Cloud Consultancy News
Apple issues patch for macOS security bypass vulnerability
Apple has fixed a vulnerability in macOS that could have allowed attackers to bypass application restrictions on the tech giant’s Gatekeeper mechanism. The vulnerability, tracked as CVE-2022-42821 and dubbed ‘Achilles’, was first uncovered by researchers at Microsoft...
NIST Finally Retires SHA-1, Kind Of
It is time to retire SHA-1, or the Secure Hash Algorithm-1, says the US National Institute of Standards and Technology (NIST). NIST has set the date of Dec. 31, 2030 to remove SHA-1 support from all software and hardware devices. The once-widely used algorithm is now...
Web skimming hackers infiltrate over 40 ecommerce websites – that we know of
A new set of web skimming attacks have been discovered by JavaScript monitoring company Jscrambler, including attacks using methods that are reportedly unrecognizable. In a blog post(opens in new tab), the company outlined how it detected a web skimming attack on a...
Cisco Warns of High-Severity Unpatched Flaw Affecting IP Phones Firmware
Cisco has released a new security advisory warning of a high-severity flaw affecting IP Phone 7800 and 8800 Series firmware that could be potentially exploited by an unauthenticated attacker to cause remote code execution or a denial-of-service (DoS) condition. The...
WhatsApp could abandon UK if government bans E2E encryption
Meta-owned WhatsApp is willing to see its messaging app blocked in the UK rather than weaken its encryption. Will Cathcart, head of WhatsApp at Meta, told The Telegraph that if the Government's new Online Safety Bill compels the firm to stop end-to-end (e2e)...
Fortinet Ships Emergency Patch for Already-Exploited VPN Flaw
Fortinet on Monday issued an emergency patch to cover a severe vulnerability in its FortiOS SSL-VPN product, warning that hackers have already exploited the flaw in the wild. A critical-level advisory from Fortinet described the bug as a memory corruption that allows...
Fear of cyberattacks drives SMBs to spend more on software
Despite fears of a looming recession, SMBs in the U.S. are spending more on software in 2023, according to Capterra’s 2023 SMB Software Buying Trends Survey. 75% of U.S. SMBs estimate they’ll spend more on software in 2023 compared to 2022. Alongside increased...
Apple unveils end-to-end encryption for iCloud backup, Photos, etc.
Apple is expanding end-to-end encryption options for users and finally offering E2EE for their iCloud backup. Advanced Data Protection for iCloud “iCloud already protects 14 sensitive data categories using end-to-end encryption by default, including passwords in...
Samsung Galaxy S22 hacked twice on first day of Pwn2Own Toronto
Contestants have hacked the Samsung Galaxy S22 smartphone twice during the first day of the Pwn2Own Toronto 2022 hacking competition, the 10th edition of the consumer-focused event. The STAR Labs team was the first to successfully exploit a zero-day on Samsung's...
Vice Society Ransomware Attackers Targeted Dozens of Schools in 2022
The Vice Society cybercrime group has disproportionately targeted educational institutions, accounting for 33 victims in 2022 and surpassing other ransomware families like LockBit, BlackCat, BianLian, and Hive. Other prominent industry verticals targeted include...