Skip to content

3CX Supply Chain Attack — Here’s What We Know So Far “The Benefits of Working Out Regularly” “Reaping the Rewards of Exercise”

On March 31, 2023, enterprise communications software maker 3CX confirmed that multiple versions of its desktop app for Windows and macOS were affected by a supply chain attack. Evidence suggests that the campaign could have started as early as February 2022 and involved the distribution of a rogue library referred to as \”ffmpeg.dll\” in the… 

Burnout in Cybersecurity – Can It Be Prevented? “Struggling to Overcome Addiction? Here’s How to Take Control of Your Life!”

Burnout is a growing problem in many professions, particularly among those in the cybersecurity field. In the coming months, burnout is likely to worsen as the economy forces teams to do more with less at the same time as cybercrime and nation-state attacks are increasing. To better understand burnout, it is important to know what… 

Exploitation of 55 Zero-Day Vulnerabilities Came to Light in 2022: Mandiant “Stop What You’re Doing: Here’s the Latest on ____”

Mandiant, owned by Google, recently performed a study on the zero-day vulnerabilities that were revealed in 2022. The results showed that more than twelve of these vulnerabilities were exploited in attacks believed to be orchestrated by cyberespionage organizations. The cybersecurity community has not yet agreed on a uniform definition of zero-day vulnerability. Mandiant, however, only… 

Zoom Paid Out $3.9 Million in Bug Bounties in 2022 “Astonishing: Here’s How You Can Make Money Quickly!”

Video communications giant Zoom recently announced that it paid out $3.9 million to security researchers as part of its bug bounty program in 2022. The company launched its bug bounty program in 2019 and has paid out over $7 million in bounty rewards to date. In 2021, Zoom paid $1.8 million in bug bounties. As… 

55 Zero-Day Vulnerabilities Weaponized in 2022 “Struggling to Stay Positive? Here’s How to Overcome It!”

On March 21, 2023, threat intelligence firm Mandiant reported that as many as 55 zero-day vulnerabilities were exploited in the wild in 2022. While this figure represents a decrease from the year before, it still represents a significant uptick in recent years of threat actors leveraging unknown security flaws to their advantage. The most exploited… 

Fortinet Finds Zero-Day Exploit in Government Attacks After Devices Detect Integrity Breach “5 Simple Steps To Make A Professional Website: Here’s How You Can Create Your Very Own!”

Fortinet recently patched a critical unauthenticated remote code execution (RCE) vulnerability in FortiOS, tracked as CVE-2022-41328. The bug was described as a medium-severity path traversal issue leading to command execution, and was addressed last week. However, Fortinet failed to mention that this was actually a zero-day vulnerability. Further investigation revealed that a sophisticated threat actor…