Pantsdown, which poses a fairly substantial problem for users given baseboard management controller positioning, remains unaddressed by Quanta Cloud Technology servers — an issue they see as emblematic of how vendors and enterprise security professionals treat firmware vulnerabilities.
State-sponsored threat actors have exploited five Android OS and Google Chrome zero-day vulnerabilities to infect Android devices with Cytrox's Predator spyware in three campaigns from August to October 2021.
HSCC medical device contracting guidance outlines what’s needed to ensure strong security policies between providers and manufacturers: sometimes that means paying more upfront for better measures.
QNAP advises customers to update their devices immediately and to not expose their NAS systems to the internet since discovering the Deadbolt ransomware.
Adoption of the security standards years after voluntary federal guidelines are low, and the majority of healthcare organizations are still struggling to keep pace, a cybersecurity expert testified at a May 18 Senate hearing.
Malware could be loaded into the Bluetooth chips of iPhones and could be executed even if the devices are turned off through a new attack surface discovered by researchers at the Technical University of Darmstadt's Secure Mobile Networking Lab, according to The Hacker News.
Novel link-layer Bluetooth Low Energy relay attacks that could evade mitigations and protections including encrypted link layer, detectable latency levels, and localization approaches could be performed by a new tool developed by NCC Group researchers, SecurityWeek reports.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.