure from Ransomware Groups and APTs - Remember when ransomware was simply getting locked out of your files? Those seem like the... https://tech-wreckblog.blogspot.com/2023/10/a-new-approach-to-defending-network.html