Skip to content

Daily Threat Intel

Menu
  • Vulnerabilities
  • Malware
  • Breaches
  • Enterprise
  • Supply Chain
  • Emerging Threats
  • Cloud
  • About us
Menu

Author: Editor DTI

NSA recommends organizations make strategic shift to memory-safe languages

Posted on November 10, 2022

Programming languages such as C and C++ rely too heavily on the programmer not making memory-related mistakes, agency says [300 words]. What: NSA says organizations should consider making a strategic shift from…

Share

Citrix discloses critical authentication bypass flaw; two other vulnerabilities

Posted on November 9, 2022

Organizations should update as soon as possible. If past is precedent, new CVE-2022-27510 flaw could be heavily targeted [286 words]. What: A critical authentication bypass vulnerability (CVE-2022-27510) is present in multiple versions…

Share

Here’s what you need to know of the 4 zero-days in Microsoft’s Nov. update

Posted on November 8, 2022

Microsoft issued patches for of 62 vulnerabilities, nine of which are “Critical” severity and 53 “Important”. Four of the vulnerabilities in Microsoft November 2022 security update are zero-day flaws that are being…

Share

Feds seize over 50K Bitcoin from underground vault and circuit board hidden in popcorn tin

Posted on November 7, 2022

Nov. 2021 seizure was valued at staggering $3.36 billion at the time [300 words]. What:  James Zhong, of Gainesville, Georgia on Nov. 4th, 2022, pleaded guilty to illegally obtaining 50,000 Bitcoin from…

Share

Black Basta ransomware operators are exploiting “PrintNightMare”, “ZeroLogon” and “NoPac” Flaws

Posted on November 3, 2022

New data that researchers at SentinelOne uncovered show that the notorious, financially-motivated FIN7 threat group may be behind—or has strong ties—to the Black Basta ransomware operation [300 words]. Why that matters: FIN7…

Share

RomCom threat actor using spoofed SolarWinds, KeePass apps to distribute RAT

Posted on November 3, 2022

Targets have been Ukraine-based but IT companies, food brokers, and food manufacturers in the U.S., Brazil, and the Philippines are also in its crosshairs, BlackBerry says [300 words]. What: The operators of…

Share

VMware patches critical authorization bypass vulnerability in Spring Security

Posted on November 2, 2022

A critical authorization rules bypass vulnerability exists in Spring Security versions 5.7.0 to 5.7.4 and versions 5.6.0 to 5.6.8. The vulnerability gives attackers a way to potentially bypass an API gateway and…

Share

Two new mobile malware threats that researchers are keeping an eye on

Posted on November 2, 2022

Organizations that have BYOD policies need to make sure personally owned mobile devices don’t offer a path into their apps and network, for attackers [277 words]. Here are the two threats Malicious…

Share

5 things to know about the bugs patched in OpenSSL version 3.0.7

Posted on November 1, 2022

The first: This isn’t Heartbleed redux [298 words]. What bugs were fixed: OpenSSL version 3.0.7 fixes two “high” severity vulnerabilities in OpenSSL versions 3.0.0 to 3.0.6. The vulnerabilities are CVE-2022-3786 an X.509…

Share

Five useful lists and tools for identifying resources with vulnerable OpenSSL in them

Posted on October 31, 2022

The OpenSSL project team will release a new version of the OpenSSL library (version 3.0.7) on Tuesday to address a critical vulnerability in version 3.0 to 3.6 of the widely used open…

Share

Posts pagination

Previous 1 … 4 5 6 … 8 Next
  • 12 Bugs in Microsoft’s April 2025 Update to Patch Now
  • NSA, CISA, Others Warn About Fast Flux Threat: Here’s Why
  • Max Severity Bug Affects MITRE Caldera Adversary Emulation Platform
  • FBI: Russia’s APT29 May Exploit These 24 vulnerabilities-Be Aware
  • Ivanti’s New 0-Days Now in CISA’s Exploit Catalog
©2025 Daily Threat Intel | Design: Newspaperly WordPress Theme