Latest Cybersecurity News and Articles


Malvertising via Dynamic Search Ads Delivers Malware Bonanza

30 October 2023
The compromised website injected malicious content, including overlays promoting software serial keys, which resulted in misleading ads being automatically generated by Google Ads.

Proofpoint to Acquire Tessian for AI-Powered Email Security Tech

30 October 2023
Proofpoint removes a formidable competitor from the crowded email security market and adds technology to address risk from misdirected emails. The post Proofpoint to Acquire Tessian for AI-Powered Email Security Tech appeared first on SecurityWeek.

Boeing Investigating Ransomware Attack Claims

30 October 2023
The LockBit ransomware gang claims to have stolen large amounts of data from aerospace giant Boeing. The post Boeing Investigating Ransomware Attack Claims appeared first on SecurityWeek.

Apple Improves iMessage Security With Contact Key Verification

30 October 2023
New capability detects attacks on iMessage servers and allows users to verify a conversation partner’s identity. The post Apple Improves iMessage Security With Contact Key Verification appeared first on SecurityWeek.

EleKtra-Leak Cryptojacking Attacks Exploit AWS IAM Credentials Exposed on GitHub

30 October 2023
The threat actor behind the campaign quickly scans and clones GitHub repositories to capture exposed keys, highlighting the importance of promptly removing and revoking any compromised credentials.

Attackers Can Use Modified Wikipedia Pages to Mount Redirection Attacks on Slack

30 October 2023
Researchers document the Wiki-Slack attack, a new technique that uses modified Wikipedia pages to target end users on Slack. The post Attackers Can Use Modified Wikipedia Pages to Mount Redirection Attacks on Slack appeared first on SecurityWeek.

CISA Launches Logging Tool for Resource-Poor Organizations

30 October 2023
The tool provides step-by-step installation instructions, prebuilt elastic security detection rules, and coding to reduce cost barriers, making it accessible for organizations aiming to implement basic logging and monitoring capabilities.

Report shows 1265% increase in phishing emails since ChatGPT launched

30 October 2023
A new report reveals a 967% increase in credential phishing attempts year-over-year, the number one access point to organizational breaches.

Hackers Earn Over $1 Million at Pwn2Own Toronto 2023

30 October 2023
Hackers have demonstrated 58 zero-days and earned more than $1 million in rewards at Pwn2Own Toronto 2023. The post Hackers Earn Over $1 Million at Pwn2Own Toronto 2023 appeared first on SecurityWeek.

IT Army of Ukraine Claims to Disrupt Internet Providers in Russia-Occupied Territories

30 October 2023
The recent DDoS attacks by pro-Ukrainian hackers targeted Russian ISPs, including Miranda-media, Krimtelekom, and MirTelekom, affecting not only Crimea but also occupied parts of other regions.

Report: 587% Surge in QR Code Quishing Attacks

30 October 2023
QR codes are particularly vulnerable to exploitation due to their ability to encode complex data and redirect users to malicious sites, making them an attractive target for hackers.

New Webinar: 5 Must-Know Trends Impacting AppSec

30 October 2023
Modern web app development relies on cloud infrastructure and containerization. These technologies scale on demand, handling millions of daily file transfers – it's almost impossible to imagine a world without them. However, they also introduce multiple attack vectors that exploit file uploads when working with public clouds, vulnerabilities in containers hosting web applications, and many other

ServiceNow Data Exposure: A Wake-Up Call for Companies

30 October 2023
Earlier this week, ServiceNow announced on its support site that misconfigurations within the platform could result in “unintended access” to sensitive data. For organizations that use ServiceNow, this security exposure is a critical concern that could have resulted in major data leakage of sensitive corporate data. ServiceNow has since taken steps to fix this issue.  This article fully analyzes

Hackers Email Stolen Student Data to Parents of Nevada School District

30 October 2023
Parents have received emails from the threat actors, with leaked PDF documents containing student data, causing concerns about potential identity theft and phishing attacks.

FTC Expands Financial Data Breach Reporting Requirements

30 October 2023
The new disclosure requirement aims to empower consumers by providing them with breach data and enabling them to make more informed decisions about which financial institutions to trust with their information.

Whistleblowers: Should CISOs Consider Them a Friend or Foe?

30 October 2023
Are whistleblowers traitors to the company, a danger to corporate brand image, and a form of insider threat? Or are they an early warning safety valve that can be used to strengthen cybersecurity and compliance? The post Whistleblowers: Should CISOs Consider Them a Friend or Foe? appeared first on SecurityWeek.

Hackers Using MSIX App Packages to Infect Windows PCs with GHOSTPULSE Malware

30 October 2023
The GHOSTPULSE malware employs multiple evasion techniques, such as DLL side-loading and module stomping, to load and execute various malware including SectopRAT, Rhadamanthys, Vidar, Lumma, and NetSupport RAT.

EleKtra-Leak Cryptojacking Attacks Exploit AWS IAM Credentials Exposed on GitHub

30 October 2023
A new ongoing campaign dubbed EleKtra-Leak has set its eyes on exposed Amazon Web Service (AWS) identity and access management (IAM) credentials within public GitHub repositories to facilitate cryptojacking activities. "As a result of this, the threat actor associated with the campaign was able to create multiple AWS Elastic Compute (EC2) instances that they used for wide-ranging and

Raven: Open-source CI/CD pipeline security scanner

30 October 2023
Raven scans GitHub workflows, breaks them into components, and utilizes a knowledge base to identify vulnerabilities, making it easier for security teams to assess and address risks.

Biden Wants to Move Fast on AI Safeguards and Will Sign an Executive Order to Address His Concerns

30 October 2023
President Joe Biden on Monday will sign a sweeping executive order to guide the development of artificial intelligence — requiring industry to develop safety and security standards, and introducing new consumer protections. The post Biden Wants to Move Fast on AI Safeguards and Will Sign an Executive Order to Address His Concerns appeared first on SecurityWeek.