This week in the Security News: Temporary phones, webcam hacks that are so much more, bags of cash, patch Wordpress plugins and patch them some more, crowd-sourced-government-funded vulnerability scanning, hiding deep in UEFI and bouncing off the moon, even more UEFI vulnerabilities, if Samaba were a fruit it would be....well vulnerable for one thi...
This Week in the Security News: UPnP strikes back, Lazarus, Samba, CISA, SMS Scams, secret pixels, OMB Zero Trust, and Wordle, along with the Expert Commentary of Jason Wood on this edition of the Security Weekly News!
The Microsoft researchers found that the second stage of the campaign was successful against victims that did not implement multi-factor authentication (MFA).
Microsoft has resealed the seams of its patch of a 2020 Outlook vulnerability after a bypass was found, according to the researcher who found both the original vulnerability and its bypass.
Vulnerabilities identified in Schneider Electric Easergy P5 protection relay used in modern electric grids, which could be abused to facilitate ransomware payload deployments, suggest the broader risk of launching cyberattack on embedded systems.
This week in the Security News: More QR codes you shouldn't trust, race conditions in Rust, encrypting railways, Pwnkit - the latest Linux exploit, tricking researchers into crashing, cybersecurity is broken?, the best cybersecurity research paper, evil Favicons, escaping Kubernetes, pimping your cubicle and someone who actually recovered their cry...
This week in the Security News, Dr. Doug talks: Control Web Panel, Russia, Belarus, Office Macros, Trickbot, MoleRats, DTPacker, and Tesla! All that along with the Expert Commentary of Jason Wood on this edition of the Security Weekly News!
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.