The Cybersecurity and Infrastructure Security Agency has required federal civilian agencies and other organizations across the U.S. to patch the actively exploited high-severity privilege escalation vulnerability in WatchGuard Firebox and XTM firewall appliances.
Operators of the Qbot botnet, also known as Qakbot, Quakbot, and Pinkslipbot, have begun leveraging phishing emails with malicious MSI Windows Installer package-laced ZIP archive attachments to spread malware instead of the traditional approach of malware distribution through phishing emails containing Microsoft Office documents with malicious macros.
Directus has issued a fix for a cross-site scripting vulnerability impacting versions 9.6.0 and earlier of the open source modular content management system.
OpenSSH has activated post-quantum cryptography by default in OpenSSH 9, as well as introduced the hybrid Streamlined NTRU Prime + x25519 key exchange method in an effort to better protect against future quantum attacks, as well as any future vulnerabilities in NTRU Prime.
The US Justice Department was able to disrupt the Russian state-sponsored Sandworm hacking operation's Cyclops Blink botnet as a result of a search warrant that enabled the FBI to remotely access computers without owner permission under an amendment to Rule 41 in 2016.
Newmark’s philanthropy says funding will go to educate the public on cybersecurity and create programs to help people launch careers in cyber. He will speak to the concept of Cyber Civil Defense during a panel at the RSA Conference in June.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.