The DHS on Thursday announced Cybersecurity Performance Goals (CPGs) to help organizations — particularly in critical infrastructure sectors — prioritize cybersecurity investments and address critical risks.
Apple Paid Out $20 Million via Bug Bounty Program
Apple has launched a new security research blog and website, which will also be the new home of the company’s bug bounty program.
Google Releases Emergency Chrome 107 Update to Patch Actively Exploited Zero-Day
Google on Thursday released an emergency update for Chrome 107 to patch an actively exploited zero-day vulnerability.
Slovak, Polish Parliaments Hit by Cyberattacks
Cyberattacks hit the Slovak and Polish parliaments on Thursday, bringing down the voting system in Slovakia’s legislature, parliamentary authorities said.
“The attack was multi-directional, including from inside the Russian Federation,” the Polish Senate said in a statement.
New York Post ‘Hacked’ in Tweets Calling for Assassination of Biden, Lawmakers
The New York Post said Thursday it had been “hacked” by an employee after the tabloid newspaper’s Twitter account posted a series of antagonistic messages, including a call for the assassination of US President Joe Biden.
The rogue tweets were removed late Thursday morning.
Asset Risk Management Firm Sepio Raises $22 Million in Series B Funding
Asset risk management firm Sepio this week announced that it has raised $22 million in Series B funding, which brings the total raised by the company to $37 million.
The new funding round was led by U.S. Venture Partners, with additional investment from Bess Ventures, Citi Ventures, Stanford University, World Trade Ventures, and angel investors.
Versa Networks Raises $120 Million in Pre-IPO Funding Round
Secure access service edge (SASE) solutions provider Versa Networks announced on Thursday that it has raised $120 million in a pre-IPO funding round.
GitHub Account Renaming Could Have Led to Supply Chain Attacks
Checkmarx warns that attackers could have exploited the renaming of popular GitHub accounts to create malicious repositories using the vacated name and launch software supply chain attacks.
See Tickets Customer Payment Card Data Stolen by Web Skimmer
Ticketing services agency See Tickets is informing users that their payment card data was likely exposed after hackers injected skimmer code on its website.
Windows Event Log Vulnerabilities Could Be Exploited to Blind Security Products
Remote attackers could exploit two Event Log vulnerabilities in Windows to crash the Event Log application and cause a denial-of-service (DoS) condition, Varonis warns.
Event Log is an Internet Explorer-specific application that exists in all Windows iterations, due to the deep integration of the browser with the operating system.












