Security News > 2021 > December > Week in review: Log4j new vulnerabilities, Microsoft patch bypass, 2022 e-commerce threat trends
The Log4j saga: New vulnerabilities and attack vectors discoveredThe Apache Log4j saga continues, as several new vulnerabilities have been discovered in the popular library since Log4Shell was fixed by releasing Log4j v2.15.0.
Cyber insurance trends: Insurers and insurees must adapt equally to growing threatsIn this interview with Help Net Security, Avi Bashan, CTO at Kovrr, talks about cyber insurance trends and how the growing threat landscape impacted both insurers and insurees.
CTO of Security at Salesforce talks e-commerce cybersecurity threat trends for 2022In this interview with Help Net Security, Dr. Taher Elgamal, cryptographer, infosec leader and currently the CTO of Security at Salesforce, talks about the obstacles retailers' need to overcome to increase their cybersecurity posture and his expectations for the threat landscape in 2022.
Cybersecurity budgets surge, as skills gap wreaks havoc on 2022 plansAs enterprises plan and set budgets for the new year ahead, the vast majority are expecting to channel more dollars toward enhancing their cybersecurity efforts.
Attackers bypass Microsoft patch to deliver Formbook malwareSophos Labs researchers have detected the use of a novel exploit able to bypass a patch for a critical vulnerability affecting the Microsoft Office file format.
According to the Identify Theft Resource Center, the total number of data breaches through September 2021 has already exceeded 2020 numbers by 17%. PCI SSC updates its device security standard for HSMsThe PCI SSC published the latest version of its device security standard for Hardware Security Modules.
News URL
Related news
- Microsoft Identifies Storm-0501 as Major Threat in Hybrid Cloud Ransomware Attacks (source)
- US Government, Microsoft Aim to Disrupt Russian threat actor ‘Star Blizzard’ (source)
- Microsoft October 2024 Patch Tuesday fixes 5 zero-days, 118 flaws (source)
- New Mamba 2FA bypass service targets Microsoft 365 accounts (source)
- Microsoft cleans up hot mess of Patch Tuesday preview (source)
- Patch Tuesday: Internet Explorer Vulnerabilities Still Pose a Problem (source)
- Threat Actors Are Exploiting Vulnerabilities Faster Than Ever (source)
- Microsoft SharePoint RCE flaw exploits in the wild – you've had 3 months to patch (source)
- Threat actors are stepping up their tactics to bypass email protections (source)
- Microsoft November 2024 Patch Tuesday fixes 4 zero-days, 91 flaws (source)