By Ionut Arghire

A critical vulnerability in Apache Roller could be used to maintain persistent access by reusing older sessions even after password changes.

The post Critical Vulnerability Found in Apache Roller Blog Server appeared first on SecurityWeek.

…read more

Source:: securityweek


Print pagePDF pageEmail page

By Ionut Arghire

In recent attacks, the state-sponsored backdoor BPFDoor is using a controller to open a reverse shell and move laterally.

The post Enhanced Version of ‘BPFDoor’ Linux Backdoor Seen in the Wild appeared first on SecurityWeek.

…read more

Source:: securityweek


Print pagePDF pageEmail page

Keith Oringer, Founder and President of Security ProAdvisors, passed away on April 11, 2025.

…read more

Source:: Security magazin


Print pagePDF pageEmail page

By Eduard Kovacs

The Rhysida ransomware gang claims to have stolen 2.5 Tb of files from the Oregon Department of Environmental Quality.

The post Ransomware Group Claims Hacking of Oregon Regulator After Data Breach Denial appeared first on SecurityWeek.

…read more

Source:: securityweek


Print pagePDF pageEmail page

By Ryan Naraine

Shield Capital leads a $9 million seed-stage funding round for Israeli startup building technologies for AI security and privacy guardrails.

The post Pillar Security Banks $9M for AI Security Guardrails appeared first on SecurityWeek.

…read more

Source:: securityweek


Print pagePDF pageEmail page

By Kevin Townsend

Top-ranked mobile apps found using hardcoded keys and exposed cloud buckets.

The post Many Mobile Apps Fail Basic Security—Posing Serious Risks to Enterprises appeared first on SecurityWeek.

…read more

Source:: securityweek


Print pagePDF pageEmail page

By algerj@bnpmedia.com (Jordyn Alger)

CISA has extended MITRE’s funding, and security leaders are sharing their thoughts.

…read more

Source:: Security magazin


Print pagePDF pageEmail page

By algerj@bnpmedia.com (Jordyn Alger)

Car rental service Hertz experienced a data breach that may have compromised sensitive customer information.

…read more

Source:: Security magazin


Print pagePDF pageEmail page

By Ryan Naraine

The US government’s cybersecurity agency CISA has “executed the option period on the contract” to keep the vulnerability catalog operational.

The post MITRE CVE Program Gets Last-Hour Funding Reprieve appeared first on SecurityWeek.

…read more

Source:: securityweek


Print pagePDF pageEmail page

By Ryan Naraine

The vulnerabilities are described as code execution and mitigation bypass issues that affect Apple’s iOS, iPadOS and macOS platforms.

The post Apple Pushes iOS, MacOS Patches to Quash Two Zero-Days appeared first on SecurityWeek.

…read more

Source:: securityweek


Print pagePDF pageEmail page