Related Articles

Microsoft accuses China-backed nation state hackers of abusing the country’s vulnerability disclosure requirements to discover and develop zero-day exploits (Jonathan Greig/The Record)

Jonathan Greig / The Record:
Microsoft accuses China-backed nation state hackers of abusing the country’s vulnerability disclosure requirements to discover and develop zero-day exploits  —  Microsoft on Friday accused state-backed hackers in China of abusing the country’s vulnerability disclosure requirements in an effort to discover and develop zero-day exploits.

Data analysis of Twitter’s Birdwatch crowdsourced moderation tool: posts regarding COVID and “stop the steal” misinformation have been top areas of focus (Corin Faife/The Verge)

Corin Faife / The Verge:
Data analysis of Twitter’s Birdwatch crowdsourced moderation tool: posts regarding COVID and “stop the steal” misinformation have been top areas of focus  —  Analysis by The Verge shows that Birdwatch users regularly tackle misinformation topics with the highest stakes, including pandemic response

Google updates Chrome to address an actively exploited high-severity zero-day vulnerability in Mojo, its sixth patch for zero-day vulnerabilities in 2022 (Sergiu Gatlan/BleepingComputer)

Sergiu Gatlan / BleepingComputer:
Google updates Chrome to address an actively exploited high-severity zero-day vulnerability in Mojo, its sixth patch for zero-day vulnerabilities in 2022  —  Google has released Chrome 105.0.5195.102 for Windows, Mac, and Linux users to address a single high-severity security flaw …

A Python directory traversal vulnerability disclosed in August 2007, but never patched, likely affects 350K+ open-source projects and can lead to code execution (Ionut Ilascu/BleepingComputer)

Ionut Ilascu / BleepingComputer:
A Python directory traversal vulnerability disclosed in August 2007, but never patched, likely affects 350K+ open-source projects and can lead to code execution  —  A vulnerability in the Python programming language that has been overlooked for 15 years is now back in the spotlight …

LastPass says attackers accessed customers’ data after breaching its cloud storage using information stolen during a security incident in August 2022 (Sergiu Gatlan/BleepingComputer)

Sergiu Gatlan / BleepingComputer:
LastPass says attackers accessed customers’ data after breaching its cloud storage using information stolen during a security incident in August 2022  —  LastPass says unknown attackers breached its cloud storage using information stolen during a previous security incident from August 2022.

Microsoft releases 63 security fixes, including patches for two zero-day flaws, one of which is under active exploit, and five critical RCE vulnerabilities (Lawrence Abrams/BleepingComputer)

Lawrence Abrams / BleepingComputer:
Microsoft releases 63 security fixes, including patches for two zero-day flaws, one of which is under active exploit, and five critical RCE vulnerabilities  —  Today is Microsoft’s September 2022 Patch Tuesday, and with it comes fixes for an actively exploited Windows vulnerability and a total of 63 flaws.