Latest Cybersecurity News and Articles
11 October 2023
Google has released Chrome 118 with fixes for 20 vulnerabilities, including a critical bug in Site Isolation that could allow for sandbox escape and arbitrary code execution.
11 October 2023
Symantec found a previously unidentified threat actor named Grayling conducting advanced persistent attacks targeting organizations in Taiwan, the Pacific Islands, Vietnam, and the U.S., with a focus on intelligence gathering. Grayling's modus operandi seems to revolve around exploiting public infrastructures for initial access. This demands a keen eye on network anomalies and a rigorous patch management flow in place.
11 October 2023
Flaw poses a direct threat to the SOCKS5 proxy handshake process in cURL and can be exploited remotely in some non-standard configurations.
The post Critical SOCKS5 Vulnerability in cURL Puts Enterprise Systems at Risk appeared first on SecurityWeek.
11 October 2023
Spanish airline Air Europa is informing customers that their payment card information has been stolen as a result of a hacker attack.
The post Payment Card Data Stolen in Air Europa Hack appeared first on SecurityWeek.
11 October 2023
Citrix has released patches for a critical information disclosure vulnerability in NetScaler ADC and NetScaler Gateway.
The post Citrix Patches Critical NetScaler ADC, Gateway Vulnerability appeared first on SecurityWeek.
11 October 2023
The lawsuit alleged that Crunchyroll had disclosed subscribers' personal information to third parties without proper consent. Initially denying the allegations, Crunchyroll ultimately chose to settle to avoid expenses and uncertainties.
11 October 2023
The vulnerability, CVE-2023-22515, allows remote attackers to create unauthorized administrator accounts and gain access to Confluence servers. Organizations using Confluence applications should upgrade to the latest versions and isolate them.
11 October 2023
More than 17,000 WordPress websites have been compromised in the month of September 2023 with malware known as Balada Injector, nearly twice the number of detections in August.
Of these, 9,000 of the websites are said to have been infiltrated using a recently disclosed security flaw in the tagDiv Composer plugin (CVE-2023-3169, CVSS score: 6.1) that could be exploited by unauthenticated users to
11 October 2023
Automation and AI are being used by cybercriminals to enhance the speed and effectiveness of attacks, particularly in areas like money laundering and credential stuffing.
11 October 2023
CISA, FBI, NSA, and US Treasury published new guidance on improving the security of open source software in OT and ICS.
The post US Government Releases Security Guidance for Open Source Software in OT, ICS appeared first on SecurityWeek.
11 October 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a high-severity flaw in Adobe Acrobat Reader to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
Tracked as CVE-2023-21608 (CVSS score: 7.8), the vulnerability has been described as a use-after-free bug that can be exploited to achieve remote code execution (RCE) with the
11 October 2023
A report reveals more than 80% of survey respondents indicated a critical security issue in deployed software impacted DevOps delivery schedule in the last year.
11 October 2023
The victims include Hughes Gill Cochrane Tinetti, Saltire Energy, Centek Industries, NachtExpress Austria, WCM Europe, Starr Finley, and an unknown firm. These attacks are part of a wider scheme by the threat actor, targeting major firms globally.
11 October 2023
Passwords are at the core of securing access to an organization's data. However, they also come with security vulnerabilities that stem from their inconvenience. With a growing list of credentials to keep track of, the average end-user can default to shortcuts. Instead of creating a strong and unique password for each account, they resort to easy-to-remember passwords, or use the same password
11 October 2023
Collaboration and information-sharing among North Korean APTs have increased during the COVID-19 pandemic, leading to a more organized and coordinated state-sponsored structure, researchers from Mandiant revealed in a report.
11 October 2023
Google has released Chrome 118 to the stable channel with patches for 20 vulnerabilities, including one rated ‘critical severity’.
The post Chrome 118 Patches 20 Vulnerabilities appeared first on SecurityWeek.
11 October 2023
Threat actors have been exploiting a zero-day vulnerability in the HTTP/2 protocol since August to launch the largest DDoS attacks ever seen, according to several tech infrastructure giants.
11 October 2023
Organizations respond to HTTP/2 Rapid Reset zero-day vulnerability exploited to launch the largest DDoS attacks seen to date.
The post Organizations Respond to HTTP/2 Zero-Day Exploited for DDoS Attacks appeared first on SecurityWeek.
11 October 2023
McLaren Health Care is facing three proposed federal class action lawsuits after a Russian ransomware-as-a-service group stole the personal information of 2.5 million patients, alleging negligence in protecting patient privacy.
11 October 2023
While there is quite a bit of buzz and hype around AI, it is a technology that can add tremendous value to security programs.
The post Applying AI to API Security appeared first on SecurityWeek.