Latest Cybersecurity News and Articles
10 January 2024
The integration of Authomize's cross-cloud identity capabilities into Delinea's platform will enable customers to detect and mitigate active identity threats across various applications and infrastructure.
10 January 2024
Organizations hit by ransomware face uncertainty regarding the deletion of stolen data, leading to a new form of extortion where a fake security researcher offers to hack into the ransomware group's server infrastructure for a fee.
10 January 2024
IT professionals have developed a sophisticated understanding of the enterprise attack surface – what it is, how to quantify it and how to manage it.
The process is simple: begin by thoroughly assessing the attack surface, encompassing the entire IT environment. Identify all potential entry and exit points where unauthorized access could occur. Strengthen these vulnerable points using
10 January 2024
The incident highlights concerns over the security of the SEC's social media accounts and the need for better protections against market manipulation through false tweets.
10 January 2024
The British Library has refuted reports that the recovery costs for its recent ransomware attack will reach nearly $9 million. The library said that the final costs are still unconfirmed and no additional funding bids have been made.
10 January 2024
A decryptor for the Tortilla variant of the Babuk ransomware has been released by Cisco Talos, allowing victims targeted by the malware to regain access to their files.
The cybersecurity firm said the threat intelligence it shared with Dutch law enforcement authorities made it possible to arrest the threat actor behind the operations.
The encryption key has also been shared with Avast,
10 January 2024
One of the vulnerabilities affects Apache Superset, a data visualization software, and allows remote code execution. The other vulnerabilities impact Adobe ColdFusion, Apple products, D-Link DSL-2750B devices, and Joomla.
10 January 2024
Microsoft's January 2024 Patch Tuesday includes security updates for 49 flaws and 12 remote code execution vulnerabilities. Two critical vulnerabilities were fixed, including a Windows Kerberos Security Feature Bypass and a Hyper-V RCE.
10 January 2024
Users are recommended to switch to the mobile versions available on iOS and Google Play. The decision to sunset the desktop app is part of Twilio's effort to focus on areas with higher demand.
10 January 2024
The vulnerability, CVE-2023-51448, requires an authenticated attacker with specific permissions or the exploitation of another vulnerability to access and exploit the Cacti database.
10 January 2024
The breach allegedly leaked 5.8 million flight logs from 2015, containing sensitive information. The motive behind the attack is unclear, but it raises concerns about cybersecurity measures in government agencies.
10 January 2024
The vulnerabilities in the wrenches could lead to production line stoppages, causing large-scale financial losses, and enable malicious actors to introduce sub-optimal tightening or excessive damage.
10 January 2024
Researchers have discovered a path traversal vulnerability in Kyocera's Device Manager, a product used for managing large printer fleets. Exploiting the vulnerability requires the attacker to be logged onto the network.
10 January 2024
The U.S. Federal Trade Commission (FTC) on Tuesday prohibited data broker Outlogic, which was previously known as X-Mode Social, from sharing or selling any sensitive location data with third-parties.
The ban is part of a settlement over allegations that the company "sold precise location data that could be used to track people's visits to sensitive locations such as medical and
10 January 2024
Microsoft has addressed a total of 48 security flaws spanning its software as part of its Patch Tuesday updates for January 2024.
Of the 48 bugs, two are rated Critical and 46 are rated Important in severity. There is no evidence that any of the issues are publicly known or under active attack at the time of release, making it the second consecutive Patch Tuesday with no zero-days.
The
09 January 2024
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added six security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
This includes CVE-2023-27524 (CVSS score: 8.9), a high-severity vulnerability impacting the Apache Superset open-source data visualization software that could enable remote code execution.
09 January 2024
The RE#TURGENCE campaign, linked to actors of Turkish origin, utilizes brute-force attacks, shell commands, and post-exploitation tools to gain access and carry out malicious activities.
09 January 2024
A threat actor called Water Curupira has been observed actively distributing the PikaBot loader malware as part of spam campaigns in 2023.
“PikaBot’s operators ran phishing campaigns, targeting victims via its two components — a loader and a core module — which enabled unauthorized remote access and allowed the execution of arbitrary commands through an established connection with
09 January 2024
Cisco Talos, in collaboration with Dutch Police and Avast, recovered a decryptor for the Babuk Tortilla ransomware variant, allowing users to quickly recover their encrypted files.
09 January 2024
The U.S. federal government is seeking synthetic data generators to train machine learning models and test systems in instances where real-world data is unavailable or poses privacy and security risks.