CISA: JasperReports flaws under active exploitation Two old security vulnerabilities impacting TIBCO Software's Java-based reporting and data analytics platform JasperReports are being leveraged in ongoing attacks, prompting their addition to the Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalog, reports The Hacker News.
Threat actors could exploit a vulnerability in the Google Home smart speaker to facilitate the installation of a backdoor that would access the microphone feed to enable spying, BleepingComputer reports.
SecurityWeek reports that Rockwell Automation controllers have been impacted by four high-severity security flaws, which have already been covered by the Cybersecurity and Infrastructure Security Agency in advisories last week.
Organizations leveraging various Netgear WiFi router models have been urged by the networking hardware firm to promptly apply the latest firmware version to address a high-severity pre-authentication buffer overflow vulnerability, according to BleepingComputer.
With the current macro economic head winds, 2023 budgets are either frozen or are flat. Where should CISOs focus these limited budgets to maximize the most out of their security program? In this segment, we invite Jon Fredrickson, Chief Risk Officer at Blue Cross Blue Shield of Rhode Island, to debate what should be in your minimum viable security ...
With the current macro economic head winds, 2023 budgets are either frozen or are flat. Where should CISOs focus these limited budgets to maximize the most out of their security program? In this segment, we invite Jon Fredrickson, Chief Risk Officer at Blue Cross Blue Shield of Rhode Island, to debate what should be in your minimum viable security ...
German researchers were reported by The New York Times to have purchased an old U.S. military biometric data collection system dubbed 'SEEK II' from eBay for $68, SiliconAngle reports.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.