Tag Archive for: scrambles

Google Scrambles to Fix Chrome’s Second Zero-Day Exploit in Just Days!


Google Chrome Users Beware: Zero-Day Vulnerability Exploited | Update NOW!

Google Chrome Users Beware: Zero-Day Vulnerability Exploited | Update NOW!

In a shocking development, Google has rushed to release an emergency fix for yet another high-severity zero-day exploit in its Chrome web browser . The flaw, known as CVE-2023-2136, is a result of an integer overflow in Skia, an open source 2D graphics library, which was discovered by Clément Lecigne of Google’s Threat Analysis Group (TAG) on April 12, 2023 .

Double Trouble: A Second Zero-Day Exploit

This is the second Chrome zero-day vulnerability exploited by malicious actors this year, coming hot on the heels of Google patching CVE-2023-2033 just last week . It remains unclear whether the two exploits have been used in tandem as part of in-the-wild attacks.

Patch it up, Folks!

Google has urged users to upgrade their browsers to version 112.0.5615.137/138 for Windows, 112.0.5615.137 for macOS, and 112.0.5615.165 for Linux in order to mitigate potential threats . Users of Chromium-based browsers such as Microsoft Edge, Brave, Opera, and Vivaldi should also apply the fixes as soon as they become available .

Act Now or Regret Later!

In light of these alarming events, it’s crucial for users to stay vigilant and take action by updating their browsers to the latest versions. Don’t let your digital lives fall into the hands of cunning cybercriminals. Stay one step ahead and protect your online presence!

Source…

Under Scrutiny, Big Ag Scrambles To Address Cyber Risk


At first glance, the LinkedIn post from a UK based security researcher was unremarkable: a photo of vendor swag – a hat, iron-on patch and gym bag he received as a “thank you” for participating in the company’s bug bounty program and reporting software flaws in a company’s products. 

What was remarkable was the company logo on the swag: the distinctive yellow stag set against the bright green of agricultural equipment giant John Deere. A handwritten note to the researcher, Sai Ganesh (@ganiganeshss79), thanked him for his participation in Deere’s bug bounty program, which is hosted by the bug bounty platform HackerOne. It was signed “The John Deere Security Team.” 

The Trustworthy Computing Memo Lands On The Farm

In 2021, such gestures are commonplace in the software industry. It has been 16 years since TippingPoint Technologies (now part of 3COM) launched its Zero Day Initiative – one of the first “cash for vulnerabilities” programs. In the intervening years, hundreds of firms have followed suit including giants like Microsoft, Yahoo and Facebook, as well as device makers like Samsung and car makers GM and Tesla. 

Tech industry firms, in 2021, draw attention to their programs for rewarding researchers with cash – sometimes lots of it – and company swag for finding and reporting software flaws in their technology. The vulnerability disclosure market is expected to grow in value from $223m annually in 2020 to more than $5 billion by the end of the decade. 

So far, however, that revolution passed over the agriculture sector, which makes Deere’s sudden about-face all the more remarkable. Despite employing more software developers than mechanical design engineers, according to its CTO, Deere – as late as March – did not have a public vulnerability disclosure program for researchers like Ganesh to partake in. On the MITRE-maintained list of Common Vulnerabilities and Exposures (CVE), the company still does not have a single, publicly disclosed software vulnerability to its…

Source…

Flagstaff News Flagstaff district scrambles to resolve cyber security issue Associated Press 5:52 PM, Sep – ABC15 Arizona

Flagstaff News Flagstaff district scrambles to resolve cyber security issue Associated Press 5:52 PM, Sep  ABC15 Arizona

FLAGSTAFF, AZ — Flagstaff Unified School District officials worked over the weekend to try to resolve a cyber security issue that forced all schools to close …

“computer security news” – read more

White House scrambles to show it’s on point at fixing security leaks – CNN

I still don’t sense an urgency to fix the problem,” said Hoekstra, R-Michigan. Hoekstra spoke after attending a high-level meeting to discuss the government computer security breach exposed by WikiLeaks. “I think that there are still other government …
Read more