[Ebook] The Guide for Speeding Time to Response for Lean IT Security Teams

Blog WriterThe Hacker News - Original news source is thehackernews.com

Most cyber security today involves much more planning, and much less reacting than in the past. Security teams spend most of their time preparing their organizations’ defenses and doing operational …

New 0-Day Attack Targeting Windows Users With Microsoft Office Documents

Blog WriterThe Hacker News - Original news source is thehackernews.com

Microsoft on Tuesday warned of an actively exploited zero-day flaw impacting Internet Explorer that’s being used to hijack vulnerable Windows systems by leveraging weaponized Office documents. Tracked as CVE-2021-40444 (CVSS …

Latest Atlassian Confluence Flaw Exploited to Breach Jenkins Project Server

Blog WriterThe Hacker News - Original news source is thehackernews.com

The maintainers of Jenkins—a popular open-source automation server software—have disclosed a security breach after unidentified threat actors gained access to one of their servers by exploiting a recently disclosed vulnerability …

ProtonMail Shares Activist’s IP Address With Authorities Despite Its “No Log” Claims

Blog WriterThe Hacker News - Original news source is thehackernews.com

End-to-end encrypted email service provider ProtonMail has drawn criticism after it ceded to a legal request and shared the IP address of anti-gentrification activists with law enforcement authorities, leading to their arrests in …

Critical Auth Bypass Bug Affect NETGEAR Smart Switches — Patch and PoC Released

Blog WriterThe Hacker News - Original news source is thehackernews.com

Networking, storage and security solutions provider Netgear on Friday issued patches to address three security vulnerabilities affecting its smart switches that could be abused by an adversary to gain full control of …

Microsoft Says Chinese Hackers Were Behind SolarWinds Serv-U SSH 0-Day Attack

Blog WriterThe Hacker News - Original news source is thehackernews.com

Microsoft has shared technical details about a now-fixed, actively exploited critical security vulnerability affecting SolarWinds Serv-U managed file transfer service that it has attributed with “high confidence” to a threat …

Apple Delays Plans to Scan Devices for Child Abuse Images After Privacy Backlash

Blog WriterThe Hacker News - Original news source is thehackernews.com

Apple is temporarily hitting the pause button on its controversial plans to screen users’ devices for child sexual abuse material (CSAM) after receiving sustained blowback over worries that the tool could be …

U.S. Cyber Command Warns of Ongoing Attacks Exploiting Atlassian Confluence Flaw

Blog WriterThe Hacker News - Original news source is thehackernews.com

The U.S. Cyber Command on Friday warned of ongoing mass exploitation attempts in the wild targeting a now-patched critical security vulnerability affecting Atlassian Confluence deployments that could be abused by …