Weekly Vulnerability Recap – Sept. 25, 2023 – Flaws in Apple Devices, DevOps Tools and More

This past week in cybersecurity saw a wide range of vulnerabilities, from Apple product patches to several flaws that hit DevSecOps teams. The Akira ransomware group made news too, expanding its attacks to include Linux-based systems, and Trend Micro issued a fix for a zero-day vulnerability in its Apex One endpoint security tools. Read about […]

The post Weekly Vulnerability Recap – Sept. 25, 2023 – Flaws in Apple Devices, DevOps Tools and More appeared first on eSecurity Planet.

September 25, 2023
Read More >>

Cisco to Acquire Splunk for $28 Billion

In a blockbuster deal that could shake up the cybersecurity market, Cisco announced this morning that it will acquire Splunk for $28 billion. If the deal clears regulatory hurdles, it would give Cisco a big position in the market for centralized cybersecurity management solutions like security information and event management (SIEM) and security orchestration, automation […]

The post Cisco to Acquire Splunk for $28 Billion appeared first on eSecurity Planet.

September 21, 2023
Read More >>

Microsoft Patch Tuesday Includes Word, Streaming Service Zero-Days

Microsoft’s Patch Tuesday for September 2023 includes 59 vulnerabilities, five of them rated critical and two currently being exploited in the wild. The two vulnerabilities currently being exploited are CVE-2023-36761, an information disclosure flaw in Microsoft Word with a CVSS score of 6.2; and CVE-2023-36802, an elevation of privilege flaw in Microsoft Streaming Service with […]

The post Microsoft Patch Tuesday Includes Word, Streaming Service Zero-Days appeared first on eSecurity Planet.

September 13, 2023
Read More >>

Server-Side Request Forgery (SSRF) – Exploitation And Defense Insights

In this section, we’ll explain what server-side request forgery is, describe some common examples, and explain how to find and exploit various kinds of SSRF vulnerabilities. What is SSRF? Server-side request forgery (also known as SSRF) is a web security vulnerability that allows an attacker to induce the server-side application to make requests to an […]

September 7, 2023
Read More >>

Burp Suite Sharpener – Advanced Features & Installation Guide

A versatile tool designed to enhance both the UI and functionality of Burp Suite, streamlining your cybersecurity testing experience. Compatible exclusively with Burp Suite version 2023.10-22956 and above, this extension offers features such as theming, streamlined tab navigation, screenshot capabilities, and much more. Built upon the legacy of the original Burp Suite Sharpener project, this […]

September 6, 2023
Read More >>