Vulnerability
Discover expert analysis on vulnerability with news, features and insights from the team at IT Pro.
-

Microsoft patches two zero-day vulnerabilities in last Patch Tuesday of 2022
News Zero-days affecting Windows SmartScreen and DirectX were identified in the latest security update
By Ross Kelly Published
News -

Businesses urged to remain vigilant as Log4Shell issues persist one year on
News Thousands of businesses globally were targeted within just days of the vulnerability disclosure
By Ross Kelly Published
News -

China-backed hackers take down Amnesty International Canada for three weeks
News Cyber security experts linked state-sponsored APTs to the tools and methodology of the attack, which may have been intended as a covert campaign
By Rory Bathgate Published
News -

US seizes millions in stolen COVID relief funds by China-backed hackers
News APT41 had stolen at least $20 million intended for small businesses, but this is a drop in the water compared to the total lost
By Rory Bathgate Published
News -

Defra's legacy software problem 'threatens' UK gov cyber security until 2030
News The department spends over two-thirds of its digital budget on maintaining the risky applications, with no plan in place for a fix within the decade
By Rory Bathgate Published
News -

Hyundai vulnerability allowed remote hacking of locks, engine
News Researchers discovered flaws in a number of apps linked to car brands that allowed for personal details and remote control of vehicles using easily-obtained IDs
By Rory Bathgate Published
News -

NSA: Phase out memory-unsafe languages like C and C++
News The US agency advises organisations to begin using languages like Rust, Java, and Swift
By Zach Marzouk Published
News -

Lenovo patches ThinkPad, Yoga, IdeaPad UEFI secure boot vulnerability
News Mistakenly used drivers could allow hackers to modify the secure boot process
By Rory Bathgate Published
News -

GitHub launches private vulnerability reporting to secure the software supply chain
News The new platform aims to simplify vulnerability disclosure and minimise instances where researchers avoid reporting out of personal convenience
By Connor Jones Published
News -

OpenSSL 3.0 vulnerability: Patch released for security scare
News The severity has been downgraded from 'critical' to 'high' and comparisons to Heartbleed have been quashed
By Connor Jones Published
News -

Major security exploits expected to rise before New Year
News Supply chain attacks are also expected to increase, along with affiliate programmes becoming more popular
By Zach Marzouk Published
News -

Second-ever OpenSSL critical vulnerability teased, 10 years after Heartbleed
News All OpenSSL versions beyond 3.0 are at risk, with more details due to be released alongside a patch on 1 November
By Rory Bathgate Published
News