Sophos introduces ZTNA for secure user and device connections
Sophos is introducing a Zero Trust Network Access (ZTNA) portfolio. Zero trust principles and far-reaching integration with Sophos Intercept X's endpoint security are key to the release.
With the arrival of Zero Trust Network Access (ZTNA), Sophos wants to offer a transparent and scalable securi... Read more
Critical Linux vulnerability affects all major distributions
Security researchers have found vulnerabilities in Linux PolicyKit (also known as Polkit). The vulnerabilities allow hackers to gain complete access to affected machines and upload malicious code. The issue has since been patched.
According to Qualys researchers, the so-called PwnKit exploit man... Read more
Log4J hackers continue targeting VMware Horizon servers
VMware is rushing to convince customers to apply the latest security guidance.
According to several cybersecurity companies monitoring the situation, attackers are still targeting VMware Horizon servers through Log4J vulnerabilities.
Two weeks ago, the UK's National Health Service (NHS)... Read more
Microsoft finds a new SolarWinds vulnerability during Log4j research
A Log4j investigation led Microsoft to a new vulnerability related to the infamous SolarWinds attack of 2020.
Microsoft states that the search for various Log4j vulnerabilities yielded a welcome byproduct. During a recent investigation, researchers stumbled upon a previously unknown vulnerabilit... Read more
WordPress plugins from AccessPress Themes have backdoors for hackers
Security specialist Jetpack discovered backdoors in legitimate WordPress plugins from AccessPress Themes, a WordPress dev. The backdoors allow hackers to take complete control of WordPress websites.
Jetpack's investigation shows that AccessPress Themes' WordPress plugins and themes feature a bac... Read more
Deloitte chooses Exabeam for XDR/SIEM capabilities in MXDR
Deloitte has chosen Exabeam for their XDR and SIEM capabilities of their new MXDR offering, which we reported on on more detail yesterday. Exabeam details why Deloitte chose them in a separate release.
Deloitte launched the MXDR suite earlier this week. It consists of the offerings of Zscaler, S... Read more
Google launches anti-phishing alerts in Google Drive
Google will now warn of phishing, malware and ransomware when opening files in Google Drive.
Google Drive integrates with numerous apps to open files in the cloud. Think of Google Docs for .docx's, Adobe Acrobat for .pdf's and Music Player for .mp3's. Although downloading a file has triggered a ... Read more
Deloitte launches Managed Extended Detect and Response platform
Deloitte has finally launched its latest threat detection and response platform, MXDR (Managed Extended Detect and Response). This SaaS platform is designed for "human-powered, flexible, technology-enabled security operations."
Essentially, clients will receive a "composable, unified, integrated... Read more
Data of half a million people at risk in hack on Red Cross
An enormous hack has hit the International Committee of the Red Cross (ICRC). The personal data of as many as 515,000 people has been stolen. The perpetrator of the attack is unknown at this time.
According to the IRCR, the hackers managed to steal personal information from databases of at least... Read more
Zoom was vulnerable to buffer overflows and memory leaks
Project Zero found two vulnerabilities in Zoom, which have since been patched. Clients of users were found to be susceptible to buffer overflows. Data from central Zoom servers was successfully leaked from outside the network.
The vulnerabilities were found by Natalie Silvanovich, a security res... Read more