Category: SecurityWeek RSS Feed

US Charges Russians With Hacking Cryptocurrency Exchange

Two Russian nationals are charged in the US with hacking a cryptocurrency exchange and conspiring to launder the proceeds. The post US Charges Russians With Hacking Cryptocurrency Exchange appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS…

Software Supply Chain: The Golden Container Ship

By having a golden image you will put a process in place that allows you to quickly take action when a vulnerability is found within your organization. The post Software Supply Chain: The Golden Container Ship appeared first on SecurityWeek.…

Intellihartx Informs 490k Patients of GoAnywhere-Related Data Breach

Intellihartx says the personal information of roughly 490,000 individuals was compromised in the GoAnywhere zero-day attack earlier this year. The post Intellihartx Informs 490k Patients of GoAnywhere-Related Data Breach appeared first on SecurityWeek. This article has been indexed from SecurityWeek…

Swiss Fear Government Data Stolen in Cyberattack

Switzerland said government operational data might have been stolen in a ransomware attack on a technology firm that provides software for several departments. The post Swiss Fear Government Data Stolen in Cyberattack appeared first on SecurityWeek. This article has been…

Fortinet Patches Critical FortiGate SSL VPN Vulnerability

Fortinet has patched CVE-2023-27997, a critical FortiGate SSL VPN vulnerability that can be exploited for unauthenticated remote code execution. The post Fortinet Patches Critical FortiGate SSL VPN Vulnerability appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS…

Blackpoint Raises $190 Million to Help MSPs Combat Cyber Threats

Blackpoint Cyber raises $190 million in a growth funding round led by Bain Capital Tech Opportunities. The post Blackpoint Raises $190 Million to Help MSPs Combat Cyber Threats appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS…

Google Cloud Now Offering $1 Million Cryptomining Protection

Google Cloud is offering up to $1 million in financial protection to cover expenses associated with undetected cryptomining attacks. The post Google Cloud Now Offering $1 Million Cryptomining Protection appeared first on SecurityWeek. This article has been indexed from SecurityWeek…

Consolidate Vendors and Products for Better Security

Instead of deploying new point products, CISOs should consider sourcing technologies from vendors that develop products designed to work together as part of a platform.  The post Consolidate Vendors and Products for Better Security appeared first on SecurityWeek. This article…

Cisco Patches Critical Vulnerability in Enterprise Collaboration Solutions

Cisco releases fixes for a critical-severity vulnerability in Expressway series and TelePresence Video Communication Server (VCS). The post Cisco Patches Critical Vulnerability in Enterprise Collaboration Solutions appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read…

Barracuda Urges Customers to Replace Hacked Email Security Appliances

Barracuda Networks is telling customers to immediately replace hacked ESG email security appliances regardless of the patches they installed. The post Barracuda Urges Customers to Replace Hacked Email Security Appliances appeared first on SecurityWeek. This article has been indexed from…

Stay Focused on What’s Important

Staying the course and sticking to strategic goals allows security professionals to steadily and continually improve the security posture of their organization. The post Stay Focused on What’s Important appeared first on SecurityWeek. This article has been indexed from SecurityWeek…

Sysdig Introduces CNAPP With Realtime CDR

Sysdig is launching what it claims to be the first CNAPP with end-to-end detection and response, consolidating CNAPP and CDR. The post Sysdig Introduces CNAPP With Realtime CDR appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS…

VMware Plugs Critical Flaws in Network Monitoring Product

VMware ships urgent patches to cover security defects that expose businesses to remote code execution attacks. The post VMware Plugs Critical Flaws in Network Monitoring Product appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read…

US, Israel Provide Guidance on Securing Remote Access Software

US and Israeli government agencies have published new guidance on preventing malicious exploitation of remote access software. The post US, Israel Provide Guidance on Securing Remote Access Software appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS…

Hackers Issue ‘Ultimatum’ Over Payroll Data Breach

The Clop ransomware gang issued “an ultimatum” companies targeted in a recent large-scale hack of payroll data The post Hackers Issue ‘Ultimatum’ Over Payroll Data Breach appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read…

Blumira Raises $15 Million for SMB-Tailored XDR Platform

Blumira raises $15 million in Series B funding and launches a new XDR platform for small and medium-sized businesses (SMBs). The post Blumira Raises $15 Million for SMB-Tailored XDR Platform appeared first on SecurityWeek. This article has been indexed from…

OWASP’s 2023 API Security Top 10 Refines View of API Risks

OWASP’s ranking for the major API security risks in 2023 has been published. The list includes many parallels with the 2019 list, some reorganizations/redefinitions, and some new concepts. The post OWASP’s 2023 API Security Top 10 Refines View of API…

