Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

How we found a Prototype Pollution in protobuf.js

Our colleagues Peter Samarin, Norbert Schneider and Fabian Meumertzheim recently built a new bug detector enabling our JavaScript fuzzing engine Jazzer.js to identify Prototype Pollution. This work is now bearing its first fruits: As part of our ongoing collaboration with Google’s OSS-Fuzz, Jazzer.js recently uncovered a new Prototype Pollution vulnerability in protobuf.js (CVE-2023-36665). This finding puts affected applications at risk of remote code execution and denial of service attacks.

Why is the Education Sector a Target for Cyber Attacks?

‍Educational institutions are among the top targets for hackers and cybercriminals. Education is among the sectors that experience the most cyber attacks, including healthcare, finance, and retail. According to Check Point’s Mid-Year Report for 2022, the education sector had 44% more cyber attacks than the year earlier. An average of about 2300 attacks against educational organizations were reported weekly.

Cybersecurity in the Entertainment Industry: Risks and Solutions

Book publishers, movie distributors, TV producers, game developers, and newspaper publishers are just a few of the many businesses in the media and entertainment industry increasing their use of online services. Streaming services and the production of digital assets are the norm for media companies around the globe.

The Vermont Dept of Financial Regulation Gets Breached, Exposing 42K Residents

The Vermont Department of Financial Regulation is an organization that oversees the financial sector within the state. The department is split into four divisions: Securities, Banking, Captive Insurance, and Insurance. Any businesses involved in these companies must answer to this department, and many Vermont residents have supplied the department with information to help it carry out its everyday role.

Beware of Clickbait PDF Phishing Attacks Lurking in Search Results

We previously reported independently on PDF-based phishing attacks skyrocketing and the rise of SEO attacks. A recent research study found that the combination of both is quite common. Most worryingly, PDF-based SEO attacks are poorly detected by common defense mechanisms such as blocklists, ad blockers or even crowdsourced antivirus services VirusTotal. PDF-based attacks can be anything from a website embedded in a PDF file to an email.

CRN Recognizes WatchGuard in Top 100 Executives List

We are thrilled to share the exciting news that CRN has named two WatchGuard leaders to its prestigious annual Top 100 Executives of 2023 list. WatchGuard CEO Prakash Panjwani is once again named as one of CRN’s Top 25 IT Innovators of the Year, a list recognizing top executives for their ability to drive innovation for technology products, solutions, and services.

Healthcare System Growth Requires Trusted Access Management

You have A LOT on your plate as a healthcare administrator in 2023. From an increase in workplace violence and the need to keep medications out of unauthorized hands, to an abundance of private data to keep safe and costly medical equipment and supplies to protect, it might feel like your to-do list goes on and on. And, we don’t have to tell you, but the healthcare sector is expanding and evolving at an increasingly rapid pace.

Cato SASE Cloud: A Two-Time Leader and Outperformer in GigaOm's Radar Report for Secure Service Access

In the ever-evolving world of cybersecurity, enterprises are constantly seeking the most effective solutions to secure their networks and data. GigaOm’s Radar Report for Secure Service Access, GigaOm’s term for SASE, provides a comprehensive look at the industry, and for the second consecutive year, names Cato Networks a “Leader” and “Outperformer.” The recognition points to Cato’s continuous commitment to innovation and improvement.