Zephyrnet Logo

Tag: Log4Shell

XZ Utils Scare Exposes Hard Truths in Software Security

The recent discovery of a backdoor in the XZ Utils data compression utility — present in nearly all major Linux distributions — is a...

Top News

Types of cyberthreats – IBM Blog

Types of cyberthreats - IBM Blog <!----> ...

How to detect and patch a Log4J vulnerability  – IBM Blog

How to detect and patch a Log4J vulnerability  - IBM Blog <!----> ...

WordPress plugin lets users become admins – Patch early, patch often!

by Paul Ducklin If you run a WordPress site with the Ultimate Members plugin installed, make sure you’ve updated it...

VMware patches break-and-enter hole in logging tools: update now!

by Paul Ducklin Logging software has made cyberinsecurity headlines many times before, notably in the case of the Apache Log4J...

Popular server-side JavaScript security sandbox “vm2” patches remote execution hole

by Paul Ducklin We’ve written before, back in 2022, about a code execution hole in the widely-used JavaScript sandbox system...

Tackling Software Supply Chain Issues With CNAPP

As more organizations shift to cloud-native application development to support new business features and digital transformation initiatives, software supply chain issues have become more...

Majority of Ransomware Attacks Last Year Exploited Old Bugs

Many vulnerabilities that ransomware operators used in 2022 attacks were years old and paved the way for the attackers to establish persistence and move...

Oligo Security Takes Aim at Open Source Vulnerabilities

Oligo Security launched out of stealth on Wednesday with its runtime application security platform for detecting vulnerabilities in open source components. Oligo generates a...

Key findings from the latest ESET Threat Report – Week in security with Tony Anscombe

What is behind the drop in ransomware and what should still be done for containing the ransomware scourge? Ransomware detections fell by...

PyTorch: Machine Learning toolkit pwned from Christmas to New Year

by Paul Ducklin PyTorch is one of the most popular and widely-used machine learning toolkits out there. (We’re not going...

Supply Chain Risks Got You Down? Keep Calm and Get Strategic!

The security industry collectively loses its mind when new vulnerabilities are discovered in software. OpenSSL is no exception, and two new vulnerabilities overwhelmed news...

Iranian APT Targets US With Drokbk Spyware via GitHub

A subgroup of the state-backed Iranian threat actor Cobalt Mirage is using a new custom malware dubbed "Drokbk" to attack a variety of US...

Latest Intelligence

spot_img
spot_img