Security
Headlines
HeadlinesLatestCVEs

Tag

#microsoft

New video provides a behind-the-scenes look at Talos ransomware hunters

Apple's emergency patch, AI-generated art and more security headlines from the past week.

TALOS
#sql#vulnerability#web#ios#android#apple#google#microsoft#cisco#ddos#dos#intel#zero_day#chrome#sap
CVE-2023-31222: Paceart Optima System

Deserialization of untrusted data in Microsoft Messaging Queuing Service in Medtronic's Paceart Optima versions 1.11 and earlier on Windows allows an unauthorized user to impact a healthcare delivery organization’s Paceart Optima system cardiac device causing data to be deleted, stolen, or modified, or the Paceart Optima system being used for further network penetration via network connectivity.

From MuddyC3 to PhonyC2: Iran's MuddyWater Evolves with a New Cyber Weapon

The Iranian state-sponsored group dubbed MuddyWater has been attributed to a previously unseen command-and-control (C2) framework called PhonyC2 that's been put to use by the actor since 2021. Evidence shows that the custom made, actively developed framework has been leveraged in the February 2023 attack on Technion, an Israeli research institute, cybersecurity firm Deep Instinct said in a

3 Tips to Increase Hybrid and Multicloud Security

As cloud adoption grows, organizations need to rethink their approaches to securing hybrid cloud and multicloud environments.

Newbie Akira Ransomware Builds Momentum With Linux Shift

A new version of the double-extortion group's malware reflects a growing trend among ransomware actors to expand cybercrime opportunities beyond Windows.

UAE, Israel Ink Pivotal Joint Cyber-Threat Intelligence Agreement

Two Mideast nations that were at odds until recently have announced the "Crystal Ball" project, aimed at better protecting against cyberattacks via collaboration and knowledge sharing.

North Korean Hacker Group Andariel Strikes with New EarlyRat Malware

The North Korea-aligned threat actor known as Andariel leveraged a previously undocumented malware called EarlyRat in attacks exploiting the Log4j Log4Shell vulnerability last year. "Andariel infects machines by executing a Log4j exploit, which, in turn, downloads further malware from the command-and-control (C2) server," Kaspersky said in a new report. Also called Silent Chollima and Stonefly,

CVE-2022-23264

Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVE-2022-26899

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVE-2022-29146

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability