Fewer-Than-Expected Log4j Attacks, but Mirai Joins the Fray

fewer-than-expected-log4j-attacks,-but-mirai-joins-the-fray

Log4Shell, the critical unauthenticated remote code execution vulnerability identified in early December 2021 in the Apache Log4j logging utility, hasn’t seen the mass exploitation that many expected, but an exploit for it is now part of the Mirai botnet’s arsenal, researchers warn.

read more

Cloud Security Provider Anitian Raises $55 Million

cloud-security-provider-anitian-raises-$55-million

Cloud security and compliance automation startup Anitian this week closed a $55 million Series B funding round led by Sageview Capital.

The new investment brings the total raised by Anitian $71 million and provides fresh capital to fuel ambitious expansion plans.

read more

F5 Patches Two Dozen Vulnerabilities in BIG-IP

f5-patches-two-dozen-vulnerabilities-in-big-ip

Cloud security and application delivery solutions provider F5 this week announced patches for 25 vulnerabilities affecting its BIG-IP, BIG-IQ, and NGINX products.

A total of 23 security flaws were addressed in the BIG-IP application delivery controller (ADC), including 13 high-severity issues, all of which carry a CVSS score of 7.5.

read more

Cisco Patches Critical Vulnerability in RCM for StarOS

cisco-patches-critical-vulnerability-in-rcm-for-staros

Cisco on Tuesday announced patches for a critical vulnerability in the Redundancy Configuration Manager (RCM) for the StarOS software running on its ASR 5000 networking devices.

A Cisco proprietary node/network function, RCM delivers redundancy of StarOS-based user plane functions.

read more