Latest Cybersecurity News and Articles


Report: Only a Fraction of Risk Leaders are Prepared for GenAI Threats

25 October 2023
New research by Riskonnect highlights a significant gap in AI risk management, with only 17% of risk and compliance leaders formally training their organizations on the risks of generative AI.

Citrix Urges NetScaler ADC, Gateway Customers to Patch

25 October 2023
Citrix is urging its customers to upgrade to the latest versions of NetScaler ADC and NetScaler Gateway due to reports of targeted attacks and session hijacking. The company released patches to address a critical vulnerability, CVE-2023-4966.

Alleged Covert Wiretap on Russian Messaging Service Blown by Expired TLS Certificate

25 October 2023
The wiretap is believed to have lasted up to 6 months, allowing the attacker to execute actions on compromised accounts without the need for passwords, potentially altering messages and accessing unencrypted data.

Report: September was a Record Month for Ransomware Attacks in 2023

25 October 2023
Ransomware activity reached an all-time high in September, with 514 attacks recorded. The previous record was in March 2023, but this new surge was led by different threat groups. LockBit 3.0, LostTrust, and BlackCat were the top attackers.

Adlumin Snags $70M to Boost Security for Mid-Market Firms

25 October 2023
The round was led by SYN Ventures, with participation from First In Ventures, Washington Harbour Partners, and BankTech Ventures. This brings Adlumin's total funding to $83 million and solidifies its position in the security operations and MDR space.

Alert: PoC Exploits Released for Citrix and VMware Vulnerabilities

25 October 2023
Virtualization services provider VMware has alerted customers to the existence of a proof-of-concept (PoC) exploit for a recently patched security flaw in Aria Operations for Logs. Tracked as CVE-2023-34051 (CVSS score: 8.1), the high-severity vulnerability relates to a case of authentication bypass that could lead to remote code execution. "An unauthenticated, malicious actor can inject files

Personal Information Stolen in City of Philadelphia Email Hack

24 October 2023
The City of Philadelphia says personal, health, and financial information was stolen in a cyberattack on its email environment. The post Personal Information Stolen in City of Philadelphia Email Hack appeared first on SecurityWeek.

Over 80% of security leaders have already received AI email attacks

24 October 2023
The impact of AI on email security was analyzed in a recent report by Abnormal Security, finding 98% of security leaders are concerned about AI.

Stealth Techniques Used in ‘Operation Triangulation’ iOS Attack Dissected

24 October 2023
Kaspersky analyzes the stealth techniques that were used in the ‘Operation Triangulation’ iOS zero-click attacks. The post Stealth Techniques Used in ‘Operation Triangulation’ iOS Attack Dissected appeared first on SecurityWeek.

There were 11% more ransomware attacks in Q3 than Q2 2023

24 October 2023
A recent global ransomware report by Corvus Insurance found that ransomware attack frequency up 11% over Q2 and 95% year-over-year (YoY).

Rockwell Automation Warns Customers of Cisco Zero-Day Affecting Stratix Switches

24 October 2023
Rockwell Automation has warned customers about the impact of the actively exploited Cisco IOS XE zero-day on its Stratix industrial switches. The post Rockwell Automation Warns Customers of Cisco Zero-Day Affecting Stratix Switches appeared first on SecurityWeek.

VMware Warns Admins of Public Exploit for RCE Flaw in Aria Operations for Logs

24 October 2023
The vulnerability (CVE-2023-34051) requires the attacker to compromise a host within the targeted environment and have permissions to add an extra interface or static IP address.

Google Chrome’s New “IP Protection” Will Hide Users’ IP Addresses

24 October 2023
The feature will route third-party traffic through proxies, making users' IP addresses invisible to specific domains, while adapting to safeguard against cross-site tracking.

Canadian Lawmakers Targeted by China-Linked ‘Spamouflage’ Disinformation Campaign

24 October 2023
Canada has warned of a disinformation campaign linked to China, dubbed "Spamouflage," involving deepfake videos and online posts aimed at discrediting Canadian lawmakers and silencing criticism of the Chinese Communist Party.

Blockaid Emerges From Stealth With $33 Million Investment

24 October 2023
The investment round was led by Ribbit Capital and Variant, with participation from Cyberstarts, Greylock Partners, and Sequoia Capital. The new funds will be used to scale the company's products and team and expand its customer base.

Norway Issues Warning After ‘Important Businesses’ Affected by Cisco Zero-Days

24 October 2023
The attacks were described as more potent than a previous incident that affected Norway's government support agency, resulting in hackers accessing the data of several government ministries.

The $64k Question: How Does AI Phishing Stack Up Against Human Social Engineers?

24 October 2023
The Rise of AI in Phishing: Will future phishing attacks that leverage artificial intelligence be more dangerous? The post The $64k Question: How Does AI Phishing Stack Up Against Human Social Engineers? appeared first on SecurityWeek.

The Double-Edged Sword of Heightened Regulation for Financial Services

24 October 2023
The financial services industry faces unique cybersecurity challenges, including the need to protect sensitive data, navigate complex regulations, and manage partnerships and interconnectedness.

OAuth Implementation Issues Allows Full Online Account Takeover for Millions of Users

24 October 2023
Flaws in the implementation of OAuth across various online services, including Grammarly, Vidio, and Bukalapak, could have exposed hundreds of millions of user accounts to credential theft and other cybercriminal activities.

Adlumin Snags $70M to Boost Security for Mid-Market Firms

24 October 2023
Adlumin, a startup working on technology to boost security for mid-market firms, has banked $70 million in new funding led by SYN Ventures. The post Adlumin Snags $70M to Boost Security for Mid-Market Firms appeared first on SecurityWeek.