Latest Cybersecurity News and Articles
12 October 2023
The hackers found a way to spam users of the app and claimed their attack left users' phones disconnected from the internet and broken. While the hack caused concern, it is unlikely that it actually damaged users' devices.
12 October 2023
Cybersecurity researchers have shed light on a new sophisticated strain of malware that masquerades a WordPress plugin to stealthily create administrator accounts and remotely control a compromised site.
"Complete with a professional looking opening comment implying it is a caching plugin, this rogue code contains numerous functions, adds filters to prevent itself from being included in the list
12 October 2023
The Athena Agent, part of the Mythic C2 framework, is a cross-platform tool with diverse functionalities, making it highly valuable for threat actors seeking to gain control over compromised systems.
12 October 2023
The federal government is investing in the infrastructure to improve collaboration and data sharing with the private sector in order to strengthen the nation's digital infrastructure against cyber threats.
12 October 2023
According to a Splunk report, nearly half (47%) of global CISOs now report to their CEO, and the vast majority (78%) are backed by a board-level cybersecurity committee, signaling the growing influence of cyber risk management in organizations.
12 October 2023
The building materials producer experienced a cybersecurity incident that has caused disruptions in its operations and is expected to continue, leading to a pause in business operations.
12 October 2023
The discontinuation of Internet Explorer, which came bundled with VBScript, eliminates a prevalent infection vector used by threat actors to distribute malware on Windows systems.
12 October 2023
ZTNA simplifies operational costs by centralizing policy controls and adapting to changing conditions, reducing the need for expensive and challenging-to-maintain traditional network security measures.
12 October 2023
High-profile government and telecom entities in Asia have been targeted as part of an ongoing campaign since 2021 that's designed to deploy basic backdoors and loaders for delivering next-stage malware.
Cybersecurity company Check Point is tracking the activity under the name Stayin' Alive. Targets include organizations located in Vietnam, Uzbekistan, Pakistan, and Kazakhstan.
"The simplistic
12 October 2023
Patches have been released for two security flaws impacting the Curl data transfer library, the most severe of which could potentially result in code execution.
The list of vulnerabilities is as follows -
CVE-2023-38545 (CVSS score: 7.5) - SOCKS5 heap-based buffer overflow vulnerability
CVE-2023-38546 (CVSS score: 5.0) - Cookie injection with none file
CVE-2023-38545 is the more severe of the
11 October 2023
A recent Deep Instinct report found that more victims were affected by ransomware in the first half of 2023 than in the entirety of 2022.
11 October 2023
FortiGuard Labs found that the IZ1H9 Mirai-based DDoS botnet campaign has strengthened its arsenal with 13 exploits for D-Link devices, Netis wireless routers, TOTOLINK routers, Zyxel devices, and others. As the botnet expands its arsenal with new exploit triggers, it underscores the importance of applying security patches on time.
11 October 2023
The "Five Families" of hacktivist gangs, including ThreatSec, GhostSec, Stormous, Blackforums, and SiegedSec, are collaborating to launch large-scale cyberattacks, causing disruptions and chaos.
11 October 2023
The letter from the lawmakers follows a recent fine of 345 million euros (~$366 million) imposed on TikTok by the Irish Data Protection Commissioner for failing to adequately protect children's privacy.
11 October 2023
A recent survey conducted by Enea reveals that 76% of cybersecurity professionals believe that malicious AI, capable of bypassing most cybersecurity measures, is a looming threat.
11 October 2023
Google has released Chrome 118 with fixes for 20 vulnerabilities, including a critical bug in Site Isolation that could allow for sandbox escape and arbitrary code execution.
11 October 2023
Symantec found a previously unidentified threat actor named Grayling conducting advanced persistent attacks targeting organizations in Taiwan, the Pacific Islands, Vietnam, and the U.S., with a focus on intelligence gathering. Grayling's modus operandi seems to revolve around exploiting public infrastructures for initial access. This demands a keen eye on network anomalies and a rigorous patch management flow in place.
11 October 2023
Flaw poses a direct threat to the SOCKS5 proxy handshake process in cURL and can be exploited remotely in some non-standard configurations.
The post Critical SOCKS5 Vulnerability in cURL Puts Enterprise Systems at Risk appeared first on SecurityWeek.
11 October 2023
Spanish airline Air Europa is informing customers that their payment card information has been stolen as a result of a hacker attack.
The post Payment Card Data Stolen in Air Europa Hack appeared first on SecurityWeek.
11 October 2023
Citrix has released patches for a critical information disclosure vulnerability in NetScaler ADC and NetScaler Gateway.
The post Citrix Patches Critical NetScaler ADC, Gateway Vulnerability appeared first on SecurityWeek.