Security
Headlines
HeadlinesLatestCVEs

Tag

#intel

Mastercard Launches Next-Generation Identity Technology with Microsoft

New 'trust' tool improves online experience and helps tackle digital fraud.

DARKReading
#microsoft#git#intel#auth
CVE-2022-29417: ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization

Plugin Settings Update vulnerability in ShortPixel's ShortPixel Adaptive Images plugin <= 3.3.1 at WordPress allows an attacker with a low user role like a subscriber or higher to change the plugin settings.

Trend Micro Launches New Security Platform

An ecosystem of native and third-party integrations provides visibility and control across the entire attack surface.

CVE-2021-45841: How to summon RCEs

In Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517), an attacker can self-sign session cookies by knowing the target's MAC address and the user's password hash. Guest users (disabled by default) can be abused using a null/empty hash and allow an unauthenticated attacker to login as guest.

CVE-2022-29264: cpu/x86/smm: Introduce SMM module loader version 2 · coreboot/coreboot@afb7a81

An issue was discovered in coreboot 4.13 through 4.16. On APs, arbitrary code execution in SMM may occur.

Many Medical Device Makers Skimp on Security Practices

Barely over a quarter of medical device companies surveyed maintain a software bill-of-materials, and less than half set security requirements at the design stage.

Sophos Buys Alert-Monitoring Automation Vendor

Acquisition of cloud-based alert security company will help Sophos automate tasks bogging down security teams, the company says.

Forescout Enhances Continuum Platform With New OT Capabilities

New capabilities enable improved OT and IoT asset visibility along with data-powered threat detection and cost-effective deployments at scale.