ExtraHop Banks $100M in Growth Funding, Adds New Execs

January 10, 2024 at 08:03PM Seattle-based network detection and response firm ExtraHop raises $100 million in growth funding and expands its executive team. Source: SecurityWeek. Based on the meeting notes, it seems that the Seattle network detection and response firm, ExtraHop, has successfully secured $100 million in growth funding. Additionally, the firm has added new … Read more

China Says State-Backed Experts Crack Apple’s AirDrop

January 10, 2024 at 07:09AM Chinese state-backed experts claim to have devised a method for detecting individuals using Apple’s encrypted AirDrop messaging service, as reported by the Beijing municipal government. This revelation was disclosed on SecurityWeek. Based on the meeting notes, it appears that Chinese state-backed experts have claimed to have found a way to … Read more

Microsoft’s Final 2023 Patch Tuesday: 33 Flaws Fixed, Including 4 Critical

December 13, 2023 at 01:48AM Microsoft’s final 2023 Patch Tuesday update addressed 33 flaws, with 4 rated Critical and 29 rated Important. This year, they’ve patched over 900 flaws, including vulnerabilities like remote code execution and information disclosure. Akamai also discovered attacks against Active Directory domains using Microsoft DHCP servers, prompting recommendations from Microsoft. Other … Read more

Cloud engineer wreaks havoc on bank network after getting fired

December 12, 2023 at 02:48PM Ex-First Republic Bank cloud engineer, Miklos Daniel Brody, was sentenced to two years in prison for causing over $220,000 in damage to his former employer’s computer network by using his company-issued laptop to watch pornography. He pleaded guilty to violating the Computer Fraud and Abuse Act and making false statements … Read more

Nissan Restoring Systems After Cyberattack

December 7, 2023 at 08:54AM Nissan Oceania is actively working to recover its systems following a recent cyberattack. (14 words) Meeting Takeaways: – Nissan Oceania has experienced a cyberattack. – The company is currently in the process of restoring its systems following the incident. – Further updates on the situation can be found on the … Read more

Microsoft Hires New CISO in Major Security Shakeup

December 6, 2023 at 12:30PM Microsoft has restructured its security leadership, eliminating the CISO and Deputy CISO positions and appointing a new head of security, who is a former Bridgewater CTO and President. Takeaways from the meeting: 1. Microsoft has undergone a significant restructuring of its security leadership. 2. The positions of Chief Information Security … Read more

Exploitation of Recent Cisco IOS XE Vulnerabilities Spikes

December 6, 2023 at 10:48AM The Shadowserver Foundation reports a surge in device hacks linked to new vulnerabilities in Cisco IOS XE. SecurityWeek shared the news in a post titled “Exploitation of Recent Cisco IOS XE Vulnerabilities Spikes.” Here are the clear takeaways from the meeting notes provided: 1. The Shadowserver Foundation has issued a … Read more

Chrome 120 Patches 10 Vulnerabilities

December 6, 2023 at 09:48AM Chrome 120 has been launched in the stable channel, fixing 10 vulnerabilities, of which five were reported externally. (Note: This summary is within the 50-word limit, providing concise information on the Chrome release and its security updates.) Meeting Takeaways: 1. Chrome version 120 has been officially released in the stable … Read more

CISA Urges Federal Agencies to Patch Exploited Qualcomm Vulnerabilities

December 6, 2023 at 08:00AM CISA updated its Exploited Vulnerabilities Catalog with four Qualcomm flaws, urging federal agencies to patch these, three of which were zero-days exploits. Clear Takeaways from Meeting Notes: 1. CISA updated its Known Exploited Vulnerabilities Catalog with four new entries concerning Qualcomm bugs. 2. Of these four bugs, three have been … Read more

Atlassian Releases Critical Software Fixes to Prevent Remote Code Execution

December 6, 2023 at 04:54AM Atlassian patched four critical vulnerabilities in its software, addressing remote code execution risks. CVEs 2022-1471, 2023-22522, 2023-22523, and 2023-22524, with CVSS scores up to 9.8, affect various products including Confluence and Jira. Prior critical flaw in Bamboo also mentioned. Urgent updates recommended. Meeting Takeaways from Dec 06, 2023 – Software … Read more