SecurityBrief Canada - Technology news for CISOs & cybersecurity decision-makers

Common Vulnerabilities and Exposures (CVE) stories - Page 1

Story image
Picus launches tool for real-time validation of exploitable risks
Last month
#
devops
#
advanced persistent threat protection
#
soc
Picus Security launches Exposure Validation, a tool using real-time attack simulations to identify which vulnerabilities are truly exploitable in organisations.
Story image
IP Fabric unveils upgrade to boost firewall visibility & compliance
Last month
#
firewalls
#
network security
#
cloud security
IP Fabric launches version 7.2 to enhance firewall visibility and compliance, aiding enterprises in detecting misconfigurations and enforcing security policies.
Story image
Red Hat launches Advanced Developer Suite with focus on AI
Last month
#
hybrid cloud
#
application security
#
devsecops
Red Hat launches Advanced Developer Suite on OpenShift, enhancing developer productivity, AI integration, and application security with new tools and templates.
Story image
Red Hat Enterprise Linux 10 brings AI & post-quantum security
Last month
#
devops
#
hybrid cloud
#
hyperscale
Red Hat launches Enterprise Linux 10, featuring AI integration, enhanced security with post-quantum cryptography, and hybrid cloud support for enterprises.
Story image
Emojis used to hide attacks & bypass major AI guardrails
Last month
#
genai
#
llms
#
ai
Mindgard reveals emoji smuggling can bypass AI guardrails from Microsoft, Meta, Nvidia, and others with up to 100% attack success, raising serious security concerns.
Story image
Black Kite launches tool for third-party vulnerability insight
Last month
#
ransomware
#
supply chain & logistics
#
breach prevention
Black Kite launches Vulnerability Intelligence Briefs to help organisations identify and manage third-party cyber risks, enhancing supply chain security.
Story image
Minimus launches with USD $51 million to cut 95% of CVEs
Wed, 30th Apr 2025
#
cloud security
#
application security
#
cybersecurity
Minimus launches with USD $51 million to cut 95% of CVEs in software supply chains, offering secure components and faster vulnerability reduction.
Story image
Armis offers free access to real-time cyber threat database
Thu, 24th Apr 2025
#
firewalls
#
network security
#
advanced persistent threat protection
Armis launches free Vulnerability Intelligence Database to help security teams anticipate and tackle cyber threats with real-time, AI-driven insights.
Story image
Funding crisis sparks fears for future of global CVE system
Thu, 17th Apr 2025
#
cybersecurity
#
software development
#
modernisation
US government funding for the crucial CVE cybersecurity programme is set to lapse, raising fears over global vulnerability tracking and defence efforts.
Story image
CVE system secures 11-month extension worth USD $44 million
Thu, 17th Apr 2025
#
advanced persistent threat protection
#
cybersecurity
#
cyber threats
CISA extends its contract with MITRE for another 11 months at USD $44 million, securing the critical CVE vulnerability programme amid funding concerns.
Story image
Future of CVE repository in doubt as MITRE contract ends
Thu, 17th Apr 2025
#
advanced persistent threat protection
#
cybersecurity
#
cyber threats
Concerns rise as MITRE's contract to manage the CVE vulnerability database nears expiry, risking disruption to global cybersecurity infrastructure.
Story image
US funding lapse casts uncertainty over global CVE system
Thu, 17th Apr 2025
#
cybersecurity
#
incident response
#
infosecurity europe
US government funding for MITRE's CVE programme has expired, risking disruption to global cybersecurity efforts and vulnerability tracking systems.
Story image
How to protect legacy medical devices from modern cyber threats
Tue, 15th Apr 2025
#
ransomware
#
risk & compliance
#
cybersecurity
Healthcare providers in Australia and New Zealand face growing cyber threats, with legacy medical devices proving vulnerable due to outdated security measures.
Story image
Microsoft April Patch Tuesday highlights zero-day risks
Fri, 11th Apr 2025
#
ransomware
#
cybersecurity
#
microsoft
Microsoft's recent Patch Tuesday sparked scrutiny with a 40-minute delay in updates and notable vulnerabilities, including a critical zero-day in the CLFS Driver.
Story image
Zscaler report urges shift from VPNs to Zero Trust
Fri, 11th Apr 2025
#
vpns
#
ransomware
#
cloud security
Zscaler's 2025 ThreatLabz VPN Risk Report reveals soaring VPN usage in Australia but warns of heightened security risks, urging a shift to Zero Trust architectures.
Story image
N-able launches new feature to boost vulnerability management
Fri, 11th Apr 2025
#
advanced persistent threat protection
#
cybersecurity
#
personal computing devices
N-able has launched a new Vulnerability Management feature for its UEM products, enhancing risk mitigation for organisations amid rising cyber threats.
Story image
April Patch Tuesday: Microsoft announces 121 vulnerabilities
Wed, 9th Apr 2025
#
cybersecurity
#
microsoft
#
patch tuesday
Microsoft has unveiled 121 vulnerabilities in its April 2025 Patch Tuesday update, marking a significant increase from last month's total.
Story image
RunZero expands platform for enhanced exposure management
Tue, 8th Apr 2025
#
risk & compliance
#
omdia
#
asset discovery
runZero has unveiled an expanded platform to enhance exposure management, promising to aid organisations in effectively managing risk across their attack surfaces.
Story image
Kaspersky discovers & patches zero-day Chrome flaw
Thu, 3rd Apr 2025
#
malware
#
edutech
#
endpoint protection
Kaspersky has uncovered and patched a critical zero-day vulnerability in Google Chrome, enabling attackers to bypass sandbox protections via malicious links.
Story image
GitHub Action compromise affects over 23,000 repositories
Thu, 20th Mar 2025
#
open source
#
software development
#
security vulnerabilities
A malicious commit in the tj-actions/changed-files GitHub Action, used in over 23,000 repositories, threatens software security across numerous CI pipelines.