Friday, 1 May 2020

Oracle Says Hackers Targeting Recently Patched Vulnerabilities

Oracle warned customers on Thursday that threat actors have been spotted attempting to exploit multiple recently patched vulnerabilities, including a critical WebLogic Server flaw tracked as CVE-2020-2883.

read more



from SecurityWeek RSS Feed https://ift.tt/2z0lbxf
via https://ifttt.com/ IFTTT

DHS Reiterates Recommendations on Securing Office 365

An alert the U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) published this week reiterates previously issued recommendations on how organizations should properly secure Microsoft Office 365 deployments.

read more



from SecurityWeek RSS Feed https://ift.tt/2yivpZB
via https://ifttt.com/ IFTTT

Critical SaltStack RCE Bug (CVSS Score 10) Affects Thousands of Data Centers

Two severe security flaws have been discovered in the open-source SaltStack Sat configuration framework that could allow an adversary to execute arbitrary code on remote servers deployed in data centers and cloud environments. The vulnerabilities were identified by F-Secure researchers earlier this March and disclosed on Thursday, a day after SaltStack released a patch (version 3000.2)

from The Hacker News https://ift.tt/2zLIWJD
via https://ifttt.com/ IFTTT

Several Vulnerabilities Patched With Release of WordPress 5.4.1

Several vulnerabilities, most of which have been described as cross-site scripting (XSS) flaws, have been patched in WordPress this week with the release of version 5.4.1.

read more



from SecurityWeek RSS Feed https://ift.tt/2yh67ey
via https://ifttt.com/ IFTTT

CISA Reminds Federal Agencies to Use Its DNS Service

A memorandum sent by the United States Cybersecurity and Infrastructure Security Agency (CISA) to Chief Information Officers (CIOs) at federal agencies reminds them to use EINSTEIN 3 Accelerated (E3A)’s Domain Name System (DNS) sinkholing capability for DNS resolution.

read more



from SecurityWeek RSS Feed https://ift.tt/35qtC0L
via https://ifttt.com/ IFTTT

Sophisticated Phishing Kit Used by Multiple Groups to Target Executives

A sophisticated phishing kit has been used by multiple cybercrime groups to target high-ranking employees in North America and other parts of the world, and researchers believe there are at least 150 victims.

read more



from SecurityWeek RSS Feed https://ift.tt/2WubWxt
via https://ifttt.com/ IFTTT

Criminals Quick to Exploit COVID-19 Crisis in Europe

Individuals and criminal organizations have taken immediate advantage of the COVID-19 pandemic to find new ways of making money, the European Union’s law enforcement agency said Thursday, citing a spike in counterfeiting and cybercrime.

read more



from SecurityWeek RSS Feed https://ift.tt/3bTNN9X
via https://ifttt.com/ IFTTT