Security News

Critical vulnerabilities persist in high-risk sectors
2024-11-15 04:30

Finance and insurance sectors found to have the highest number of critical vulnerabilities, according to Black Duck. Finance and insurance industry faces highest vulnerabilities The report, which...

Zero-days dominate top frequently exploited vulnerabilities
2024-11-14 05:00

A joint report by leading cybersecurity agencies from the U.S., UK, Canada, Australia, and New Zealand has identified the most commonly exploited vulnerabilities of 2023. Zero-day vulnerabilities...

Patch Tuesday: Four Critical Vulnerabilities Paved Over
2024-11-13 19:55

The November 2024 Microsoft updates let Windows 11 users remap the Copilot button.

OvrC Platform Vulnerabilities Expose IoT Devices to Remote Attacks and Code Execution
2024-11-13 09:28

A security analysis of the OvrC cloud platform has uncovered 10 vulnerabilities that could be chained to allow potential attackers to execute code remotely on connected devices. "Attackers...

FBI, CISA, and NSA reveal most exploited vulnerabilities of 2023
2024-11-12 16:48

​The FBI, the NSA, and cybersecurity authorities of the Five Eyes intelligence alliance have released today a list of the top 15 routinely exploited vulnerabilities throughout last year. [...]

HPE Issues Critical Security Patches for Aruba Access Point Vulnerabilities
2024-11-11 09:57

Hewlett Packard Enterprise (HPE) has released security updates to address multiple vulnerabilities impacting Aruba Networking Access Point products, including two critical bugs that could result...

AIs Discovering Vulnerabilities
2024-11-05 12:08

I’ve been writing about the possibility of AIs automatically discovering code vulnerabilities since at least 2018. This is an ongoing area of research: AIs doing source code scanning, AIs finding...

Researchers Uncover Vulnerabilities in Open-Source AI and ML Models
2024-10-29 13:00

A little over three dozen security vulnerabilities have been disclosed in various open-source artificial intelligence (AI) and machine learning (ML) models, some of which could lead to remote code...

Exploited: Cisco, SharePoint, Chrome vulnerabilities
2024-10-25 10:25

Threat actors have been leveraging zero and n-day vulnerabilities in Cisco security appliances (CVE-2024-20481), Microsoft Sharepoint (CVE-2024-38094), and Google’s Chrome browser (CVE-2024-4947)....

Threat Actors Are Exploiting Vulnerabilities Faster Than Ever
2024-10-23 16:15

It only takes five days on average for attackers to exploit a vulnerability, according to a new report.