Category: SecurityWeek RSS Feed

CISA, NSA Share Guidance on Securing CI/CD Environments

New guidance from CISA and the NSA provides recommendations on securing CI/CD pipelines against malicious attacks. The post CISA, NSA Share Guidance on Securing CI/CD Environments appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read…

White House Outlines Cybersecurity Budget Priorities for Fiscal 2025

The White House has released a memorandum outlining the cybersecurity investment priorities for government departments and agencies for fiscal year 2025. The post White House Outlines Cybersecurity Budget Priorities for Fiscal 2025 appeared first on SecurityWeek. This article has been…

Venn Software Snags $29M to Build MDM for Laptops Technology

New York startup scores early stage financing to build new technology to replace virtual desktop infrastructure. The post Venn Software Snags $29M to Build MDM for Laptops Technology appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS…

Venn Software Snags $29M to build MDM for Laptops Technology

New York startup scores early stage financing to build new technology to replace virtual desktop infrastructure. The post Venn Software Snags $29M to build MDM for Laptops Technology appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS…

What is Cyberwar?

Ask any three people to define cyberwar and you will get three different answers. But as global geopolitics worsen and aggressive cyberattacks increase, this becomes more than an academic question. The post What is Cyberwar? appeared first on SecurityWeek. This…

Submarine Cables at Risk of Nation-State Sabotage, Spying: Report

Recorded Future underlines threats to submarine telecommunication cables, such as the risk of intentional sabotage and spying by nation-state threat actors. The post Submarine Cables at Risk of Nation-State Sabotage, Spying: Report appeared first on SecurityWeek. This article has been…

Sensitive Information Stolen in LetMeSpy Stalkerware Hack

Emails, phone numbers, calls logs, and collected messages stolen in data breach at Android stalkware LetMeSpy. The post Sensitive Information Stolen in LetMeSpy Stalkerware Hack appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the…

Reminder: CFP for ICS Cybersecurity Conference Closes June 30th

The official Call for Presentations for SecurityWeek’s 2023 ICS Cybersecurity Conference, being held October 23-26, 2023 at the InterContinental Atlanta is open through Friday, June 30, 2023. The post Reminder: CFP for ICS Cybersecurity Conference Closes June 30th appeared first…

HashiCorp Buys BluBracket for Secrets Scanning Tech

HashiCorp acquires BluBracket secrets-scanning technology to help businesses block accidental leaks and fight secret sprawl. The post HashiCorp Buys BluBracket for Secrets Scanning Tech appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the original…

Data Security Firm Cyera Attracts $100M Investment

Cyera closes a massive $100 million round as investors continue to pour cash into the data security posture management (DSPM) space. The post Data Security Firm Cyera Attracts $100M Investment appeared first on SecurityWeek. This article has been indexed from…

Patented.ai Raises $4 Million for AI Data Privacy Solution

Patented.ai has raised $4 million in pre-seed funding to help organizations protect sensitive information from artificial intelligence. The post Patented.ai Raises $4 Million for AI Data Privacy Solution appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS…

Socure Acquires ID Verification Company Berbix for $70 Million

Identity verification solutions provider Socure has acquired automated ID verification firm Berbix for roughly $70 million in cash and stock. The post Socure Acquires ID Verification Company Berbix for $70 Million appeared first on SecurityWeek. This article has been indexed…

Chrome 114 Update Patches High-Severity Vulnerabilities

Google says it handed out $35,000 in bug bounty rewards for three high-severity vulnerabilities in Chrome 114. The post Chrome 114 Update Patches High-Severity Vulnerabilities appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the…

CalypsoAI Raises $23 Million for AI Security Tech

CalypsoAI is building tools to help “accelerate trust and governance” in enterprise adoption of AI and machine learning technologies. The post CalypsoAI Raises $23 Million for AI Security Tech appeared first on SecurityWeek. This article has been indexed from SecurityWeek…

Gas Stations Impacted by Cyberattack on Canadian Energy Giant Suncor

Some services at Petro-Canada gas stations have been disrupted following a cyberattack on parent company Suncor, one of North America’s largest energy companies. The post Gas Stations Impacted by Cyberattack on Canadian Energy Giant Suncor appeared first on SecurityWeek. This…

