Category Security

CISA Updates Zero Trust Maturity Model With Public Feedback

The US Cybersecurity and Infrastructure Security Agency (CISA) published the second version of its Zero Trust maturity model on Tuesday. It incorporates recommendations from the public comment period. The updated guidelines are intended to facilitate federal progress toward a Zero…

Can’t See or Secure Them Until It’s Too Late

A difficult question to answer: “How many service accounts do you have in your environment?” The harder question is, “Do you know what these accounts are doing?” And perhaps the hardest part is, “If one of your service accounts is…

Microsoft Fixes Zero-Day Bug This Patch Tuesday

Microsoft’s Patch Tuesday release this month included a security update for a zero-day Windows vulnerability in the wild. The bug in question, CVE-2023-28252, has been described as a privilege escalation vulnerability in the Windows Common Log File System (CLFS) driver.…

Researchers Uncover 7000 Malicious Open Source Packages

Security vendor Sonatype detected 6,933 malicious open source packages in March alone, bringing the total number detected since 2019 to 115,165. The infostealer consisted of quite a few of these malicious components, including imitations of the popular W4SP stealer, such…

New Zero-Click iOS Exploit Deploys Israeli Spyware

Security researchers have discovered a new zero-click, zero-day exploit targeting iPhone users in 2021 using commercial spyware created by Israeli secret company QuaDream. Together, Microsoft and Citizen Labs have unveiled a campaign targeting at least five “victims of civil society”…