Skip to main content

Tag: software security

47 articles

software procurement Must-Have Guide: Essential Security

software procurement Must-Have Guide: Essential Security

CISA’s new Software Acquisition Guide Web Tool puts buyers back in control of supply‑chain risk with practical checklists, vendor assessment criteria and contract language to make secure software purchasing repeatable and auditable. If adopted thoughtfully, it can turn procurement from a blind spot into a frontline defense—though success will hinge on implementation, resources and market incentives.

Analyst 207
Secure Software Development: Must-Have Best Practices

Secure Software Development: Must-Have Best Practices

Worried about the security of the software we all depend on? Join NIST NCCoE’s interactive DevSecOps virtual event on August 27, 2025, to hear experts, learn practical secure development practices, and help turn security from an afterthought into a foundation for every project.

Analyst 207
Microsoft SharePoint Under Zero-Day Attack Despite Patch Failures

Microsoft SharePoint Under Zero-Day Attack Despite Patch Failures

In a digital world where collaboration is key, a troubling zero-day vulnerability in Microsoft SharePoint has left users vulnerable and questioning the reliability of their trusted platforms. With critical systems at risk and past patch failures haunting stakeholders, its time to address the urgent need for accountability in software security.

Analyst 207
June 2025 Patch Tuesday: Must-Have Critical Fixes

June 2025 Patch Tuesday: Must-Have Critical Fixes

June’s Patch Tuesday addresses 67 vulnerabilities across Windows, Office and related products — including at least one actively exploited — so patching isn’t optional anymore. Prioritize internet-facing and critical systems, apply temporary mitigations if needed, and reboot promptly to close the window for attackers.

Analyst 207
CrushFTP vulnerability: Exclusive Critical Alert

CrushFTP vulnerability: Exclusive Critical Alert

A critical CrushFTP flaw (CVE-2025-54309) lets remote attackers gain admin control over HTTPS—putting file servers, backups, and connected systems at serious risk. If you run CrushFTP, patch immediately, lock down access, and audit logs to ensure you’re not already compromised.

Analyst 207
Microsoft’s First 2025 Patch Tuesday Arrives Without Active Exploits

Microsoft’s First 2025 Patch Tuesday Arrives Without Active Exploits

Microsoft’s first Patch Tuesday of 2025 brings over 130 crucial fixes—and for the first time this year, none are actively exploited, giving everyone a rare chance to update and stay ahead of cyber threats.

Analyst 207
Security Alert: Malicious Pull Request Affects Over 6,000 Developers Through Vulnerable Ethcode VS Code Extension

Security Alert: Malicious Pull Request Affects Over 6,000 Developers Through Vulnerable Ethcode VS Code Extension

Security Alert: A malicious pull request targets over 6,000 developers via the vulnerable Ethcode VS Code extension. Update your security measures now.

Analyst 207
Veeam Addresses Critical RCE Vulnerability CVE-2025-23121 with New Patches

Veeam Addresses Critical RCE Vulnerability CVE-2025-23121 with New Patches

Veeam releases new patches to address the critical RCE vulnerability CVE-2025-23121, enhancing security and protecting user data.

Analyst 207
Introducing MicroDicom: A Powerful and User-Friendly DICOM Viewer

Introducing MicroDicom: A Powerful and User-Friendly DICOM Viewer

Introducing MicroDicom: a powerful and user-friendly DICOM viewer designed for advanced imaging analysis and seamless diagnostic workflows.

Analyst 207
Trump’s Bold Cybersecurity Overhaul via Executive Order

Trump’s Bold Cybersecurity Overhaul via Executive Order

Trump’s Executive Order launches a bold cybersecurity overhaul to fortify digital defenses and modernize federal systems against evolving cyber threats.

Analyst 207
Code Transparency: Unveiling the Secret to Strong Security

Code Transparency: Unveiling the Secret to Strong Security

Unlock robust security by revealing hidden vulnerabilities through code transparency, ensuring precise risk management and flawless system integrity.

