War in Ukraine is making firms more anxious
Social media firm claims its systems were not compromised
This time last year, we wrote about the more than 190 Trail of Bits-authored pull requests that were merged into non-Trail of Bits repositories in 2021. In 2022, we continued that trend by having more than 400 pull requests merged into non-Trail of Bits repositories! Why is this significant? While w...
It's still unclear whether customer data has been compromised
The group began operations as early as mid-2021, but its activity increased in mid-to-late 2022
Andrew A explains what you must check before giving Managed Service Providers (MSPs) the keys to your kingdom.
The attack also affected IT financial industry solutions developer Bankdata
The leaked files include some 120,000 files, with specific allegations of child abuse
Le district scolaire de Des Moines a été victime d'une cyberattaque en janvier 2023. Près de 6 700 personnes ont été informées de l'incident et de la possible exposition de leurs données personnelles. Des mesures de sécurité ont été prises pour empêcher de futures attaques similaires. Les personnes...
Customer and employee data accounts for almost half all stolen data while credit cards and password see a decline
Veracode’s 2023 State of Software Security Report is focused on flaw introduction
Known Issues
AuthPoint external identity does not sync users
Cannot configure a link aggregation interface to use both built-in and interface module 10G SFP ports (M590/M690)
Cannot fully uninstall the DNSWatchGO client through Group Policy Object (GPO)
HTTPS Proxy no longer works on a Firebox in B...
Microsoft's January Patch Tuesday resolved over 100 CVEs, including an actively exploited zero day
WhatsApp can now sue for damages ensued by the installation of the Pegasus spyware
There is a combination of lesser known tools and techniques to capture and later decrypt SSL/TLS network traffic on Windows. This technique is neat because it does not require the installation of additional driver/software when capturing the traffic.
Technique, Tools and Steps It is quite straight f...
An attacker could perform RCE on a server verifying a maliciously crafted JWT request
Called “default setup,” the novel capability simplifies starting code scanning on repositories
OSCP Reborn - 2023 Exam Preparation Guide Prologue Many of you are likely aware that the Offensive Security Certified Professional Exam was revised, with the changes officially published on January 11, 2022. The old version of the exam required the student to perform a buffer overflow attack (it sti...
The NCSC’s new Funded Cyber Essentials Programme will support SMEs as well as charities
A Ukrainian official revealed that evidence of Russian cyber-attacks are being gathered to support potential war crime prosecutions