Latest Cybersecurity News and Articles
19 October 2023
Henry Schein, Inc. experienced a cybersecurity incident that temporarily disrupted some of its business operations but did not impact its clients' practice management software.
19 October 2023
The Iran-linked OilRig threat actor targeted an unnamed Middle East government between February and September 2023 as part of an eight-month-long campaign.
The attack led to the theft of files and passwords and, in one instance, resulted in the deployment of a PowerShell backdoor called PowerExchange, the Symantec Threat Hunter Team, part of Broadcom, said in a report shared with The Hacker News
19 October 2023
A hacker in Finland has been charged with over 21,000 counts of extortion for stealing psychotherapy patient records and attempting to extort money from a therapy center.
19 October 2023
Multiple North Korean hacking groups have exploited a recent TeamCity vulnerability and Microsoft warns of potential supply chain attacks.
The post North Korean Hackers Exploiting Recent TeamCity Vulnerability appeared first on SecurityWeek.
19 October 2023
Google has announced a significant update to its Google Play Protect feature in response to the increasing threats targeting mobile devices. It includes real-time code-level scanning during the installation process to counter evasion techniques.
19 October 2023
Pro-Ukrainian hackers known as the Ukrainian Cyber Alliance claim to have wiped out the servers of the Trigona ransomware gang, a group linked to the Russian cybercriminal underground.
19 October 2023
San Francisco-based startup Darwinium has raised $18 million in a Series A funding round led by U.S. Venture Partners. The company, which focuses on fraud prevention, has developed a digital security platform that runs on the perimeter edge.
19 October 2023
The recent campaigns targeting various sectors, including the energy and government sectors, highlight the effectiveness of known vulnerabilities even with available patches, emphasizing the importance of proactive software security measures.
19 October 2023
The vulnerability allows attackers to execute arbitrary code on the server, potentially leading to the theft of source code and private keys. TeamCity is used by many high-profile organizations, making it an attractive target for hackers.
19 October 2023
North Korean threat actors are actively exploiting a critical security flaw in JetBrains TeamCity to opportunistically breach vulnerable servers, according to Microsoft.
The attacks, which entail the exploitation of CVE-2023-42793 (CVSS score: 9.8), have been attributed to Diamond Sleet (aka Labyrinth Chollima) and Onyx Sleet (aka Andariel or Silent Chollima).
It's worth noting that both the
19 October 2023
A number of state-back threat actors from Russia and China have been observed exploiting a recent security flaw in the WinRAR archiver tool for Windows as part of their operations.
The vulnerability in question is CVE-2023-38831 (CVSS score: 7.8), which allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The shortcoming has been actively
18 October 2023
Finland charged a hacker, accused of the theft of tens of thousands of records from psychotherapy patients, with over 21,000 counts of extortion.
The post Finland Charges Psychotherapy Hacker With Extortion appeared first on SecurityWeek.
18 October 2023
Google says it is still catching government-backed groups linked to China and Russia launching WinRAR exploits in targeted attacks.
The post Three Months After Patch, Gov-Backed Actors Exploiting WinRAR Flaw appeared first on SecurityWeek.
18 October 2023
A critical security flaw in Citrix NetScaler ADC and Gateway appliances (CVE-2023-4966) is being actively exploited, potentially allowing hijacking of authenticated sessions and bypassing multi-factor authentication.
18 October 2023
Oracle has released 387 new security patches to address vulnerabilities in its own code and third-party components, with over 40 patches addressing critical severity flaws.
18 October 2023
The fraud prevention provider's $33 million Series C funding round brings the total raised by the company to $77 million. The new investment round was led by Nexus Venture Partners, with additional funding from Uncorrelated Ventures.
18 October 2023
IT administrators are putting enterprise networks at risk by using weak passwords, including default passwords, leaving them vulnerable to cyberattacks, as per a new report by Outpost24.
18 October 2023
The number of registered data brokers in states with operative registries does not accurately reflect the size and reach of the industry, raising concerns about non-compliance.
18 October 2023
Jordan Lippel, Vice President of Sales at ECAMSECURE, discusses how security professionals can stay updated regarding integration of automation and AI into their security operations.
18 October 2023
The threat actor behind Qubitstrike, likely from Tunisia, employs sophisticated techniques to evade detection and exploit cloud services, with the potential for carrying out various attacks on compromised systems.