Latest Cybersecurity News and Articles
08 December 2023
This vulnerability could allow attackers to run arbitrary PHP code on a target website. The vulnerability is a Property Oriented Programming (POP) chain that requires an attacker to control all the properties of a deserialized object.
08 December 2023
The Russian founder of the now-defunct Bitzlato cryptocurrency exchange has pleaded guilty, nearly 11 months after he was arrested in Miami earlier this year.
Anatoly Legkodymov (aka Anatolii Legkodymov, Gandalf, and Tolik), according to the U.S. Justice Department, admitted to operating an unlicensed money-transmitting business that enabled other criminal actors to launder their
07 December 2023
FS-ISAC has announced the appointment of John Denning as Chief Information Security Officer (CISO) effective as of January 1, 2024.
07 December 2023
Chrome version 120 includes 10 bug fixes, with two of them being highly critical security patches. The high-ranked security vulnerabilities include "Use after free" exploits in Media Stream and Side Panel Search.
07 December 2023
A Cambridge NHS trust has admitted to two historic data breaches, involving the accidental disclosure of patient data while responding to Freedom of Information requests.
07 December 2023
The vulnerability, which impacts the Syrus4 IoT gateway made by Digital Communications Technologies (DCT), gives hackers access to the software and commands used to manage thousands of vehicles.
07 December 2023
The BlackSuit ransomware group was able to hack into two servers belonging to the school district, impacting Windows devices, file services, printers, and copiers. Phones were not impacted.
07 December 2023
The SLAM attack exploits hardware features in upcoming CPUs from Intel, AMD, and Arm to obtain the root password hash from kernel memory, highlighting potential security vulnerabilities.
07 December 2023
According to a report, there was a 26% increase in supply chain breaches in 2022 and 9% of organizations are working with suppliers to fix them.
07 December 2023
Over 3,800 PACS servers across 110 countries are unintentionally exposing the private data of 16 million patients, including names, addresses, and even Social Security numbers.
07 December 2023
A Bluetooth authentication bypass vulnerability, tracked as CVE-2023-45866, allows attackers to connect to Apple, Android, and Linux devices and inject keystrokes to run arbitrary commands.
07 December 2023
The threat actor known as COLDRIVER has continued to engage in credential theft activities against entities that are of strategic interests to Russia while simultaneously improving its detection evasion capabilities.
The Microsoft Threat Intelligence team is tracking under the cluster as Star Blizzard (formerly SEABORGIUM). It's also called Blue Callisto, BlueCharlie (or TAG-53),
07 December 2023
Russian APT group TA422 has been actively exploiting patched vulnerabilities to target government, aerospace, education, finance, manufacturing, and technology sectors in Europe and North America.
07 December 2023
Researchers at ZeroFox found that LockBit was leveraged in more than a quarter of global ransomware and digital extortion (R&DE) attacks in the seven quarters analyzed from January 2022 to September 2023.
07 December 2023
The Henry County Schools district in Georgia and the Hermon School Department in Maine are among the latest victims, with the former experiencing a ransomware attack and the latter having outdated software vulnerabilities exploited.
07 December 2023
Microsoft will offer Extended Security Updates (ESU) for Windows 10 users after the end of support, but they will have to pay for them. ESUs will provide critical security updates but not new features or design changes.
07 December 2023
Nissan's warning to customers to remain vigilant suggests a potential data breach may have occurred, highlighting the ongoing threat to personal information in the automotive industry.
07 December 2023
A new report shows increasing instances of remote access software abuse and the rise of cyber adversaries using password-stealers.
07 December 2023
Since the release of the CPG program, organizations enrolled in CISA's vulnerability scanning service have reduced their average number of known exploited vulnerabilities by about 20%.
07 December 2023
According to the experts, to mitigate AWS token abuse, organizations should log CloudTrail event data, detect role-chaining events and MFA abuse, and rotate long-term IAM user access keys.