Fortinet Patches Critical RCE Vulnerability in FortiNAC

Fortinet releases patches for a critical FortiNAC vulnerability leading to remote code execution without authentication. The post Fortinet Patches Critical RCE Vulnerability in FortiNAC appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the original…

British Twitter Hacker Sentenced to Prison in US

UK national Joseph James O’Connor was sentenced to five years in a US prison for hacking into Twitter accounts and stealing cryptocurrency. The post British Twitter Hacker Sentenced to Prison in US appeared first on SecurityWeek. This article has been…

Remotely Exploitable DoS Vulnerabilities Patched in BIND

The latest BIND updates address three high-severity, remotely exploitable vulnerabilities leading to denial-of-service (DoS). The post Remotely Exploitable DoS Vulnerabilities Patched in BIND appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the original article:…

CISA Says Critical Zyxel NAS Vulnerability Exploited in Attacks

CISA has warned users of Zyxel NAS products that the recently patched critical vulnerability CVE-2023-27992 has been exploited in attacks. The post CISA Says Critical Zyxel NAS Vulnerability Exploited in Attacks appeared first on SecurityWeek. This article has been indexed…

NSA Issues Guidance on Mitigating BlackLotus Bootkit Infections

The National Security Agency (NSA) has released mitigation guidance to help organizations stave off BlackLotus UEFI bootkit infections. The post NSA Issues Guidance on Mitigating BlackLotus Bootkit Infections appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS…

CISA Tells US Agencies to Patch Exploited Roundcube, VMware Flaws

The US government’s cybersecurity agency adds VMware and Roundcube server flaws to its Known Exploited Vulnerabilities (KEV) catalog. The post CISA Tells US Agencies to Patch Exploited Roundcube, VMware Flaws appeared first on SecurityWeek. This article has been indexed from…

VMware Patches Code Execution Vulnerabilities in vCenter Server

VMware published software updates to address multiple memory corruption vulnerabilities in vCenter Server that could lead to remote code execution. The post VMware Patches Code Execution Vulnerabilities in vCenter Server appeared first on SecurityWeek. This article has been indexed from…

US Military Personnel Receiving Unsolicited, Suspicious Smartwatches

The US army says soldiers says unsolicited, suspicious smartwatches are being sent to soldiers, exposing them to malware attacks. The post US Military Personnel Receiving Unsolicited, Suspicious Smartwatches appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS…

The Benefits of Red Zone Threat Intelligence

Incorporating Red Zone threat intelligence into your security strategy will help you stay on top of the latest threats and better protect your organization. The post The Benefits of Red Zone Threat Intelligence appeared first on SecurityWeek. This article has…

PoC Exploit Published for Cisco AnyConnect Secure Vulnerability

A security researcher has published proof-of-concept (PoC) exploit code targeting a recent high-severity vulnerability (CVE-2023-20178) in Cisco AnyConnect Secure. The post PoC Exploit Published for Cisco AnyConnect Secure Vulnerability appeared first on SecurityWeek. This article has been indexed from SecurityWeek…

CISOs’ New Stressors Brought on by Digitalization: Report

Digitalization brings new security challenges, new concerns, and new threats, and CISOs should not think that it’s just business as usual. The post CISOs’ New Stressors Brought on by Digitalization: Report appeared first on SecurityWeek. This article has been indexed…

Enphase Ignores CISA Request to Fix Remotely Exploitable Flaws

Enphase Energy has ignored CISA requests to fix remotely exploitable vulnerabilities in Enphase products. The post Enphase Ignores CISA Request to Fix Remotely Exploitable Flaws appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the…

Kaspersky Dissects Spyware Used in iOS Zero-Click Attacks

Russian anti-malware vendor shares technical details on spyware implant deployed as part of recent zero-click iMessage attacks. The post Kaspersky Dissects Spyware Used in iOS Zero-Click Attacks appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed…

