Uncategorized

Nasty regreSSHion bug in OpenSSH puts around 700K Linux boxes at risk

Nasty regreSSHion bug in OpenSSH puts around 700K Linux boxes at risk 2024-07-01 at 17:16 By Connor Jones Full system takeovers on the cards, for those with enough patience to pull it off Glibc-based Linux systems are vulnerable to a new bug (CVE-2024-6387) in OpenSSH’s server (sshd) and should upgrade to the latest version.… This

Nasty regreSSHion bug in OpenSSH puts around 700K Linux boxes at risk Read More »

Indian Software Firm’s Products Hacked to Spread Data-Stealing Malware

Indian Software Firm’s Products Hacked to Spread Data-Stealing Malware 2024-07-01 at 16:16 By Installers for three different software products developed by an Indian company named Conceptworld have been trojanized to distribute information-stealing malware. The installers correspond to Notezilla, RecentX, and Copywhiz, according to cybersecurity firm Rapid7, which discovered the supply chain compromise on June 18,

Indian Software Firm’s Products Hacked to Spread Data-Stealing Malware Read More »

CapraRAT Spyware Disguised as Popular Apps Threatens Android Users

CapraRAT Spyware Disguised as Popular Apps Threatens Android Users 2024-07-01 at 16:16 By The threat actor known as Transparent Tribe has continued to unleash malware-laced Android apps as part of a social engineering campaign to target individuals of interest. “These APKs continue the group’s trend of embedding spyware into curated video browsing applications, with a

CapraRAT Spyware Disguised as Popular Apps Threatens Android Users Read More »

Clockwork Blue: Automating Security Defenses with SOAR and AI

Clockwork Blue: Automating Security Defenses with SOAR and AI 2024-07-01 at 16:01 By David Broggy It’s impractical to operate security operations alone, using manual human processes. Finding opportunities to automate SecOps is an underlying foundation of Zero Trust and an essential architecture component for enterprise-scale SOCs. Let’s discuss what SOAR is, its common uses, and

Clockwork Blue: Automating Security Defenses with SOAR and AI Read More »

Asda kisses Walmart goodbye with half a billion dollar tech breakup bill

Asda kisses Walmart goodbye with half a billion dollar tech breakup bill 2024-07-01 at 15:31 By Lindsay Clark Project including SAP upgrade beset by cost increases and delays The UK’s third-largest grocery retailer has spent £430 million ($544 million) on its IT separation from US giant Walmart.… This article is an excerpt from The Register

Asda kisses Walmart goodbye with half a billion dollar tech breakup bill Read More »

End-to-End Secrets Security: Making a Plan to Secure Your Machine Identities

End-to-End Secrets Security: Making a Plan to Secure Your Machine Identities 2024-07-01 at 15:01 By At the heart of every application are secrets. Credentials that allow human-to-machine and machine-to-machine communication. Machine identities outnumber human identities by a factor of 45-to-1 and represent the majority of secrets we need to worry about. According to CyberArk’s recent

End-to-End Secrets Security: Making a Plan to Secure Your Machine Identities Read More »

New OpenSSH Vulnerability Could Lead to RCE as Root on Linux Systems

New OpenSSH Vulnerability Could Lead to RCE as Root on Linux Systems 2024-07-01 at 15:01 By OpenSSH maintainers have released security updates to contain a critical security flaw that could result in unauthenticated remote code execution with root privileges in glibc-based Linux systems. The vulnerability has been assigned the CVE identifier CVE-2024-6387. It resides in

New OpenSSH Vulnerability Could Lead to RCE as Root on Linux Systems Read More »

Juniper Networks flings out emergency patches for perfect 10 router vuln

Juniper Networks flings out emergency patches for perfect 10 router vuln 2024-07-01 at 14:46 By Connor Jones Get ’em while they’re hot A critical vulnerability affecting Juniper Networks routers forced the vendor to issue emergency patches last week, and users are advised to apply them as soon as possible.… This article is an excerpt from

Juniper Networks flings out emergency patches for perfect 10 router vuln Read More »

Poyfill.io claims reveal new cracks in supply chain, but how deep do they go?

