Latest Cybersecurity News and Articles
24 October 2023
While application development has evolved rapidly, the API management suites used to access these services remain a spooky reminder of a different era. Introducing new API management infrastructure with these legacy models still poses challenges for organizations as they modernize. Transitioning from monolithic architectures to agile microservices empowers developers to make quick changes. Using
24 October 2023
While the exact identity of the threat actor is unknown, thousands of devices have been affected, with the number of compromised devices decreasing recently due to changes made to hide the implant.
24 October 2023
Ransomware attacks have seen a shocking 153% increase in September, with healthcare being a particularly concerning target due to its potential impact on patient safety, according to NCC Group's Threat Pulse report.
24 October 2023
Spanish authorities arrested 34 members of a cybercrime group that defrauded victims of $3.12 million using phishing and other tactics. Over 4 million people may have been affected by their activities.
24 October 2023
The TriangleDB implant used to target Apple iOS devices packs in at least four different modules to record microphone, extract iCloud Keychain, steal data from SQLite databases used by various apps, and estimate the victim's location.
The findings come from Kaspersky, which detailed the great lengths the adversary behind the campaign, dubbed Operation Triangulation, went to conceal and cover up
24 October 2023
The acquisition reflects the growing importance of cybersecurity in the industrial sector, with several M&A deals involving industrial cybersecurity companies taking place in recent years.
24 October 2023
The breach occurred in Okta's customer support management system, allowing an unknown attacker to access files uploaded by some Okta customers. 1Password is the second known Okta customer to be targeted in a follow-on attack.
24 October 2023
The company said the investment was led by Prysm Capital at a valuation of $1.5 billion. Existing backers Canapi Ventures, Insight Partners, Stripes, Sequoia, Cyberstarts, and Georgian also expanded equity positions.
24 October 2023
The hackers gained access to Social Security numbers, driver's license numbers, financial account information, health records, and other sensitive data, potentially impacting a large number of individuals.
24 October 2023
The backdoor implanted on Cisco devices by exploiting a pair of zero-day flaws in IOS XE software has been modified by the threat actor so as to escape visibility via previous fingerprinting methods.
"Investigated network traffic to a compromised device has shown that the threat actor has upgraded the implant to do an extra header check," NCC Group's Fox-IT team said. "Thus, for a lot of devices
24 October 2023
Popular password management solution 1Password said it detected suspicious activity on its Okta instance on September 29 following the support system breach, but reiterated that no user data was accessed.
"We immediately terminated the activity, investigated, and found no compromise of user data or other sensitive systems, either employee-facing or user-facing," Pedro Canahuati, 1Password CTO,
23 October 2023
Chinese authorities have netted thousands of people in a crackdown on cyber scams, but the criminal networks remain intact.
The post China Crackdown on Cyber Scams in Southeast Asia Nets Thousands but Leaves Networks Intact appeared first on SecurityWeek.
23 October 2023
Blockaid raises a Series A funding round to build technology to secure blockchain applications from hacks and scams.
The post Blockaid Emerges From Stealth With $33 Million Investment appeared first on SecurityWeek.
23 October 2023
Hackers access the personal information of Casio customers after compromising the server for an education web application.
The post Casio Says Personal Information Accessed in Web Application Server Hack appeared first on SecurityWeek.
23 October 2023
The city of Philadelphia released a notice regarding a data breach that occurred between May and July of 2023, including suspicious email activity.
23 October 2023
Rockwell Automation agreed to acquire ICS/OT cybersecurity firm Verve Industrial Protection to expand its offerings.
The post Rockwell Automation to Acquire ICS/OT Security Firm Verve Industrial appeared first on SecurityWeek.
23 October 2023
SolarWinds patches high-severity flaws in its Access Rights Manager product, including three unauthenticated remote code execution issues.
The post SolarWinds Patches High-Severity Flaws in Access Rights Manager appeared first on SecurityWeek.
23 October 2023
Researchers have linked DoNot Team, a threat actor believed to be of Indian origin, to a .NET-based backdoor called Firebird. The backdoor has been used to target victims in Pakistan and Afghanistan.
23 October 2023
Researchers suspect that Meta was either tricked into providing access to the threat actor or the threat actor obtained credentials for a legitimate law enforcement account.
23 October 2023
Since 2020, Island has raised a total of $325 million to help protect corporate data flowing through SaaS and internal web applications.
The post Enterprise Browser Startup Island Banks $100M in Funding appeared first on SecurityWeek.