Category: SecurityWeek RSS Feed

Malware Trends: What’s Old is Still New

Many of the most successful cybercriminals are shrewd; they want good ROI, but they don’t want to have to reinvent the wheel to get it. The post Malware Trends: What’s Old is Still New appeared first on SecurityWeek. This article…

CISA Expands Cybersecurity Committee, Updates Baseline Security Goals

CISA announces adding more experts to its Cybersecurity Advisory Committee and updating the Cybersecurity Performance Goals. The post CISA Expands Cybersecurity Committee, Updates Baseline Security Goals appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read…

BreachForums Shut Down Over Law Enforcement Takeover Concerns

The popular cybercrime forum BreachForums is being shut down following the arrest of Conor Brian Fitzpatrick, who is accused of running the website. The post BreachForums Shut Down Over Law Enforcement Takeover Concerns appeared first on SecurityWeek. This article has…

Spain Needs More Transparency Over Pegasus: EU Lawmakers

Spain needs more transparency over the Pegasus spyware hacking scandal, a European Parliament committee said. The post Spain Needs More Transparency Over Pegasus: EU Lawmakers appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the…

Burnout in Cybersecurity – Can it be Prevented?

Security professionals understand the need for resilience in their company’s security posture, but often fail to build their own psychological resilience to stress. The post Burnout in Cybersecurity – Can it be Prevented? appeared first on SecurityWeek. This article has…

Virtual Event Today: Supply Chain & Third-Party Risk Summit

Join us for the virtual experience as we bring together security experts to discuss the complex nature of the supply chain problem, best practices for mitigating security issues. The post Virtual Event Today: Supply Chain & Third-Party Risk Summit appeared first…

Google Suspends Chinese Shopping App Amid Security Concerns

Google has suspended the Chinese shopping app Pinduoduo on its app store after malware was discovered in versions of the app from other sources. The post Google Suspends Chinese Shopping App Amid Security Concerns appeared first on SecurityWeek. This article…

Verosint Launches Account Fraud Detection and Prevention Platform

443ID is refocusing its solution to tackle account fraud detection and prevention, and has changed its name to Verosint. The post Verosint Launches Account Fraud Detection and Prevention Platform appeared first on SecurityWeek. This article has been indexed from SecurityWeek…

Zoom Paid Out $3.9 Million in Bug Bounties in 2022

Zoom says it paid out $3.9 million in bug bounty rewards in 2022, with a total of over $7 million awarded to researchers since 2019. The post Zoom Paid Out $3.9 Million in Bug Bounties in 2022 appeared first on…

Google Pixel Vulnerability Allows Recovery of Cropped Screenshots

A vulnerability in Google Pixel phones allows for the recovery of an original, unedited screenshot from the cropped version. The post Google Pixel Vulnerability Allows Recovery of Cropped Screenshots appeared first on SecurityWeek. This article has been indexed from SecurityWeek…

Malicious NuGet Packages Used to Target .NET Developers

Software developers have been targeted in a new attack via malicious packages in the NuGet repository. The post Malicious NuGet Packages Used to Target .NET Developers appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read…

Oleria Scores $8M Seed Funding for ID Authentication Technology

Seattle startup founded by former Salesforce CISO Jim Alkove banks $8 million to build technology in the identity and authentication space. The post Oleria Scores $8M Seed Funding for ID Authentication Technology appeared first on SecurityWeek. This article has been…

Ferrari Says Ransomware Attack Exposed Customer Data

Ferrari said that a ransomware attack was responsible for a data breach that exposed customer details, but did not impact company operations. The post Ferrari Says Ransomware Attack Exposed Customer Data appeared first on SecurityWeek. This article has been indexed…

Aembit Scores $16.6M Seed Funding for Workload IAM Technology

Maryland startup Aembit gets funding to build an identity platform designed to manage, enforce, and audit access between federated workloads. The post Aembit Scores $16.6M Seed Funding for Workload IAM Technology appeared first on SecurityWeek. This article has been indexed…

Waterfall Security, TXOne Networks Launch New OT Security Appliances

Waterfall Security Solutions and TXOne Networks have each announced launching new OT security appliances. The post Waterfall Security, TXOne Networks Launch New OT Security Appliances appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the…

New York Man Arrested for Running BreachForums Cybercrime Website

Conor Brian Fitzpatrick of New York was arrested and charged last week for allegedly running the popular cybercrime forum BreachForums. The post New York Man Arrested for Running BreachForums Cybercrime Website appeared first on SecurityWeek. This article has been indexed…

