Latest Cybersecurity News and Articles
17 October 2023
Researchers from Radware found that Israel endured 143 DDoS attacks between October 2 and October 10, making it the most targeted nation-state during that period. These attacks were all claimed by hacktivists on the messaging service Telegram.
17 October 2023
The Kansas Supreme Court and other district courts in the state are experiencing a disruption in their IT systems due to a security incident, leading to the suspension of electronic filing of documents.
17 October 2023
NSA has released Elitewolf, a repository of intrusion detection signatures and analytics for OT environments.
The post NSA Publishes ICS/OT Intrusion Detection Signatures and Analytics appeared first on SecurityWeek.
17 October 2023
Recently, the cybersecurity landscape has been confronted with a daunting new reality – the rise of malicious Generative AI, like FraudGPT and WormGPT. These rogue creations, lurking in the dark corners of the internet, pose a distinctive threat to the world of digital security. In this article, we will look at the nature of Generative AI fraud, analyze the messaging surrounding these creations,
17 October 2023
A severity flaw impacting industrial cellular routers from Milesight may have been actively exploited in real-world attacks, new findings from VulnCheck reveal.
Tracked as CVE-2023-43261 (CVSS score: 7.5), the vulnerability has been described as a case of information disclosure that affects UR5X, UR32L, UR32, UR35, and UR41 routers before version 35.3.0.7 that could enable attackers to access
17 October 2023
CISA, FBI, and MS-ISAC warn of potential widespread exploitation of CVE-2023-22515, a critical vulnerability in Atlassian Confluence.
The post US Gov Expects Widespread Exploitation of Atlassian Confluence Vulnerability appeared first on SecurityWeek.
17 October 2023
Cisco is warning customers that a new IOS XE zero-day vulnerability tracked as CVE-2023-20198 is being exploited to hack devices.
The post Cisco Devices Hacked via IOS XE Zero-Day Vulnerability appeared first on SecurityWeek.
17 October 2023
A critical vulnerability in the Royal Elementor WordPress plugin has been exploited as a zero-day since August 30.
The post WordPress Websites Hacked via Royal Elementor Plugin Zero-Day appeared first on SecurityWeek.
17 October 2023
Void Rabisu has been found deploying the new RomCom 4.0 backdoor against participants of the Women Political Leaders (WPL) Summit in Brussels. According to researchers, the latest variant has undergone some significant changes in its architecture, making it lighter and stealthier. Organizations are advised to stay protected by staying updated on the RomCom attack trends and making use of the IoCs shared by Trend Micro.
17 October 2023
Air Vice-Marshal Tim Neal-Hopes has been appointed as the new commander of the United Kingdom's National Cyber Force (NCF). He joins the NCF from Strategic Command, where he served as the director for cyber, intelligence, and information integration.
17 October 2023
The vendor has released a patch (version 1.3.79) to fix the flaw (CVE-2023-5360), and users are recommended to upgrade as soon as possible, but a website cleanup may be necessary to remove any infections or malicious files.
17 October 2023
The company conducted a thorough investigation and found no indication that the vulnerability is real. Signal also reached out to the US government, which provided no information to support the claim.
17 October 2023
The recently disclosed flaw (CVE-2023-22515) in Atlassian Confluence Data Center and Server allows malicious actors to create unauthorized administrator accounts, leading to widespread exploitation and the need for immediate application of upgrades.
17 October 2023
The agreement between the US and the UAE comes ahead of the International Counter Ransomware Initiative summit, where governments are expected to pledge not to pay ransoms to cybercriminals.
17 October 2023
The vulnerability affects enterprise networking gear with the Web UI feature enabled and exposed to the internet or untrusted networks, and it is recommended to disable the HTTP server feature as a mitigation.
17 October 2023
The Computer Emergency Response Team of Ukraine (CERT-UA) has revealed that threat actors "interfered" with at least 11 telecommunication service providers in the country between May and September 2023.
The agency is tracking the activity under the name UAC-0165, stating the intrusions led to service interruptions for customers.
The starting point of the attacks is a reconnaissance phase in
17 October 2023
Cisco has warned of a critical, unpatched security flaw impacting IOS XE software that’s under active exploitation in the wild.
Rooted in the web UI feature, the zero-day vulnerability is assigned as CVE-2023-20198 and has been assigned the maximum severity rating of 10.0 on the CVSS scoring system.
It’s worth pointing out that the shortcoming only affects enterprise networking gear that have
16 October 2023
Henry Schein announced that a part of the company's manufacturing and distribution business suffered a data breach on October 14, 2023.
16 October 2023
Dozens of vulnerabilities in the Squid caching and forwarding web proxy, a widely used open-source proxy, remain unpatched two years after being discovered by researcher Joshua Rogers.
16 October 2023
Generative artificial intelligence use within the workplace was analyzed in a recent report, finding 9% of organizations feel prepared for the threat.