Skip to content

Daily Threat Intel

Menu
  • Vulnerabilities
  • Malware
  • Breaches
  • Enterprise
  • Supply Chain
  • Emerging Threats
  • Cloud
  • About us
Menu

Category: Enterprise

Russia’s Iridium group deploying new ransomware payload

Posted on November 10, 2022

Prestige ransomware marks dangerous shift in strategy for threat actor Microsoft says [299 words]. What: Security researchers at Microsoft have spotted Russia-based threat group Iridium dropping a new ransomware payload dubbed “Prestige”…

Share

NSA recommends organizations make strategic shift to memory-safe languages

Posted on November 10, 2022

Programming languages such as C and C++ rely too heavily on the programmer not making memory-related mistakes, agency says [300 words]. What: NSA says organizations should consider making a strategic shift from…

Share

VMware patches critical authorization bypass vulnerability in Spring Security

Posted on November 2, 2022

A critical authorization rules bypass vulnerability exists in Spring Security versions 5.7.0 to 5.7.4 and versions 5.6.0 to 5.6.8. The vulnerability gives attackers a way to potentially bypass an API gateway and…

Share

5 things to know about the bugs patched in OpenSSL version 3.0.7

Posted on November 1, 2022

The first: This isn’t Heartbleed redux [298 words]. What bugs were fixed: OpenSSL version 3.0.7 fixes two “high” severity vulnerabilities in OpenSSL versions 3.0.0 to 3.0.6. The vulnerabilities are CVE-2022-3786 an X.509…

Share

Five useful lists and tools for identifying resources with vulnerable OpenSSL in them

Posted on October 31, 2022

The OpenSSL project team will release a new version of the OpenSSL library (version 3.0.7) on Tuesday to address a critical vulnerability in version 3.0 to 3.6 of the widely used open…

Share

ConnectWise patches critical flaw in its Recover and R1Soft Server Backup Manager technology

Posted on October 31, 2022

Vulnerability gives attackers a way to target thousands of MSPs and their downstream customers. Company urges customers to treat issue as a top priority [298 words]. What: ConnectWise has patched a critical,…

Share

Four quick things to know about the critical bug in OpenSSL that will be disclosed Nov.1

Posted on October 31, 2022

The OpenSSL project team will release a new version of the OpenSSL library (version 3.0.7) on Tuesday to address a critical vulnerability in version 3.0 to 3.6 of the widely used open…

Share

CISA will adopt TLP version 2.0 on Nov. 1

Posted on October 26, 2022

Prepare now for move to the new version of FIRST’s standard for sharing security information [300 words]. What: Beginning Nov. 1, 2022, CISA will officially adopt version 2.0 of the Forum of…

Share

Attackers actively exploiting VMware flaw that CISA deemed as posing “unacceptable risk” in May

Posted on October 21, 2022

Multiple campaigns are using CVE-2022-22954 to drop ransomware, coin miners and Mirai [299 words]. What: Multiple malicious campaigns are actively targeting a previously disclosed and now patched remote code execution vulnerability in…

Share

Google’s open-source GUAC initiative will make information for securing the software supply chain readily available to everyone.

Posted on October 20, 2022

GUAC will allow developers, auditors, and risk management teams to evaluate risk more easily in their codebases. What: Google is seeking contributors to a new open-source project it has launched called Graph…

Share

Posts pagination

Previous 1 2 3 4 Next
  • 12 Bugs in Microsoft’s April 2025 Update to Patch Now
  • NSA, CISA, Others Warn About Fast Flux Threat: Here’s Why
  • Max Severity Bug Affects MITRE Caldera Adversary Emulation Platform
  • FBI: Russia’s APT29 May Exploit These 24 vulnerabilities-Be Aware
  • Ivanti’s New 0-Days Now in CISA’s Exploit Catalog
©2025 Daily Threat Intel | Design: Newspaperly WordPress Theme