Israeli cybersecurity startup Mesh Security today emerged from stealth mode with a zero trust posture management (ZTPM) solution that helps organizations implement a zero trust architecture in the cloud.
Number of Ransomware Attacks on Industrial Orgs Drops Following Conti Shutdown
The number of ransomware attacks on industrial organizations decreased from 158 in the first quarter of 2022 to 125 in the second quarter, and it may be — at least partially — a result of the Conti operation shutting down.
Intel Patches Severe Vulnerabilities in Firmware, Management Software
Intel on Tuesday published 27 security advisories detailing roughly 60 vulnerabilities across firmware, software libraries, and endpoint and data center management products.
Cyberattack Victims Often Attacked by Multiple Adversaries: Research
It’s not if, but when and how often you get attacked
Sophos research for its Active Adversary Playbook 2022 revealed that victims are often attacked by multiple adversaries – usually, in rapid succession but sometimes simultaneously. Further analysis now suggests the aphorism ‘it’s not if, but when you are attacked’ should be expanded with the extension, ‘and how often’.
UnRAR Vulnerability Exploited in the Wild, Likely Against Zimbra Servers
The US Cybersecurity and Infrastructure Security Agency (CISA) revealed on Tuesday that a recently patched vulnerability affecting the UnRAR archive extraction tool is being exploited in the wild.
SAP Patches Information Disclosure Vulnerabilities in BusinessObjects
SAP on Tuesday announced the release of five new and two updated security notes as part of its August 2022 Security Patch Day.
Of the five new security notes, four address information disclosure vulnerabilities, three of which impact SAP’s BusinessObjects Business Intelligence Platform.
Jury Finds Ex-Twitter Worker Spied for Saudi Royals
Exploit Code Published for Critical VMware Security Flaw
The race to mitigate a gaping authentication bypass vulnerability in VMware Workspace ONE Access, Identity Manager and vRealize Automation products just got a lot more urgent.
Already Exploited Zero-Day Headlines Microsoft Patch Tuesday
Microsoft on Tuesday released a critical-severity bulletin to warn of a newly discovered zero-day attack exploiting a remote code execution vulnerability in its flagship Windows operating system.
ÆPIC Leak: Architectural Bug in Intel CPUs Exposes Protected Data
A group of researchers from several universities and companies has disclosed a new Intel CPU attack method that could allow an attacker to obtain potentially sensitive information.


