Latest Cybersecurity News and Articles
06 December 2023
Third-party data breaches against energy organizations were analyzed in a recent report, finding that 90% of global organizations have had a breach.
06 December 2023
According to a recent Claroty report, 75% of respondents reported being targeted by ransomware in the past year and 69% paid the ransom.
06 December 2023
Healthcare of Ontario Pension Plan (HOOPP) has announced Jennifer Williams will be the new Vice President, Information Security.
06 December 2023
More than five years after domain name registrars started redacting personal data from all public domain registration records, the non-profit organization overseeing the domain industry has introduced a centralized online service designed to make it easier for researchers, law enforcement and others to request the information directly from registrars.
06 December 2023
In Episode 18 of The Cybersecurity & Geopolitical Discussion, Lisa Forte, Phil Ingram and Ian Thornton-Trump discuss the impact of cryptocurrency on geopolitical and economic conflict.
06 December 2023
According to a new report, documents that had been shared externally often contained confidential information, with 18,000 files flagged as having “highly sensitive” data, like PII.
06 December 2023
According to a report, 42% of organizations say employees with BYOD policies that use tools like WhatsApp have led to new security incidents.
06 December 2023
Seoul police have seized the servers and virtual asset exchanges used by Andariel, arrested the person involved in transferring ransomware funds, and advised organizations to strengthen their cybersecurity measures to prevent future attacks.
06 December 2023
Battery Ventures and PayPal Ventures are co-leading this round, with participation also from Nationwide Ventures and all its previous backers, including Saban Ventures, Gradient Ventures, MassMutual Ventures, and Headline Ventures.
06 December 2023
Threat actors can take advantage of Amazon Web Services Security Token Service (AWS STS) as a way to infiltrate cloud accounts and conduct follow-on attacks.
The service enables threat actors to impersonate user identities and roles in cloud environments, Red Canary researchers Thomas Gardner and Cody Betsworth said in a Tuesday analysis.
AWS STS is a web service that enables
06 December 2023
Admins are advised to upgrade to the latest ALEOS version, change default SSL certificates, disable non-essential services, implement web application firewalls, and install an OT/IoT-aware IDS for enhanced protection against these vulnerabilities.
06 December 2023
Hackers can manipulate Lockdown Mode to provide visual cues of activation without actually implementing any protections. Lockdown Mode should not be relied upon as a comprehensive security measure and users should be aware of its limitations.
06 December 2023
These apps trick users into providing sensitive personal and financial information, which is then used to blackmail them. The apps focus on users in Southeast Asia, Africa, and Latin America.
06 December 2023
Compromising the browser is a high-return target for adversaries. Browser extensions, which are small software modules that are added to the browser and can enhance browsing experiences, have become a popular browser attack vector. This is because they are widely adopted among users and can easily turn malicious through developer actions or attacks on legitimate extensions.
Recent incidents like
06 December 2023
A collection of 21 security flaws have been discovered in Sierra Wireless AirLink cellular routers and open-source software components like TinyXML and OpenNDS.
Collectively tracked as Sierra:21, the issues expose over 86,000 devices across critical sectors like energy, healthcare, waste management, retail, emergency services, and vehicle tracking to cyber threats, according
06 December 2023
Kali Linux 2023.4, the latest version of the Linux distribution for ethical hackers and cybersecurity professionals, has been released. It includes fifteen new tools and the GNOME 45 desktop environment.
06 December 2023
IT services company HTC Global Services has confirmed that it has suffered a cyberattack. The ALPHV ransomware gang has leaked screenshots of stolen data, including passports, contact lists, emails, and confidential documents.
06 December 2023
Chipmaker Qualcomm has released more information about three high-severity security flaws that were exploited in targeted attacks in October 2023. The vulnerabilities involve memory corruption in DSP Services and Graphics.
06 December 2023
In an increasingly complex and fast-paced digital landscape, organizations strive to protect themselves from various security threats. However, limited resources often hinder security teams when combatting these threats, making it difficult to keep up with the growing number of security incidents and alerts. Implementing automation throughout security operations helps security teams alleviate
06 December 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned of active exploitation of a high-severity Adobe ColdFusion vulnerability by unidentified threat actors to gain initial access to government servers.
"The vulnerability in ColdFusion (CVE-2023-26360) presents as an improper access control issue and exploitation of this CVE can result in arbitrary code execution,"