Software maker Adobe has rolled out a major security update for its flagship Acrobat and Reader products to fix at least 22 documented vulnerabilities, some serious enough to cause arbitrary code execution attacks.
Free Decryptors Released for AstraLocker Ransomware
Cybersecurity firm Emsisoft has released free decryptor tools for AstraLocker, a “smash-and-grab” ransomware family that was recently retired.
The History and Evolution of Zero Trust

“The term ‘zero trust’ is now used so much and so widely that it has almost lost its meaning”
CEO Accused of Making Millions via Sale of Fake Cisco Devices
The US Department of Justice announced on Friday that a man has been arrested and charged for allegedly selling fraudulent and counterfeit Cisco products.
10 Vulnerabilities Found in Widely Used Robustel Industrial Routers
Cisco’s Talos threat intelligence and research unit has identified several critical vulnerabilities in a widely used industrial cellular IoT gateway made by Chinese company Robustel.
OpenSSL Patches Remote Code Execution Vulnerability
OpenSSL has issued an urgent advisory to warn of a memory corruption vulnerability that exposes servers to remote code execution attacks.
The vulnerability, tracked as CVE-2022-2274, was introduced in OpenSSL 3.0.4 and could potentially allow malicious hackers to launch remote code attacks on unpatched SSL/TLS server side devices.
As Cybercriminals Recycle Ransomware, They’re Getting Faster
Hackers Using ‘Brute Ratel C4’ Red-Teaming Tool to Evade Detection
The Brute Ratel C4 (BRc4) red-teaming and adversarial attack simulation tool has been used by nation-state attackers to evade detection, according to security researchers at Palo Alto Networks.
Apple Adds ‘Lockdown Mode’ to Thwart .Gov Mercenary Spyware
Faced with a surge in state-sponsored mercenary spyware attacks targeting its flagship iOS platform, Apple plans to add a new ‘Lockdown Mode’ that significantly reduces attack surface and adds technical roadblocks to limit sophisticated software exploits.
Researchers Flag ‘Significant Escalation’ in Software Supply Chain Attacks
Security researchers at ReversingLabs are warning of a “significant escalation in software supply chain attacks” after discovering more than two dozen malicious NPM packages siphoning user data from mobile and desktop applications.












