Category: SecurityWeek RSS Feed

Zero-Day Breach at Rackspace Sparks Vendor Blame Game

A breach at Rackspace exposes the fragility of the software supply chain, triggering a blame game among vendors over an exploited zero-day. The post Zero-Day Breach at Rackspace Sparks Vendor Blame Game appeared first on SecurityWeek. This article has been…

MITRE Adds Mitigations to EMB3D Threat Model

MITRE has expanded the EMB3D Threat Model with essential mitigations to help organizations address threats to embedded devices. The post MITRE Adds Mitigations to EMB3D Threat Model appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed…

Cryptocurrency Wallets Targeted via Python Packages Uploaded to PyPI

Multiple Python packages referencing dependencies containing cryptocurrency-stealing code were published to PyPI. The post Cryptocurrency Wallets Targeted via Python Packages Uploaded to PyPI appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the original article:…

Apono Raises $15.5 Million for Cloud Access Platform

Cloud access provider Apono has raised $15.5 million in a Series A funding round led by New Era Capital Partners. The post Apono Raises $15.5 Million for Cloud Access Platform appeared first on SecurityWeek. This article has been indexed from…

UMC Health System Diverts Patients Following Ransomware Attack

UMC Health System has been forced to divert patients after a ransomware attack resulted in a network outage. The post UMC Health System Diverts Patients Following Ransomware Attack appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS…

Patelco Credit Union Data Breach Impacts Over 1 Million People

Patelco Credit Union has informed authorities that data on more than 1 million individuals was stolen in a ransomware attack this summer. The post Patelco Credit Union Data Breach Impacts Over 1 Million People appeared first on SecurityWeek. This article…

Accounting Firm WMDDH Discloses Data Breach Impacting 127,000

The personal information of over 127,000 individuals was stolen in a July 2023 data breach at Wright, Moore, DeHart, Dupuis & Hutchinson (WMDDH). The post Accounting Firm WMDDH Discloses Data Breach Impacting 127,000 appeared first on SecurityWeek. This article has…

British National Arrested, Charged for Hacking US Companies

UK national Robert Westbrook was charged in the US for executing a hack-to-trade scheme against five public companies. The post British National Arrested, Charged for Hacking US Companies appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS…

Torq Secures $70M Series C for HyperSOC

The New York late-stage startup banks $70 million in a new funding round led by Evolution Equity Partners. The post Torq Secures $70M Series C for HyperSOC appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed…

Millions of Kia Cars Were Vulnerable to Remote Hacking: Researchers

Security researchers detail vulnerabilities in Kia owners’ portal that allowed them to control vehicles remotely. The post Millions of Kia Cars Were Vulnerable to Remote Hacking: Researchers appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed…

Remote Code Execution, DoS Vulnerabilities Patched in OpenPLC

Critical and high-severity vulnerabilities that can be exploited for DoS attacks and remote code execution have been patched in OpenPLC. The post Remote Code Execution, DoS Vulnerabilities Patched in OpenPLC appeared first on SecurityWeek. This article has been indexed from…

Cisco Patches High-Severity Vulnerabilities in IOS Software

Cisco has released patches for seven high-severity vulnerabilities affecting products running IOS and IOS XE software. The post Cisco Patches High-Severity Vulnerabilities in IOS Software appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the…

Cyber Founder Recipe for Success: Clear Vision and Trusted Experts

A clear, consistent vision, along with reliable experts, are the two essential ingredients for startup founders to achieve success—both in cyber and beyond. The post Cyber Founder Recipe for Success: Clear Vision and Trusted Experts appeared first on SecurityWeek. This…

Tamnoon Raises $12 Million for Cloud Security Remediation Service

Tamnoon has raised $12 million in Series A funding for its Managed Cloud Security Remediation service. The post Tamnoon Raises $12 Million for Cloud Security Remediation Service appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed…

AI-Generated Malware Found in the Wild

HP has intercepted an email campaign comprising a standard malware payload delivered by an AI-generated dropper. The post AI-Generated Malware Found in the Wild appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the original…

Cyberattack Causes MoneyGram Service Outage

MoneyGram’s money transfer services are down after the company took systems offline to contain a cyberattack. The post Cyberattack Causes MoneyGram Service Outage appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the original article:…

