Moussouris: U.S. Should Resist Urge to Match China Vuln Reporting Mandate
A prominent cybersecurity executive is calling on the U.S. government to resist the urge to match China’s reported mandates around early vulnerability disclosure, warning that such a move would “meaningfully and dramatically increase the risk” of zero-day flaws landing in the wrong hands.
Juniper Networks Patches Over 200 Third-Party Component Vulnerabilities
Juniper Networks last week published 21 security advisories to inform customers about more than 200 vulnerabilities affecting its products.
The security holes impact Junos OS (including on SRX, EX, PTX, QFX and MX series devices), Junos Space, Contrail Networking, and Northstar Controller products.
New Deanonymization Attack Works on Major Browsers, Websites
Researchers with the New Jersey Institute of Technology have devised a new targeted deanonymization attack that relies on a cache side-channel and which they say is efficient on multiple architectures, operating systems, and browser versions, and works on major websites.
Digium Phones Targeted in Cybercrime Campaign Aimed at VoIP Systems
Security researchers with Palo Alto Networks have detailed a recent campaign targeting the Elastix system in Digium phones with a web shell that allows attackers to drop and execute additional payloads.
Researchers Say Thai Pro-Democracy Activists Hit by Spyware
Cybersecurity researchers reported details Monday of cases where Thai activists involved in the country’s pro-democracy protests had their cell phones or other devices infected and attacked with government-sponsored spyware.
PLC and HMI Password Cracking Tools Deliver Malware
Tools advertised as being capable of cracking passwords for HMIs, PLCs and other industrial products have been found to exploit a zero-day vulnerability, and threat actors are using these tools to deliver malware.
SecurityWeek Analysis: Over 230 Cybersecurity M&A Deals Announced in First Half of 2022
Unpatched WPBakery WordPress Plugin Vulnerability Increasingly Targeted in Attacks
The Wordfence team at WordPress security company Defiant warns of an increase in attacks targeting an unpatched vulnerability in the Kaswara addon for the WPBakery Page Builder WordPress plugin.
Supply Chain Attack Technique Spoofs GitHub Commit Metadata
Security researchers at Checkmarx are warning of a new supply chain attack technique that relies on spoofed commit metadata to add legitimacy to malicious GitHub repositories.













