Threat actors could chain two critical security vulnerabilities in Schneider Electric's Unity line of Modicon programmable logic controllers, tracked as CVE-2022-45788 and CVE-2022-45789, to compromise safety protections for limiting physical damage, according to The Record, a news site by cybersecurity firm Recorded Future.
Several high-severity vulnerabilities in Citrix Systems' Virtual Apps and Desktops, as well as its Workspace Apps, which could be exploited to achieve privilege escalation and system takeovers, have been patched in recently issued security updates, BleepingComputer reports.
Once the domain of sophisticated attackers, the availability of automated translation tools lowers the barrier-of-entry to wage the financially destructive business email compromise (BEC) attacks.
Inka talks about harnessing Behavioural Science (BS) to influence people’s cyber security behaviours. Focusing on psychology theories (e.g. Behaviour change wheel) she explores some of our barriers (and motivations) to cybersecurity. What are our FMEs ('frequently made excuses') to taking protective action online and how organisations' could create...
Novel info-stealing malware leveraged by North Korean hackers BleepingComputer reports the North Korean state-sponsored threat group APT37, also known as RedEyes or ScarCruft, has been launching attacks with the new M2RAT information-stealing malware aimed at compromising Windows and mobile devices since last month.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.