KeePass Update Patches Vulnerability Exposing Master Password

KeePass 2.54 patches a vulnerability allowing attackers to retrieve the cleartext master password from a memory dump. The post KeePass Update Patches Vulnerability Exposing Master Password appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read…

Zoom Expands Privacy Options for European Customers

New options allow paid Zoom customers to specify certain data for meetings, webinars, and team chat to be stored within the EEA. The post Zoom Expands Privacy Options for European Customers appeared first on SecurityWeek. This article has been indexed…

Google Workspace Gets Passkey Authentication

Google Workspace now offers support for passwordless authentication using passkeys, in beta. The post Google Workspace Gets Passkey Authentication appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the original article: Google Workspace Gets Passkey…

Keep Aware Raises $2.4M to Eliminate Browser Blind Spots

Keep Aware scores seed investment to build a human-centric browser security platform that provides protection against browser-based attacks. The post Keep Aware Raises $2.4M to Eliminate Browser Blind Spots appeared first on SecurityWeek. This article has been indexed from SecurityWeek…

Apple Unveils Upcoming Privacy and Security Features

Apple on Monday detailed new privacy and security features rolling out to both desktop and mobile users. The post Apple Unveils Upcoming Privacy and Security Features appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read…

Several Major Organizations Confirm Being Impacted by MOVEit Attack

Major companies have confirmed being impacted by the recent MOVEit zero-day attack, including BBC, British Airways and Zellis. The post Several Major Organizations Confirm Being Impacted by MOVEit Attack appeared first on SecurityWeek. This article has been indexed from SecurityWeek…

Google Patches Third Chrome Zero-Day of 2023

Google has released a Chrome 114 security update that patches CVE-2023-3079, the third zero-day vulnerability patched in the browser in 2023. The post Google Patches Third Chrome Zero-Day of 2023 appeared first on SecurityWeek. This article has been indexed from…

Dozens of Malicious Extensions Found in Chrome Web Store

Security researchers have identified over 30 malicious extensions with millions of installs in the Chrome web store. The post Dozens of Malicious Extensions Found in Chrome Web Store appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS…

What if the Current AI Hype Is a Dead End?

If we should face a Dead-End AI future, the cybersecurity industry will continue to rely heavily on traditional approaches, especially human-driven ones. It won’t quite be business as usual though. The post What if the Current AI Hype Is a…

Gigabyte Rolls Out BIOS Updates to Remove Backdoor From Motherboards

Gigabyte has announced BIOS updates that remove a recently identified backdoor feature in hundreds of its motherboards. The post Gigabyte Rolls Out BIOS Updates to Remove Backdoor From Motherboards appeared first on SecurityWeek. This article has been indexed from SecurityWeek…

Cybersecurity M&A Roundup: 36 Deals Announced in May 2023

Thirty-six cybersecurity-related merger and acquisition (M&A) deals were announced in May 2023. The post Cybersecurity M&A Roundup: 36 Deals Announced in May 2023 appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the original article:…

Galvanick Banks $10 Million for Industrial XDR Technology

Los Angeles startup Galvanick scores $10 million seed capital to build a modern industrial detection and response platform. The post Galvanick Banks $10 Million for Industrial XDR Technology appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS…

OpenAI Unveils Million-Dollar Cybersecurity Grant Program

OpenAI plans to shell out $1 million in grants for projects that empower defensive use-cases for generative AI technology. The post OpenAI Unveils Million-Dollar Cybersecurity Grant Program appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed…

High-Severity Vulnerabilities Patched in Splunk Enterprise

Splunk has resolved multiple high-severity vulnerabilities in Splunk Enterprise, including bugs in third-party packages used by the product. The post High-Severity Vulnerabilities Patched in Splunk Enterprise appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read…

US, South Korea Detail North Korea’s Social Engineering Techniques

The US and Korea are warning of North Korean social engineering attacks targeting employees of think tanks, academic and research institutions, and news media organizations. The post US, South Korea Detail North Korea’s Social Engineering Techniques appeared first on SecurityWeek.…

Apple Denies Helping US Government Hack Russian iPhones

Apple has denied working with any government to add backdoors to its products after Russia accused the company of helping the NSA hack iPhones. The post Apple Denies Helping US Government Hack Russian iPhones appeared first on SecurityWeek. This article…

Russia Blames US Intelligence for iOS Zero-Click Attacks

Kaspersky said its corporate network has been targeted with a zero-click iOS exploit, just as Russia’s FSB said iPhones have been targeted by US intelligence. The post Russia Blames US Intelligence for iOS Zero-Click Attacks appeared first on SecurityWeek. This…

