Friday , January 3 2025

International

Microsoft Issues CVE Numbers for Cloud Service Vulnerabilities

Microsoft

Microsoft will assign Common Vulnerabilities and Exposures (CVE) numbers to important vulnerabilities found and fixed in their cloud services. This improves transparency and security by publicly disclosing vulnerabilities that can be fixed without user intervention. Microsoft’s decision to assign CVE numbers to cloud service vulnerabilities, regardless of whether customer action …

Read More »

Google Blocking Entrust Certificates in Chrome in November 2024

entrust

Starting November 1, 2024, Google will block websites that use certificates from Entrust. Google made this decision because Entrust has not been able to handle security issues promptly and has not complied with their requirements. “Over the past several years, publicly disclosed incident reports highlighted a pattern of concerning behaviors …

Read More »

GitLab issues Critical Patches to Address Multiple Vulnerabilities

Gitlab

GitLab, a platform for DevOps tools, released critical updates for its Community Edition (CE) and Enterprise Edition (EE). The new versions, 17.1.1, 17.0.3, and 16.11.5, include security and bug fixes. Users should upgrade now to protect their installations from possible exploits. Key Security Fixes: CVE-2024-5655 (CVSS 9.6) – Run Pipelines …

Read More »

BSNL Data Breach: Data worth 278GB leaked: Report claim

BSNL

According to digital risk management firm Athenian Technology, BSNL, India’s state-owned telecom provider, suffered a significant data breach. A cybercriminal named “kiberphant0m” performed the attack, resulting in the exposure of a large amount of sensitive data. This puts millions of users at risk. Zee news reported, Kanishk Gaur, CEO of …

Read More »

CISA released Guidance for Modern Approaches to Network Access Security

network

CISA and the FBI released guidance, Modern Approaches to Network Access Security, with support from other organizations including New Zealand’s GCSB, CERT-NZ, and the Canadian CCCS. Business owners of all sizes are encouraged to adopt stronger security solutions like Zero Trust, Secure Service Edge (SSE), and Secure Access Service Edge …

Read More »

AWS Announced New Malware Detection Tool For S3 Buckets

aws

AWS announced new security features at its re:Inforce conference, such as identity and malware protection services. The cloud giant added passkeys to the list of supported multi-factor authentication (MFA) mechanisms for root and Identity and Access Management (IAM) users. The company also started enforcing MFA on root users, particularly AWS …

Read More »

CISA Releases Twenty Industrial Control Systems Advisories

ics

CISA released 20 advisories about Industrial Control Systems (ICS) on June 13, 2024. These advisories give important information about security issues, vulnerabilities, and exploits related to ICS. ICSA-24-165-01 Siemens Mendix Applications ICSA-24-165-02 Siemens SIMATIC S7-200 SMART Devices ICSA-24-165-03 Siemens TIA Administrator ICSA-24-165-04 Siemens ST7 ScadaConnect ICSA-24-165-05 Siemens SITOP UPS1600 ICSA-24-165-06 …

Read More »