On the first day of the Pwn2Own Toronto 2022 hacking competition, participants earned a total of $400,000 for new exploits targeting phones, printers, routers and NAS devices.
Over 75 Vulnerabilities Patched in Android With December 2022 Security Updates
Google this week announced the December 2022 Android updates with patches for over 75 vulnerabilities, including multiple critical remote code execution (RCE) flaws.
The most severe of the RCE bugs is CVE-2022-20411, an issue in Android’s System component that could be exploited over Bluetooth.
Iran Arrests News Agency Deputy After Reported Cyberattack
Iran has arrested the deputy chief editor of Fars news agency, state media said, more than a week after the agency was reportedly hit by a cyberattack.
“The deputy head of Fars news agency, Abbas Darvish Tavanger, has been arrested for falsifying news,” state broadcaster IRIB said late Monday.
Brazilian PAM Company Senhasegura Raises $13 Million
Brazilian privileged access management (PAM) solutions provider Senhasegura today announced that it has raised $13 million in a Series A funding round led by Graphene Ventures.
Founded in 2010 and having a market presence in over 55 countries, the Sao Paulo-based PAM vendor officially launched its North American operations in August this year.
Rackspace Confirms Ransomware Attack as It Tries to Determine If Data Was Stolen
Cloud company Rackspace has confirmed being targeted in a ransomware attack after it was forced to shut down its Hosted Exchange environment.
Rackspace’s hosted Microsoft Exchange service started experiencing problems on Friday, December 2. The company shut down the impacted environment and confirmed on Saturday that it was a security incident.
‘Scattered Spider’ Cybercrime Group Targets Mobile Carriers via Telecom, BPO Firms
A threat actor tracked as ‘Scattered Spider’ is targeting telecommunications and business process outsourcing (BPO) companies in an effort to gain access to mobile carrier networks and perform SIM swapping, cybersecurity firm CrowdStrike warns.
Several Code Execution Vulnerabilities Patched in Sophos Firewall
Sophos has informed customers that Sophos Firewall version 19.5, whose general availability was announced in mid-November, patches several vulnerabilities, including ones that can lead to arbitrary code execution.
Online Event Today: Security Operations Summit
Netgear Neutralizes Pwn2Own Exploits With Last-Minute Nighthawk Router Patches
Last week, Netgear released hotfixes for a network misconfiguration in Nighthawk RAX30 (AX2400) routers that could allow a remote attacker to gain unrestricted access to services otherwise intended for the local network.
Amnesty International Canada Says It Was Hacked by Beijing
The Canadian branch of Amnesty International said Monday it was the target of a cyberattack sponsored by China.
The human rights organization said it first detected the breach Oct. 5 and hired forensic investigators and cybersecurity experts to investigate.













