Tag: software security
47 articles

software procurement Must-Have Guide: Essential Security
CISA’s new Software Acquisition Guide Web Tool puts buyers back in control of supply‑chain risk with practical checklists, vendor assessment criteria and contract language to make secure software purchasing repeatable and auditable. If adopted thoughtfully, it can turn procurement from a blind spot into a frontline defense—though success will hinge on implementation, resources and market incentives.

Secure Software Development: Must-Have Best Practices
Worried about the security of the software we all depend on? Join NIST NCCoE’s interactive DevSecOps virtual event on August 27, 2025, to hear experts, learn practical secure development practices, and help turn security from an afterthought into a foundation for every project.

Microsoft SharePoint Under Zero-Day Attack Despite Patch Failures
In a digital world where collaboration is key, a troubling zero-day vulnerability in Microsoft SharePoint has left users vulnerable and questioning the reliability of their trusted platforms. With critical systems at risk and past patch failures haunting stakeholders, its time to address the urgent need for accountability in software security.

June 2025 Patch Tuesday: Must-Have Critical Fixes
June’s Patch Tuesday addresses 67 vulnerabilities across Windows, Office and related products — including at least one actively exploited — so patching isn’t optional anymore. Prioritize internet-facing and critical systems, apply temporary mitigations if needed, and reboot promptly to close the window for attackers.

CrushFTP vulnerability: Exclusive Critical Alert
A critical CrushFTP flaw (CVE-2025-54309) lets remote attackers gain admin control over HTTPS—putting file servers, backups, and connected systems at serious risk. If you run CrushFTP, patch immediately, lock down access, and audit logs to ensure you’re not already compromised.

Microsoft’s First 2025 Patch Tuesday Arrives Without Active Exploits
Microsoft’s first Patch Tuesday of 2025 brings over 130 crucial fixes—and for the first time this year, none are actively exploited, giving everyone a rare chance to update and stay ahead of cyber threats.

Security Alert: Malicious Pull Request Affects Over 6,000 Developers Through Vulnerable Ethcode VS Code Extension
Security Alert: A malicious pull request targets over 6,000 developers via the vulnerable Ethcode VS Code extension. Update your security measures now.

Veeam Addresses Critical RCE Vulnerability CVE-2025-23121 with New Patches
Veeam releases new patches to address the critical RCE vulnerability CVE-2025-23121, enhancing security and protecting user data.

Introducing MicroDicom: A Powerful and User-Friendly DICOM Viewer
Introducing MicroDicom: a powerful and user-friendly DICOM viewer designed for advanced imaging analysis and seamless diagnostic workflows.

Trump’s Bold Cybersecurity Overhaul via Executive Order
Trump’s Executive Order launches a bold cybersecurity overhaul to fortify digital defenses and modernize federal systems against evolving cyber threats.

Code Transparency: Unveiling the Secret to Strong Security
Unlock robust security by revealing hidden vulnerabilities through code transparency, ensuring precise risk management and flawless system integrity.

Firefox Addresses Two Critical Zero-Day Exploits at Pwn2Own Berlin with a $100K Reward
Firefox patches two critical zero-day vulnerabilities at Pwn2Own Berlin, awarding a $100K bounty to fortify its browser against emerging threats.

Researchers Expose New Intel CPU Flaws Enabling Memory Leaks and Spectre v2 Attacks
Researchers reveal new Intel CPU vulnerabilities that enable memory leaks and Spectre v2 attacks, prompting urgent security patches.

Unicode Camouflage: How a Malicious NPM Package Evades Detection
Discover how a malicious NPM package uses Unicode camouflage to evade detection by hiding harmful code within secure-looking modules.

Commvault Resolves Major Command Center Vulnerability Following Flaw Alert
Commvault resolves critical Command Center vulnerability after flaw alert, reinforcing security measures and safeguarding vital data integrity.

ASUS DriverHub Vulnerability Enables Malicious Websites to Execute Commands with Admin Rights
ASUS DriverHub vulnerability lets malicious websites run admin-level commands, exposing systems to severe security risks.

Britain’s cyber agents and industry clash over how to tackle shoddy software
Britain’s cyber agents and tech industry clash over shoddy software. Debate intensifies as both sides push for tougher cybersecurity standards.

Researchers Discover Malware in Bogus Discord PyPI Package Accumulating Over 11,500 Downloads
Researchers uncovered malware in a fake Discord PyPI package, racking up over 11,500 downloads and sparking significant cybersecurity alerts.

Malicious PyPI packages abuse Gmail, websockets to hijack systems
Malicious PyPI packages exploit Gmail and websockets to hijack systems, raising cybersecurity concerns and necessitating enhanced threat detection mechanisms.

Critical Commvault Command Center Flaw Enables Attackers to Execute Code Remotely
Critical Commvault Command Center flaw allows remote code execution. Patch the vulnerability now to secure your systems against potential threats.

Socket Acquires Coana to Enhance Code Risk Accuracy
Socket acquires Coana to improve code risk accuracy, enhancing software security and reliability for developers and businesses alike.

Malicious npm Packages Imitate Telegram Bot API to Install SSH Backdoors on Linux
Malicious npm packages mimic the Telegram Bot API to install SSH backdoors on Linux, posing serious security risks for developers and systems.

Urgent: Easy Exploit Found in Erlang/OTP SSH Pre-Auth RCE – Immediate Patching Required
Urgent: A critical RCE vulnerability in Erlang/OTP SSH pre-authentication has been discovered. Immediate patching is required to ensure security.