Recent Security News

  • Critical SOCKS5 Vulnerability in cURL Puts Enterprise Systems at Risk

    October 11, 2023 at 12:06PM Patches have been released for a critical memory corruption vulnerability in the cURL data transfer project. The flaw, tracked as CVE-2023-38545, affects the SOCKS5 proxy handshake process in cURL, allowing remote exploitation in certain configurations. The bug can lead to heap buffer overflow, and affected versions are 7.69.0 to 8.3.0.…

    Read More

  • Securely Moving Financial Services to the Cloud

    October 11, 2023 at 11:55AM Moving financial services to the cloud requires careful consideration of security, compliance, and governance. It is important to establish secure use of the cloud and comply with regulations. Cloud governance, including three lines of governance, is crucial. Implementing infrastructure, application, and data pipelines, as well as change management and monitoring,…

    Read More

  • Data Thieves Test-Drive Unique Certificate Abuse Tactic

    October 11, 2023 at 11:41AM Attackers are using a new method of certificate abuse to spread info-stealing malware, including stealing cryptocurrency from Windows systems. The campaign involves search engine optimization poisoning to deliver malicious pages promoting illegal software downloads. The malware uses special certificates with long strings of non-English characters, making them difficult to detect.…

    Read More

  • Windows 11 21H2 and Windows Server 2012 reach end of support

    October 11, 2023 at 11:32AM Microsoft has officially ended support for Windows Server 2012 and Windows 11, version 21H2. This means that these operating systems will no longer receive security updates, bug fixes, or technical support. Microsoft advises users to upgrade to newer versions or obtain Extended Security Updates (ESUs) to continue receiving essential updates.…

    Read More