Tag: security

Even the FBI says you need to patch this Atlassian Confluence bug right now

The Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), and Multi-State Information Sharing and Analysis Center (MS-ISAC) warned Atlassian Confluence server users to patch their endpoints immediately.  The warning was issued after new findings suggesting a recently discovered flaw – CVE-2023-22515 – is being actively exploited in…

Read More

Another major WordPress security flaw has been discoverd – so patch now

A zero-day vulnerability was recently discovered in a highly popular add-on for the WordPress website builder, potentially putting at risk some 200,000 people who are using it.  Cybersecurity researchers from Wordfence and WPScan (both WordPress security firms) discovered the vulnerability in Royal Elementor Addons and Templates, a website-building add-on kit…

Read More

Cisco reports major security flaw, users urged to patch immediately

Hackers are exploiting a critical vulnerability in some Cisco devices to gain full admin control of entire networks, the company has revealed..  In a security advisory from its Talos research team, the company urged users to apply the newly released patch without hesitation. The vulnerability is found in the Web…

Read More

Hacked Skype accounts are being used to spread malware

Hackers are reportedly abusing compromised Skype accounts in an attempt to distribute the DarkGate malware. In a new report, Trend Micro researchers claimed multiple Skype accounts had been  compromised and then used to share a VBA loader script attachment. The script’s file name was modified in such a way to…

Read More

Microsoft is killing off this authentication protocol in Windows – here’s why

Microsoft is stripping Windows 11 users of an old protocol that authenticates remote users. The New Technology LAN Manager (NTLM) was effectively usurped by Kerberos, the MIT-developed cross-platform tool which works as the authentication protocol for any version of Windows since Windows 2000.  In fact, Microsoft even recommended users refrain…

Read More

A worrying amount of corporate IDs still aren’t properly protected

A shockingly high proportion corporate identities are not properly protected, a new report from SailPoint has found – a particularly worrying finding as 90% of all cybersecurity breaches are reportedly identity-related. To better understand the state of enterprise identity security, SailPoint recently polled roughly 375 global cybersecurity executives across the…

Read More