Poyfill.io claims reveal new cracks in supply chain, but how deep do they go? 2024-07-01 at 13:37 By Rupert Goodwins There will always be bad actors in the system. We can always learn from the drama they create Opinion  Libraries. Hushed temples to the civilizing power of knowledge, or launchpads of global destruction? Yep, another

Poyfill.io claims reveal new cracks in supply chain, but how deep do they go? Read More »

CISA director: US is ‘not afraid’ to shout about Big Tech’s security failings

CISA director: US is ‘not afraid’ to shout about Big Tech’s security failings 2024-07-01 at 12:47 By Connor Jones Jen Easterly hopes CSRB’s Microsoft report won’t impede future private sector collaboration CISA director Jen Easterly says the Cybersecurity Safety Review Board (CSRB) “is not afraid to say when something is amiss” in response to questions

CISA director: US is ‘not afraid’ to shout about Big Tech’s security failings Read More »

What do CTOs hate most about GenAI? Tool changes that break stuff

What do CTOs hate most about GenAI? Tool changes that break stuff 2024-07-01 at 11:46 By Lindsay Clark With so many DB vendors to choose from, our vulture claws over the bewildering choices DataStax recently joined a growing band of database specialists in launching new tooling with the promise of helping customers build GenAI apps

What do CTOs hate most about GenAI? Tool changes that break stuff Read More »

Juniper Networks Releases Critical Security Update for Routers

Juniper Networks Releases Critical Security Update for Routers 2024-07-01 at 10:01 By Juniper Networks has released out-of-band security updates to address a critical security flaw that could lead to an authentication bypass in some of its routers. The vulnerability, tracked as CVE-2024-2973, carries a CVSS score of 10.0, indicating maximum severity. “An Authentication Bypass Using

Juniper Networks Releases Critical Security Update for Routers Read More »

Chinese space company accidentally launches rocket in test gone wrong

Chinese space company accidentally launches rocket in test gone wrong 2024-07-01 at 09:31 By Simon Sharwood 10, 9, 8 … hang on, did anyone check we bolted this thing down properly? Private Chinese launch outfit Space Pioneer has launched a rocket by mistake.… This article is an excerpt from The Register View Original Source

Chinese space company accidentally launches rocket in test gone wrong Read More »

Police allege ‘evil twin’ of in-flight Wi-Fi used to steal passenger’s credentials

Police allege ‘evil twin’ of in-flight Wi-Fi used to steal passenger’s credentials 2024-07-01 at 09:02 By Simon Sharwood Fasten your seat belts, secure your tray table, and try not to give away your passwords Australia’s Federal Police (AFP) has charged a man with running a fake Wi-Fi networks on at least one commercial flight and

Police allege ‘evil twin’ of in-flight Wi-Fi used to steal passenger’s credentials Read More »

Indonesian government didn’t have backups of ransomwared data, because DR was only an option

Indonesian government didn’t have backups of ransomwared data, because DR was only an option 2024-07-01 at 08:02 By Laura Dobberstein President has ordered a datacenter audit and made backups mandatory Indonesia’s president Joko Widodo has ordered an audit of government datacenters after it was revealed that most of the data they store is not backed

Indonesian government didn’t have backups of ransomwared data, because DR was only an option Read More »

Alibaba Cloud closing Australian and Indian datacenters

Alibaba Cloud closing Australian and Indian datacenters 2024-07-01 at 03:31 By Simon Sharwood Prioritizing Mexico and Southeast Asia Alibaba Cloud has revealed that it will soon close its datacenter operations in Australia and India – despite previously telling The Register its Australian operations remained intact.… This article is an excerpt from The Register View Original

Alibaba Cloud closing Australian and Indian datacenters Read More »

Scroll to Top