Cisco Acquiring Armorblox for Predictive and Generative AI Technology

Cisco is in the process of acquiring email security firm Armorblox for its predictive and generative artificial intelligence (AI) technology. The post Cisco Acquiring Armorblox for Predictive and Generative AI Technology appeared first on SecurityWeek. This article has been indexed…

Adobe Inviting Researchers to Private Bug Bounty Program

Adobe is inviting security researchers to join its private bug bounty program on the HackerOne platform. The post Adobe Inviting Researchers to Private Bug Bounty Program appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read…

Amazon Settles Ring Customer Spying Complaint

The FTC charged Amazon-owned Ring with failing to implement basic protections to stop hackers or employees from accessing people’s devices or accounts. The post Amazon Settles Ring Customer Spying Complaint appeared first on SecurityWeek. This article has been indexed from…

Critical Vulnerabilities Found in Faronics Education Software

Faronics patches critical-severity remote code execution (RCE) vulnerabilities in the Insight education software. The post Critical Vulnerabilities Found in Faronics Education Software appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the original article: Critical…

Chrome 114 Released With 18 Security Fixes

Chrome 114 stable brings 18 security fixes, including 13 for vulnerabilities reported by external researchers. The post Chrome 114 Released With 18 Security Fixes appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the original…

Breaking Enterprise Silos and Improving Protection

When teams have a way to break down enterprise silos and see and understand what is happening, they can improve protection across their increasingly dispersed and diverse environment. The post Breaking Enterprise Silos and Improving Protection appeared first on SecurityWeek.…

Many Vulnerabilities Found in PrinterLogic Enterprise Software

Multiple vulnerabilities in PrinterLogic’s enterprise management printer solution could expose organizations to various types of attacks. The post Many Vulnerabilities Found in PrinterLogic Enterprise Software appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the…

Industrial Giant ABB Confirms Ransomware Attack, Data Theft

Industrial giant ABB has confirmed that it has been targeted in a ransomware attack, with the cybercriminals stealing some data. The post Industrial Giant ABB Confirms Ransomware Attack, Data Theft appeared first on SecurityWeek. This article has been indexed from…

NCC Group Releases Open Source Tools for Developers, Pentesters

NCC Group announces new open source tools for finding hardcoded credentials and for distributing cloud workloads. The post NCC Group Releases Open Source Tools for Developers, Pentesters appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed…

Watch Now: Threat Detection and Incident Response Virtual Summit

Join thousands of attendees as we dive into threat hunting tools and frameworks, and explore value of threat intelligence data in the defender’s security stack. (Login Now) The post Watch Now: Threat Detection and Incident Response Virtual Summit appeared first…

Zyxel Firewalls Hacked by Mirai Botnet

A Mirai botnet has been exploiting a recently patched vulnerability tracked as CVE-2023-28771 to hack many Zyxel firewalls. The post Zyxel Firewalls Hacked by Mirai Botnet appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read…

Google Cloud Users Can Now Automate TLS Certificate Lifecycle

Google makes ACME API available to all Google Cloud users to allow them to automatically acquire and renew TLS certificates for free. The post Google Cloud Users Can Now Automate TLS Certificate Lifecycle appeared first on SecurityWeek. This article has…

New Russia-Linked CosmicEnergy ICS Malware Could Disrupt Electric Grids

Mandiant has analyzed a new Russia-linked ICS malware named CosmicEnergy that is designed to cause electric power disruption. The post New Russia-Linked CosmicEnergy ICS Malware Could Disrupt Electric Grids appeared first on SecurityWeek. This article has been indexed from SecurityWeek…

New Russia-Linked CosmicEnergy ICS Malware Could Disrupt Electric Grid

Mandiant has analyzed a new Russia-linked ICS malware named CosmicEnergy that is designed to cause electric power disruption. The post New Russia-Linked CosmicEnergy ICS Malware Could Disrupt Electric Grid appeared first on SecurityWeek. This article has been indexed from SecurityWeek…

European Cybersecurity Firm Sekoia.io Raises $37.5 Million

European XDR and threat intelligence provider Sekoia.io has raised €35 million ($37.5 million) in Series A funding. The post European Cybersecurity Firm Sekoia.io Raises $37.5 Million appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read…

GitLab Security Update Patches Critical Vulnerability

GitLab CE/EE version 16.0.1 patches a critical arbitrary file read vulnerability tracked as CVE-2023-2825. The post GitLab Security Update Patches Critical Vulnerability appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the original article: GitLab…