Recent Security News

  • ICS Patch Tuesday: Siemens Ruggedcom Devices Affected by Nozomi Component Flaws

    October 11, 2023 at 06:42AM Siemens and Schneider Electric have released their Patch Tuesday advisories for October 2023, addressing over 40 vulnerabilities in their products. Siemens has published a dozen advisories, including vulnerabilities in the Ruggedcom APE1808 platform and Nozomi Networks’ Guardian product. Nozomi has already patched these vulnerabilities. Schneider Electric has released advisories for…

    Read More

  • curl vulnerabilities ironed out with patches after week-long tease

    October 11, 2023 at 06:09AM The latest version of the curl command line transfer tool was released today, addressing two separate vulnerabilities. The first vulnerability is a heap-based buffer overflow flaw that affects both libcurl and the curl tool. The second vulnerability is a less-severe cookie injection flaw that only affects libcurl. Users are advised…

    Read More

  • What to expect when the UK-US Data Bridge comes into force this week

    October 11, 2023 at 05:19AM The UK Extension to the EU-US Data Privacy Framework, also known as the Data Bridge, will allow for the transfer of personal data from the UK to the US starting on October 12. This is necessary due to the UK no longer being a member of the EU. However, the…

    Read More

  • Microsoft Releases October 2023 Patches for 103 Flaws, Including 2 Active Exploits

    October 11, 2023 at 03:12AM Microsoft has released its October 2023 Patch Tuesday updates, addressing 103 flaws, two of which are actively being exploited. Among the vulnerabilities are information disclosure in Microsoft WordPad and privilege escalation in Skype for Business. Microsoft also fixed flaws in Microsoft Message Queuing and Layer 2 Tunneling Protocol. Additionally, Microsoft…

    Read More

  • Microsoft Warns of Nation-State Hackers Exploiting Critical Atlassian Confluence Vulnerability

    October 11, 2023 at 12:30AM Microsoft has identified a critical flaw in Atlassian Confluence Data Center and Server that is being exploited by a nation-state actor called Storm-0062. The vulnerability, known as CVE-2023-22515, allows attackers to create unauthorized administrator accounts. Atlassian has been made aware of the issue and advises users to upgrade to the…

    Read More