A group of academic researchers on Tuesday published a paper describing the first side-channel attack targeting the scheduler queues of modern processors.
Adobe Patch Tuesday: Code Execution Flaws in Acrobat, Reader
Software maker Adobe has released patches for at least 25 documented security vulnerabilities that expose Windows and macOS users to malicious hacker attacks.
The most urgent fix affects the ubiquitous Adobe Acrobat and Reader software used to create, view and manage PDF files across platforms.
Privya Emerges From Stealth With Data Privacy Code Scanning Platform
Privya emerged from stealth mode on Tuesday with a data privacy-focused code scanning platform and $6 million in seed funding.
Microsoft Publishes Office Symbols to Improve Bug Hunting
Microsoft Office has started publishing Office symbols for Windows in an effort to help bug hunters find and report security issues.
Symbols are pieces of information used during debugging, and are contained within Symbol files, which are created by the compiler during application build.
ICS Patch Tuesday: Siemens, Schneider Electric Fix Only 11 Vulnerabilities
Industrial giants Siemens and Schneider Electric have addressed less than a dozen vulnerabilities in their August 2022 Patch Tuesday advisories, far fewer than in most of the previous months.
Black Hat 2022: Ten Presentations Worth Your Time and Attention
LAS VEGAS – The security industry makes its annual pilgrimage to the hot Sonoran desert this week for skills training, hacking demos, research presentations and cybersecurity vendors showing off shiny new products.
IBM Patches High-Severity Vulnerabilities in Cloud, Voice, Security Products
IBM on Monday announced patches for multiple high-severity vulnerabilities impacting products such as Netezza for Cloud Pak for Data, Voice Gateway, and SiteProtector.
US Sanctions Crypto ‘Laundering’ Service Tornado
The United States placed sanctions Monday on Tornado Cash, a leading “crypto mixer” for transactions in virtual currency that US officials describe as a hub for laundering stolen funds, including by North Korean hackers.
Open Redirect Flaws in American Express and Snapchat Exploited in Phishing Attacks
Open redirect vulnerabilities affecting American Express and Snapchat websites were exploited earlier this year as part of phishing campaigns targeting Microsoft 365 users, email security firm Inky reports.
Twilio Hacked After Employees Tricked Into Giving Up Login Credentials
Enterprise software vendor Twilio (NYSE: TWLO) has been hacked by a relentless threat actor who successfully tricked employees into giving up login credentials that were then used to steal third-party customer data.

