NSA’s Top 10 Cloud Best Practices

NSA’s Top 10 Cloud Best Practices

NSA researchers released cloud security mitigation strategies in an attempt to educate best security practices. Threat actors mostly target cloud users while they shift their data to cloud environments. For…
GUAC tool joins OpenSSF Project

GUAC tool joins OpenSSF Project

The developers of GUAC, a tool for finding vulnerabilities, announced that they have donated the project to the OpenSSF consortium. GUAC was released in 2022 by Google, Kusari, Citibank, and…
Cisco fixes Secure Client Vulnerabilities

Cisco fixes Secure Client Vulnerabilities

Cisco released patches for two high severity vulnerabilities in Secure Client, the enterprise VPN application that also incorporates security and monitoring capabilities. The first issue, tracked as CVE-2024-20337, impacts the…
VMware Ceitical Sandbox escape Bug

VMware Ceitical Sandbox escape Bug

VMware is urging customers to patch critical vulnerabilities that make it possible for hackers to break out of sandbox and hypervisor protections in all versions, including out-of-support ones, of VMware…
CISA KEV Update March 2024 – Part I

CISA KEV Update March 2024 – Part I

The U.S. CISA has added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2023-21237 Android Pixel Information Disclosure Vulnerability CVE-2021-36380 Sunhillo SureLine OS Command Injection Vulnerablity CVE-2024-21338 Microsoft Windows Kernel Exposed IOCTL with Insufficient…
Apple addressed iOS Zeroday Vulnerabilities

Apple addressed iOS Zeroday Vulnerabilities

Apple has released emergency updates to fix two iOS zero-day vulnerabilities that were exploited in attacks against iPhone devices. The first vulnerability tracked as CVE-2024-23225 is a Kernel memory corruption…