At least 9,000 exposed virtual network computing endpoints have been found by security weakness hunters at Cyble, and since they don't require authorization or passwords to use, it is simple for threat actors to access internal networks, BleepingComputer reports.
SecurityWeek reports that CVE-2022-27255, a high severity security vulnerability that affects Realtek eCos SDK, could allow remote attackers to get arbitrary code execution or cause networking devices that use the SDK to crash.
An ongoing phishing campaign is targeting the healthcare sector with malspam emails that appear as legitimate Evernote sites, in an attempt to harvest credentials.
SecurityWeek reports that organizations have been warned about two critical NetModule Router Software vulnerabilities, which could be exploited to evade authentication and obtain administrative access.
In the last year, the FDA has signaled that the responsibility of medical device security is moving to manufacturers, designing with security in mind; an effort that could address systemic issues.
SC Media caught up with the chief research officer at Finnish cybersecurity firm WithSecure to hear what risk might look like as rapid increases in computing power usher in an era of building "with no restrictions."
We welcome the infamous Eclypsium security researchers Mickey and Jesse to talk about Secure Boot vulnerabilities. They walk us through the history of Secure Boot, how it works, previous research they've performed ("Boothole"), and some details on their current research presented at Defcon this year in a talk titled "One bootloader to rule them all...
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.