Remove 04
article thumbnail

Apple backported patches for CVE-2022-42856 zero-day on older iPhones, iPads

Security Affairs

Apple has backported the security updates for the zero-day vulnerability CVE-2022-42856 to older iPhones and iPads. On December 2022, Apple released security updates to address a new zero-day vulnerability, tracked as CVE-2022-42856 , that is actively exploited in attacks against iPhones. On December 14, 2022, the U.S.

article thumbnail

Threat Actor of the Month - August 2022

Outpost24

Threat Actor of the Month - August 2022. Fri, 08/12/2022 - 08:04. Florian Barre. Gerard, Jacobo, from Threat Context. Threat Intelligence. This month we’re introducing you to GhostSec, a hacktivist group with ties to the Anonymous collective.

52
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

CISA adds Sophos firewall bug to Known Exploited Vulnerabilities Catalog

Security Affairs

Cybersecurity and Infrastructure Security Agency (CISA) added the recently disclosed CVE-2022-1040 flaw in the Sophos firewall, along with seven other issues, to its Known Exploited Vulnerabilities Catalog. The new vulnerabilities added to the catalog have to be addressed by federal agencies by April 21, 2022. MR3 (18.5.3) and earlier.

article thumbnail

Malware-laced npm packages used to target Discord users

Security Affairs

2022-07-17 20:28:29 small-sm 4.2.0 2022-07-17 19:47:56 small-sm 4.0.0 2022-07-17 19:43:57 small-sm 1.1.0 2022-06-18 16:19:47 small-sm 1.0.9 2022-06-17 12:23:33 small-sm 1.0.8 2022-06-17 12:22:31 small-sm 1.0.7 2022-06-17 03:36:45 small-sm 1.0.5 2022-06-17 03:31:40 pern-valids 1.0.3

article thumbnail

Identity Management Day 2022: Identity Security Is Our Responsibility

Thales Cloud Protection & Licensing

Identity Management Day 2022: Identity Security Is Our Responsibility. Tue, 04/12/2022 - 09:41. Identity Management Day 2022 , sponsored by Identity Defined Security Alliance and National Cybersecurity Alliance, is a reminder to make identity management and digital identity security a priority.

article thumbnail

CISA adds Windows CLFS Driver Privilege Escalation flaw to its Known Exploited Vulnerabilities Catalog

Security Affairs

CISA added the CVE-2022-24521 Microsoft Windows CLFS Driver Privilege Escalation Vulnerability to its Known Exploited Vulnerabilities Catalog. Cybersecurity and Infrastructure Security Agency (CISA) added the CVE-2022-24521 privilege escalation vulnerability in Microsoft Windows Common Log File System (CLFS) Driver.

IT 98
article thumbnail

Google fixed a new Chrome Zero-Day actively exploited in the wild

Security Affairs

The actively exploited flaw, tracked as CVE-2022-2856, is an Insufficient validation of untrusted input in Intents. The flaw was discovered by Ashley Shen and Christian Resell of Google Threat Analysis Group on 19 July 2022. “Google is aware that an exploit for CVE-2022-2856 exists in the wild.”