Critical WordPress Plugin Vulnerabilities Impact Thousands of Sites

Two critical-severity authentication bypass vulnerabilities in WordPress plugins with tens of thousands of installations. The post Critical WordPress Plugin Vulnerabilities Impact Thousands of Sites appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the original…

DOJ Launches Cyber Unit to Prosecute Nation-State Threat Actors

New National Security Cyber Section will help the US disrupt and prosecute nation-state threat actors and state-sponsored cybercriminals. The post DOJ Launches Cyber Unit to Prosecute Nation-State Threat Actors appeared first on SecurityWeek. This article has been indexed from SecurityWeek…

CISO Conversations: Three Leading CISOs From the Payment Industry

SecurityWeek talks to Chief Information Security Officers from Bill.com, FreedomPay, and Tassat about their role and experience as CISOs. The post CISO Conversations: Three Leading CISOs From the Payment Industry appeared first on SecurityWeek. This article has been indexed from…

VMware Confirms Live Exploits Hitting Just-Patched Security Flaw

VMware updates a critical-level bulletin: “VMware has confirmed that exploitation of CVE-2023-20887 has occurred in the wild.” The post VMware Confirms Live Exploits Hitting Just-Patched Security Flaw appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed…

Russian APT Group Caught Hacking Roundcube Email Servers

A Russian hacking group has been caught hacking into Roundcube servers to spy on government institutions and military entities in Ukraine. The post Russian APT Group Caught Hacking Roundcube Email Servers appeared first on SecurityWeek. This article has been indexed…

New ‘RDStealer’ Malware Targets RDP Connections

Bitdefender finds new malware capable of monitoring incoming RDP connections and infect the connecting clients that have client drive mapping enabled. The post New ‘RDStealer’ Malware Targets RDP Connections appeared first on SecurityWeek. This article has been indexed from SecurityWeek…

OT:Icefall: Vulnerabilities Identified in Wago Controllers

Forescout Technologies has disclosed the details of vulnerabilities impacting operational technology (OT) products from Wago and Schneider Electric. The post OT:Icefall: Vulnerabilities Identified in Wago Controllers appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read…

Asus Patches Highly Critical WiFi Router Flaws

Asus patches nine WiFi router security defects, including a highly critical 2018 vulnerability that exposes users to code execution attacks. The post Asus Patches Highly Critical WiFi Router Flaws appeared first on SecurityWeek. This article has been indexed from SecurityWeek…

New Information Stealer ‘Mystic Stealer’ Rising to Fame

A new information stealer malware named Mystic Stealer is gaining traction among cybercriminals on prominent underground forums. The post New Information Stealer ‘Mystic Stealer’ Rising to Fame appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed…

Ransomware Gang Takes Credit for February Reddit Hack

The Alphv/BlackCat ransomware gang has taken responsibility for the February cyberattack that hit social media site Reddit. The post Ransomware Gang Takes Credit for February Reddit Hack appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed…

Akeyless Launches SaaS-based External Secrets Manager

New SaaS-based secrets manager from Akeyless requires no new infrastructure, and no specialist staff nor secrets management team. The post Akeyless Launches SaaS-based External Secrets Manager appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read…

Western Digital Blocks Unpatched Devices From Cloud Services

Western Digital is blocking access to its cloud services for devices running firmware versions impacted by a critical security vulnerability. The post Western Digital Blocks Unpatched Devices From Cloud Services appeared first on SecurityWeek. This article has been indexed from…

Watch on Demand: 2023 CISO Forum Sessions

All panel discussions and technical presentations from SecurityWeek’s 2023 CISO Forum are available to watch free on demand. The post Watch on Demand: 2023 CISO Forum Sessions appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed…

MOVEit Customers Urged to Patch Third Critical Vulnerability

A critical vulnerability (CVE-2023-35708) in MOVEit software could allow unauthenticated attackers to access database content. The post MOVEit Customers Urged to Patch Third Critical Vulnerability appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the…

CISA, NSA Share Guidance on Hardening Baseboard Management Controllers

CISA and the NSA have published new guidance to help organizations harden baseboard management controllers (BMCs). The post CISA, NSA Share Guidance on Hardening Baseboard Management Controllers appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed…

