Vulnerabilities addressed recently in Jira Align could allow an attacker to elevate privileges, obtain Atlassian cloud credentials, and potentially go after Atlassian infrastructure, researchers with Bishop Fox warn.
Apple Fixes Exploited Zero-Day With iOS 16.1 Patch
Apple on Monday shipped a major iOS update with fixes at least 20 documented security defects, including a kernel flaw that’s already being actively exploited in the wild.
Microsoft Confirms Data Breach, But Claims Numbers Are Exaggerated
Microsoft has confirmed that it inadvertently exposed information related to prospective customers, but claims that the company which reported the incident has exaggerated the numbers.
New PowerShell Backdoor Poses as Part of Windows Update Process
Cybersecurity firm SafeBreach has issued a warning about a new PowerShell backdoor that disguises itself as part of the Windows update process to remain fully undetected.
Microsoft Patches Vulnerability Allowing Full Access to Azure Service Fabric Clusters
Microsoft recently patched a vulnerability that can allow an attacker to gain full administrator permissions on Azure Service Fabric clusters.
Bolsters Raises $15M to Tackle Fakes and Frauds
California startup Bolster, Inc. has raised $15 million in venture capital funding to build a fraud prevention platform for businesses.
The early-stage funding round was led by Cervin, Liberty Global Ventures, and Cheyenne Ventures with participation from previous investors Thomvest Ventures and Crosslink Capital.
IDA Pro Owner Hex-Rays Acquired by European VC Firm
European venture capital and private equity firm Smartfin on Tuesday announced a deal to acquire Hex-Rays, the Belgian company behind the widely deployed IDA Pro software disassembler.
Zimbra Patches Under-Attack Code Execution Bug
Messaging and collaboration software maker Zimbra has rushed out patches to provide cover for a code execution flaw that has already been exploited to plant malware on target machines.
Zoom for macOS Contains High-Risk Security Flaw
Video messaging technology powerhouse Zoom has rolled out a high-priority patch for macOS users alongside a warning that hackers could abuse the software flaw to connect to and control Zoom Apps.
Timing Attacks Can Be Used to Check for Existence of Private NPM Packages
Container and cloud-native application security provider Aqua Security warns that the existence of private NPM packages can be disclosed by performing timing attacks.












