Active exploitation of a critical zero-day flaw in Sophos' firewall product has prompted Sophos to immediately issue a patch update, reports The Hacker News.
Millions of devices, including those manufactured by Microsoft, HP, Intel, Dell, Siemens, Framework, and Fujitsu, are being affected by seven firmware vulnerabilities in Insyde Software's InsydeH20 UEFI firmware, which could be exploited to facilitate persistent device access, SecurityWeek reports.
Morgan Stanley's wealth and asset management division Morgan Stanley Smith Barney has agreed to pay a $35 million fine to settle charges filed by the U.S. Securities and Exchange Commission pertaining to federal regulation violations on customer data protection and disposal, TechRepublic reports.
SecurityWeek reports that various Netgear routers and Orbi WiFi systems are affected by a vulnerability in third-party online game acceleration module FunJSQ, which could be exploited to facilitate arbitrary code execution.