4 ways to keep the cybersecurity conversation going after the crisis has passed
CISO Bill Brown knows how high-profile cybersecurity breaches like SolarWinds can raise alarm bells among executives and board members when they become headline news.
Facebook is taking a more aggressive approach to shut down coordinated groups of real-user accounts engaging in certain harmful activities on its platform, using the same strategy its security teams take against campaigns using fake accounts, the company told Reuters. The new approach uses the tactics usually taken by Facebook’s security teams for wholesale shutdowns…
Five security vulnerabilities in commonly used infusion pump products from B. Braun Medical Inc. could collectively allow malicious actors to dangerously modify the dose of medicines delivered to patients, says Douglas McKee, a security researcher on a team at security vendor McAfee Enterprise, which recently discovered the flaws. The vulnerabilities exist in both the B….
Application Security , Critical Infrastructure Security , Cybercrime Security Agency Will Use Bugcrowd, EnDyna for Platform Scott Ferguson (Ferguson_Writes) • June 8, 2021 The U.S. Cybersecurity and Infrastructure Security Agency is preparing to expand its vulnerability research and disclosure program, which is now mandatory for nearly all executive branch agencies within the federal…
Cybercrime , Fraud Management & Cybercrime , Malware as-a-Service Ransomware Suspected as a Possible Reason for the Outage at Some Outlets Doug Olenick (DougOlenick) • June 4, 2021 Cox Media Group’s TV and radio affiliates’ ability to livestream content was mostly offline Thursday evening, possibly due to an unspecified cyber incident, says the…
Executive Summary Informations Name CVE-2021-20734 First vendor Publication 2021-06-22 Vendor Cve Last vendor Modification 2021-06-22 Security-Database Scoring CVSS v3 Cvss vector : N/A Overall CVSS Score NA Base Score NA Environmental Score NA impact SubScore NA Temporal Score NA Exploitabality Sub Score NA Calculate full CVSS 3.0 Vectors scores Security-Database Scoring CVSS v2 Cvss…
Following the public release of a Proof-of-Concept (PoC) exploit for a recently disclosed Atlassian Confluence Remote Code Execution (RCE) bug, cybercriminals are actively searching for and abusing it to install cryptocurrency mining malware. CVE-2021-26084 Flaw Damage According to the Atlassian security advisory, this vulnerability impacts Confluence Server and Data Center versions before version 6.13.23, from…