Remove weekly-update-73
article thumbnail

Weekly Update 73

Troy Hunt

All that and more in this week's update. I'm not entirely sure how I've gotten to the end of the week feeling completely wrung out whilst having only written the one thing, but here we are. In fairness though, I've put a heap of work into Pwned Passwords version 2 and finally completed the data set. References.

Passwords 110
article thumbnail

AT&T Confirms Massive Data Breach Impacting 73 Million Customers

SecureWorld News

After weeks of denial, AT&T has finally acknowledged a massive data breach impacting 73 million current and former customer accounts. This includes updating credentials, using password managers, enabling multi-factor authentication, freezing credit reports, and signing up for identity theft protection services. "In

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

VulnRecap 2/19/2024: News from Microsoft, Zoom, SolarWinds

eSecurity Planet

While this week was a little light on vulnerability news, it’s still been significant, with Microsoft’s Patch Tuesday happening as well as updates for major products, like Zoom. Your IT teams should regularly check your vendors’ security bulletins for any vulnerability news or updates.

VPN 112
article thumbnail

Fortinet FortiNAC CVE-2022-39952 flaw exploited in the wild hours after the release of PoC exploit

Security Affairs

Last week, Fortinet has released security updates to address two critical vulnerabilities in FortiNAC and FortiWeb solutions. An external control of file name or path vulnerability [CWE-73]in FortiNAC webserver may allow an unauthenticated attacker to perform arbitrary write on the system.” The CVE-2022-39952 flaw (CVSS score of 9.8)

Hacking 91
article thumbnail

Key Takeaways for Developers From SOSS v11: Open Source Edition

Veracode Security

The majority of library vulnerabilities are fixable with minor updates It might surprise you that most vulnerabilities in third-party libraries are easy to fix with a minor update. But… …Most libraries are never updated at all. Or, there may not even be an update at all as is the case with number four.

Software 111
article thumbnail

Thinking of a Cybersecurity Career? Read This

Krebs on Security

” Fully 85 percent ranked networking as a critical or “very important” skill, followed by a mastery of the Linux operating system (77 percent), Windows (73 percent), common exploitation techniques (73 percent), computer architectures and virtualization (67 percent) and data and cryptography (58 percent).

article thumbnail

PoC exploit code for critical Fortinet FortiNAC bug released online

Security Affairs

Last week, Fortinet has released security updates to address two critical vulnerabilities in FortiNAC and FortiWeb solutions. An external control of file name or path vulnerability [CWE-73]in FortiNAC webserver may allow an unauthenticated attacker to perform arbitrary write on the system.” The CVE-2022-39952 flaw (CVSS score of 9.8)

Hacking 98