Latest Cybersecurity News and Articles
13 October 2023
Progress Software has received a subpoena from the SEC and faces multiple class action lawsuits and claims for indemnification due to the MOVEit vulnerability, resulting in significant costs.
13 October 2023
After nearly a week of intense speculation regarding the security issues in cURL, the latest version of this command-line transfer tool has been released with a fix. Vulnerable systems could allow potential attacks via a malicious HTTPS server redirect. Organizations are urged to promptly update and secure systems using cURL or libcurl.
13 October 2023
The AvosLocker ransomware gang has been linked to attacks against critical infrastructure sectors in the U.S., with some of them detected as recently as May 2023.
That's according to a new joint cybersecurity advisory released by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) detailing the ransomware-as-a-service (RaaS) operation's
13 October 2023
The Reichsadler Cybercrime Group attempted to deploy ransomware on unpatched WS_FTP servers using a stolen LockBit 3.0 builder. The attackers used the GodPotato tool to escalate privileges on the servers.
13 October 2023
Dozens of Squid caching proxy vulnerabilities remain unpatched two years after a researcher reported them to developers.
The post Dozens of Squid Proxy Vulnerabilities Remain Unpatched 2 Years After Disclosure appeared first on SecurityWeek.
13 October 2023
Microsoft is offering rewards of up to $15,000 in a new bug bounty program dedicated to its new AI-powered Bing.
The post Microsoft Offers Up to $15,000 in New AI Bug Bounty Program appeared first on SecurityWeek.
13 October 2023
Apple has released iOS and iPadOS updates to fix a local privilege escalation kernel vulnerability (CVE-2023-42824) that has been actively exploited in attacks, potentially by commercial spyware vendors.
13 October 2023
The luxury hotel group Edwardian Hotels London has reportedly been targeted by the Black Basta ransomware group. Cybersecurity researchers have shared screenshots of the claims made by the hackers.
13 October 2023
ShellBot is capable of launching DDoS attacks and deploying cryptocurrency miners, highlighting the importance of strong passwords and regular password changes to resist dictionary attacks.
12 October 2023
The Italian Postal Police and CERT-AgID have recently reported numerous phishing campaigns impersonating popular brands such as Poste Italiane, Intesa Sanpaolo, and Zimbra.
12 October 2023
While Air Canada previously stated that the breach only involved limited personal information, the hackers now say they have accessed much more extensive data, amounting to 210GB.
12 October 2023
Bot attacks were analyzed in a recent report by Kasada, finding that bot attacks were becoming increasingly difficult to detect by security teams.
12 October 2023
Progress Software confirms the SEC has launched its own investigation into costly ransomware zero-days in the MOVEit file transfer software.
The post SEC Investigating Progress Software Over MOVEit Hack appeared first on SecurityWeek.
12 October 2023
The venture capital firm, led by former Fortune 500 CISOs and security executives, plans to focus on the seed stage to help early-stage companies develop next-generation cyber solutions and find product-market fit faster.
12 October 2023
The package contains a malicious install script that executes covertly during installation, downloading an obfuscated batch script that ultimately constructs and executes a PowerShell script.
12 October 2023
The three-day operation took place in the Dutch municipality of Apeldoorn, with officers from all 22 EU member states and four “third countries” taking part, alongside representatives from Interpol, the European Labour Authority, and others.
12 October 2023
The breach occurred due to a social engineering attack targeting an employee, resulting in the theft of customer data including names, email addresses, billing addresses, and credit card expiration dates.
12 October 2023
Healthcare communication methods were analyzed in a recent report by Spok Holdings, including budget constraints and security concerns.
12 October 2023
A backdoor deployed on a compromised WordPress website poses as a legitimate plugin to hide its presence.
The post Backdoor Malware Found on WordPress Website Disguised as Legitimate Plugin appeared first on SecurityWeek.
12 October 2023
ReadyToRun (R2R) stomping is a new method that allows for hidden implanted code in .NET binaries, altering the original intermediate language (IL) code and prioritizing pre-compiled native code for execution.