Latest Cybersecurity News and Articles
07 November 2023
Internet-exposed Apache ActiveMQ servers are being targeted by ransomware attacks exploiting a critical remote code execution vulnerability. Over 4,770 vulnerable Apache ActiveMQ servers are at risk of exploitation.
07 November 2023
New macOS malware, tracked by Jamf as ObjCShellz, is likely being used by North Korean hackers to target crypto exchanges
The post New MacOS Malware Linked to North Korean Hackers appeared first on SecurityWeek.
07 November 2023
The North Korea-linked nation-state group called BlueNoroff has been attributed to a previously undocumented macOS malware strain dubbed ObjCShellz.
Jamf Threat Labs, which disclosed details of the malware, said it's used as part of the RustBucket malware campaign, which came to light earlier this year.
"Based on previous attacks performed by BlueNoroff, we suspect that this malware was a late
07 November 2023
Password health and hygiene have improved globally over the past year, reducing the risk of account takeover. However, password reuse remains prevalent, making user accounts vulnerable to password-spraying attacks.
07 November 2023
A new free tool named OpalOPC helps industrial organizations find OPC UA misconfigurations and vulnerabilities.
The post Free Tool Helps Industrial Organizations Find OPC UA Vulnerabilities appeared first on SecurityWeek.
07 November 2023
The vulnerability, known as CVE-2023-22518, impacts all versions of Atlassian Confluence Data Center and Server, and users are strongly advised to update to the latest version to mitigate the risk.
07 November 2023
Cloud infrastructure poses the greatest exposure risk for organizations, requiring effective integration of user identity and access privileges into preventive cybersecurity practices.
07 November 2023
The Android security updates released this week resolve 37 vulnerabilities, including a critical information disclosure bug.
The post 37 Vulnerabilities Patched in Android With November 2023 Security Updates appeared first on SecurityWeek.
07 November 2023
In a security update yesterday, the firm revealed CVE-2023-38547, a CVSS 9.9-rated flaw in Veeam ONE 11, 11a, and 12. The second critical bug (CVE-2023-38548) affects Veeam ONE version 12 and has a CVSS score of 9.8.
07 November 2023
A new variant of the GootLoader malware called GootBot has been found to facilitate lateral movement on compromised systems and evade detection.
"The GootLoader group's introduction of their own custom bot into the late stages of their attack chain is an attempt to avoid detections when using off-the-shelf tools for C2 such as CobaltStrike or RDP," IBM X-Force researchers Golo Mühr and Ole
07 November 2023
Myrror Security emerges from stealth mode to disrupt supply chain attacks with binary-to-source code analysis.
The post Myrror Security Emerges From Stealth Mode With $6 Million in Funding appeared first on SecurityWeek.
07 November 2023
The acquisition aims to strengthen security for unmanaged devices used by employees to access work-related material. Last week, Palo Alto Networks purchased cloud safety firm Dig Security.
07 November 2023
AI can truly disrupt all elements of the SOC and provide an analyst with 10x more data and save 10x more time than what currently exists.
The post Narrowing the Focus of AI in Security appeared first on SecurityWeek.
07 November 2023
Numerous industries—including technology, financial services, energy, healthcare, and government—are rushing to incorporate cloud-based and containerized web applications.
The benefits are undeniable; however, this shift presents new security challenges.
OPSWAT's 2023 Web Application Security report reveals:
75% of organizations have modernized their infrastructure this year.
78% have
07 November 2023
The Medusa ransomware group has demanded a ransom of $10,000 to delay the publication of compromised data by another day, and a staggering $200,000 for the complete deletion of the data.
07 November 2023
While the pledge is a step in the right direction, legislative measures are needed to effectively deter organizations from paying ransoms and address the growing issue of ransomware attacks.
07 November 2023
A new report from Duke University reveals that data brokers are selling highly sensitive information on American military service members, posing a threat to national security.
07 November 2023
Secure-by-design is clearly important to the federal government, and there is a strong possibility that it will become a regulatory requirement for the critical industries enforced through an Executive Order.
The post Federal Push for Secure-by-Design: What It Means for Developers appeared first on SecurityWeek.
07 November 2023
Five Canadian hospitals have confirmed a ransomware attack as data allegedly stolen from them was posted online.
The post Ransomware Gang Leaks Data Allegedly Stolen From Canadian Hospitals appeared first on SecurityWeek.
07 November 2023
As per Microsoft, the vulnerabilities do not meet the criteria of actual zero-days and require authentication for exploitation, reducing their chances of being used in malicious attacks.