Adobe Acrobat Sign Abused to Distribute Malware

Cybercriminals are abusing the Adobe Acrobat Sign service in a campaign distributing the RedLine information stealer malware. The post Adobe Acrobat Sign Abused to Distribute Malware appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read…

Latitude Financial Services Data Breach Impacts 300,000 Customers

Latitude Financial Services says the personal information of 300,000 customers was stolen in a cyberattack. The post Latitude Financial Services Data Breach Impacts 300,000 Customers appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the…

New ‘Trigona’ Ransomware Targets US, Europe, Australia

The recently identified Trigona ransomware has been highly active, targeting tens of organizations globally. The post New ‘Trigona’ Ransomware Targets US, Europe, Australia appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the original article:…

US Government Warns Organizations of LockBit 3.0 Ransomware Attacks

Three US government agencies have issued a joint warning to organizations about LockBit 3.0 ransomware attacks. The post US Government Warns Organizations of LockBit 3.0 Ransomware Attacks appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed…

Exploitation of Recent Fortinet Zero-Day Linked to Chinese Cyberspies

Mandiant links exploitation of the Fortinet zero-day CVE-2022-41328, exploited in government attacks, to a Chinese cyberespionage group. The post Exploitation of Recent Fortinet Zero-Day Linked to Chinese Cyberspies appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS…

Meta Develops New Kill Chain Thesis

Meta has developed a ten-phase cyber kill chain model that it believes will be more inclusive and more effective than the existing range of models. The post Meta Develops New Kill Chain Thesis appeared first on SecurityWeek. This article has…

Poland Breaks up Russian Spy Ring

Polish counter-intelligence has dismantled a Russian spy ring that gathered information on military equipment deliveries to Ukraine. The post Poland Breaks up Russian Spy Ring appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the…

CISA Seeks Public Opinion on Cloud Application Security Guidance

CISA this week announced it is seeking public input on draft guidance for securing cloud business applications. The post CISA Seeks Public Opinion on Cloud Application Security Guidance appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS…

Make Your Picks: Cyber Madness Bracket Challenge Starts Today

SecurityWeek’s Cyber Madness Bracket Challenge is a contest designed to bring the community together in a fun, competitive way through one of America’s top sporting events. The post Make Your Picks: Cyber Madness Bracket Challenge Starts Today appeared first on…

Facebook ‘Unlawfully’ Used Dutch Personal Data: Court

Social media platform Facebook unlawfully processed Dutch users’ personal details without consent for advertising purposes for almost a decade, Amsterdam-based judges ruled on Wednesday. The post Facebook ‘Unlawfully’ Used Dutch Personal Data: Court appeared first on SecurityWeek. This article has…

Rapid7 Buys Anti-Ransomware Firm Minerva Labs for $38 Million

Rapid7 spends $38 million to acquire Israeli anti-ransomware startup Minerva Labs to beef up its managed detection and response portfolio. The post Rapid7 Buys Anti-Ransomware Firm Minerva Labs for $38 Million appeared first on SecurityWeek. This article has been indexed…

NSA Shares Guidance on Maturing ICAM Capabilities for Zero Trust

NSA publishes recommendations on maturing identity, credential, and access management capabilities to improve cyberthreat protections. The post NSA Shares Guidance on Maturing ICAM Capabilities for Zero Trust appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed…

Are Encryption and Zero Trust Breaking Key Protections?

Compliance and ZTNA are driving encryption into every aspect of an organization’s network and enterprise and, in turn, forcing us to change how we think about protecting our environments. The post Are Encryption and Zero Trust Breaking Key Protections? appeared…

Dero, Monero Cryptojackers Fighting for Same Kubernetes Clusters

Dero cryptojacking operation infecting Kubernetes infrastructure is being targeted by Monero criptojackers for control over the same clusters. The post Dero, Monero Cryptojackers Fighting for Same Kubernetes Clusters appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS…

The Rise of the BISO in Contemporary Cybersecurity

While the BISO might appear to be a new role, it is not – and understanding its past provides insights into its present. The post The Rise of the BISO in Contemporary Cybersecurity appeared first on SecurityWeek. This article has…

