Synology, a networking and storage solutions provider based in Taiwan, has published two advisories before the end of last year notifying its customers that patches to several recently discovered bugs had been released, SecurityWeek reports.
Security researchers with the Shadowserver Foundation announced that 60,865 Microsoft Exchange servers have not yet been patched to defend against the CVE-2022-41082 remote code execution flaw, reports BleepingComputer.
U.S. Federal Communications Commissioner Brendan Carr said that the total TikTok ban in India was an "incredibly important precedent" that should be used by the U.S. and other countries amid concerns over the Chinese video sharing app's potential threat to national security, The Economic Times reports.
Chinese fraudsters part of the RedZei operation, also known as RedThief, have been targeting U.K.-based Chinese international students for more than a year, The Hacker News reports.
Play ransomware gang behind Rackspace attack Texas Public Radio reports that the Play ransomware gang has been noted by Rackspace to be the perpetrators of an attack against its Hosted Exchange platform in early December.
CISA: JasperReports flaws under active exploitation Two old security vulnerabilities impacting TIBCO Software's Java-based reporting and data analytics platform JasperReports are being leveraged in ongoing attacks, prompting their addition to the Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalog, reports The Hacker News.
Threat actors could exploit a vulnerability in the Google Home smart speaker to facilitate the installation of a backdoor that would access the microphone feed to enable spying, BleepingComputer reports.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.