2 Android Zero-Day Bugs Under Active Exploit

Neither security issue requires user interaction, and one of the vulnerabilities was used to unlock a student activist’s device in an attempt to install spyware.

darkreading – ​Read More

Adobe Calls Urgent Attention to Critical ColdFusion Flaws

The Adobe Patch Tuesday rollout covers 54 vulnerabilities, including code execution issues in the oft-targeted Adobe ColdFusion software.

The post Adobe Calls Urgent Attention to Critical ColdFusion Flaws appeared first on SecurityWeek.

SecurityWeek – ​Read More

Amazon EC2 SSM Agent Flaw Patched After Privilege Escalation via Path Traversal

Cybersecurity researchers have disclosed details of a now-patched security flaw in the Amazon EC2 Simple Systems Manager (SSM) Agent that, if successfully exploited, could permit an attacker to achieve privilege escalation and code execution.
The vulnerability could permit an attacker to create directories in unintended locations on the filesystem, execute arbitrary scripts with root privileges,

The Hacker News – ​Read More

How Meta’s new teen accounts aim to keep your kids safer on Facebook

These teen accounts for Facebook and Messenger are packed with restrictions.

Latest stories for ZDNET in Security – ​Read More

Network Access Vendor Portnox Secures $37.5 Million Investment

Texas network access control startup closes a Series B round led by Updata Partners and brings the total raised to $60 million.

The post Network Access Vendor Portnox Secures $37.5 Million Investment appeared first on SecurityWeek.

SecurityWeek – ​Read More

Vulnerability Management Firm Spektion Emerges From Stealth With $5 Million in Funding

Spektion has emerged from stealth mode with $5 million in seed funding for its vulnerability management solution.

The post Vulnerability Management Firm Spektion Emerges From Stealth With $5 Million in Funding appeared first on SecurityWeek.

SecurityWeek – ​Read More

Octane Raises $6.75M for Smart Contract Security Tech

San Francisco smart contract security startup closes a $6.75 million seed funding round led by Archetype and Winklevoss Capital.

The post Octane Raises $6.75M for Smart Contract Security Tech appeared first on SecurityWeek.

SecurityWeek – ​Read More

Google fixes two Android zero-day bugs actively exploited by hackers

The most severe security bug can be exploited without user interaction, per Google.

Security News | TechCrunch – ​Read More

DNS: The Secret Weapon CISOs May Be Overlooking In the Fight Against Cyberattacks

While often relegated to a purely functional role, DNS offers unparalleled opportunities for preemptive defense against cyberattacks.

The post DNS: The Secret Weapon CISOs May Be Overlooking In the Fight Against Cyberattacks appeared first on SecurityWeek.

SecurityWeek – ​Read More

Anecdotes Raises $30 Million for Enterprise GRC Platform

Anecdotes has raised $55 million in an extended Series B funding round that brings the total raised by the company to $85 million. 

The post Anecdotes Raises $30 Million for Enterprise GRC Platform appeared first on SecurityWeek.

SecurityWeek – ​Read More