article thumbnail

Microsoft Patch Tuesday, June 2022 Edition

Krebs on Security

On top of the critical heap this month is CVE-2022-30190 , a vulnerability in the Microsoft Support Diagnostics Tool (MSDT), a service built into Windows. “Most malicious Word documents leverage the macro feature of the software to deliver their malicious payload. . that earned a CVSS score of 9.8 (10 10 being the worst).

Cloud 244
article thumbnail

Weakness at the Network Edge: Mandiant Examines 2022’s Zero-Day Exploits

eSecurity Planet

Mandiant tracked 55 zero-day vulnerabilities that were actively exploited in 2022. Overall, the proportion of financially motivated zero-day exploitation decreased in 2022. Far more of the 16 cases with a clear motive were state-sponsored – 13 of the zero-days tracked in 2022 appear to have been leveraged by cyber espionage groups.

Cloud 104
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

ISO 27001:2022 Has Been Released – What Does It Mean for Your Organisation?

IT Governance

The Standard was last revised almost a decade ago (although a new iteration of the supplementary standard ISO 27002 was published in February 2022), meaning that the release of ISO 27001:2022 has been much needed and highly anticipated. However, the most significant changes with the 2022 version of ISO 27002 are in its structure.

IT 119
article thumbnail

9 cyber security predictions for 2022

IT Governance

But there remains great uncertainty about how we’ll come out of the crisis and what business challenges await us. To help you understand what might be in store in 2022, we’ve collected nine forecasts from cyber security experts. Panel discussion: How to prevent and respond to the most successful vulnerabilities exploited by attackers.

Security 142
article thumbnail

Data Breaches and Cyber Attacks Quarterly Review: Q2 2022

IT Governance

Welcome to our second quarterly review of security incidents for 2022, in which we take a closer look at the information gathered in our monthly list of data breaches and cyber attacks. IT Governance discovered 237 security incidents between April and June 2022, which accounted for 99,019,967 breached records. This represents an 11.5%

article thumbnail

California Privacy Agency: CPRA Regs Not Likely Until Late 2022

Data Matters

Final regulations implementing the California Privacy Rights Act (CPRA) may not be issued until Q3 or Q4 2022, as reported by Executive Director Soltani of the California Privacy Protection Agency (“CalPPA”) at its February 17th Board meeting. The initial regulations will need to be approved by the CalPPA Board.

Privacy 88
article thumbnail

How to Use MITRE ATT&CK to Understand Attacker Behavior

eSecurity Planet

ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) documents adversary behaviors to be used by red teams (e.g., The ATT&CK framework organizes information in a consistent and structured way, allowing people with varying knowledge, from beginners to advanced security teams, to use its documents.

Analytics 113