Common Vulnerabilities and Exposures (CVE) stories - Page 3
CVE system secures 11-month extension worth USD $44 million
Thu, 17th Apr 2025
#
advanced persistent threat protection
#
cybersecurity
#
cyber threat
CISA extends its contract with MITRE for another 11 months at USD $44 million, securing the critical CVE vulnerability programme amid funding concerns.
Future of CVE repository in doubt as MITRE contract ends
Thu, 17th Apr 2025
#
advanced persistent threat protection
#
cybersecurity
#
cyber threat
Concerns rise as MITRE's contract to manage the CVE vulnerability database nears expiry, risking disruption to global cybersecurity infrastructure.
US funding lapse casts uncertainty over global CVE system
Thu, 17th Apr 2025
#
cybersecurity
#
incident response
#
infosecurity europe
US government funding for MITRE's CVE programme has expired, risking disruption to global cybersecurity efforts and vulnerability tracking systems.
Microsoft April Patch Tuesday highlights zero-day risks
Fri, 11th Apr 2025
#
ransomware
#
cybersecurity
#
microsoft
Microsoft's recent Patch Tuesday sparked scrutiny with a 40-minute delay in updates and notable vulnerabilities, including a critical zero-day in the CLFS Driver.
Zscaler report urges shift from VPNs to Zero Trust
Fri, 11th Apr 2025
#
vpns
#
ransomware
#
cloud security
Zscaler's 2025 ThreatLabz VPN Risk Report reveals soaring VPN usage in Australia but warns of heightened security risks, urging a shift to Zero Trust architectures.
N-able launches new feature to boost vulnerability management
Fri, 11th Apr 2025
#
advanced persistent threat protection
#
cybersecurity
#
windows
N-able has launched a new Vulnerability Management feature for its UEM products, enhancing risk mitigation for organisations amid rising cyber threats.
RunZero expands platform for enhanced exposure management
Tue, 8th Apr 2025
#
risk & compliance
#
omdia
#
asset discovery
runZero has unveiled an expanded platform to enhance exposure management, promising to aid organisations in effectively managing risk across their attack surfaces.
Kaspersky discovers & patches zero-day Chrome flaw
Thu, 3rd Apr 2025
#
malware
#
edutech
#
endpoint protection
Kaspersky has uncovered and patched a critical zero-day vulnerability in Google Chrome, enabling attackers to bypass sandbox protections via malicious links.
GitHub Action compromise affects over 23,000 repositories
Thu, 20th Mar 2025
#
supply chain
#
open source
#
software development
A malicious commit in the tj-actions/changed-files GitHub Action, used in over 23,000 repositories, threatens software security across numerous CI pipelines.
Building a culture of cyber hygiene
Tue, 18th Mar 2025
#
data protection
#
phishing
#
physical security
As cyber attacks surge, the World Economic Forum warns of a widening skills gap, urging organisations to foster a culture of cyber hygiene for better security.
JFrog & Hugging Face join forces to secure AI models
Tue, 18th Mar 2025
#
advanced persistent threat protection
#
supply chain
#
ai security
JFrog has partnered with Hugging Face to enhance security for machine learning models, boosting safety measures on the Hugging Face Hub against potential threats.
Microsoft patches 56 vulnerabilities, 7 zero days fixed
Tue, 18th Mar 2025
#
phishing
#
email security
#
cybersecurity
Microsoft has patched 56 vulnerabilities in its latest update, including seven zero-day flaws, six of which have been actively exploited.
February 2025 reports record spike in ransomware attacks
Mon, 17th Mar 2025
#
ransomware
#
semiconductors
#
socs
A recent Bitdefender report reveals February 2025 as the worst month for ransomware, with victims rising 126% to 962, including a notable impact on Australia.
Mandiant uncovers UNC3886 cyber-attack on Juniper routers
Thu, 13th Mar 2025
#
malware
#
firewalls
#
network infrastructure
Mandiant has uncovered a sophisticated cyber espionage campaign by the China-linked group UNC3886, targeting outdated Juniper Networks routers with advanced malware.
Australia ranks fourth in global cybersecurity attack list
Thu, 27th Feb 2025
#
iot security
#
wireless networks
#
cybersecurity
Australia has climbed to fourth place globally for cyberattacks on critical infrastructure, as a report reveals a surge in diverse threats targeting various sectors.
2025 forecast predicts a rise in global cyber threats
Wed, 26th Feb 2025
#
risk & compliance
#
cybersecurity
#
cyber espionage
The Forum of Incident Response and Security Teams predicts a staggering 45,505 reported vulnerabilities for 2025, marking an 11% rise from 2024.
FBI & CISA warn of Ghost ransomware threats worldwide
Tue, 25th Feb 2025
#
malware
#
ransomware
#
advanced persistent threat protection
The FBI and CISA have alerted organisations to increased cyber threats from China's Ghost ransomware group, affecting over 70 countries through outdated software.
Microsoft's February 2025 patch fixes 56 vulnerabilities
Mon, 24th Feb 2025
#
malware
#
encryption
#
cybersecurity
Microsoft has patched 56 vulnerabilities in its February 2025 update, including two now exploited, marking a fifth month of no critical zero-days released.
High-severity SQL vulnerability found in PostgreSQL tool
Fri, 14th Feb 2025
#
rapid7
#
beyondtrust
#
postgresql
Rapid7 has revealed a critical SQL injection vulnerability in PostgreSQL's psql tool, potentially exposing users to severe security risks.
GitHub partners with Endor Labs to boost security features
Fri, 14th Feb 2025
#
cloud security
#
application security
#
devsecops
GitHub has partnered with Endor Labs, integrating advanced security software to help developers swiftly identify and manage critical vulnerabilities within the platform.