GitHub Launches Fund to Improve Open Source Project Security
GitHub has launched a $1.25 million fund to be invested in improving the security of 125 open source projects.
The post GitHub Launches Fund to Improve Open Source Project Security appeared first on SecurityWeek.
Cyera Raises $300 Million at $3 Billion Valuation
Data security firm Cyera has raised $300 million in Series D funding, which brings the total investment in the company to $760 million.
The post Cyera Raises $300 Million at $3 Billion Valuation appeared first on SecurityWeek.
Oracle Patches Exploited Agile PLM Zero-Day
Oracle has patched a high-severity information disclosure zero-day in Agile PLM that has been exploited in the wild.
The post Oracle Patches Exploited Agile PLM Zero-Day appeared first on SecurityWeek.
Ford Says Leaked Data Comes From Supplier and Is Not Sensitive
Ford has completed its investigation into recent data breach claims and determined that its systems and customer data have not been compromised.
The post Ford Says Leaked Data Comes From Supplier and Is Not Sensitive appeared first on SecurityWeek.
Decades-Old Security Vulnerabilities Found in Ubuntu’s Needrestart Package
The Qualys Threat Research Unit (TRU), which identified and reported the flaws early last month, said they are trivial to exploit, necessitating that
China-Backed Hackers Leverage SIGTRAN, GSM Protocols to Infiltrate Telecom Networks
Cybersecurity company CrowdStrike is tracking the adversary under the name Liminal Panda, describing it as possessing deep knowledge about telecommunications
Apple Releases Urgent Updates to Patch Actively Exploited Zero-Day Vulnerabilities
The flaws are listed below –
CVE-2024-44308 – A vulnerability in JavaScriptCore that could lead to arbitrary code execution when processing malicious web content
CVE-2024-44309 – A cookie management vulnerability in
Oracle Warns of Agile PLM Vulnerability Currently Under Active Exploitation
The vulnerability, tracked as CVE-2024-21287 (CVSS score: 7.5), could be exploited sans authentication to leak sensitive information.
“This vulnerability is remotely exploitable without authentication, i.e., it may be exploited over a network
