Details have been disclosed on a remote code execution flaw in Azure Cosmos DB, which was previously fixed by Microsoft in October.
Thousands of internet-exposed servers remain vulnerable to the critical-severity ConnectWise flaw.
VMware Cloud Foundation is impacted by a remote code execution vulnerability in the XStream open source library.
OpenSSL will patch a critical security flaw in version 3.0.x on Nov.1, though details of the bug are still private.
Welcome to Source Code: Decipher's behind the scenes look at the weekly news with input from our sources.
The voluntary goals aim to provide a security baseline, in particular for small- and medium-sized critical infrastructure organizations.
Kelley Misata, senior director of open source of open source at Corelight and CEO of Sightline Security, joins Dennis Fisher to talk about her road to get into security, the importance of protecting at-risk populations, and the challenges of building community in the open source world.
The DoJ said that a 26-year-old Ukrainian national, Mark Sokolovky, had been arrested in March by Dutch authorities as an alleged operator of the Raccoon Stealer malware.
Microsoft is adding number matching and geographic and app context to Authenticator to defend against MFA fatigue attacks.
Apple has fixed a kernel zero day in iOS 16.1, along with a huge number of vulnerabilities in macOS Ventura.
A newly proposed order against Drizly will also bind its CEO to specific data security-related requirements after a 2020 data breach.
The Daixin group has been targeting healthcare organizations with double extortion ransomware attacks, U.S. government agencies warned.
Threat actors are using customized exfiltration tools in hopes of increasing the speed for their ransomware attacks.
Welcome to Source Code: Decipher's behind the scenes look at the weekly news with input from our sources.
The FBI is warning companies about hack-and-leak operations from Iranian threat actor Emennet Pasargad.