Microsoft on Tuesday issued a warning for an in-the-wild zero-day attack hitting Windows users and raised eyebrows when it credited the U.S. government National Security Agency (NSA) with reporting the live exploitation.
Adobe Patches Gaping Security Holes in Acrobat, Reader, Photoshop
Adobe’s security update engine revved into overdrive this month with the release of patches for at least 78 documented software vulnerabilities, some serious enough to expose corporate customers to remote code execution attacks.
OpenSSH Moves to Prevent ‘Capture Now, Decrypt Later’ Attacks
OpenSSH has joined the high-stakes fight to protect data from quantum computers.
The latest version of the widely used encryption and connectivity tool has been fitted with new features to prevent “capture now, decrypt later” attacks linked to advancements in quantum computing.
Energy Provider in Ukraine Targeted With Industroyer2 ICS Malware
An energy provider in Ukraine was recently targeted with a new piece of malware designed to cause damage by manipulating industrial control systems (ICS).
The attack, which targeted high-voltage electrical substations, has been analyzed by Ukraine’s Computer Emergency Response Team (CERT-UA), cybersecurity firm ESET, and Microsoft.
CISA Tells Orgs to Patch WatchGuard Flaw Exploited for Months Before Disclosure
The Cybersecurity and Infrastructure Security Agency (CISA) has given federal agencies three weeks to patch a WatchGuard firewall vulnerability exploited in attacks linked to a Russian state-sponsored threat actor. While the US government has known about the exploitation of this flaw for several months, federal agencies are apparently only now being told to patch it.
Thoma Bravo to Take SailPoint Private in $6.9B All-Cash Deal
Private equity firm Thoma Bravo’s deep push into the cybersecurity market continued Monday with the announcement of plans to spend $6.9 billion to acquire identity and access management powerhouse SailPoint.
‘Octo’ Android Trojan Allows Cybercrooks to Conduct On-Device Fraud
Threat Fabric security researchers have analyzed an Android banking trojan that allows its operators to perform on-device fraud.
Spring4Shell Vulnerability Exploited by Mirai Botnet
Cybersecurity firm Trend Micro on Friday confirmed some earlier reports that the new Spring4Shell vulnerability has been exploited by the Mirai botnet.
Two critical vulnerabilities have been patched recently in the popular Java application development framework Spring: CVE-2022-22965 (aka Spring4Shell and SpringShell) and CVE-2022-22963.
SharkBot Android Malware Continues Popping Up on Google Play
Over the past couple of months, security researchers identified several applications in Google Play that were designed to download the SharkBot Android trojan.
Nudge Security Bags $7M Seed Round
Nudge Security, an early stage startup promising to help organizations manage cybersecurity decisions, has banked a $7 million seed round.












