Latest Cybersecurity News and Articles
11 October 2023
The lawsuit alleged that Crunchyroll had disclosed subscribers' personal information to third parties without proper consent. Initially denying the allegations, Crunchyroll ultimately chose to settle to avoid expenses and uncertainties.
11 October 2023
The vulnerability, CVE-2023-22515, allows remote attackers to create unauthorized administrator accounts and gain access to Confluence servers. Organizations using Confluence applications should upgrade to the latest versions and isolate them.
11 October 2023
More than 17,000 WordPress websites have been compromised in the month of September 2023 with malware known as Balada Injector, nearly twice the number of detections in August.
Of these, 9,000 of the websites are said to have been infiltrated using a recently disclosed security flaw in the tagDiv Composer plugin (CVE-2023-3169, CVSS score: 6.1) that could be exploited by unauthenticated users to
11 October 2023
Automation and AI are being used by cybercriminals to enhance the speed and effectiveness of attacks, particularly in areas like money laundering and credential stuffing.
11 October 2023
CISA, FBI, NSA, and US Treasury published new guidance on improving the security of open source software in OT and ICS.
The post US Government Releases Security Guidance for Open Source Software in OT, ICS appeared first on SecurityWeek.
11 October 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a high-severity flaw in Adobe Acrobat Reader to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
Tracked as CVE-2023-21608 (CVSS score: 7.8), the vulnerability has been described as a use-after-free bug that can be exploited to achieve remote code execution (RCE) with the
11 October 2023
A report reveals more than 80% of survey respondents indicated a critical security issue in deployed software impacted DevOps delivery schedule in the last year.
11 October 2023
The victims include Hughes Gill Cochrane Tinetti, Saltire Energy, Centek Industries, NachtExpress Austria, WCM Europe, Starr Finley, and an unknown firm. These attacks are part of a wider scheme by the threat actor, targeting major firms globally.
11 October 2023
Passwords are at the core of securing access to an organization's data. However, they also come with security vulnerabilities that stem from their inconvenience. With a growing list of credentials to keep track of, the average end-user can default to shortcuts. Instead of creating a strong and unique password for each account, they resort to easy-to-remember passwords, or use the same password
11 October 2023
Collaboration and information-sharing among North Korean APTs have increased during the COVID-19 pandemic, leading to a more organized and coordinated state-sponsored structure, researchers from Mandiant revealed in a report.
11 October 2023
Google has released Chrome 118 to the stable channel with patches for 20 vulnerabilities, including one rated ‘critical severity’.
The post Chrome 118 Patches 20 Vulnerabilities appeared first on SecurityWeek.
11 October 2023
Threat actors have been exploiting a zero-day vulnerability in the HTTP/2 protocol since August to launch the largest DDoS attacks ever seen, according to several tech infrastructure giants.
11 October 2023
Organizations respond to HTTP/2 Rapid Reset zero-day vulnerability exploited to launch the largest DDoS attacks seen to date.
The post Organizations Respond to HTTP/2 Zero-Day Exploited for DDoS Attacks appeared first on SecurityWeek.
11 October 2023
McLaren Health Care is facing three proposed federal class action lawsuits after a Russian ransomware-as-a-service group stole the personal information of 2.5 million patients, alleging negligence in protecting patient privacy.
11 October 2023
While there is quite a bit of buzz and hype around AI, it is a technology that can add tremendous value to security programs.
The post Applying AI to API Security appeared first on SecurityWeek.
11 October 2023
A new card skimming campaign discovered by Akamai utilizes 404 error pages on online retailers' websites to hide malicious code and steal customers' credit card information. The stolen data is exfiltrated via seemingly benign image requests, thus evading network monitoring tools. One effective mitigation is to regularly monitor and audit website resources, ensuring that no unauthorized modifications have been made.
11 October 2023
The two actively exploited flaws include information disclosure in Microsoft WordPad and privilege escalation in Skype for Business. Microsoft has also fixed flaws in Microsoft Message Queuing, Layer 2 Tunneling Protocol, and Windows IIS Server.
11 October 2023
The Joint Cyber Defense Collaborative published a series of recommendations on Tuesday for operational technology vendors and critical infrastructure facilities to promote the secure use of open-source software.
11 October 2023
CISA has added five bugs to its Known Exploited Vulnerabilities catalog, including the recent WordPad, Skype, and HTTP/2 zero-days.
The post CISA Warns of Attacks Exploiting Adobe Acrobat Vulnerability appeared first on SecurityWeek.
11 October 2023
Organizations are advised to check all their software for the presence of the CVE-2023-4863 vulnerability in the libwebp image rendering library and apply patches accordingly.