Recent Security News

  • LockBit ransomware exploits Citrix Bleed in attacks, 10K servers exposed

    November 14, 2023 at 03:05PM LockBit ransomware attacks are exploiting the Citrix Bleed vulnerability (CVE-2023-4966) to breach large organizations’ systems, steal data, and encrypt files. Despite Citrix releasing fixes for the vulnerability over a month ago, thousands of vulnerable appliances are still running, many in the U.S. LockBit affiliates are likely responsible for the attacks,…

    Read More

  • 21 Vulnerabilities Discovered in Crucial IT-OT Connective Routers

    November 14, 2023 at 02:41PM Researchers have discovered 21 vulnerabilities in a popular brand of industrial router commonly used in the medical and manufacturing sectors. These vulnerabilities range from design flaws like hardcoded credentials to how the device handles potentially malicious inputs. Attackers who exploit these vulnerabilities can bypass security measures and target critical devices…

    Read More

  • 100 Quarters of Profitability: Insights from a Trender

    November 14, 2023 at 02:30PM The text describes the author’s reflections on 100 straight quarters of profitability at Trend Micro. It highlights how the company’s conservative approach to spending has allowed them to give back to communities and support various charitable initiatives. The author expresses pride in being part of an organization that prioritizes non-revenue…

    Read More

  • CacheWarp Attack: New Vulnerability in AMD SEV Exposes Encrypted VMs

    November 14, 2023 at 02:27PM Researchers from the CISPA Helmholtz Center for Information Security have discovered a new software fault attack called CacheWarp that targets AMD’s Secure Encrypted Virtualization (SEV) technology. The attack exploits a vulnerability in SEV to infiltrate encrypted virtual machines and achieve privilege escalation. AMD has released a microcode update to address…

    Read More

  • Microsoft November 2023 Patch Tuesday fixes 5 zero-days. 58 flaws

    November 14, 2023 at 02:00PM The text provides a list of various CVE IDs and their corresponding titles and severities. These vulnerabilities span across different Microsoft products such as .NET Framework, ASP.NET, Azure, Mariner, Microsoft Edge, Microsoft Dynamics, Microsoft Exchange Server, Microsoft Office, and others. The severity of the vulnerabilities ranges from Important to Critical.…

    Read More