Cybersecurity incidents dominated headlines in 2022, with notable breaches and zero-day attacks carried out by groups like Lapsus$. Furthermore, there was an uptick in mercenary spyware vendors with surveillance-for-hire operations springing up around the globe. Attention was also placed on securing the software supply chain, as the US government began mandating software bill of materials (SBOMs), but big tech lobbied against this move. Meanwhile, investment in cybersecurity startups remained strong.

Unpatched Windows Shortcut Vulnerability Let Attackers Execute Remote Code
Security researcher Nafiez disclosed a vulnerability in Windows LNK files that allows remote code execution without user interaction. Microsoft will not patch it, citing “inadequate