Microsoft SmartScreen Zero-Day Exploited to Deliver Magniber Ransomware

A cybercrime group has been exploiting a Microsoft SmartScreen zero-day vulnerability tracked as CVE-2023-24880 to deliver the Magniber ransomware. The post Microsoft SmartScreen Zero-Day Exploited to Deliver Magniber Ransomware appeared first on SecurityWeek. This article has been indexed from SecurityWeek…

Adobe Warns of ‘Very Limited Attacks’ Exploiting ColdFusion Zero-Day

Adobe issues urgent warning for “very limited attacks” exploiting a zero-day vulnerability in its ColdFusion web app development platform. The post Adobe Warns of ‘Very Limited Attacks’ Exploiting ColdFusion Zero-Day appeared first on SecurityWeek. This article has been indexed from…

How the Best CISOs Drive Operational Resilience

Cyberattacks have exposed a myriad of vulnerabilities in our healthcare infrastructure, and will continue to do so as new and innovative medical technologies are developed. The post How the Best CISOs Drive Operational Resilience appeared first on SecurityWeek. This article…

Cloud Forensics Startup Mitiga Completes $45M Series A

Israeli cloud security startup Mitiga adds Samsung Next as an investor in a completed $45 million Series A financing round. The post Cloud Forensics Startup Mitiga Completes $45M Series A appeared first on SecurityWeek. This article has been indexed from…

Ring Denies Falling Victim to Ransomware Attack

Ring says it has no indications it has fallen victim to a ransomware attack after cybergang threatens to publish supposedly stolen data. The post Ring Denies Falling Victim to Ransomware Attack appeared first on SecurityWeek. This article has been indexed…

New ‘GoBruteforcer’ Botnet Targets Web Servers

The recently identified Golang-based GoBruteforcer botnet is targeting web servers running FTP, MySQL, phpMyAdmin, and Postgres services. The post New ‘GoBruteforcer’ Botnet Targets Web Servers appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the…

Euler Loses Nearly $200 Million to Flash Loan Attack

London, UK based De-Fi platform company Euler has lost a reported $196 million to a flash loan attack. The post Euler Loses Nearly $200 Million to Flash Loan Attack appeared first on SecurityWeek. This article has been indexed from SecurityWeek…

CISA Warns of Plex Vulnerability Linked to LastPass Hack

CISA has added vulnerabilities in Plex Media Server and VMware NSX-V to its Known Exploited Vulnerabilities catalog. The post CISA Warns of Plex Vulnerability Linked to LastPass Hack appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS…

Cybercrime Losses Exceeded $10 Billion in 2022: FBI

The FBI received more than 800,000 cybercrime-related complaints in 2022, with losses totaling over $10 billion. The post Cybercrime Losses Exceeded $10 Billion in 2022: FBI appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read…

Zoll Medical Data Breach Impacts 1 Million Individuals

Zoll Medical is notifying one million individuals that their personal information was compromised in a data breach earlier this year. The post Zoll Medical Data Breach Impacts 1 Million Individuals appeared first on SecurityWeek. This article has been indexed from…

Silicon Valley Bank Seized by FDIC as Depositors Pull Cash

The FDIC seized the assets of Silicon Valley Bank on Friday, which could impact cybersecurity firms that use the bank’s services. The post Silicon Valley Bank Seized by FDIC as Depositors Pull Cash appeared first on SecurityWeek. This article has…

Cyber Madness Bracket Challenge – Register to Play

SecurityWeek’s Cyber Madness Bracket Challenge is a contest designed to bring the community together in a fun, competitive way through one of America’s top sporting events. The post Cyber Madness Bracket Challenge – Register to Play appeared first on SecurityWeek.…

Cerebral Informing 3.1 Million Individuals of Inadvertent Data Exposure

Cerebral is informing 3.1 million individuals that their PHI was inadvertently exposed via third-party tracking technologies. The post Cerebral Informing 3.1 Million Individuals of Inadvertent Data Exposure appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed…

Serious Vulnerability Patched in Veeam Data Backup Solution

A serious vulnerability in Veeam Backup & Replication may allow attackers to obtain encrypted credentials from the configuration database. The post Serious Vulnerability Patched in Veeam Data Backup Solution appeared first on SecurityWeek. This article has been indexed from SecurityWeek…

White House Budget Plan Seeks to Boost Cybersecurity Spending

President Biden’s new $6.9 trillion budget proposal for 2024 shows that the administration wants to increase cybersecurity spending. The post White House Budget Plan Seeks to Boost Cybersecurity Spending appeared first on SecurityWeek. This article has been indexed from SecurityWeek…

