📰 Software Security News
Page 40 - Software Security News Today
Fast, Ad-Free News Updates
Stay updated with breaking news from Software Security. Real-time updates on events, politics, business and more.
May 12, 2021
GovInfoSecurity Compliance DougOlenick) • May 12, 2021 Get Permission Microsoft issued patches Tuesday for four more vulnerabilities in on-premises versions of the Exchange Server corporate email platform, one of which is a zero-day flaw. These latest patches come after Microsoft in March patched four critical flaws in Exchange Server that had been widely exploited by attackers. Microsoft said a China-based gro...
May 12, 2021
Security Labs: A Boost for Software Development Training Download this eBook and learn about: Findings from the latest State of Software Security report; Why developer training falls short on security; The new Security Labs initiative and how it aims to change the game for developer training.
May 12, 2021
Rise of DarkSide: Ransomware Victims Have Been Surging Compliance euroinfosec) • May 12, 2021 Count of known DarkSide victims from August 2020 to April 2021 (Sources: Mandiant, Sophos) For anyone wondering how a Russian-speaking, ransomware-wielding crime syndicate was able to disrupt a major U.S. fuel pipeline, a more pertinent question might be: Why didn’t it happen sooner? The DarkSide operation first appeared in August 2020 with ...
May 12, 2021
GovInfoSecurity Compliance Compliance Compliance @prajeetspeaks) • May 12, 2021 Architecture of the Moriya rootkit (Source: Kaspersky) An ongoing advanced persistent threat campaign dubbed "Operation TunnelSnake" has been using a Windows rootkit named Moriya to deploy a passive backdoor to spy on victims, the security firm Kaspersky reports. Researchers observed the campaign being conducted on public-facing serve...
May 12, 2021
The ransomware attack against Colonial Pipeline, which has disrupted the flow of gasoline and other petroleum products throughout the eastern U.S. since Friday, is
May 12, 2021
Acting CISA Director Brandon Wales testifying before the Senate Homeland Security and Governmental Affairs Committee The Cybersecurity and Infrastructure Security Agency is still awaiting more technical details from Colonial Pipeline about the Friday ransomware attack that forced it to shut down its operations, the agencys acting director told a Senate committee Tuesday. "Right now, we are waiting for additional technical information on exactly what happened at Colonial so that we can use that ...
May 11, 2021
Secretary of Homeland Security Alejandro Mayorkas About 50% to 70% of all ransomware attacks in the U.S. are targeting small and medium-sized businesses, costing the victims an estimated total of $350 million in the last year, Secretary of Homeland Security Alejandro Mayorkas said Wednesday in a speech to the U.S. Chamber of Commerce. "The losses from ransomware are staggering. And the pace at which those losses are being realized is equally staggering," Mayorkas said, noting this is why DHS h...
May 11, 2021
Colonial Pipeline: A Global Day of Reckoning Compliance Compliance SecurityEditor) • May 11, 2021 Gregory Touhill, director, CMU SEIs CERT Division Gregory Touhill, the retired Air Force general and former federal CISO under President Obama, minces no words when he describes the Colonial Pipeline ransomware attack as a "global day of reckoning" for critical infrastructure protection. "Its a global day of reckonin...
May 11, 2021
DarkSides Pipeline Ransomware Hit: Strictly Business? Compliance euroinfosec) • May 11, 2021 "Its not personal, Sonny. Its strictly business." That immortal line from "The Godfather" encapsulates the mindset of criminals who extort businesses using ransomware and other tools: Its all about profits. "If the group behind these attacks does mean to avoid social consequences in the future, they should stop carrying out attacks." One of ...
May 11, 2021
FTC Nixes Cybersecurity as Point Against Right to Repair Compliance Compliance Twitter Removing the screen on an iPhone 8 (Photo: iFixit/CC) The "right to repair" movement is gaining momentum. This movement seeks to require manufacturers to offer diagnostic tools, manuals and other resources to allow for third-party or consumer-initiated repairs. The fact that software is wrapped into everything has made it easier for manufacturers to only allow authorized service providers to access trouble ...