Apple has rolled out security updates to address a zero-day vulnerability in the Safari web browser that was exploited during the recent Pwn2Own Vancouver hacking competition, BleepingComputer reports.
Security pros say the industry can expect to see this bug exploited soon, so patch, monitor and conduct other measures, like browser isolation and sandboxing.
A new Absolute Security report found that many organizations are failing to ensure that the endpoint protection platforms and network access security applications on their managed PCs are running in compliance with basic security policies, reports TechRepublic.
Jason joins us to discuss the current enterprise landscape for defending against supply chain attacks, remediating firmware issues, and the current challenges with patch management. This segment is sponsored by Eclypsium. Visit https://securityweekly.com/eclypsium to learn more about them!
Fifty-seven percent of more than 90,000 internet-exposed hosts continue to run TinyProxy instances unpatched against the critical use-after-free vulnerability, tracked as CVE-2023-49606, which could be leveraged to facilitate remote code execution attacks via an unauthenticated HTTP request, reports The Hacker News.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.