-
New MOVEit Transfer Vulnerability Under Active Exploitation – Patch ASAP!
A newly disclosed critical security flaw impacting Progress Software MOVEit Transfer is already seeing exploitation attempts in the wild shortly after details of the bug were publicly disclosed. The vulnerability, tracked as CVE-2024-5806 (CVSS score: 9.1), concerns an authentication bypass that impacts the following versions – From 2023.0.0 before 2023.0.11 From 2023.1.0 before 2023.1.6, and&
-
Chinese and N. Korean Hackers Target Global Infrastructure with Ransomware
Threat actors with suspected ties to China and North Korea have been linked to ransomware and data encryption attacks targeting government and critical infrastructure sectors across the world between 2021 and 2023. While one cluster of activity has been associated with the ChamelGang (aka CamoFei), the second cluster overlaps with activity previously attributed to Chinese…
-
Practical Guidance For Securing Your Software Supply Chain
The heightened regulatory and legal pressure on software-producing organizations to secure their supply chains and ensure the integrity of their software should come as no surprise. In the last several years, the software supply chain has become an increasingly attractive target for attackers who see opportunities to force-multiply their attacks by orders of magnitude. For…
-
Apple Patches AirPods Bluetooth Vulnerability That Could Allow Eavesdropping
Apple has released a firmware update for AirPods that could allow a malicious actor to gain access to the headphones in an unauthorized manner. Tracked as CVE-2024-27867, the authentication issue affects AirPods (2nd generation and later), AirPods Pro (all models), AirPods Max, Powerbeats Pro, and Beats Fit Pro. “When your headphones are seeking a connection…
-
New Credit Card Skimmer Targets WordPress, Magento, and OpenCart Sites
Multiple content management system (CMS) platforms like WordPress, Magento, and OpenCart have been targeted by a new credit card web skimmer called Caesar Cipher Skimmer. A web skimmer refers to malware that is injected into e-commerce sites with the goal of stealing financial and payment information. According to Sucuri, the latest campaign entails making malicious…
-
How Straightaway is bringing batch cocktails to the masses
Batch cocktail maker Straightaway has kept high quality craft at the heart of its business. Now, its cans and bottles are getting into more consumers’ hands.
-
Expo Center could get $440M makeover
The Metro Council is considering an Expo Center plan that could cost $446 million.
-
Legal aid groups lease 17,000 SF in downtown Portland historic building
A historic office building purchased at a discount last year signed two new tenants.
-
Oregon sued over access to magic mushrooms
The plaintiffs are challenging OHA’s “failure to ensure” that the psilocybin program doesn’t discriminate against physically disabled individuals.
-
Nike apparel VP jumps to Gap to lead design
Flynn started with Nike as a U.S. men’s apparel designer in 2005 and worked her way up to her most recent position in 2022.