NIST details executive order’s ‘critical software’ categories — GCN

NIST details executive order’s ‘critical software’ categories — GCN

NIST details executive order’s ‘critical software’ categories By Chris Riotta Jun 28, 2021 To help agencies comply with the Biden administration’s cybersecurity executive order, the National Institute of Standards and Technology on June 25 posted a new definition of “critical software” for production systems and operational purposes. Critical software is defined as covering…

NVD – CVE-2021-32720

CVE-2021-32720 Detail Awaiting Analysis This vulnerability is currently awaiting analysis. Description Sylius is an Open Source eCommerce platform on top of Symfony. In versions of Sylius prior to 1.9.5 and 1.10.0-RC.1, part of the details (order ID, order number, items total, and token value) of all placed orders were exposed…

4 Dell Bugs Could Affect 30 Million Users

4 Dell Bugs Could Affect 30 Million Users

Application Security , Endpoint Security , Fraud Management & Cybercrime Dell Issues Security Advisory to Address Flaws Rashmi Ramesh • June 28, 2021     Researchers at security firm Eclypsium report that they have identified four vulnerabilities that could affect 30 million users of computer technology company Dell’s laptops, desktops and tablets. See Also: Live…

SolarWinds Hackers Breach Microsoft Customer Support to Target its Customers

SolarWinds Hackers Breach Microsoft Customer Support to Target its Customers

In yet another sign that the Russian hackers who breached SolarWinds network monitoring software to compromise a slew of entities never really went away, Microsoft said the threat actor behind the malicious cyber activities used password spraying and brute-force attacks in an attempt to guess passwords and gain access to its customer accounts. “This recent…

Data-Wiping Attacks Hit Outdated Western Digital Devices

Data-Wiping Attacks Hit Outdated Western Digital Devices

Breach Notification , Cybercrime , Endpoint Security Manufacturer Stopped Supporting Targeted Network-Attached Storage Devices in 2015 Mathew J. Schwartz (euroinfosec) • June 28, 2021     Screen grab posted by the owner of a LAN-connected Western Digital My Book Live after it was apparently hit by a data-wiping attack that also changed the device’s admin…

Microsoft Edge Bug Could’ve Let Hackers Steal Your Secrets for Any Site

Microsoft Edge Bug Could’ve Let Hackers Steal Your Secrets for Any Site

Microsoft Edge Bug Could’ve Let Hackers Steal Your Secrets for Any Site | IT Security News 28. June 2021 This article has been indexed from The Hacker News Microsoft last week rolled out updates for the Edge browser with fixes for two security issues, one of which concerns a security bypass vulnerability that could be exploited…

John McAfee, anti-virus software pioneer turned fugitive, dies in prison at 75

John McAfee, anti-virus software pioneer turned fugitive, dies in prison at 75

AP — John McAfee, the outlandish security software pioneer who tried to live life as a hedonistic outsider while running from a host of legal troubles, was found dead in his jail cell near Barcelona on Wednesday. His death came just hours after a Spanish court announced that it had approved his extradition to the…