Researchers Scan for Supply-Side Threats in Open Source
A recent project to scan the main Python repository's 268,000 packages found only a few potentially malicious programs, but work earlier this year uncovered hundreds of instances of malware.Open...
EFF, Security Experts Condemn Politicization of Election Security
Enterprise VulnerabilitiesFrom DHS/US-CERT's National Vulnerability Database
CVE-2020-28092PUBLISHED: 2020-11-17PESCMS Team 2.3.2 has multiple reflected XSS via the id parameter:?g=Team&m=Task&a=my&status=3&id=,?g=Team&m=Task&a=my&status=0&id=,?g=Team&m=Task&a=my&status=1&id=,?g=Team&m=Task&a=my&status=10&id=
CVE-2020-28914PUBLISHED: 2020-11-17
An improper file permissions vulnerability affects Kata Containers prior to 1.11.5. When...
Malsmoke operators abandon exploit kits in favor of social engineering scheme
Threat actors behind malsmoke, one of the largest malvertising campaigns we've seen in recent months, have switched malware delivery tactics.
Exploit kits continue to be used as a malware...
A Call for Change in Physical Security
We're at an inflection point. The threats we face are dynamic, emerging, and global. Are you ready?Despite dedicating the majority of my life to protective intelligence in the private...
Breakdown of a Break-in: A Manufacturer’s Ransomware Response
The analysis of an industrial ransomware attack reveals common tactics and proactive steps that businesses can take to avoid similar incidents.While no two organizations are the same, they can...
CISA Director Expects to Be Fired Following Secure Election
Meanwhile, key legislators and former DHS officials are speaking out in support of CISA director Chris Krebs, who has led the agency's efforts in election security.Kelly Jackson Higgins contributed...
Apple Issues Security Updates
Enterprise VulnerabilitiesFrom DHS/US-CERT's National Vulnerability Database
CVE-2020-15481PUBLISHED: 2020-11-13
An issue was discovered in PassMark BurnInTest v9.1 Build 1008, OSForensics v7.1 Build 1012, and PerformanceTest v10.0 Build 1008. The kernel driver exposes...
Credential Stuffing Fills E-commerce Pipeline in 2020
There were 1.3 billion attacks in the third quarter alone, according to new analysis from Arkose Labs.The pandemic-driven consumer shift to digital commerce has been accompanied by a similar...
Manufacturing Sees Rising Ransomware Threat
Crypto-ransomware groups are increasingly adopting malware and tools that can probe and attack operational technology, such as industrial control systems, according to an assessment of current threats.Ransomware groups are...
Security Hiring Plans Remain Constant Despite Pandemic
Although we saw workforce gains this year, 56% of businesses surveyed report staff shortages are putting their organization at risk.Enterprise plans to increase cybersecurity staff remain constant despite the...