Category: SecurityWeek RSS Feed

GoDaddy Says Recent Hack Part of Multi-Year Campaign

GoDaddy recently discovered a hacker attack where a sophisticated threat group infected websites and servers with malware. The post GoDaddy Says Recent Hack Part of Multi-Year Campaign appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed…

Spain Orders Extradition of British Alleged Hacker to US

Spanish Court agreed to extradite Joseph James O’Connor to he U.S., who allegedly took part in the July 2020 hacking of Twitter accounts of public figures such as Joseph Biden, Barack Obama and Bill Gates. The post Spain Orders Extradition…

Spain Orders Extradition of British Alleged Hacker to U.S.

Spanish Court agreed to extradite Joseph James O’Connor to he U.S., who allegedly took part in the July 2020 hacking of Twitter accounts of public figures such as Joseph Biden, Barack Obama and Bill Gates. The post Spain Orders Extradition…

Newly Disclosed Vulnerability Exposes EOL Arris Routers to Attacks

Malwarebytes warns of a remote code execution vulnerability impacting Arris G2482A, TG2492, and SBG10 routers, which have reached end-of-life (EOL). The post Newly Disclosed Vulnerability Exposes EOL Arris Routers to Attacks appeared first on SecurityWeek. This article has been indexed…

Atlassian Investigating Security Breach After Hackers Leak Data

A group of hackers has leaked Atlassian employee records and floorplans, information that was obtained from third-party workplace platform Envoy. The post Atlassian Investigating Security Breach After Hackers Leak Data appeared first on SecurityWeek. This article has been indexed from…

Hackers Earn $180,000 for ICS Exploits at Pwn2Own Miami 2023

White hat hackers received $180,000 at Pwn2Own Miami 2023 for exploits targeting widely used ICS products. The post Hackers Earn $180,000 for ICS Exploits at Pwn2Own Miami 2023 appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS…

EU Organizations Warned of Chinese APT Attacks

ENISA and CERT-EU warn of Chinese threat actors targeting businesses and government organizations in the European Union. The post EU Organizations Warned of Chinese APT Attacks appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read…

SolarWinds Announces Upcoming Patches for High-Severity Vulnerabilities

SolarWinds advisories describe multiple high-severity vulnerabilities that a Platform update will patch by the end of February. The post SolarWinds Announces Upcoming Patches for High-Severity Vulnerabilities appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read…

Security Experts Warn of Foreign Cyber Threat to 2024 Voting

Top state election and cybersecurity officials warned about threats posed by Russia and other foreign adversaries ahead of the 2024 elections The post Security Experts Warn of Foreign Cyber Threat to 2024 Voting appeared first on SecurityWeek. This article has…

Chris Inglis Steps Down as US National Cyber Director

The former NSA deputy director Chris Inglis was picked 17 months ago to be President Joe Biden’s top advisor on cybersecurity issues. The post Chris Inglis Steps Down as US National Cyber Director appeared first on SecurityWeek. This article has…

Firefox Updates Patch 10 High-Severity Vulnerabilities

Mozilla releases Firefox 110 and Firefox ESR 102.8 with patches for 10 high-severity vulnerabilities. The post Firefox Updates Patch 10 High-Severity Vulnerabilities appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the original article: Firefox…

Critical Vulnerability Patched in Cisco Security Products

Cisco updates endpoint, cloud, and web security products to address a critical vulnerability in third-party scanning library ClamAV. The post Critical Vulnerability Patched in Cisco Security Products appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed…

Splunk Enterprise Updates Patch High-Severity Vulnerabilities

Splunk updates for Enterprise products resolve multiple high-severity vulnerabilities, including several in third-party packages. The post Splunk Enterprise Updates Patch High-Severity Vulnerabilities appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the original article: Splunk…

Recently Patched IBM Aspera Faspex Vulnerability Exploited in the Wild

A vulnerability affecting IBM’s Aspera Faspex file transfer solution, tracked as CVE-2022-47986, has been exploited in attacks. The post Recently Patched IBM Aspera Faspex Vulnerability Exploited in the Wild appeared first on SecurityWeek. This article has been indexed from SecurityWeek…

Descope Targets Customer Identity Market with Massive $53M Seed Round

Descope raises an abnormally large $53 million seed-stage funding round for technology in the customer identity and authentication space. The post Descope Targets Customer Identity Market with Massive $53M Seed Round appeared first on SecurityWeek. This article has been indexed…

Dozens of Vulnerabilities Patched in Intel Products

Intel has released patches for multiple critical- and high-severity vulnerabilities across its product portfolio. The post Dozens of Vulnerabilities Patched in Intel Products appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the original article:…

Russian Businessman Guilty in Hacking, Insider Trade Scheme

Vladislav Klyushin was found guilty on all charges against him, including wire fraud and securities fraud, after a two-week trial in federal court in Boston. The post Russian Businessman Guilty in Hacking, Insider Trade Scheme appeared first on SecurityWeek. This…

SAP’s February 2023 Security Updates Patch High-Severity Vulnerabilities

SAP has released 21 notes on February 2023 Security Patch Day, including three notes addressing high-severity vulnerabilities in SAP Start Service and BusinessObjects. The post SAP’s February 2023 Security Updates Patch High-Severity Vulnerabilities appeared first on SecurityWeek. This article has…

Citrix Patches High-Severity Vulnerabilities in Windows, Linux Apps

Citrix released patches for multiple vulnerabilities in Virtual Apps and Desktops, and Workspace apps for Windows and Linux. The post Citrix Patches High-Severity Vulnerabilities in Windows, Linux Apps appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS…

Zscaler to Acquire Israeli Startup Canonic Security

Zcaler plans to acquire Israeli startup Canonic Security to expand into the red-hot software supply chain security business. The post Zscaler to Acquire Israeli Startup Canonic Security appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed…

Patch Tuesday: Microsoft Warns of Exploited Windows Zero-Days

Microsoft’s Patch Tuesday machine is humming loudly with software updates to fix at least 76 vulnerabilities in Windows and OS components. The post Patch Tuesday: Microsoft Warns of Exploited Windows Zero-Days appeared first on SecurityWeek. This article has been indexed from…

Pepsi Bottling Ventures Discloses Data Breach

Pepsi Bottling Ventures, the largest privately-held bottler of Pepsi-Cola products in the United States, says data was stolen from its systems following a malware attack. The post Pepsi Bottling Ventures Discloses Data Breach appeared first on SecurityWeek. This article has…

CISO Conversations: The Role of the vCISO

SecurityWeek examines the role of the virtual CISO in a conversation with Chris Bedel and Greg Schaffer. The post CISO Conversations: The Role of the vCISO appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read…

Record-Breaking 71 Million RPS DDoS Attack Seen by Cloudflare

Cloudflare over the weekend mitigated a record-setting DDoS attack that peaked at 71 million requests per second. The post Record-Breaking 71 Million RPS DDoS Attack Seen by Cloudflare appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS…

Hackers Target Bahrain Airport, News Sites to Mark Uprising

Hackers took down the websites of Bahrain’s international airport and state news agency to mark the 12-year anniversary of an Arab Spring uprising in the small Gulf country. The post Hackers Target Bahrain Airport, News Sites to Mark Uprising appeared…

GoAnywhere Zero-Day Attack Victims Start Disclosing Significant Impact

Organizations hit by exploitation of the GoAnywhere MFT zero-day vulnerability CVE-2023-0669 have started coming forward. The post GoAnywhere Zero-Day Attack Victims Start Disclosing Significant Impact appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the…

Apple Patches Actively Exploited WebKit Zero-Day Vulnerability

Apple has released updates for macOS, iOS and Safari and they all include a WebKit patch for a zero-day vulnerability tracked as CVE-2023-23529. The post Apple Patches Actively Exploited WebKit Zero-Day Vulnerability  appeared first on SecurityWeek. This article has been…

The Lessons From Cyberwar, Cyber-in-War and Ukraine

The war in Ukraine is the first major conflagration between two technologically advanced powers in the age of cyber. It prompts us to question the nature of modern warfare and the role of cyber in its operation. The post The…

Cybersecurity Firm Group-IB Repeatedly Targeted by Chinese APT

Cybersecurity company Group-IB claims it was repeatedly targeted by a Chinese APT called Tonto Team, CactusPete, and Karma Panda. The post Cybersecurity Firm Group-IB Repeatedly Targeted by Chinese APT appeared first on SecurityWeek. This article has been indexed from SecurityWeek…

City of Oakland Hit by Ransomware Attack

The City of Oakland has disclosed a ransomware attack that impacted several non-emergency systems. The post City of Oakland Hit by Ransomware Attack appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the original article:…

Play Ransomware Group Claims Attack on A10 Networks

The Play ransomware group has claimed responsibility for a cyberattack on application delivery controller maker A10 Networks The post Play Ransomware Group Claims Attack on A10 Networks appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed…

Cybersecurity M&A Roundup: 40 Deals Announced in January 2023

Forty cybersecurity-related M&A deals were announced in January 2023. The post Cybersecurity M&A Roundup: 40 Deals Announced in January 2023 appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the original article: Cybersecurity M&A Roundup:…

SecurityWeek Cyber Insights 2023 Series

SecurityWeek spoke with more than 300 cybersecurity experts to see what is bubbling beneath the surface, and examine how those evolving threats will present new and expanded risk for cybersecurity teams in 2023 and beyond. The post SecurityWeek Cyber Insights…

US Blacklists 6 Chinese Entities Over Balloon Program

The United States blacklisted six Chinese entities it said were linked to Beijing’s aerospace programs as part of its retaliation over an alleged Chinese spy balloon that traversed the country’s airspace. The post US Blacklists 6 Chinese Entities Over Balloon…

Microsoft OneNote Abuse for Malware Delivery Surges

Threat actors are increasingly abusing Microsoft OneNote documents to deliver malware in both targeted and spray-and-pray campaigns. The post Microsoft OneNote Abuse for Malware Delivery Surges appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read…

Security Awareness Training Startup Riot Raises $12 Million

Series A funding brings the total amount raised by cybersecurity training company to $15 million. The post Security Awareness Training Startup Riot Raises $12 Million appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the…

GoAnywhere MFT Zero-Day Exploitation Linked to Ransomware Attacks

The exploitation of a GoAnywhere MFT zero-day vulnerability has been linked to a cybercrime group and ransomware attacks. The post GoAnywhere MFT Zero-Day Exploitation Linked to Ransomware Attacks appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS…

Documents, Code, Business Systems Accessed in Reddit Hack

Reddit says its systems were hacked following a sophisticated phishing attack aimed at employees. The post Documents, Code, Business Systems Accessed in Reddit Hack appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the original…

Australian Defense Department to Remove Chinese-Made Cameras

Australia’s Defense Department said that they will remove surveillance cameras made by Chinese Communist Party-linked companies from its buildings. The post Australian Defense Department to Remove Chinese-Made Cameras appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS…

VulnCheck Raises $3.2M Seed Round for Threat Intel

Massachusetts startup with VulnCheck has attracted $3.2 million in seed-stage funding from several prominent investors. The post VulnCheck Raises $3.2M Seed Round for Threat Intel appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the…

US, UK Slap Sanctions on Trickbot Cybercrime Gang

The US Treasury has frozen assets and announced travel bans against seven Russians accused of running the Trickbot ransomware operation. The post US, UK Slap Sanctions on Trickbot Cybercrime Gang appeared first on SecurityWeek. This article has been indexed from…

US Says Chinese Military Behind Vast Aerial Spy Program

China’s spy balloon that crossed the US could collect intelligence signals and was part of a multi-national, military-linked aerial spy program, the Biden administration said. The post US Says Chinese Military Behind Vast Aerial Spy Program appeared first on SecurityWeek.…

Google Describes Privacy, Security Improvements in Android 14

Google has released the first Android 14 developer preview and has announced some of the security improvements the platform update will include. The post Google Describes Privacy, Security Improvements in Android 14 appeared first on SecurityWeek. This article has been…

Vulnerabilities in Popular DMS Products Can Expose Sensitive Documents

Multiple XSS vulnerabilities in popular document management system (DMS) products could allow attackers to access sensitive documents. The post Vulnerabilities in Popular DMS Products Can Expose Sensitive Documents appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS…

Android’s February 2023 Updates Patch 40 Vulnerabilities

The February 2023 security updates for Android patch 40 vulnerabilities, including multiple high-severity escalation of privilege bugs. The post Android’s February 2023 Updates Patch 40 Vulnerabilities appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read…

Minister: Cybercrimes Now 20% of Spain’s Registered Offenses

Spain’s government pledged stronger action against cybercrime, saying it has come to account for about a fifth of all offenses registered in the country. The post Minister: Cybercrimes Now 20% of Spain’s Registered Offenses appeared first on SecurityWeek. This article…

Tor Network Under DDoS Pressure for 7 Months

For the past seven months, the Tor network has been hit with numerous DDoS attacks, some impacting availability. The post Tor Network Under DDoS Pressure for 7 Months appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS…

Application Security Protection for the Masses

While there are many routes to application security, bundles that allow security teams to quickly and easily secure applications and affect security posture in a self-service manner are becoming increasingly popular. The post Application Security Protection for the Masses appeared…

Chrome 110 Patches 15 Vulnerabilities

The first stable release of Chrome 110 brings 15 security fixes, including 10 for externally reported vulnerabilities. The post Chrome 110 Patches 15 Vulnerabilities appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the original…

Australian Man Sentenced for Scam Related to Optus Hack

Australian authorities sentence Sydney man for using leaked data stolen from wireless carrier Optus to conduct SMS scams. The post Australian Man Sentenced for Scam Related to Optus Hack  appeared first on SecurityWeek. This article has been indexed from SecurityWeek…

Spies, Hackers, Informants: How China Snoops on the US

An alleged Chinese surveillance balloon over the United States last week sparked a diplomatic furore and renewed fears over how Beijing gathers intelligence on its largest strategic rival. The post Spies, Hackers, Informants: How China Snoops on the US appeared…

Skybox Security Raises $50M, Hires New CEO

Late-stage California startup Skybox Security turns the reins over to former Digital Guardian chief executive Mordecai Rosen. The post Skybox Security Raises $50M, Hires New CEO appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read…

UN Experts: North Korean Hackers Stole Record Virtual Assets

North Korean hackers working for the government stole virtual assets last year estimated to be worth between $630 million and more than $1 billion, U.N. experts said in a report. The post UN Experts: North Korean Hackers Stole Record Virtual Assets appeared…

Siemens License Manager Vulnerabilities Allow ICS Hacking

The Siemens Automation License Manager is affected by two serious vulnerabilities that could be chained to hack industrial control systems (ICS). The post Siemens License Manager Vulnerabilities Allow ICS Hacking appeared first on SecurityWeek. This article has been indexed from…

A Deep Dive Into the Growing GootLoader Threat

Cybereason GootLoader as a ‘severe’ threat, as the malware uses a combination of evasion and living off the land techniques, making its presence difficult to dectec. The post A Deep Dive Into the Growing GootLoader Threat appeared first on SecurityWeek.…

OpenSSL Ships Patch for High-Severity Flaws

The most serious of the vulnerabilities may allow an attacker to read memory contents or launch denial-of-service exploits. The post OpenSSL Ships Patch for High-Severity Flaws appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read…

Germany Appoints Central Bank IT Chief to Head Cybersecurity

Germany appointed Claudia Plattner to lead its cybersecurity agency, months after her predecessor was removed following reports of possible problematic ties to Russia. The post Germany Appoints Central Bank IT Chief to Head Cybersecurity appeared first on SecurityWeek. This article…

Linux Variant of Cl0p Ransomware Emerges

A Cl0p ransomware variant targeting Linux systems emerged recently, but a flaw in the encryption algorithm has already allowed for the creation of a free decryptor. The post Linux Variant of Cl0p Ransomware Emerges appeared first on SecurityWeek. This article…

Patch Released for Actively Exploited GoAnywhere MFT Zero-Day

A patch has been released for the GoAnywhere MFT zero-day vulnerability that has been exploited in attacks. The post Patch Released for Actively Exploited GoAnywhere MFT Zero-Day appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed…

Vulnerability Provided Access to Toyota Supplier Management Network

Security researcher finds severe vulnerability providing system admin access to Toyota’s global supplier management network. The post Vulnerability Provided Access to Toyota Supplier Management Network appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the…

Software Supply Chain Security Firm Lineaje Raises $7 Million

Software supply chain security management startup Lineaje raises $7 million in a seed funding round led by Tenable Ventures. The post Software Supply Chain Security Firm Lineaje Raises $7 Million appeared first on SecurityWeek. This article has been indexed from…

Comcast Wants a Slice of the Enterprise Cybersecurity Business

Comcast jumps into the enterprise cybersecurity business, betting that its internal security tools and inventions can find traction in an expanding marketplace. The post Comcast Wants a Slice of the Enterprise Cybersecurity Business appeared first on SecurityWeek. This article has…

Cyber Insights 2023 | The Coming of Web3

As it evolves, web3 will contain and increase all the security issues of web2 – and perhaps add a few more. The post Cyber Insights 2023 | The Coming of Web3 appeared first on SecurityWeek. This article has been indexed…

Florida Hospital Cancels Procedures, Diverts Patients Following Cyberattack

Tallahassee Memorial HealthCare was forced to cancel procedures and divert patients after taking systems offline following a Thursday night cyberattack. The post Florida Hospital Cancels Procedures, Diverts Patients Following Cyberattack appeared first on SecurityWeek. This article has been indexed from…

European Police Arrest 42 After Cracking Covert App

European police arrested 42 suspects and seized guns, drugs and millions in cash, after cracking another encrypted online messaging service used by criminals. The post European Police Arrest 42 After Cracking Covert App appeared first on SecurityWeek. This article has…