Analyst 207
Firefox Addresses Two Critical Zero-Day Exploits at Pwn2Own Berlin with a $100K Reward

Firefox Addresses Two Critical Zero-Day Exploits at Pwn2Own Berlin with a $100K Reward

Firefox patches two critical zero-day vulnerabilities at Pwn2Own Berlin, awarding a $100K bounty to fortify its browser against emerging threats.

Analyst 207
Researchers Expose New Intel CPU Flaws Enabling Memory Leaks and Spectre v2 Attacks

Researchers Expose New Intel CPU Flaws Enabling Memory Leaks and Spectre v2 Attacks

Researchers reveal new Intel CPU vulnerabilities that enable memory leaks and Spectre v2 attacks, prompting urgent security patches.

Analyst 207
Unicode Camouflage: How a Malicious NPM Package Evades Detection

Unicode Camouflage: How a Malicious NPM Package Evades Detection

Discover how a malicious NPM package uses Unicode camouflage to evade detection by hiding harmful code within secure-looking modules.

Analyst 207
Commvault Resolves Major Command Center Vulnerability Following Flaw Alert

Commvault Resolves Major Command Center Vulnerability Following Flaw Alert

Commvault resolves critical Command Center vulnerability after flaw alert, reinforcing security measures and safeguarding vital data integrity.

Analyst 207
ASUS DriverHub Vulnerability Enables Malicious Websites to Execute Commands with Admin Rights

ASUS DriverHub Vulnerability Enables Malicious Websites to Execute Commands with Admin Rights

ASUS DriverHub vulnerability lets malicious websites run admin-level commands, exposing systems to severe security risks.

Analyst 207
Britain’s cyber agents and industry clash over how to tackle shoddy software

Britain’s cyber agents and industry clash over how to tackle shoddy software

Britain’s cyber agents and tech industry clash over shoddy software. Debate intensifies as both sides push for tougher cybersecurity standards.

Analyst 207
Researchers Discover Malware in Bogus Discord PyPI Package Accumulating Over 11,500 Downloads

Researchers Discover Malware in Bogus Discord PyPI Package Accumulating Over 11,500 Downloads

Researchers uncovered malware in a fake Discord PyPI package, racking up over 11,500 downloads and sparking significant cybersecurity alerts.

Analyst 207
Malicious PyPI packages abuse Gmail, websockets to hijack systems

Malicious PyPI packages abuse Gmail, websockets to hijack systems

Malicious PyPI packages exploit Gmail and websockets to hijack systems, raising cybersecurity concerns and necessitating enhanced threat detection mechanisms.

Analyst 207
Critical Commvault Command Center Flaw Enables Attackers to Execute Code Remotely

Critical Commvault Command Center Flaw Enables Attackers to Execute Code Remotely

Critical Commvault Command Center flaw allows remote code execution. Patch the vulnerability now to secure your systems against potential threats.

Analyst 207
Socket Acquires Coana to Enhance Code Risk Accuracy

Socket Acquires Coana to Enhance Code Risk Accuracy

Socket acquires Coana to improve code risk accuracy, enhancing software security and reliability for developers and businesses alike.

Analyst 207
Malicious npm Packages Imitate Telegram Bot API to Install SSH Backdoors on Linux

Malicious npm Packages Imitate Telegram Bot API to Install SSH Backdoors on Linux

Malicious npm packages mimic the Telegram Bot API to install SSH backdoors on Linux, posing serious security risks for developers and systems.

Analyst 207
Urgent: Easy Exploit Found in Erlang/OTP SSH Pre-Auth RCE – Immediate Patching Required

Urgent: Easy Exploit Found in Erlang/OTP SSH Pre-Auth RCE – Immediate Patching Required

Urgent: A critical RCE vulnerability in Erlang/OTP SSH pre-authentication has been discovered. Immediate patching is required to ensure security.

Analyst 207