Vulnerabilities
More Cyberattacks in the First Half of 2020 Than in All of 2019
A recent study by CrowdStrike showed more cyberattacks in the first six months of this year than in all of 2019 in the network activity of Crowdstrike customers. It's a trend that's ...
The ENISA Cybersecurity Threat Landscape
ENISA, the European Union Agency for CyberSecurity, met on October 6, 2020 to review their current recommendations and get any last minute changes. On October 20, 2020, they released a huge batch ...
Disconnect Your TCL Smart TV From the Internet—NOW
Researchers are sounding the alarm about Android TVs from TCL. A pair of bugs make them serious targets for hackers, and the TVs have a Chinese backdoor ...
One Key Cyber Security Fact
Earlier this year, in March of 2020, CSO Online published an article on the key facts and figures around cyber security for 2020, including the astonishing fact that 60% of attacks were ...
Contrast Security’s Approach to SCA Enables Vulnerability Prioritization and Faster Remediation
Open Source Is a Mainstay in Modern Development It goes without saying that modern applications are rarely built from scratch today. Open-source software (OSS) communities are well-organized and licensing is usually pretty ...
Attackers vs. Hackers – Two *Very* Different Animals
The cybersecurity industry is more well-informed than most, but even so, misconceptions arise and spread, helped along by the fact that the rise in cybersecurity incidents has led to substantial “pop culture” ...
VERT Threat Alert: November 2020 Patch Tuesday Analysis
Today’s VERT Alert addresses Microsoft’s November 2020 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-915 on Wednesday, November 11th. Note: Microsoft has changed their ...
Discord.dll: successor to npm “fallguys” malware went undetected for 5 months
This week, the Sonatype Security Research team has identified a series of counterfeit components in the npm ecosystem. These intentionally malicious packages seem to be doing similar, shady things to the malicious ...
Great British Prank: Company Name Contains XSS Hack
A prankster registered a British company name containing a cross-site scripting (XSS) attack. Hilarity ensued ...
Gitpaste-12: A dozen exploits that silently lived on GitHub, attacked Linux servers
Just months after Octopus Scanner was caught infecting 26 open-source projects on GitHub, new reports have already surfaced of another, new sophisticated malware infection. Gitpaste-12, a worming botnet, is extremely versatile in ...

