Common Vulnerabilities and Exposures (CVE) stories - Page 16

Vulnerability disclosures back to expected rates despite COVID-19 disruption
Tue, 16th Feb 2021
#
security vulnerabilities
#
risk based security
#
covid-19
Vulnerability disclosures are returning to normal levels, with 2020 on track to surpass 2019, according to a report by Risk Based Security.

Sophos unearths origin of prominent cryptominer
Fri, 22nd Jan 2021
#
firewalls
#
network infrastructure
#
network security
The cryptominer was recently discovered when attackers targeted internet-facing database servers (SQL servers), and the MrbMiner was downloaded and installed.

Check Point uncovers live Linux attack, urges users to take action
Wed, 20th Jan 2021
#
ddos
#
open source
#
cybersecurity
Ongoing cyber attacks targeting Linux systems have been discovered, with users urged to patch their systems immediately, warns Check Point Research.

Sophos named a Numbering Authority in CVE programme
Tue, 19th Jan 2021
#
firewalls
#
network infrastructure
#
network security
Sophos has become a Numbering Authority in the Common Vulnerabilities and Exposures programme, enabling it to assign CVE identification to its own products.

22 billion records exposed from breaches in 2020 — report
Fri, 15th Jan 2021
#
vpns
#
breach prevention
#
cybersecurity
The research also found that 35% of the breaches recorded by Tenable were caused by ransomware attacks, while 14% of breaches stemmed from email compromises.

Emotet remains leading malware in global threat index
Mon, 11th Jan 2021
#
malware
#
cybersecurity
#
check point software
The malware has impacted 7% of organisations globally, following a spam campaign which targeted more than 100,000 users per day during the holiday season.

GitHub hosts more than 56 million developers in 2020
Mon, 7th Dec 2020
#
martech
#
apm
#
low-code
GitHub's 2020 State of the Octoverse report reveals the latest trends in developer activity, including top languages and security vulnerabilities.

Claroty finds four vulnerabilities in Schneider Electric OT device
Thu, 19th Nov 2020
#
datacentre infrastructure
#
encryption
#
power / energy
Unmitigated vulnerabilities could give an attacker access to the device, enabling the attacker to break encryption, modify code, and run certain commands.

2020's most wanted malware: Trickbot and Emotet trojans driving spike in ransomware attacks
Tue, 10th Nov 2020
#
malware
#
ransomware
#
cybersecurity
Trickbot and Emotet are being used to distribute ransomware against hospitals globally, according to research from Check Point.

Securing SAP to ensure better operational security
Thu, 8th Oct 2020
#
cybersecurity
#
sap
#
cybersafety
Australian government warns of growing cybercrime threat; organisations' intellectual property and financial information at risk.

McAfee finds vulnerabilities in 'temi' the videoconferencing robot
Tue, 22nd Sep 2020
#
robots
#
uc
#
casb
Temi is commonly used in environments including businesses, healthcare, retail, hospitality, and other environments including the home.

Malware and email scams targeting employees spread rapidly in Q2
Fri, 18th Sep 2020
#
malware
#
vpns
#
email security
Malware exploiting a decade-old Microsoft Office vulnerability has surged by 400%, according to a study by NordVPN.

OT networks warned of vulnerabilities in CodeMeter software
Wed, 16th Sep 2020
#
iot
#
industrial iot
#
security vulnerabilities
Manufacturers using Wibu-Systems CodeMeter are urged to update to version 7.10 due to vulnerabilities that could allow attackers to take control of OT networks.

Ripple20 threat has potential for 'vast exploitation', ExtraHop researchers find
Tue, 15th Sep 2020
#
advanced persistent threat protection
#
ndr
#
healthtech
One in three IT environments vulnerable to Ripple20 cyber threat, says ExtraHop. Attackers can exploit 19 vulnerabilities in the Treck networking stack.

Ripple20 threat could affect 35% of all IT environments – ExtraHop
Mon, 14th Sep 2020
#
advanced persistent threat protection
#
healthtech
#
extrahop
The vulnerabilities have the potential to ‘ripple’ through complex software supply chains, enabling attackers to steal data or execute code.

COVID-19 related email threats pose huge risk in 2020
Mon, 31st Aug 2020
#
advanced persistent threat protection
#
trend micro
#
cyber threats
According to the company’s annual mid-year roundup report, Trend Micro blocked 8.8 million COVID-19 related threats, nearly 92% of which were email-based.

Cyber threats on the rise for industrial control systems, new research finds
Tue, 25th Aug 2020
#
advanced persistent threat protection
#
cyber threats
#
claroty
Industrial control system (ICS) vulnerabilities are increasing due to remote access, says a report by The Claroty Research Team.

Kaspersky finds zero-day exploits in Windows OS and Internet Explorer used in targeted attack
Tue, 18th Aug 2020
#
cybersecurity
#
windows
#
internet explorer
Kaspersky uncovers zero-day exploits in Windows OS and Internet Explorer used in targeted attack, prompting security patches.

42% more plaintext HTTP servers than HTTPS counterparts - report
Wed, 5th Aug 2020
#
vpns
#
datacentre infrastructure
#
cybersecurity
Rapid7 has released a report detailing the changing internet risk landscapes of 2020, and other issues facing cybersecurity teams.

VPN vulnerabilities pose serious risk to OT Networks
Thu, 30th Jul 2020
#
ddos
#
vpns
#
security vulnerabilities
Vulnerable VPN servers and clients used in critical industries have been discovered by cybersecurity firm Claroty, potentially leading to security breaches.