Content Moderation Tech Startup Trust Lab Snags $15M Investment

Investors pour $15 million into Silicon Valley startup building AI-powered technology to detect and monitor harmful content on the internet. The post Content Moderation Tech Startup Trust Lab Snags $15M Investment appeared first on SecurityWeek. This article has been indexed…

SquareX Launches Bug Bounty Program for Browser Security Product

Cybersecurity startup SquareX launches a temporary bug bounty program for its cloud-based browser security solution. The post SquareX Launches Bug Bounty Program for Browser Security Product appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read…

Barracuda Zero-Day Attacks Attributed to Chinese Cyberespionage Group

Attacks exploiting the Barracuda zero-day CVE-2023-2868 have been linked to a Chinese cyberespionage group that has targeted government and other organizations. The post Barracuda Zero-Day Attacks Attributed to Chinese Cyberespionage Group appeared first on SecurityWeek. This article has been indexed…

OT Security Firm Shift5 Adds $33 Million in Funding

Shift5 has now raised $108 million in funding to bring cybersecurity to OT within fleet vehicles: planes and boats and trains – and military vehicles and weapon systems. The post OT Security Firm Shift5 Adds $33 Million in Funding appeared…

How Europe is Leading the World in the Push to Regulate AI

Authorities worldwide are racing to rein in artificial intelligence, including in the European Union, where groundbreaking legislation is set to pass a key hurdle. The post How Europe is Leading the World in the Push to Regulate AI appeared first…

Microsoft Outs New Russian APT Linked to Wiper Attacks in Ukraine

Microsoft is publicly exposing a Russian hacking group that worked on destructive wiper malware attacks that hit organizations in Ukraine. The post Microsoft Outs New Russian APT Linked to Wiper Attacks in Ukraine appeared first on SecurityWeek. This article has…

CISA Instructs Federal Agencies to Secure Internet-Exposed Devices

CISA’s Binding Operational Directive 23-02 requires federal agencies to secure the network management interfaces of certain classes of devices. The post CISA Instructs Federal Agencies to Secure Internet-Exposed Devices appeared first on SecurityWeek. This article has been indexed from SecurityWeek…

Chrome 114 Update Patches Critical Vulnerability

Google has released a Chrome 114 security update to address five vulnerabilities, including a critical-severity bug in Autofill payments. The post Chrome 114 Update Patches Critical Vulnerability appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed…

Spotify Fined $5 Million for Breaching EU Data Rules

Music streaming giant Spotify was fined 58 million kronor ($5.4 million) for not properly informing users on how data it collected on them was being used, Swedish authorities said. The post Spotify Fined $5 Million for Breaching EU Data Rules…

Chinese Cyberspies Caught Exploiting VMware ESXi Zero-Day

Mandiant has observed a Chinese cyberespionage group exploiting a VMware ESXi zero-day vulnerability for privilege escalation. The post Chinese Cyberspies Caught Exploiting VMware ESXi Zero-Day appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the…

Microsoft Patches Critical Windows Vulns, Warn of Code Execution Risks

Patch Tuesday: Microsoft ships updates to over at least 70 documented vulnerabilities affecting the Windows ecosystem. The post Microsoft Patches Critical Windows Vulns, Warn of Code Execution Risks appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS…

Patch Tuesday: Critical Flaws in Adobe Commerce Software

Adobe ships urgent fixes for at least a dozen flaws that expose Adobe Commerce users to code execution attacks. The post Patch Tuesday: Critical Flaws in Adobe Commerce Software appeared first on SecurityWeek. This article has been indexed from SecurityWeek…

Virtual Event Today: CISO Forum 2023 – Register to Join

SecurityWeek’s 2023 CISO Forum Virtual Summit is taking place June 13-14 as a fully immersive online experience. The post Virtual Event Today: CISO Forum 2023 – Register to Join appeared first on SecurityWeek. This article has been indexed from SecurityWeek…

Data of 8.8 Million Zacks Users Emerges Online

A database containing the personal information of roughly 9 million Zacks users has emerged online. The post Data of 8.8 Million Zacks Users Emerges Online appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the…