Zyxel has released fixes for at least 15 major security vulnerabilities impacting its network access storage devices, firewalls, and access points, according to SecurityWeek.
Organizations in the water and wastewater systems sector have been warned by the Cybersecurity and Infrastructure Security Agency regarding ongoing attacks targeted at vulnerable Unitronics programmable logic controllers, one of which has already compromised the Municipal Water Authority of Aliquippa in Pennsylvania, reports The Record, a news site by cybersecurity firm Recorded Future.
Sixty-eight percent of U.S. websites lacked defenses against simple bot attacks and permitted all nine different bot types, while only 10% totally averted bot requests, reports SiliconAngle.
TechRadar reports that cyberattacks enabling remote access and unauthorized access could be launched against 5,860 internet-exposed gas pump controllers around the world, most of which are in the U.S.
Microsoft, Dell, and Lenovo laptops had faulty implementations of the Secure Device Connection Protocol in their fingerprint sensors, which enabled Windows Hello authentication bypass and potential app access and data exfiltration activities, SiliconAngle reports.
Threat actors have been targeting macOS devices with the Atomic Stealer information-stealing malware, also known as AMOS, through fraudulent web browser updates as part of the new "ClearFake" campaign, The Hacker News reports.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.