Reports of an impending deal between the notorious spyware vendor and L3Harris troubles some about the potential for spyware to spread throughout state and local governments.
ZDNet reports that Android users are having their passwords, cryptocurrency wallets, and bank information targeted by the new MaliBot malware, which has multi-factor authentication bypassing capabilities.
Man-in-the-middle attacks are being deployed by sophisticated Chinese APT group Drifting Cloud through the exploitation of a zero-day vulnerability in Sophos firewall, according to SecurityWeek.
Successful implementation of zero-trust architecture in the federal government will take “more than procuring new hardware and software” and require surmounting multiple budgetary, bureaucratic and cultural hurdles at different agencies, a national security think tank concluded in a report released Wednesday.
Cisco has called on the users of its Email Security Appliance and Secure Email and Web Manager appliances with non-default configurations to immediately patch a critical security flaw, tracked as CVE-2022-20798, which could be abused to evade authentication and access the appliances' web management interface, according to BleepingComputer. "An attacker could exploit this vulnerability by entering a specific input on the login page of the affected device.
The Hacker News reports that threat actors could exploit a high-severity Zimbra email suite flaw to facilitate the theft of user passwords in cleartext.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.