Versa Networks Patches Vulnerability Exposing Authentication Tokens

Versa Networks has released patches for a Versa Director vulnerability for which proof-of-concept (PoC) code exists. The post Versa Networks Patches Vulnerability Exposing Authentication Tokens appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the…

Google Now Syncing Passkeys Across Desktop, Android Devices

Users can now save passkeys to Google Password Manager on computers running Windows, macOS, and Linux, in addition to Android devices. The post Google Now Syncing Passkeys Across Desktop, Android Devices appeared first on SecurityWeek. This article has been indexed…

Kubernetes Container Isolation Startup Edera Raises $5 Million

Edera has raised $5 million in seed funding to help organizations secure Kubernetes containers and AI workloads. The post Kubernetes Container Isolation Startup Edera Raises $5 Million appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed…

Tor Responds to Reports of German Police Deanonymizing Users

The Tor Project has responded to claims that German law enforcement has found a way to deanonymize users. The post Tor Responds to Reports of German Police Deanonymizing Users appeared first on SecurityWeek. This article has been indexed from SecurityWeek…

Ivanti Warns of Second CSA Vulnerability Exploited in Attacks

In addition to the Ivanti CSA flaw CVE-2024-8190, another vulnerability affecting the same product, tracked as CVE-2024-8963, has been exploited. The post Ivanti Warns of Second CSA Vulnerability Exploited in Attacks appeared first on SecurityWeek. This article has been indexed…

Security Validation Firm Picus Security Raises $45 Million

Attack simulation firm has raised $45 million in growth funding, bringing the total amount raised to $80 million. The post Security Validation Firm Picus Security Raises $45 Million appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read…

SecurityWeek to Host 2024 Attack Surface Management Summit Today

SecurityWeek will host its 2024 Attack Surface Management Summit as a fully immersive virtual event on Wednesday, September 18th. The post SecurityWeek to Host 2024 Attack Surface Management Summit Today appeared first on SecurityWeek. This article has been indexed from…

Russian Security Firm Doctor Web Hacked

Antimalware company Doctor Web was recently targeted in a cyberattack that prompted it to disconnect all resources from its networks. The post Russian Security Firm Doctor Web Hacked appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS…

Intezer Raises $33M to Extend AI-Powered SOC Platform

Intezer is looking to tap into booming market for AI-powered tooling to address the severe shortage of skilled cybersecurity professionals.  The post Intezer Raises $33M to Extend AI-Powered SOC Platform appeared first on SecurityWeek. This article has been indexed from…

C/side Raises $6 Million to Secure the Browser Supply Chain

C/side has raised $6 million in a seed-stage funding round to help organizations protect against malicious browser third-party scripts. The post C/side Raises $6 Million to Secure the Browser Supply Chain appeared first on SecurityWeek. This article has been indexed…

Apple Patches Major Security Flaws With iOS 18 Refresh

Apple warns that attackers can use Siri to access sensitive user data, control nearby devices, or view recent photos without authentication.  The post Apple Patches Major Security Flaws With iOS 18 Refresh appeared first on SecurityWeek. This article has been…

Apple Patches Major Security Flaws with iOS 18 Refresh

Apple warns that attackers can use Siri to access sensitive user data, control nearby devices, or view recent photos without authentication.  The post Apple Patches Major Security Flaws with iOS 18 Refresh appeared first on SecurityWeek. This article has been…

EasyDMARC Lands $20M for Email Security Authentication Tech

EasyDMARC lands venture capital funding after finding traction in the email security and authentication business. The post EasyDMARC Lands $20M for Email Security Authentication Tech appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the…

FBI, CISA Warn of Fake Voter Data Hacking Claims

Hackers keep making claims about voter information compromise, but the US government says they’re just trying to sow distrust in the elections. The post FBI, CISA Warn of Fake Voter Data Hacking Claims appeared first on SecurityWeek. This article has…

Microsoft Says Recent Windows Vulnerability Exploited as Zero-Day

Microsoft warns that a recently patched Windows vulnerability was exploited in the wild as a zero-day prior to July 2024. The post Microsoft Says Recent Windows Vulnerability Exploited as Zero-Day appeared first on SecurityWeek. This article has been indexed from…

