A cross-site request forgery (CSRF) vulnerability impacting the source control management (SCM) service Kudu could be exploited to achieve remote code execution (RCE) in multiple Azure services, cloud infrastructure security firm Ermetic has discovered.
Sophos has confirmed reports that it's laying off employees. The company joins several other major cybersecurity companies that have announced cutting staff over the past year.
Vendors and agencies are actively bypassing the security patch that Adobe released in February 2022 to address CVE-2022-24086, a critical mail template vulnerability in Adobe Commerce and Magento stores, ecommerce security firm Sansec warns.
Vulnerabilities found in GE's Proficy Historian product could be exploited by hackers for espionage and to cause damage and disruption in industrial environments.
The US government's cybersecurity agency CISA is giving federal agencies an early February deadline to patch a critical -- and already exploited -- security vulnerability in the widely used CentOS Control Web Panel utility.
Nissan North America is informing roughly 18,000 customers that their personal information was exposed in a data breach at a third-party services provider.