Enterprise

Enterprise Vulnerabilities

VMware patches critical authorization bypass vulnerability in Spring Security

A critical authorization rules bypass vulnerability exists in Spring Security versions 5.7.0 to 5.7.4 and versions 5.6.0 to 5.6.8. The vulnerability gives attackers a way to potentially bypass an API gateway and access backend services with a simple “forward” [299 words]. What: VMware released Spring Security 5.6.9 and 5.7.5 on October 31 to fix the […]

Read More
Enterprise Vulnerabilities

5 things to know about the bugs patched in OpenSSL version 3.0.7

The first: This isn’t Heartbleed redux [298 words]. What bugs were fixed: OpenSSL version 3.0.7 fixes two “high” severity vulnerabilities in OpenSSL versions 3.0.0 to 3.0.6. The vulnerabilities are CVE-2022-3786 an X.509 Email Address Variable Length Buffer Overflow and CVE-2022-3602, an X.509 Email Address 4-byte Buffer Overflow. The bugs are tied to a punycode decoding […]

Read More
Emerging Threats Enterprise Vulnerabilities

Five useful lists and tools for identifying resources with vulnerable OpenSSL in them

The OpenSSL project team will release a new version of the OpenSSL library (version 3.0.7) on Tuesday to address a critical vulnerability in version 3.0 to 3.6 of the widely used open source, command-line toolkit [184 words]. Five useful tools and lists for keeping on top of the OpenSSL vulnerability to be disclosed Nov 1. […]

Read More
Enterprise Supply Chain Vulnerabilities

ConnectWise patches critical flaw in its Recover and R1Soft Server Backup Manager technology

Vulnerability gives attackers a way to target thousands of MSPs and their downstream customers. Company urges customers to treat issue as a top priority [298 words]. What: ConnectWise has patched a critical, remote code execution vulnerability in its ConnectWise Recover and R1Soft Server Backup Manager (SBM) software. The flaw exists in ConnectWise Recover SBM v2.9.7 […]

Read More
Emerging Threats Enterprise Vulnerabilities

Four quick things to know about the critical bug in OpenSSL that will be disclosed Nov.1

The OpenSSL project team will release a new version of the OpenSSL library (version 3.0.7) on Tuesday to address a critical vulnerability in version 3.0 to 3.6 of the widely used open source, command-line toolkit [296 words]. Four key things to know: Impact will likely be wide: The OpenSSL team rates a vulnerability as “Critical” […]

Read More
Enterprise

CISA will adopt TLP version 2.0 on Nov. 1

Prepare now for move to the new version of FIRST’s standard for sharing security information [300 words]. What: Beginning Nov. 1, 2022, CISA will officially adopt version 2.0 of the Forum of Incident Response and Security Teams (FIRST) Traffic Light Protocol (TLP) standard to facilitate information sharing among cybersecurity incident response teams. TLP 2.0 will […]

Read More
Breaches Enterprise Vulnerabilities

Attackers actively exploiting VMware flaw that CISA deemed as posing “unacceptable risk” in May

Multiple campaigns are using CVE-2022-22954 to drop ransomware, coin miners and Mirai [299 words]. What: Multiple malicious campaigns are actively targeting a previously disclosed and now patched remote code execution vulnerability in VMware Workspace ONE Access and Identity Manager (CVE-2022-22954). Researchers from Fortinet’s FortiGuard Labs on Thursday said they had observed threat actors exploiting the […]

Read More
Enterprise Supply Chain

Google’s open-source GUAC initiative will make information for securing the software supply chain readily available to everyone.

GUAC will allow developers, auditors, and risk management teams to evaluate risk more easily in their codebases. What: Google is seeking contributors to a new open-source project it has launched called Graph for Understanding Artifact Composition or GUAC. The goal of the effort, according to the company is to democratize the availability of software build, […]

Read More
Enterprise Vulnerabilities

HelpSystems releases Cobalt Strike 4.7.2 to address new RCE vulnerability

Out-of-band update addresses an issue for which IBM X-Force researchers had wanted a new CVE, but which HelpSystems says is not specific to its software [300 words] What: HelpSystems on October 17 released Cobalt Strike 4.7.2, an OOB update to fix an RCE vulnerability reported to it by IBM’s X-Force threat intelligence team. IBM’s researchers […]

Read More
Enterprise

California, Texas tops list of states with most cybersecurity job openings

For the year ended Sept. 2022 employers listed close to 770K job openings for cybersecurity professionals.  Security analysts, pen-testers were among top required skills. CyberSeek’s interactive map shows the states and metro regions with the greatest number of job opportunities for information security professionals. What: CyberSeek in collaboration with CompTIA, the National Initiative for Cybersecurity […]

Read More