Latest Cybersecurity News and Articles


AI Security Firm Cranium Raises $25 Million

26 October 2023
AI cybersecurity firm Cranium has raised $25 million in Series A funding, which brings the total investment in the company to $32 million. The post AI Security Firm Cranium Raises $25 Million appeared first on SecurityWeek.

Nine Vulnerabilities Found in VPN Software, Including One Critical RCE Issue

26 October 2023
Cisco Talos has disclosed multiple vulnerabilities in popular VPN software, including a critical heap-based buffer overflow vulnerability, posing a significant risk to users' connections and allowing for arbitrary code execution.

The Rise and Tactics of Octo Tempest: A Cyber Threat Analysis

26 October 2023
Octo Tempest, a financially motivated threat group known for extensive social engineering campaigns and SIM-swapping techniques, has become a major concern for businesses worldwide. It has been affiliated with ALPHV/BlackCat and began deploying ransomware payloads as well. Given Octo Tempest's relentless evolution and aggressive approach, organizations must be proactive in their defense strategies.

Key Learnings from “Big Game” Ransomware Campaigns

26 October 2023
There are key steps every organization should take to leverage threat and event data across the lifecycle of a cyber incident. The post Key Learnings from “Big Game” Ransomware Campaigns appeared first on SecurityWeek.

Kansas Court System Down Nearly 2 Weeks in ‘Security Incident’ That Has Hallmarks of Ransomware

26 October 2023
Kansas is calling a massive computer outage that’s kept most of the state’s courts offline for 2 weeks a “security incident” and experts say it's likely ransomware. The post Kansas Court System Down Nearly 2 Weeks in ‘Security Incident’ That Has Hallmarks of Ransomware appeared first on SecurityWeek.

Citrix Bleed Exploit Lets Hackers Hijack Netscaler Accounts

26 October 2023
The vulnerability arises from an unauthenticated buffer-related flaw in Citrix devices, which can be exploited to gain unrestricted access to the appliances and potentially hijack user accounts.

CISA, HHS Release Cybersecurity Healthcare Toolkit

26 October 2023
CISA and the HHS have released resources for healthcare and public health organizations to improve their security. The post CISA, HHS Release Cybersecurity Healthcare Toolkit appeared first on SecurityWeek.

UK Parliament Opens Inquiry into Cyber-Resilience

26 October 2023
The Science, Innovation and Technology Committee will oversee the inquiry, alarmed at the proliferation of state and non-state actors using offensive cyber capabilities against UK organizations.

iLeakage Attack Exploits Safari to Steal Sensitive Data From Macs, iPhones

26 October 2023
New iLeakage side-channel speculative execution attack exploits Safari to steal sensitive information from Macs and iPhones. The post iLeakage Attack Exploits Safari to Steal Sensitive Data From Macs, iPhones appeared first on SecurityWeek.

Critical Flaw in NextGen's Mirth Connect Could Expose Healthcare Data

26 October 2023
The vulnerability (CVE-2023-43208) is a patch bypass for a critical remote command execution vulnerability (CVE-2023-37679), and all instances of Mirth Connect are susceptible to it.

Seiko Discloses Data Breach Resulting From BlackCat Ransomware Attack

26 October 2023
Seiko Group Corporation (SGC) has confirmed a data breach that occurred in July 2023. The breach resulted in unauthorized access to 60,000 records, including customer data, contact details, employment applicant information, and personnel details.

Apple Ships Major iOS, macOS Security Updates

26 October 2023
The updates cover fixes for a range of components including Contacts, WebKit, and kernel, among others, and aim to fix code execution flaws and privilege escalation issues.

The holiday season leads to a rise in business payment fraud

26 October 2023
A payment security report found that three-fourths of business leaders are more concerned about business payment fraud during the holiday season.

Redcliffe Labs Database with Over 12 Million Patient Records Exposed

26 October 2023
The diagnostic service left 7 terabytes of sensitive data vulnerable, including medical diagnostic scans, test results, patient information, and even the names of attending doctors.

Winter Vivern APT Resurfaces to Target European Entities

26 October 2023
The Winter Vivern espionage group targeted European government entities and a think tank using a zero-day vulnerability in Roundcube Webmail, enabling email exfiltration with minimal interaction. The payload used in the campaign worked even on fully patched Roundcube instances. Despite the low sophistication of the group’s toolset, Winter Vivern remains a significant threat to organizations in Europe.

Google Announces Bug Bounty Program and Other Initiatives to Secure AI

26 October 2023
Google announces a bug bounty program and other initiatives for increasing the safety and security of AI. The post Google Announces Bug Bounty Program and Other Initiatives to Secure AI appeared first on SecurityWeek.

Microsoft Warns as Scattered Spider Expands from SIM Swaps to Ransomware

26 October 2023
The prolific threat actor known as Scattered Spider has been observed impersonating newly hired employees in targeted firms as a ploy to blend into normal on-hire processes and takeover accounts and breach organizations across the world. Microsoft, which disclosed the activities of the financially motivated hacking crew, described the adversary as "one of the most dangerous financial criminal

Japanese Watchmaking Giant Seiko Confirms Personal Data Stolen in Ransomware Attack

26 October 2023
Japanese watchmaking giant Seiko has confirmed that personal information was stolen in a recent ransomware attack. The post Japanese Watchmaking Giant Seiko Confirms Personal Data Stolen in Ransomware Attack appeared first on SecurityWeek.

Octo Tempest aka 0ktapus has Become 'One of the Most Dangerous Financial' Hacker Groups

26 October 2023
The group gains initial access through social engineering tactics, including impersonating victims and using fake login portals, to target a wide range of industries for extortion.

Weapons Systems Provide Valuable Lessons for ICS/OT Security

26 October 2023
Cybersecurity techniques and penetration testing used in the field of weapons systems can provide valuable lessons for ICS/OT security. The post Weapons Systems Provide Valuable Lessons for ICS/OT Security appeared first on SecurityWeek.