Category: CyberSecurity

Microsoft DRM Hacking Raises Questions on Vulnerability Disclosures

A research project targeting vulnerabilities in widely used content access and protection technology from Microsoft raises some questions over certain aspects of responsible disclosure. For the past several years, Adam Gowdiak, founder and CEO of AG Security Research (formerly Security Explorations) has been looking into the security of digital content, specifically video streaming platforms. Gowdiak […]

Explore More

Darktrace to Acquire Incident Investigation Firm Cado Security

Darktrace on Thursday announced the “proposed acquisition” of UK-based incident investigation and response firm Cado Security.  Financial terms have not been disclosed for the deal that is expected to be completed in February, but the Australian Financial Review (AFR) reported (paywalled link) that Darktrace will pay an estimated $50 million to $100 million, subject to […]

Explore More

Medical Billing Firm Medusind Says Data Breach Impacts 360,000 People

Florida-based medical and dental billing and revenue cycle management company Medusind has revealed that a data breach discovered in December 2023 impacts over 360,000 individuals. The company, which serves thousands of healthcare providers, revealed in letters sent to affected individuals that it discovered an intrusion on December 29, 2023.  An investigation conducted with the aid […]

Explore More

GFI KerioControl Firewall Vulnerability Exploited in the Wild

Threat actors are exploiting a recently disclosed GFI KerioControl firewall vulnerability that leads to one-click remote code execution (RCE), threat intelligence firm GreyNoise warns. GFI KerioControl is a network security solution that provides firewall functionality and unified threat management capabilities, including threat detection and blocking, traffic control, intrusion prevention, and VPN features. The exploited issue, […]

Explore More

SonicWall Patches Authentication Bypass Vulnerabilities in Firewalls

SonicWall this week announced patches for multiple vulnerabilities in its firewalls, including two high-severity flaws that could lead to authentication bypass. Tracked as CVE-2024-40762, the first issue exists because the authentication token generator in SonicOS versions running on tens of SSL-VPN firewalls uses a cryptographically weak pseudo-random number generator (PRNG) that could be predicted by […]

Explore More

Palo Alto Networks Patches High-Severity Vulnerability in Retired Migration Tool

Palo Alto Networks on Wednesday announced patches for multiple vulnerabilities in the Expedition migration tool, including a high-severity bug leading to sensitive information disclosure. A free tool previously known as the Migration Tool, Expedition allows organizations to migrate from other firewall vendors to the Palo Alto Networks NGFW platform. Designed as a temporary migration solution […]

Explore More

Excelsior Orthopaedics Data Breach Impacts 357,000 People

Excelsior Orthopaedics is notifying approximately 357,000 people that their personal and health information was compromised in a data breach resulting from a ransomware attack that came to light in June 2024. Operating several clinics in Amherst, New York, including the Buffalo Surgery Center and Northtowns Orthopaedics, Excelsior Orthopaedics is a healthcare company that specializes in […]

Explore More

Exploitation of New Ivanti VPN Zero-Day Linked to Chinese Cyberspies

Google Cloud’s Mandiant has linked the exploitation of a newly patched Ivanti VPN zero-day vulnerability to Chinese cyberspies. Ivanti alerted customers on Wednesday that two vulnerabilities, tracked as CVE-2025-0282 and CVE-2025-0283, have been patched in its Connect Secure (ICS) VPN appliances.  CVE-2025-0282, a critical stack-based buffer overflow that allows unauthenticated remote attackers to execute arbitrary […]

Explore More

Let’s Work Together!
Just Drop Us a line - [email protected]

Subscribe to our Newsletter

copyright 2024 by Digital Creations LLC