The Impacts of Government Regulations on PQC Product Availability
U.S. government regulation has an impact on PQC availability, with different certified encryption methods being required for products handling government info.
CISA Requests Public Comment for Draft National Cyber Incident Response Plan Update
Today, CISA—through the Joint Cyber Defense Collaborative and in coordination with the Office of the National Cyber Director (ONCD)—released the National Cyber Incident Response Plan Update Public Comment Draft. The draft requests public comment on...
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. CVE-2024-20767 Adobe ColdFusion Improper Access Control Vulnerability CVE-2024-35250 Microsoft Windows Kernel-Mode Driver...
Cybersecurity best practices toolkit: Power up your mid-market defenses
Mid-market enterprises need strong defenses. This Cybersecurity Best Practices Toolkit features cheat sheets and tabletop exercises to help organization stay ahead of threats.
Closing the SMB cybersecurity skills gap: Key steps
SMBs face a growing cybersecurity crisis, exacerbated by a severe shortage of skilled professionals. A global survey commissioned by Sophos highlights the pressing nature of the challenge.
A thwarted attack demonstrates that threat actors using yet another delivery method for the malware, which already has been spread using phishing emails, malvertising, hijacking of instant messages, and SEO poisoning.
Exploit attempts inspired by recent Struts2 File Upload Vulnerability (CVE-2024-53677, CVE-2023-50164), (Sun, Dec 15th)
Last week, Apache announced a vulnerability in Struts2 [1]. The path traversal vulnerability scored 9.5 on the CVSS scale. If exploited, the vulnerability allows file uploads into otherwise restricted directories, which may lead to remote code...