Security News > 2021

Attackers tried to insert backdoor into PHP source code
2021-03-29 11:20

The PHP development team has averted an attempted supply chain compromise that could have opened a backdoor into many web servers. Php.net server," developer Nikita Popov explained in a message sent out through one of the project's mailing lists.

Patch alert for Apple fans: Cybercrooks have already been exploiting this flaw in iPhones, iPads, and watches
2021-03-29 10:27

Apple has issued critical security patches for all supported phones, fondleslabs, and watches after being alerted to multiple possible intrusions by Google. According to Apple, the flaw allows for the creation of "Maliciously crafted web content," which "May lead to universal cross-site scripting." Apple has heard that the code snafu "May have been actively exploited."

Blockchain may be the machinery of mischief, but it can't help telling the truth
2021-03-29 09:32

The non-fungible bit merely means it's not the same as other NFTs so can't be considered as their equivalent nor traded as such. There is a single nugget of magic in NFT: authenticity.

Flaws in Ovarro TBox RTUs Could Open Industrial Systems to Remote Attacks
2021-03-29 08:28

As many as five vulnerabilities have been uncovered in Ovarro's TBox remote terminal units that, if left unpatched, could open the door for escalating attacks against critical infrastructures, like remote code execution and denial-of-service. TBox is an "All-in-one" solution for automation and control systems for supervisory control and data acquisition applications, with its telemetry software used for remote control and monitoring of assets in a number of critical infrastructure sectors, such as water, power, oil and gas, transportation, and process industries.

PHP's Git server hacked to add backdoors to PHP source code
2021-03-29 07:32

In the latest software supply chain attack, the official PHP Git repository was hacked and the code base tampered with. Yesterday, two malicious commits were pushed to the php-src Git repository maintained by the PHP team on their git.

Which cyberthreat should you care about most? Here’s a clue … all of them
2021-03-29 06:30

The last year has probably seen a chunk of your workforce shift to home, negating any concept of an easily defensible corporate "Perimeter" around your systems and data. Probably, have more data than ever before to worry about, as your business increasingly relies on analytics and AI. But where is that data? In a data centre? Somewhere in the cloud? On your workers' home networks and devices?

McAfee unveils MVISION CNAPP, a new security service designed to secure cloud native applications
2021-03-29 05:45

McAfee announced the general availability of McAfee MVISION Cloud Native Application Protection Platform, a new security service designed to secure cloud native applications. McAfee MVISION CNAPP is the industry's first platform that brings application and data context to converge Cloud Security Posture Management for public cloud infrastructure, and Cloud Workload Protection Platform to protect applications distributed across virtual machines, compute instances and containers.

Stop using your employees as scapegoats: Change their behavior
2021-03-29 05:24

Businesses who change risky employee behavior methodically and effectively through personalized, timely, and relevant learning will see an improvement to their overall security posture and a reduction in the number of security incidents. It stands to reason that the training and coaching offered to employees needs to meet the same level of personalization in order to effectively combat these threats and change risky habits and behaviors over time.

How do I select a bot protection solution for my business?
2021-03-29 05:00

To select a suitable bot protection solution for your business, you need to think about a variety of factors. A successful bot mitigation solution has to be effective immediately, stopping new bots and never seen before attack methods.

New Bugs Could Let Hackers Bypass Spectre Attack Mitigations On Linux Systems
2021-03-29 04:49

Cybersecurity researchers on Monday disclosed two new vulnerabilities in Linux-based operating systems that, if successfully exploited, could let attackers circumvent mitigations for speculative attacks such as Spectre and obtain sensitive information from kernel memory. While CVE-2020-27170 can be abused to reveal content from any location within the kernel memory, CVE-2020-27171 can be used to retrieve data from a 4GB range of kernel memory.