Ten state attorneys general are asking Apple to address data privacy gaps in the wake of the U.S. Supreme Court abortion ruling by enacting stricter app standards and an auditing program.
Navigating the UEFI waters is treacherous. While UEFI has become the standard on most PCs, servers, and laptops, replacing legacy BIOS, it is a complex set of standards and protocols. Jesse joins us to help explain how some of this works and describe how vulnerabilities, specifically with SMM, can manifest and be exploited. Segment Resources: CHIPS...
A number of state attorneys general announced Monday the largest consumer privacy settlement in U.S. history as tech giant Google agreed to pay nearly $400 million over its location tracking practices.
An update to the much-lauded medical device cybersecurity playbook centers around preparedness and response plans, particularly for cyber incidents that impact medical devices.
Threat actors could leverage three security vulnerabilities in the LiteSpeed Web Server to facilitate arbitrary code execution with elevated privileges and achieve complete server takeovers, SecurityWeek reports.
The Hacker News reports that two Android apps Todo: Day manager and "経費キーパ" have been found to serve as Xenomorph banking malware droppers, with both apps already removed from the Google Play Store.
Uyghurs in China and around the world have been targeted by two prolonged surveillance campaigns leveraging Android spyware tools BadBazaar and new MOONSHINE variants that sought to monitor individuals' whereabouts and exfiltrate sensitive data, according to The Hacker News.
Security updates have been issued by Citrix to fix three vulnerabilities, including a critical authentication bypass bug, impacting its Application Delivery Controller and Gateway offerings, The Hacker News reports.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.