Microsoft has warned users about a large-scale phishing campaign that has been targeting over 10,000 organizations to perform follow-on business email compromise (BEC).
The Pendulum Effect and Security Automation
The last few years have been filled with examples of the “Pendulum Effect”, where trends swing from one extreme to another before settling at an equilibrium, somewhere in the middle. Think about it from an IT and security perspective.
Bishop Fox Lands $75 Million Series B Funding
Arizona-based Bishop Fox raised a massive funding round as venture capital investors continue to bet big on the continuous attack surface management category
CIA Coder Convicted of Massive Leak of US Hacking Tools
A former CIA programmer was found guilty in New York federal court Wednesday of the 2017 leak of the US spy agency’s most valuable hacking tools to WikiLeaks, two years after his initial prosecution ended in mistrial.
Lenovo Patches UEFI Code Execution Vulnerability Affecting Many Laptops
Lenovo has released a security advisory to inform customers that more than 70 of its laptops are affected by a UEFI/BIOS vulnerability that can lead to arbitrary code execution.
Retbleed: New Speculative Execution Attack Targets Intel, AMD Processors
Researchers at Swiss university ETH Zurich have devised a new speculative execution attack that can lead to information leaks and works against both Intel and AMD processors.
DLL Hijacking Flaw Fixed in Microsoft Azure Site Recovery
Microsoft’s massive Patch Tuesday rollout this month included fixes for multiple high-severity vulnerabilities impacting the Azure Site Recovery service.
Microsoft Releases Open Source Toolkit for Generating SBOMs
Software giant Microsoft has open-sourced its internal tool for generating SBOMs (software bill of materials) as part of a move to help organizations be more transparent about supply chain relationships between components used when building a software product.
Blockchain Security Startup BlockSec Raises $8 Million
Blockchain security startup BlockSec has raised $8 million in a seed funding round co-led by Vitalbridge Capital and Matrix Partners, with participation from CoinSummer, Mirana Ventures, and YM Capital.
SAP Patches High-Severity Vulnerabilities in Business One Product
German software maker SAP on Tuesday announced the release of 20 new security notes and three updates to previous security notes as part of its July 2022 Security Patch Day.
Of the new security notes, four deal with high-severity vulnerabilities, one impacting SAP BusinessObjects and three found in Business One.











