Latest Cybersecurity News and Articles
03 October 2023
Chalk offers convenience for compliance by producing SBOMs, embedding code provenance details and digitally signing reports, addressing regulatory requirements, and saving costs on unnecessary tools licenses.
03 October 2023
The issue, credited to Maddie Stone of Google's Threat Analysis Group (TAG) and Jann Horn of Google Project Zero, has been addressed in Bifrost, Valhall and Arm 5th Gen GPU Architecture Kernel Driver r43p0.
03 October 2023
Firewall and distributed denial-of-service (DDoS) attack prevention mechanisms in Cloudflare can be circumvented by exploiting gaps in cross-tenant security controls, defeating the very purpose of these safeguards, it has emerged.
"Attackers can utilize their own Cloudflare accounts to abuse the per-design trust-relationship between Cloudflare and the customers' websites, rendering the
03 October 2023
The acquisition of Trustwave by The Chertoff Group's affiliate MC2 Security Fund signifies the private equity firm's continued investment in cybersecurity and its recognition of the potential value in Trustwave's offerings.
03 October 2023
The LockBit ransomware gang claimed responsibility for the attack and demanded an undisclosed ransom, but the impact on student and staff information was minimal, and the school district has remained fully operational.
03 October 2023
One of the vulnerabilities allows remote unauthenticated attackers to execute code in the context of the service account. The other two vulnerabilities patched include a remote code execution bug and an information disclosure issue.
03 October 2023
A survey by Moody's reveals that cybersecurity spending has increased by 70% from 2019 to 2023, with organizations allocating a larger share of their technology budgets to cybersecurity.
03 October 2023
The cyberattack has had ripple effects on Clorox's operations, potentially impacting quarterly earnings and allowing rival firms to gain a foothold with consumers. The company is now focusing on ramping up production to replenish inventories.
03 October 2023
Some packages exfiltrate data via webhooks or file-sharing links, while others scan for sensitive files and directories. Users are advised to be cautious and watch for suspicious install scripts.
03 October 2023
Arm has released security patches to contain a security flaw in the Mali GPU Kernel Driver that has come under active exploitation in the wild.
Tracked as CVE-2023-4211, the shortcoming impacts the following driver versions -
Midgard GPU Kernel Driver: All versions from r12p0 - r32p0
Bifrost GPU Kernel Driver: All versions from r0p0 - r42p0
Valhall GPU Kernel Driver: All versions from r19p0 -
02 October 2023
Five tax preparation companies have been warned by the FTC in regards to what information can and can't be shared for outside purposes.
02 October 2023
According to a Juniper Research report, the rate of digital identity verification checks is on the rise in response to increased identity theft.
02 October 2023
Cloudflare has been found to have vulnerabilities in its Firewall and DDoS prevention system. Hackers can exploit these flaws by creating a free Cloudflare account and knowing the IP address of a targeted web server.
02 October 2023
The Android banking Trojan Zanubis has taken on a new guise, posing as the official app for the Peruvian governmental organization SUNAT (Superintendencia Nacional de Aduanas y de Administración Tributaria).
02 October 2023
Threat actors are selling a new crypter and loader called ASMCrypt, which is an evolved version of the DoubleFinger loader. It allows them to build payloads for their campaigns by establishing contact with a backend service over the TOR network.
02 October 2023
ETSI has taken immediate action, involving France's cybersecurity agency, ANSSI, to investigate and fix the vulnerability that led to the attack and has strengthened its IT security procedures.
02 October 2023
According to the recent KnowBe4 report, healthcare is the top infrastructure topic for ransomware attacks with an increase in cyberattack frequency.
02 October 2023
The FBI warned about a new scam called the "Phantom Hacker" scam, which is specifically targeting senior citizens. It involves imposters posing as tech support, financial institutions, and government representatives to gain the trust of victims.
02 October 2023
Many organizations — including quite a few Fortune 500 firms — have exposed web links that allow anyone to initiate a Zoom video conference meeting as a valid employee. These company-specific Zoom links, which include a permanent user ID number and an embedded passcode, can work indefinitely and expose an organization’s employees, customers or partners to phishing and other social engineering attacks.
02 October 2023
The publicly accessible AWS S3 buckets contained personal data, invoices, and internal documents, potentially disrupting trade and operations of India's ports and leading to significant ransom demands.