News

Application security and coding requirements

  • December 18, 2024 18 Dec'24

    Top 10 cyber security stories of 2024

    Data breaches, data privacy and protection, and the thorny issue of open source security were all hot topics this year. Meanwhile, security companies frequently found themselves hitting the headlines, and not always for good reasons. Here are ...

  • December 10, 2024 10 Dec'24

    Dangerous CLFS and LDAP flaws stand out on Patch Tuesday

    Microsoft has fixed over 70 CVEs in its final Patch Tuesday update of the year, and defenders should prioritise a zero-day in the Common Log File System Driver, and another impactful flaw in the Lightweight Directory Access Protocol

  • December 10, 2024 10 Dec'24

    iOS vuln leaves user data dangerously exposed

    Jamf threat researchers detail an exploit chain for a recently patched iOS vulnerability that enables a threat actor to steal sensitive data, warning that many organisations are still neglecting mobile updates

  • December 04, 2024 04 Dec'24

    Nordics move to deepen cyber security cooperation

    Nordic countries are increasing collaboration on cyber security amid more sophisticated and aggressive attacks

  • November 27, 2024 27 Nov'24

    Scientists demonstrate Pixelator deepfake image verification tool

    With the age of deepfake imagery upon us, a team led by York St John University researchers has created a tool to help people ‘navigate the fine line between reality and fabrication’

  • November 26, 2024 26 Nov'24

    Russian threat actors poised to cripple power grid, UK warns

    UK government escalates cyber rhetoric in a speech at a Nato event, saying Russian advanced persistent threats stand ready to conduct cyber attacks that could ‘turn off the lights for millions’

  • November 20, 2024 20 Nov'24

    Apple addresses two iPhone, Mac zero-days

    Two zero-day vulnerabilities uncovered in Apple’s operating systems could have allowed for arbitrary code execution and cross-site scripting attacks

  • November 12, 2024 12 Nov'24

    Microsoft fixes 89 CVEs on penultimate Patch Tuesday of 2024

    High-profile vulns in NTLM, Windows Task Scheduler, Active Directory Certificate Services and Microsoft Exchange Server should be prioritised from November’s Patch Tuesday update

  • November 12, 2024 12 Nov'24

    Zero-day exploits increasingly sought out by attackers

    Threat actors increasingly favour zero-day exploits to attack their victims before patches become available, according to the NCSC and CISA, which have just published a list of the most widely used vulnerabilities of 2023

  • October 28, 2024 28 Oct'24

    Inside Google Cloud’s secure AI framework

    Google Cloud’s secure AI framework that’s integrated into its Vertex AI platform offers practical tools and guidance to manage the lifecycle, data governance and operational risks of AI