SecurityBrief UK - Technology news for CISOs & cybersecurity decision-makers

Common Vulnerabilities and Exposures (CVE) stories - Page 15

Cybersecurity8

Sophos named a Numbering Authority in CVE programme

Tue, 19th Jan 2021
#
firewalls
#
network infrastructure
#
network security
Sophos has become a Numbering Authority in the Common Vulnerabilities and Exposures programme, enabling it to assign CVE identification to its own products.
Gettyimages 811239600

Emotet remains leading malware in global threat index

Mon, 11th Jan 2021
#
malware
#
cybersecurity
#
check point software
The malware has impacted 7% of organisations globally, following a spam campaign which targeted more than 100,000 users per day during the holiday season.
Gettyimages 1194430840

GitHub hosts more than 56 million developers in 2020

Mon, 7th Dec 2020
#
martech
#
supply chain
#
apm
GitHub's 2020 State of the Octoverse report reveals the latest trends in developer activity, including top languages and security vulnerabilities.
Gettyimages 473158924

Claroty finds four vulnerabilities in Schneider Electric OT device

Thu, 19th Nov 2020
#
datacentre infrastructure
#
encryption
#
power / energy
Unmitigated vulnerabilities could give an attacker access to the device, enabling the attacker to break encryption, modify code, and run certain commands.
Gettyimages 465135327

McAfee finds vulnerabilities in 'temi' the videoconferencing robot

Tue, 22nd Sep 2020
#
robots
#
uc
#
casb
Temi is commonly used in environments including businesses, healthcare, retail, hospitality, and other environments including the home.
Gettyimages 1152389612

Malware and email scams targeting employees spread rapidly in Q2

Fri, 18th Sep 2020
#
malware
#
vpns
#
email security
Malware exploiting a decade-old Microsoft Office vulnerability has surged by 400%, according to a study by NordVPN.
Gettyimages 586063360

OT networks warned of vulnerabilities in CodeMeter software

Wed, 16th Sep 2020
#
iot
#
iiot
#
security vulnerabilities
Manufacturers using Wibu-Systems CodeMeter are urged to update to version 7.10 due to vulnerabilities that could allow attackers to take control of OT networks.
Gettyimages 1054070700

Ripple20 threat has potential for 'vast exploitation', ExtraHop researchers find

Tue, 15th Sep 2020
#
advanced persistent threat protection
#
supply chain
#
ndr
One in three IT environments vulnerable to Ripple20 cyber threat, says ExtraHop. Attackers can exploit 19 vulnerabilities in the Treck networking stack.
Gettyimages 1155157574

Ripple20 threat could affect 35% of all IT environments – ExtraHop

Mon, 14th Sep 2020
#
advanced persistent threat protection
#
supply chain
#
healthtech
The vulnerabilities have the potential to 'ripple' through complex software supply chains, enabling attackers to steal data or execute code.
Trend micro

COVID-19 related email threats pose huge risk in 2020

Mon, 31st Aug 2020
#
advanced persistent threat protection
#
trend micro
#
cyber threat
According to the company's annual mid-year roundup report, Trend Micro blocked 8.8 million COVID-19 related threats, nearly 92% of which were email-based.
Gettyimages 1141007335

Cyber threats on the rise for industrial control systems, new research finds

Tue, 25th Aug 2020
#
advanced persistent threat protection
#
cyber threat
#
claroty
Industrial control system (ICS) vulnerabilities are increasing due to remote access, says a report by The Claroty Research Team.
Gettyimages 1185282377

Kaspersky finds zero-day exploits in Windows OS and Internet Explorer used in targeted attack

Tue, 18th Aug 2020
#
cybersecurity
#
windows
#
internet explorer
Kaspersky uncovers zero-day exploits in Windows OS and Internet Explorer used in targeted attack, prompting security patches.
Cybersecurity10

42% more plaintext HTTP servers than HTTPS counterparts - report

Wed, 5th Aug 2020
#
vpns
#
datacentre infrastructure
#
cybersecurity
Rapid7 has released a report detailing the changing internet risk landscapes of 2020, and other issues facing cybersecurity teams.
Gettyimages 473158924

VPN vulnerabilities pose serious risk to OT Networks

Thu, 30th Jul 2020
#
ddos
#
vpns
#
security vulnerabilities
Vulnerable VPN servers and clients used in critical industries have been discovered by cybersecurity firm Claroty, potentially leading to security breaches.
Close up key keyboard 39389

DNS recursive resolvers vulnerability can launch DDoS attacks against any victim

Fri, 5th Jun 2020
#
ddos
#
radware
#
cyber attacks
A newly discovered vulnerability in DNS resolvers, dubbed NXNSAttack, enables cybercriminals to launch highly amplified DDoS attacks, warns Radware.
Gettyimages 473158924

Cisco ASA firewall users urged to patch systems now

Mon, 11th May 2020
#
firewalls
#
network infrastructure
#
network security
Since early January 2020, the number of internet-accessible Cisco ASA devices considered vulnerable has jumped from 170,000 to 220,000.
Iot12

COVID-19: How analysis of IoT devices highlights our changing behaviour

Thu, 7th May 2020
#
data analytics
#
martech
#
iot
COVID-19 has reshaped consumer and enterprise behaviour, as revealed by ExtraHop's IoT device analysis, highlighting long-term security risks.
Motherboard

Unfixable vulnerability found in Intel chipsets 'impossible' to detect

Mon, 9th Mar 2020
#
semiconductors
#
cybersecurity
#
intel
Positive Technologies says it is 'impossible' to detect this kind of key breach, and no firmware updates can fix the vulnerability.
Malware skull

Cyber-gangs using SSH identities to sell on the black market

Mon, 17th Feb 2020
#
malware
#
advanced persistent threat protection
#
cybersecurity
Only 10% of organisations believe they have complete and accurate intelligence over all SSH machine identities.
Cybersecurity breach

15,000 companies still critically vulnerable from Citrix security flaws - report

Fri, 7th Feb 2020
#
malware
#
virtualisation
#
hyperscale
More than a month after a critical Citrix software flaw endangered 80,000 firms globally, new data reveals 15,000 companies remain at high risk.