The Transportation Security Administration (TSA) has updated its directive for oil and natural gas pipeline cybersecurity, providing owners and operators more flexibility in achieving the outlined goals.
Atlassian Expects Confluence App Exploitation After Hardcoded Password Leak
Atlassian has warned customers that a vulnerability in Questions for Confluence will likely be used in attacks after someone made public a piece of information needed to exploit a recently addressed vulnerability.
T-Mobile Settles to Pay $350M to Customers in Data Breach
T- Mobile has agreed to pay $350 million to customers affected by a class action lawsuit filed after the company disclosed last August that personal data like social security numbers had been stolen in a read more
SonicWall Warns of Critical GMS SQL Injection Vulnerability
Network security appliance vendor SonicWall late Thursday shipped urgent patches for a critical flaw in its Global Management System (GMS) software, warning that the issue exposes businesses to remote hacker attacks.
Chrome Flaw Exploited by Israeli Spyware Firm Also Impacts Edge, Safari
A recently patched Chrome vulnerability that appears to have been exploited by an Israeli spyware company also impacts Microsoft’s Edge and Apple’s Safari web browsers.
Intezer Documents Powerful ‘Lightning Framework’ Linux Malware
Security researchers at Intezer are documenting the discovery of a powerful piece of Linux malware that can stay undetected and has the ability to install rootkits.
New Default Account Lockout Policy in Windows 11 Blocks Brute Force Attacks
Recent Windows 11 builds come with an account lockout policy enabled by default, to prevent remote desktop protocol (RDP) and other types of brute force attacks.
Edge Management and Orchestration Firm Zededa Raises $26 Million
Edge management and orchestration provider Zededa has raised $26 million in Series B funding, which brings the total investment in the company to $57 million.
New Cross-Platform ‘Luna’ Ransomware Only Offered to Russian Affiliates
A new cross-platform ransomware named Luna can encrypt files on Windows, Linux and ESXi, but its developers are only offering it to Russian-speaking affiliates.
Code Execution and Other Vulnerabilities Patched in Drupal
Drupal developers have announced the release of updates that patch several vulnerabilities in the open source content management system (CMS).

