Sat.Jul 22, 2023

article thumbnail

Crossing the road

Security Boulevard

Last week I spoke for Jersey Cyber Security Centre ( CERT.JE ) about the changing threats facing us — from the very active offensive cyber campaign forming part of the war in Ukraine, to the emerging threat from AI tools that can be used for harm as well as for good. But the important part of my comments was to show that whilst these cyber threats are real, there are sensible steps we can take to respond — we do not have to bury our heads in the sand and hope for the best.

article thumbnail

Multiple DDoS botnets were observed targeting Zyxel devices

Security Affairs

Researchers warn of several DDoS botnets exploiting a critical flaw tracked as CVE-2023-28771 in Zyxel devices. Fortinet FortiGuard Labs researchers warned of multiple DDoS botnets exploiting a vulnerability impacting multiple Zyxel firewalls. The flaw, tracked as CVE-2023-28771 (CVSS score: 9.8), is a command injection issue that could potentially allow an unauthorized attacker to execute arbitrary code on vulnerable devices.

DDOS 97
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

2023 OWASP Top-10 Series: Introduction

Security Boulevard

In early June 2023, OWASP released the final version of the OWASP API Security Top-10 list update. At that time we published a “hot take” on this final version and followed that up with an in-depth look at the new risk ratings for 2023. Today we’re kicking off a multi-post series in which we take [.] The post 2023 OWASP Top-10 Series: Introduction appeared first on Wallarm.

Risk 98
article thumbnail

Windows 11 23H2 to give you greater control over power consumption

Bleeping Computer

Microsoft is making it easier to see how much energy your apps use in Windows 11 over a given period by introducing a detailed power consumption page in the latest 23H2 update. [.

article thumbnail

The Importance of User Roles and Permissions in Cybersecurity Software

How many people would you trust with your house keys? Chances are, you have a handful of trusted friends and family members who have an emergency copy, but you definitely wouldn’t hand those out too freely. You have stuff that’s worth protecting—and the more people that have access to your belongings, the higher the odds that something will go missing.

article thumbnail

China’s Breach of Microsoft Cloud Email May Expose Deeper Problems

WIRED Threat Level

Plus: Microsoft expands access to premium security features, AI child sexual abuse material is on the rise, and Netflix’s password crackdown has its intended effect.

article thumbnail

Over 15K Citrix servers likely vulnerable to CVE-2023-3519 attacks

Bleeping Computer

Thousands of Citrix Netscaler ADC and Gateway servers exposed online are likely vulnerable against a critical remote code execution (RCE) bug exploited by unauthenticated attackers in the wild as a zero-day. [.

87

More Trending

article thumbnail

Microsoft force-migrating Windows Mail & Calendar apps to Outlook app in August

Bleeping Computer

Microsoft will retire the Windows Mail and Calendar applications on Windows 10 and Windows 11 at the end of the year, first auto-migrating users to the new Outlook for Windows app in August. [.

82
article thumbnail

Review: Can We Trust the Waterfox Browser? (Updated 2023)

Security Boulevard

Waterfox came into the browser scene in 2011, coming right out the box with official x64 support (a rarity among browsers at the time) and promoted itself as an "ethical browser." However, many things have changed in the browser landscape, and even the Waterfox project as whole since 2011. With these changes, can Waterfox be a viable privacy-focused browser?

article thumbnail

Windows 11 23H2 getting an energy report with app's power usage

Bleeping Computer

Microsoft is making it easier to see how much energy your apps use in Windows 11 over a given period by introducing a detailed power consumption page in the latest 23H2 update. [.

article thumbnail

BSides Sofia 2023 – Victor Bonev – Secure Distroless OCI Images Via YAML

Security Boulevard

Our thanks to BSides Sofia for publishing their presenter’s tremendous BSides Sofia 2023 content on the organizations’ YouTube channel. Permalink The post BSides Sofia 2023 – Victor Bonev – Secure Distroless OCI Images Via YAML appeared first on Security Boulevard.

article thumbnail

IDC Analyst Report: The Open Source Blind Spot Putting Businesses at Risk

In a recent study, IDC found that 64% of organizations said they were already using open source in software development with a further 25% planning to in the next year. Most organizations are unaware of just how much open-source code is used and underestimate their dependency on it. As enterprises grow the use of open-source software, they face a new challenge: understanding the scope of open-source software that's being used throughout the organization and the corresponding exposure.

article thumbnail

Over 15K Citrix servers vulnerable to CVE-2023-3519 RCE attacks

Bleeping Computer

Thousands of Citrix Netscaler ADC and Gateway servers exposed online are vulnerable to attacks exploiting a critical remote code execution (RCE) bug that was previously abused in the wild as a zero-day. [.

67