Ivanti CSA Vulnerability Exploited in Attacks Days After DIsclosure

The Ivanti Cloud Service Appliance vulnerability CVE-2024-8190 has been exploited in the wild, with attacks starting just days after disclosure. The post Ivanti CSA Vulnerability Exploited in Attacks Days After DIsclosure appeared first on SecurityWeek. This article has been indexed…

SolarWinds Patches Critical Vulnerability in Access Rights Manager

SolarWinds has announced patches for a critical-severity remote code execution vulnerability in Access Rights Manager. The post SolarWinds Patches Critical Vulnerability in Access Rights Manager appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the…

Apple Suddenly Drops NSO Group Spyware Lawsuit

Apple said there’s “too significant a risk” of exposing the anti-exploit work needed to fend off the very adversaries involved in the case. The post Apple Suddenly Drops NSO Group Spyware Lawsuit appeared first on SecurityWeek. This article has been…

New ‘Hadooken’ Linux Malware Targets WebLogic Servers

The recently observed Hadooken malware targeting Oracle WebLogic applications is linked to multiple ransomware families. The post New ‘Hadooken’ Linux Malware Targets WebLogic Servers appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the original…

1.3 Million Android TV Boxes Infected by Vo1d Malware

Doctor Web warns of the new Vo1d Android malware infecting roughly 1.3 million TV boxes running older OS versions. The post 1.3 Million Android TV Boxes Infected by Vo1d Malware appeared first on SecurityWeek. This article has been indexed from…

GitLab Updates Resolve Critical Pipeline Execution Vulnerability

GitLab has released security updates to resolve multiple vulnerabilities in GitLab CE/EE, including a critical-severity pipeline execution flaw. The post GitLab Updates Resolve Critical Pipeline Execution Vulnerability appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed…

Evasion Tactics Used By Cybercriminals To Fly Under The Radar

Relentless in their methods, attackers will continue employing evasion tactics to circumvent traditional security measures. The post Evasion Tactics Used By Cybercriminals To Fly Under The Radar appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed…

Cisco Patches High-Severity Vulnerabilities in Network Operating System

Cisco has announced security updates that patch eight vulnerabilities in IOS XR software, including six high-severity bugs. The post Cisco Patches High-Severity Vulnerabilities in Network Operating System appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed…

Iranian Hackers Targeting Iraqi Government: Security Firm

Hackers believed to be operating on behalf of the Iranian government have deployed malware to Iraqi government networks.  The post Iranian Hackers Targeting Iraqi Government: Security Firm appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed…

Google Introduces ‘Air-Gapped’ Backup Vault to Thwart Ransomware

“It’s critical to not only back up your critical workloads, but also to secure those backups against subsequent modification and deletion.” The post Google Introduces ‘Air-Gapped’ Backup Vault to Thwart Ransomware appeared first on SecurityWeek. This article has been indexed…

SplxAI Raises $2 Million to Protect AI Chatbot Apps

SplxAI has raised $2 million in pre-seed funding to help organizations identify vulnerabilities in AI chat applications. The post SplxAI Raises $2 Million to Protect AI Chatbot Apps appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS…

Intel Informs Customers About Over a Dozen Processor Vulnerabilities

Intel on Tuesday published advisories covering more than 20 vulnerabilities affecting processors and other products. The post Intel Informs Customers About Over a Dozen Processor Vulnerabilities appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read…

PIXHELL Attack Allows Air-Gap Jumping via Noise From Screens

Noise generated by the pixels on a screen can be leveraged to exfiltrate data from air-gapped computers in what is called a PIXHELL attack. The post PIXHELL Attack Allows Air-Gap Jumping via Noise From Screens appeared first on SecurityWeek. This…

Microsoft Adds Support for Post-Quantum Algorithms in SymCrypt Library

Microsoft has started introducing support for post-quantum algorithms in SymCrypt, its main cryptographic library. The post Microsoft Adds Support for Post-Quantum Algorithms in SymCrypt Library appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the…

Data Breach at Golf Course Management Firm KemperSports Impacts 62,000

Golf course management company KemperSports has disclosed a cyberattack and data breach impacting over 62,000 individuals.  The post Data Breach at Golf Course Management Firm KemperSports Impacts 62,000 appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS…