The US Cybersecurity and Infrastructure Security Agency (CISA) has warned organizations about two actively exploited VMware product vulnerabilities, and the agency believes two other freshly patched flaws will also be exploited soon.
US Government Says North Korean IT Workers Enable DPRK Hacking Operations
The US government has warned companies that some of their IT workers may be from North Korea, and these individuals could be aiding their country’s hacking operations.
Now Live: SecurityWeek Threat Intelligence Summit Virtual Event
National Cybersecurity Agencies Describe Commonly Used Initial Access Techniques
Cybersecurity agencies in the United States, the United Kingdom, Canada, the Netherlands, and New Zealand warn that threat actors exploit poor security practices for initial access to victim environments.
SecurityWeek to Host Threat Intelligence Summit Virtual Event on May 18th
CISA Removes Windows Vulnerability From ‘Must-Patch’ List Due to Buggy Update
The US Cybersecurity and Infrastructure Security Agency (CISA) has temporarily removed a Windows flaw from its Known Exploited Vulnerabilities Catalog after it was informed by Microsoft that a recent update can cause problems on some types of systems.
BalkanID Raises $6M for Intelligent IGA Technology
BalkanID, a startup with ambitious plans to disrupt the Identity Governance and Administration (IGA) space, has banked $5.75 million in seed funding to help organizations find and remediate risky privileges across SaaS and public cloud infrastructure.
Patch Tuesday: Microsoft Warns of New Zero-Day Being Exploited
Microsoft on Tuesday released critical software updates to fix at least 73 documented security flaws in the Windows ecosystem and warned that unknown attackers are already launching zero-day man-in-the-middle attacks.
Technical Details, IoCs Available for Actively Exploited BIG-IP Vulnerability
Indicators of compromise (IoCs) and other resources have been released to help defenders deal with the actively exploited F5 BIG-IP vulnerability tracked as CVE-2022-1388.














