Security News

Windows 10 KB5039299 update released with 10 changes or fixes
2024-06-26 14:32

The June 2024 optional update for Windows 10 is now available. Today's update brings KB5039299 for Windows 10 version 22H2 with up to ten bug fixes or changes.

Snowblind malware abuses Android security feature to bypass security
2024-06-26 13:33

A novel Android attack vector from a piece of malware tracked as Snowblind is abusing a security feature to bypass existing anti-tampering protections in apps that handle sensitive user data. [...]

Batten down the hatches, it's time to patch some more MOVEit bugs
2024-06-26 13:32

Your profile can be used to present content that appears more relevant based on your possible interests, such as by adapting the order in which content is shown to you, so that it is even easier for you to find content that matches your interests. Information regarding which content is presented to you and how you interact with it can be used to determine whether the content e.g. reached its intended audience and matched your interests.

Malware peddlers experimenting with BPL sideloading and masking malicious payloads as PGP keys
2024-06-26 12:34

"The LNK file triggered the first element of the novel technique used in this infection chain for distributing IDAT Loader. The LNK file was using mshta.exe to execute what appeared to be a 'PGP Secret Key,' hosted again on Bunny CDN," Kroll's threat analysts found. Static analysis of that file showed that it was not a PGP key, but a combination of junk bytes, an embedded HTA file and an embedded EXE file.

The 6 Best LastPass Alternatives for 2024
2024-06-26 12:30

Looking for LastPass alternatives? Check out our list of the top password managers that offer secure and convenient options for managing your passwords.

Fortinet vs Palo Alto (2024): Which NGFW Is Best for Your Team?
2024-06-26 12:00

As two top NGFWs, Fortinet FortiGate seems to best fit small businesses, while Palo Alto works best for larger organizations. Find out in our comparison below.

Developer errors lead to long-term exposure of sensitive data in Git repos
2024-06-26 12:00

By scanning the most popular 100 organizations on GitHub, which collectively includes more than 50,000 publicly accessible repositories, researchers found active secrets from open source organizations and enterprises such as Cisco and Mozilla providing access to sensitive data and software. The exposed secrets could lead to significant financial losses, reputational damage, and legal consequences.

The US Is Banning Kaspersky
2024-06-26 11:06

The Biden administration on Thursday said it's banning the company from selling its products to new US-based customers starting on July 20, with the company only allowed to provide software updates to existing customers through September 29. The ban-­the first such action under authorities given to the Commerce Department in 2019­-follows years of warnings from the US intelligence community about Kaspersky being a national security threat because Moscow could allegedly commandeer its all-seeing antivirus software to spy on its customers.

Chinese and N. Korean Hackers Target Global Infrastructure with Ransomware
2024-06-26 10:13

Threat actors with suspected ties to China and North Korea have been linked to ransomware and data encryption attacks targeting government and critical infrastructure sectors across the world...

Practical Guidance For Securing Your Software Supply Chain
2024-06-26 09:52

The heightened regulatory and legal pressure on software-producing organizations to secure their supply chains and ensure the integrity of their software should come as no surprise. In the last...