'Netfetcher' package drops illicit 'node' binary on Windows

‘Netfetcher’ package drops illicit ‘node’ binary on Windows

Recently identified PyPI packages called "netfetcher" and "pyfetcher" impersonate open source libraries and target Windows users with malicious executables that have a zero detection rate among leading antivirus engines. Furthermore, some of ...
owasp top 10 application vulnerabilities

Understanding the OWASP Top 10 Application Vulnerabilities

The OWASP Top 10 provides a standardized catalog of the most critical security risks to web applications. Compiled by a global community of security experts, this influential document highlights the... The post ...
SMBs, threats, shutdown SMBs cybercriminals business ransomware malware Kaseya 6 Ways Poor Cybersecurity Hurts Businesses

Are Proof-of-Concepts Benefiting Cybercriminals?   

Public proof-of-concepts (POCs) may be helping cybercriminals more than the organizations they were designed to protect. Sophos’ Active Adversary Playbook 2022 provides an in-depth analysis of cyberattacker behavior, tactics and tools from ...
Security Boulevard
Cloudflare ransomware FCC Google mobile Cybersecurity Issues in Mobile App Development

Google Shares Format for Open Source Vulnerability Data

Google, in collaboration with several open source communities, today unveiled a schema for describing vulnerabilities in open source software that will make it easier to for developers to track security issues that ...
Security Boulevard
How did Masato find the Google Search XSS?

Top 10 Application Vulnerabilities of 2019

In application security, so often the cause of vulnerabilities can be traced to the development process. It’s the nature of application development and a consequence of moving faster with shorter deadlines. It’s ...
Security Boulevard
patching

Adobe Releases Critical Security Patches for 9 Products

Adobe Systems has released security patches for nine of its products to fix 86 vulnerabilities, the majority of which are rated as critical and important. In addition to Flash Player, Reader and ...
Akamai JavaScript

Black Duck Releases Free Tool to Help You Avoid Becoming the Next Equifax

Equifax recently became headline news for all the wrong reasons when it revealed it had been the victim of a data breach that exposed the sensitive financial history and personal data of ...
Time to step up your Acrobat Reader patching. Attacks are on the rise.

Time to step up your Acrobat Reader patching. Attacks are on the rise.

If you haven't patched the latest Acrobat Reader from two weeks ago, it might be time to step up the pace. If you look at this blogpost from F-secure, you'll see that ...

Application Security Check Up