Latest Cybersecurity News and Articles
25 October 2023
The threat actor known as Winter Vivern has been observed exploiting a zero-day flaw in Roundcube webmail software on October 11, 2023, to harvest email messages from victims' accounts.
"Winter Vivern has stepped up its operations by using a zero-day vulnerability in Roundcube," ESET security researcher Matthieu Faou said in a new report published today. Previously, it was using known
25 October 2023
The escalating reliance on information operations by these groups aims to influence the global perception of the conflict, with strategic campaigns designed to manipulate social media platforms and influence media outlets.
25 October 2023
The Cybersecurity Resilience Quotient empowers organizations to assess their security posture comprehensively, considering asset exposure, vulnerabilities, and criticality alongside process and network architecture and disaster recovery plans.
The post The Cybersecurity Resilience Quotient: Measuring Security Effectiveness appeared first on SecurityWeek.
25 October 2023
Critical security flaws have been disclosed in the Open Authorization (OAuth) implementation of popular online services such as Grammarly, Vidio, and Bukalapak, building upon previous shortcomings uncovered in Booking[.]com and Expo.
The weaknesses, now addressed by the respective companies following responsible disclosure between February and April 2023, could have allowed malicious actors to
25 October 2023
VMware described the bug as an out-of-bounds write issue in its implementation of the DCE/RPC protocol. CVSS severity score of 9.8/10.
The post VMware vCenter Flaw So Critical, Patches Released for End-of-Life Products appeared first on SecurityWeek.
25 October 2023
The White House aims to establish a global norm against paying ransoms to cybercriminals and may seek a UN process or an international partnership to achieve this objective.
25 October 2023
The TSA directives require operators to test their cybersecurity incident response plans annually, submit updated cybersecurity assessment plans, and report on the effectiveness of their efforts.
25 October 2023
SecurityWeek’s 2023 ICS Cybersecurity Conference continues in Atlanta, as hundreds of industrial cybersecurity stakeholders gather for Day 2 of the annual industrial cybersecurity conference.
The post Critical Infrastructure Stakeholders Gather for Day 2 of SecurityWeek’s 2023 ICS Cybersecurity Conference appeared first on SecurityWeek.
25 October 2023
Russian state organizations and industrial sectors have been targeted with a custom Go-based backdoor. The backdoor, distributed through phishing emails, steals data, including passwords from popular web browsers and the Thunderbird email client.
25 October 2023
Censys aims to offer customers insights into the historical and real-time status of their data, enabling them to identify how long their data has been vulnerable and what changes have made it exploitable.
25 October 2023
In today's digital landscape, around 60% of corporate data now resides in the cloud, with Amazon S3 standing as the backbone of data storage for many major corporations.
Despite S3 being a secure service from a reputable provider, its pivotal role in handling vast amounts of sensitive data (customer personal information, financial data, intellectual property, etc.), provides a juicy target for
25 October 2023
ASVEL has reported the incident to the national data protection authority and law enforcement authorities, while also assessing the potential impact on third parties, including fans who made purchases on the club's official website.
25 October 2023
Although humans currently outperform AI in terms of click rates and detection, the advancing sophistication of AI suggests it may eventually surpass human capabilities in the phishing industry.
25 October 2023
Passkeys are digital credentials that can only be used by authorized users and require biometric or unique factor authentication. Tech giants like Apple, Google, and Microsoft have embraced passkeys in their products.
25 October 2023
VMware has released security updates to address a critical flaw in the vCenter Server that could result in remote code execution on affected systems.
The issue, tracked as CVE-2023-34048 (CVSS score: 9.8), has been described as an out-of-bounds write vulnerability in the implementation of the DCE/RPC protocol.
"A malicious actor with network access to vCenter Server may trigger an out-of-bounds
25 October 2023
Researchers also targeted other devices such as smartphones, printers, smart speakers, and surveillance cameras, demonstrating the wide range of potential targets for hackers.
25 October 2023
Additional resources and funding, along with harmonized authorities and improved coordination, are necessary to enhance the cybersecurity measures of federal executive agencies.
25 October 2023
The popularity of Brazil's PIX instant payment system has made it a lucrative target for threat actors looking to generate illicit profits using a new malware called GoPIX.
Kaspersky, which has been tracking the active campaign since December 2022, said the attacks are pulled off using malicious ads that are served when potential victims search for "WhatsApp web" on search engines.
"The
25 October 2023
The Akira ransomware gang breached BHI Energy's network through a stolen VPN credential and stole a significant amount of data, including the personal information of employees.
25 October 2023
Scam emails can be sent directly to SERS via a new button organisations can add to their Microsoft Office 365 accounts.