Latest Cybersecurity News and Articles
17 October 2023
Amir Golestan, the 40-year-old CEO of the Charleston, S.C. based technology company Micfo LLC, has been sentenced to five years in prison for wire fraud. Golestan's sentencing comes nearly two years after he pleaded guilty to using an elaborate network of phony companies to secure more than 735,000 Internet Protocol (IP) addresses from the American Registry for Internet Numbers (ARIN), the nonprofit which oversees IP addresses assigned to entities in the U.S., Canada, and parts of the Caribbean.
17 October 2023
The Black Basta ransomware gang claimed responsibility for the attack, but the extent of the data stolen is unknown. The company confirmed the incident and stated that they are working with law enforcement to address the issue.
17 October 2023
Startup with roots in the ecommerce mobile payments space raises $40 million for digital identity verification and authentication technology.
The post Prove Identity Snags $40M Funding for ID Verification Tech appeared first on SecurityWeek.
17 October 2023
The attackers behind the XorDDoS campaign have migrated their offensive infrastructure to legitimate public hosting services, making it harder to block their command and control (C2) traffic.
17 October 2023
In what's the latest evolution of threat actors abusing legitimate infrastructure for nefarious ends, new findings show that nation-state hacking groups have entered the fray in leveraging the social platform for targeting critical infrastructure.
Discord, in recent years, has become a lucrative target, acting as a fertile ground for hosting malware using its content delivery network (CDN) as
17 October 2023
The feared ‘cryptopocalypse’ (the death of current encryption) might be sooner than expected – caused by in-memory computing ASICs rather than quantum computers.
The post Beyond Quantum: MemComputing ASICs Could Shatter 2048-bit RSA Encryption appeared first on SecurityWeek.
17 October 2023
Two critical security flaws discovered in the open-source CasaOS personal cloud software could be successfully exploited by attackers to achieve arbitrary code execution and take over susceptible systems.
The vulnerabilities, tracked as CVE-2023-37265 and CVE-2023-37266, both carry a CVSS score of 9.8 out of a maximum of 10.
Sonar security researcher Thomas Chauchefoin, who discovered the bugs,
17 October 2023
The Knight group threatened to release stolen files and provided countdown links. However, the parent company, BMW, has not confirmed the attack. The website for BMW Munique Motors is still operational.
17 October 2023
The security concerns of generative artificial intelligence (AI) use within the workplace were analyzed in a recent report by ExtraHop.
17 October 2023
These include authenticated remote code execution via "zip slip" and WebDAV path traversal, session fixation on the remote administration server, information disclosure via path traversal on FTP, and information disclosure in the admin interface.
17 October 2023
Data transmission faces a looming threat from Harvest Now, Decrypt Later (HNDL) attacks, where encrypted data is collected and stored with the intention of decrypting it in the future using advancements in computing or quantum technologies.
17 October 2023
Anonybit has raised $3 million in seed funding extension for its biometric authentication and data protection solutions.
The post Anonybit Raises $3 Million for Biometric Authentication Platform appeared first on SecurityWeek.
17 October 2023
A new report by Trellix reveals that Discord, a popular communication platform, is being increasingly used by hackers, including advanced persistent threat (APT) groups, to target critical infrastructure.
17 October 2023
A recent survey by Hornetsecurity reveals that 60% of companies are highly concerned about ransomware attacks, highlighting the urgency for robust protection measures and the active involvement of leadership in preventing such incidents.
17 October 2023
Weintek has patched critical and high-severity vulnerabilities found in its cMT series HMIs by industrial cybersecurity firm TXOne.
The post Critical Vulnerabilities Expose Weintek HMIs to Attacks appeared first on SecurityWeek.
17 October 2023
The exact reason for the significant increase in affected individuals since July is unclear, but ongoing investigation and the discovery of additional compromised locations may be contributing factors.
17 October 2023
A recently released report reveals more than half of senior leaders have no involvement in their company's cyber cases.
17 October 2023
Security researchers discovered threat actors using the Discord platform to distribute Lumma Stealer, an information-stealing malware. The malware is designed to steal user credentials, cryptocurrency wallets, and browser data. Users need to exercise caution while clicking links or downloading files from unverified sources.
17 October 2023
The hackers used reconnaissance techniques to identify vulnerabilities in the telecom providers' networks and gained unauthorized access using compromised servers in the Ukrainian internet segment.
17 October 2023
Financial data is much more than just a collection of numbers; it is a crucial component of any business and a prime target for cybercriminals. It's important to understand that financial records can be a veritable treasure trove for digital pirates.
A security breach not only puts customers' personal information in jeopardy but also enables fraudsters to drain company funds and exploit clients.