ZDI-22-1027: Adobe Acrobat Reader DC Font Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

Read Time:12 Second

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

Read More

India’s cybersecurity skills shortage: Airtel Payments Bank’s CISO proposes a path forward

Read Time:43 Second

Manish Pandey, CISO of Airtel Payments Bank, has worked in several industries, including e-commerce, academics and fast-moving consumer goods ITeS, and banking. So he has seen first-hand the challenges of the cybersecurity skills gap in multiple contexts.

Pandey started his professional journey in cybersecurity with the Indian Computer Emergency Response Team, the government’s nodal agency to deal with cybersecurity threats. From there, he moved to several organisations with the intent of learning various domains within cybersecurity and information security. His goal was to eventually join the financial sector as cybersecurity plays a critical role in it — not only are the implications of a breach are profound in the financial sector, but he found the cybersecurity landscape challenging in that sector and thus an industry he could learn much in.

To read this article in full, please click here

Read More

Smashing Security podcast #285: Uber’s hidden hack, tips for travel, and AI accent fixes

Read Time:25 Second

Uber may not face prosecution over its handling of a 2016 data breach – but its former chief security head does; how to defend your digital devices’ data while on vacation, and how to change your accent with artificial intelligence.

All this and much much more is discussed in the latest edition of the “Smashing Security” podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Paul Ducklin.

Plus don’t miss our featured interview with Ian Farquhar of Gigamon.

Read More

[R1] Tenable.sc 5.22.0 Fixes One Third-Party Vulnerability

Read Time:29 Second

[R1] Tenable.sc 5.22.0 Fixes One Third-Party Vulnerability
Arnie Cabral
Wed, 07/27/2022 – 18:26

Tenable.sc leverages third-party software to help provide underlying functionality. One of the third-party components (moment.js) was found to contain vulnerabilities, and updated versions have been made available by the providers.

Out of caution, and in line with best practice, Tenable has upgraded the bundled components to address the potential impact of these issues. Tenable.sc 5.22.0 updates moment.js to version 2.29.4 to address the identified vulnerabilities.

Read More