Acronis Clarifies Hack Impact Following Data Leak

Acronis said a single customer’s account was compromised after a hacker leaked gigabytes of information on a cybercrime forum. The post Acronis Clarifies Hack Impact Following Data Leak appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS…

Custom Chinese Malware Found on SonicWall Appliance

Malware deployed by Chinese hackers on a SonicWall SMA appliance includes credential theft, shell access, and persistence functionality. The post Custom Chinese Malware Found on SonicWall Appliance appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed…

Vulnerability Exposes Cisco Enterprise Routers to Disruptive Attacks

Cisco has released patches for a high-severity DoS vulnerability in IOS XR software for several enterprise-grade routers. The post Vulnerability Exposes Cisco Enterprise Routers to Disruptive Attacks appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed…

Jenkins Server Vulnerabilities Chained for Remote Code Execution

Two vulnerabilities recently addressed in Jenkins server can be chained to achieve arbitrary code execution. The post Jenkins Server Vulnerabilities Chained for Remote Code Execution  appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the…

QuSecure Unveils Quantum-Resilient Communications Satellite Link

QuSecure announced an end-to-end quantum resilient encrypted communications link that protects data delivered by satellite. The post QuSecure Unveils Quantum-Resilient Communications Satellite Link appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the original article:…

Google Discontinuing Chrome Tool for Removing Unwanted Software

Google has announced the discontinuation of the Chrome Cleanup Tool, an application for identifying and removing unwanted software. The post Google Discontinuing Chrome Tool for Removing Unwanted Software appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS…

Defeating the Deepfake Danger

Deepfakes are becoming increasingly popular with cybercriminals, and as these technologies become even easier to use, organizations must become even more vigilant. The post Defeating the Deepfake Danger appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS…

Fortinet Patches Critical Unauthenticated RCE Vulnerability in FortiOS

Fortinet has patched a critical buffer underflow vulnerability in FortiOS and FortiProxy that could lead to remote code execution without authentication. The post Fortinet Patches Critical Unauthenticated RCE Vulnerability in FortiOS appeared first on SecurityWeek. This article has been indexed…

Congress Members Warned of Significant Health Data Breach

House and Senate members informed that hackers may have gained access to their sensitive personal data in DC Health Link breach. The post Congress Members Warned of Significant Health Data Breach appeared first on SecurityWeek. This article has been indexed…

Cado Security Banks $20M in Series B Funding

French investment firm Eurazeo leads a $20 million bet on Cado Security, a British cloud forensics technology startup. The post Cado Security Banks $20M in Series B Funding appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS…

Watch Sessions: Ransomware Resilience & Recovery Summit

Watch sessions from SecurityWeek’s Ransomware Resilience & Recovery Summit, a virtual event designed to help businesses to plan, prepare, and recover from a ransomware incident. The post Watch Sessions: Ransomware Resilience & Recovery Summit appeared first on SecurityWeek. This article…

Revelstoke Security Raises $20 Million for SOAR Platform

Revelstoke Security has raised $20 million in a Series B funding round co-led by ClearSky Security and SYN Ventures. The post Revelstoke Security Raises $20 Million for SOAR Platform appeared first on SecurityWeek. This article has been indexed from SecurityWeek…

‘Sys01 Stealer’ Malware Targeting Government Employees

The Sys01 Stealer has been observed targeting the Facebook accounts of critical government infrastructure employees. The post ‘Sys01 Stealer’ Malware Targeting Government Employees appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the original article:…

Chrome 111 Patches 40 Vulnerabilities

Google has released Chrome 111 in the stable channel with patches for 40 vulnerabilities, including eight high-severity bugs The post Chrome 111 Patches 40 Vulnerabilities appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the…

Virtual Event Today: Ransomware Resilience & Recovery Summit

Register for SecurityWeek’s Ransomware Resilience & Recovery Summit, a virtual event designed to help businesses to plan, prepare, and recover from a ransomware incident. The post Virtual Event Today: Ransomware Resilience & Recovery Summit appeared first on SecurityWeek. This article…

TSA Requires Aviation Sector to Enhance Cybersecurity Resilience

TSA instructs airport and aircraft operators to improve their cybersecurity resilience and prevent infrastructure disruption and degradation. The post TSA Requires Aviation Sector to Enhance Cybersecurity Resilience appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed…