Category: SecurityWeek RSS Feed

Microsoft Details ‘Skeleton Key’ AI Jailbreak Technique

Microsoft has tricked several gen-AI models into providing forbidden information using a jailbreak technique named Skeleton Key. The post Microsoft Details ‘Skeleton Key’ AI Jailbreak Technique appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read…

Fortra Patches Critical SQL Injection in FileCatalyst Workflow

Fortra has patched a critical-severity vulnerability in FileCatalyst Workflow leading to the creation of administrator accounts. The post Fortra Patches Critical SQL Injection in FileCatalyst Workflow appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read…

Russian APT Reportedly Behind New TeamViewer Hack

TeamViewer’s corporate network was hacked and some reports say the Russian group APT29 is behind the attack. The post Russian APT Reportedly Behind New TeamViewer Hack appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read…

Inside the Mind of a CISO: Survey and Analysis

Inside the Mind of a CISO 2024 is a survey of 209 security leaders to understand the thinking and operational methods and motivations of CISOs. The post Inside the Mind of a CISO: Survey and Analysis appeared first on SecurityWeek.…

US, Allies Warn of Memory Unsafety Risks in Open Source Software

Most critical open source software contains code written in a memory unsafe language, US, Australian, and Canadian government agencies warn. The post US, Allies Warn of Memory Unsafety Risks in Open Source Software appeared first on SecurityWeek. This article has…

GitLab Security Updates Patch 14 Vulnerabilities

GitLab CE and EE updates resolve 14 vulnerabilities, including a critical- and three high-severity bugs. The post GitLab Security Updates Patch 14 Vulnerabilities appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the original article:…

Designed Receivable Solutions Data Breach Impacts 585,000 People

Healthcare services provider Designed Receivable Solutions says the number of individuals affected by a recent data breach has increased to 585,000. The post Designed Receivable Solutions Data Breach Impacts 585,000 People appeared first on SecurityWeek. This article has been indexed…

Gas Chromatograph Hacking Could Have Serious Impact: Security Firm

Critical vulnerabilities have been found in an Emerson gas chromatograph and Claroty warns that attacks could have a serious impact. The post Gas Chromatograph Hacking Could Have Serious Impact: Security Firm appeared first on SecurityWeek. This article has been indexed…

‘Phantom’ Source Code Secrets Haunt Major Organizations

Aqua Security shows that code in repositories remains accessible even after being deleted or overwritten, continuing to leak secrets. The post ‘Phantom’ Source Code Secrets Haunt Major Organizations appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS…

Google Disrupts More China-Linked Dragonbridge Influence Operations

Google has disrupted over 175,000 YouTube and Blogger instances related to the Chinese influence operation Dragonbridge. The post Google Disrupts More China-Linked Dragonbridge Influence Operations appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the…

Gaining and Retaining Security Talent: A Cheat Sheet for CISOs

Freed from the shackles of always demanding a technical background, the CISO can concentrate on building a diverse team comprising multiple skills. The post Gaining and Retaining Security Talent: A Cheat Sheet for CISOs appeared first on SecurityWeek. This article…

P2Pinfect Worm Now Dropping Ransomware on Redis Servers

The P2Pinfect worm targeting Redis servers has been updated with ransomware and cryptocurrency mining payloads. The post P2Pinfect Worm Now Dropping Ransomware on Redis Servers appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the…

Polyfill Supply Chain Attack Hits Over 100k Websites

More than 100,000 websites are affected by a supply chain attack injecting malware via a Polyfill domain. The post Polyfill Supply Chain Attack Hits Over 100k Websites  appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed…

Exploitation Attempts Target New MOVEit Transfer Vulnerability

Exploitation attempts targeting CVE-2024-5806, a critical MOVEit Transfer vulnerability patched recently, have started. The post Exploitation Attempts Target New MOVEit Transfer Vulnerability appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the original article: Exploitation…

EU Sanctions Six Russian Hackers

The European Council has added six Russian hackers to the EU’s sanctions list for their cyberattacks against member states and Ukraine. The post EU Sanctions Six Russian Hackers appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS…

Recent Zyxel NAS Vulnerability Exploited by Botnet

A Mirai-like botnet has started exploiting a critical-severity vulnerability in discontinued Zyxel NAS products. The post Recent Zyxel NAS Vulnerability Exploited by Botnet appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the original article:…

Several Plugins Compromised in WordPress Supply Chain Attack

Five WordPress plugins were injected with malicious code that creates a new administrative account. The post Several Plugins Compromised in WordPress Supply Chain Attack  appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the original…

Malware Sandbox Any.Run Targeted in Phishing Attack

Employees of the Any.Run malware analysis service were recently targeted in a phishing attack that was part of a BEC campaign. The post Malware Sandbox Any.Run Targeted in Phishing Attack appeared first on SecurityWeek. This article has been indexed from…

Chrome 126 Update Patches Memory Safety Bugs

Google has released a Chrome security update to resolve four high-severity use-after-free vulnerabilities. The post Chrome 126 Update Patches Memory Safety Bugs appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the original article: Chrome…

LivaNova USA Discloses Data Breach Impacting 130,000 Individuals

LivaNova USA says the personal and medical information of 130,000 individuals was compromised in an October 2023 data breach. The post LivaNova USA Discloses Data Breach Impacting 130,000 Individuals appeared first on SecurityWeek. This article has been indexed from SecurityWeek…

Vietnamese Members of FIN9 Hacking Group Charged in US

The US has announced charges against four Vietnamese nationals for hacking businesses and causing $71 million in losses. The post Vietnamese Members of FIN9 Hacking Group Charged in US appeared first on SecurityWeek. This article has been indexed from SecurityWeek…

US Sanctions 12 Kaspersky Executives

The US has imposed sanctions on 12 individuals who have leadership roles at Kaspersky in Russia and the UK. The post US Sanctions 12 Kaspersky Executives  appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read…

Facial Recognition Startup Clearview AI Settles Privacy Suit

Facial recognition startup Clearview AI has reached a settlement in an Illinois lawsuit alleging its massive photographic collection of faces violated the subjects’ privacy rights. The post Facial Recognition Startup Clearview AI Settles Privacy Suit appeared first on SecurityWeek. This…

Recent SolarWinds Serv-U Vulnerability Exploited in the Wild

Threat actors are exploiting a recent path traversal vulnerability in SolarWinds Serv-U using public PoC code. The post Recent SolarWinds Serv-U Vulnerability Exploited in the Wild appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read…

Santander Employee Data Breach Linked to Snowflake Attack

Santander US is notifying over 12,000 employees that their personal information was compromised in a data breach. The post Santander Employee Data Breach Linked to Snowflake Attack appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed…

Access Management Startup Pomerium Raises $13.75 Million

Pomerium raises $13.75 million in Series A funding for dynamic user identity verification and access management platform. The post Access Management Startup Pomerium Raises $13.75 Million appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read…

Highly Evasive SquidLoader Malware Targets China

A threat actor targeting Chinese-speaking victims has been using the SquidLoader malware loader in recent attacks. The post Highly Evasive SquidLoader Malware Targets China appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the original…

Semperis Eyes IPO With $125 Million in Growth Financing

Enterprise identity company raises new capital from JP Morgan and Hercules Capital as it prepares for an IPO exit. The post Semperis Eyes IPO With $125 Million in Growth Financing appeared first on SecurityWeek. This article has been indexed from…

Post-Quantum Cryptography Firm PQShield Raises $37 Million

Post-quantum cryptography (PQC) company PQShield has raised $37 million in Series B funding for its quantum-safe cryptography solutions. The post Post-Quantum Cryptography Firm PQShield Raises $37 Million appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed…

Atlassian Patches High-Severity Vulnerabilities in Confluence, Crucible, Jira

Atlassian has released Confluence, Crucible, and Jira updates to address multiple high-severity vulnerabilities. The post Atlassian Patches High-Severity Vulnerabilities in Confluence, Crucible, Jira appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the original article:…

Massachusetts 911 Outage Caused by Errant Firewall

A statewide outage of the Massachusetts 911 system was the result of a firewall that blocked calls from reaching emergency responders. The post Massachusetts 911 Outage Caused by Errant Firewall appeared first on SecurityWeek. This article has been indexed from…

Cybersecurity M&A Roundup for First Half of June 2024

Roundup of the cybersecurity-related merger and acquisition (M&A) deals announced in the first half of June 2024. The post Cybersecurity M&A Roundup for First Half of June 2024 appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS…

US, Allies Publish Guidance on Securing Network Access

Government agencies in the US, New Zealand, and Canada have published new guidance on improving network security. The post US, Allies Publish Guidance on Securing Network Access appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed…

The Perilous Role of the CISO: Navigating Modern Minefields

As organizations grapple with the implications of cybersecurity on their bottom line and reputation, the question of whether the CISO role is worth the inherent risks looms large. The post The Perilous Role of the CISO: Navigating Modern Minefields appeared…

AMD Investigating Breach Claims After Hacker Offers to Sell Data

AMD has launched an investigation after a notorious hacker announced selling sensitive data allegedly belonging to the company. The post AMD Investigating Breach Claims After Hacker Offers to Sell Data appeared first on SecurityWeek. This article has been indexed from…

Non-human Identity Lifecycle Firm Entro Security Raises $18 Million

Entro’s platform is designed to bring order to the increasingly chaotic management of non-human identities. The post Non-human Identity Lifecycle Firm Entro Security Raises $18 Million appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read…

New BadSpace Backdoor Deployed in Drive-By Attacks

The BadSpace backdoor is being distributed via drive-by attacks involving infected websites and JavaScript downloaders. The post New BadSpace Backdoor Deployed in Drive-By Attacks appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the original…

Insurance Company Globe Life Investigating Data Breach

US insurance company Globe Life is investigating a data breach involving unauthorized access to consumer and policyholder information.  The post Insurance Company Globe Life Investigating Data Breach appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed…

Keytronic Says Personal Information Stolen in Ransomware Attack

Keytronic confirms that personal information was compromised after a ransomware group leaked allegedly stolen data. The post Keytronic Says Personal Information Stolen in Ransomware Attack appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the…

CISA Conducts First AI Cyber Incident Response Exercise

The US cybersecurity agency CISA has conducted a tabletop exercise with the private sector focused on AI cyber incident response. The post CISA Conducts First AI Cyber Incident Response Exercise appeared first on SecurityWeek. This article has been indexed from…

Ascension Says Personal, Health Information Stolen in Ransomware Attack

Ascension says patient information was stolen in an early-May ransomware attack that involved an employee downloading malware. The post Ascension Says Personal, Health Information Stolen in Ransomware Attack appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS…

Edge Devices: The New Frontier for Mass Exploitation Attacks

The increase in mass exploitation involving edge services and devices is likely to worsen. The post Edge Devices: The New Frontier for Mass Exploitation Attacks appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the…

Pakistani Threat Actors Caught Targeting Indian Gov Entities

Security researchers at Cisco Talos and Volexity flag two Pakistani espionage campaigns targeting Indian government entities. The post Pakistani Threat Actors Caught Targeting Indian Gov Entities appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read…

Microsoft Delaying Recall Feature to Improve Security

Microsoft is not rolling out Recall with Copilot+ PCs as it’s seeking additional feedback and working on improving security. The post Microsoft Delaying Recall Feature to Improve Security appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS…

CISA Warns of Progress Telerik Vulnerability Exploitation

CISA urges federal agencies to apply mitigations for an exploited Progress Telerik vulnerability as soon as possible. The post CISA Warns of Progress Telerik Vulnerability Exploitation appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read…

AWS Announces Authentication and Malware Protection Enhancements

AWS announced passkey MFA for IAM and root users, IAM Access Analyzer updates, and Amazon GuardDuty Malware Protection for S3. The post AWS Announces Authentication and Malware Protection Enhancements appeared first on SecurityWeek. This article has been indexed from SecurityWeek…

Pyte Raises $5 Million for Secure Data Collaboration Solutions

Pyte has raised $5 million for its secure computation platform, bringing the total investment in the company to $12 million.  The post Pyte Raises $5 Million for Secure Data Collaboration Solutions appeared first on SecurityWeek. This article has been indexed…

French Bug Bounty Platform YesWeHack Raises $28 Million

YesWeHack has raised more than $52 million to date to build and market a crowdsourced vulnerability reporting platform. The post French Bug Bounty Platform YesWeHack Raises $28 Million appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS…

Fortinet Patches Code Execution Vulnerability in FortiOS

Fortinet has patched multiple vulnerabilities in FortiOS, including a high-severity code execution security flaw. The post Fortinet Patches Code Execution Vulnerability in FortiOS appeared first on SecurityWeek. This article has been indexed from SecurityWeek RSS Feed Read the original article:…

Ransomware Group May Have Exploited Windows Vulnerability as Zero-Day

The Black Basta ransomware gang may have exploited the Windows privilege escalation flaw CVE-2024-26169 before it was patched. The post Ransomware Group May Have Exploited Windows Vulnerability as Zero-Day appeared first on SecurityWeek. This article has been indexed from SecurityWeek…