Common Vulnerabilities and Exposures (CVE) stories
Following a coordinated disclosure of a zero-day vulnerability by Volexity in Atlassian Confluence, attackers went wild to exploit it.
Black Lotus Labs, the threat intelligence team at Lumen, has discovered a new, rapidly growing, multipurpose malware written in the Go programming language.
The Q2 Internet Security Report found office exploits continue to spread more than any other category of malware.
In terms of the share of vulnerabilities with publicly available exploits, three countries out of top five are located in Southeast Asia.
Trellix has announced the establishment of the Trellix Advanced Research Center to advance global threat intelligence.
FormBook is now the most prevalent malware, taking over from Emotet, which has held that position since its reappearance in January.
Rapid7 has issued a vulnerability advisory for two Baxter Healthcare TCP/IP-enabled medical devices: SIGMA Spectrum Infusion Pump and SIGMA WiFi Battery.
In 2017 the Ponemon Institute reported that fileless attacks are ten times more successful than file-based attacks.
Vulnerability disclosures impacting IoT devices increased by 57% in the first half of 2022 compared to the previous six months.
Exploit trends demonstrate the endpoint remains a target as work-from-anywhere continues, according to a new report.
Check Point Software uncovers vulnerabilities in Xiaomi's mobile payment system, potentially affecting up to 1 billion users. Fixes have been provided.
New data shows up to 75% of critical vulnerabilities could be mitigated through a rights and privileges crackdown.
Exploits for vulnerabilities in Microsoft Office have surged, accounting for 82% of total exploits in Q2 2022, according to Kaspersky.
Tenable has announced additions to Tenable Cloud Security that represent the next step in assessing threats related to cloud vulnerabilities.
Nozomi Networks' latest research reveals wiper malware, IoT botnet activity, and the Russia/Ukraine war as key threats in 2022.
Claroty's research arm (Team82) has uncovered and disclosed two critical vulnerabilities in FileWave's Mobile Device Management (MDM) system.
Aqua Security has launched out-of-the-box runtime protection with minimal configuration to stop attacks in real-time on running workloads.
Hackers are exploiting security vulnerabilities faster than ever before, with the average time to exploitation down from 42 days to just 12 days.
New Android banking malware, MaliBot, emerges following FluBot takedown. It disguises itself as crypto mining apps and targets mobile banking users.
Flashpoint launches K-12 risk management and security offering to tackle cyber and physical threats facing schools.