Latest Cybersecurity News and Articles
22 November 2023
Microsoft invites researchers to new bug bounty program focused on vulnerabilities in its Defender products.
The post Microsoft Offers Up to $20,000 for Vulnerabilities in Defender Products appeared first on SecurityWeek.
22 November 2023
Customers, investors, and suppliers are increasingly seeking proof of security and compliance, and companies that cannot provide evidence may miss out on revenue and growth opportunities.
22 November 2023
North Korean threat actors have been linked to two campaigns in which they masquerade as both job recruiters and seekers to distribute malware and obtain unauthorized employment with organizations based in the U.S. and other parts of the world.
The activity clusters have been codenamed Contagious Interview and Wagemole, respectively, by Palo Alto Networks Unit 42.
While the first set of attacks
22 November 2023
When too much subjectivity is mixed into risk assessment, it can produce a risk picture that is not an accurate representation of reality.
The post Humans Are Notoriously Bad at Assessing Risk appeared first on SecurityWeek.
22 November 2023
Researchers from Unit 42 have discovered two separate campaigns, named Contagious Interview and Wagemole, targeting job seekers. These campaigns are linked to state-sponsored threat actors associated with North Korea.
22 November 2023
Cybercriminals hacked into the Kansas court system, stole sensitive data and threatened to post it on the dark web in a ransomware attack that has hobbled access to records.
The post Kansas Officials Blame 5-Week Disruption of Court System on ‘Sophisticated Foreign Cyberattack’ appeared first on SecurityWeek.
22 November 2023
Retailers are preparing for a surge in cyber threats during the Thanksgiving holiday and Black Friday weekend. Phishing attacks are a major concern, with threat groups using social engineering to bypass security measures.
22 November 2023
Ambitious Employees Tout New AI Tools, Ignore Serious SaaS Security RisksLike the SaaS shadow IT of the past, AI is placing CISOs and cybersecurity teams in a tough but familiar spot.
Employees are covertly using AI with little regard for established IT and cybersecurity review procedures. Considering ChatGPT’s meteoric rise to 100 million users within 60 days of launch, especially with little
22 November 2023
Administrators are urged to patch the recent CitrixBleed NetScaler vulnerability as LockBit starts exploiting it.
The post Citrix, Gov Agencies Issue Fresh Warnings on CitrixBleed Vulnerability appeared first on SecurityWeek.
22 November 2023
The attack on Kronos Research involved unauthorized access to the company's API keys, highlighting the importance of robust security measures in protecting against modern API attacks.
22 November 2023
With a significant increase in interest expected, organizations must quickly bridge the gap between generative AI tool usage and security by implementing measures such as zero-trust architecture and thorough security risk assessments.
22 November 2023
The vulnerability, known as "Looney Tunables" and tracked as CVE-2023-4911, allows attackers to gain root privileges on major Linux distributions. It affects popular platforms like Fedora, Ubuntu, and Debian.
22 November 2023
Attackers are exploiting CAPTCHA-based attacks by using CloudFlare's CAPTCHAs and randomized domain names to mask credential-harvesting forms on fake websites, making it difficult for automated security systems to identify them.
22 November 2023
CISA has added a critical pre-auth command injection vulnerability in Sophos Web Appliance to its Known Exploited Vulnerabilities catalog, which was patched by the company in April 2023.
22 November 2023
Threat actors targeting small- and medium-sized businesses are increasingly using legitimate tools like remote monitoring and management software to evade detection and gain unauthorized access to networks.
22 November 2023
The Cybersecurity and Infrastructure Security Agency (CISA), FBI, MS-ISAC, and ASD's ACSC have released a joint advisory in response to LockBit 3.0 ransomware affiliates exploiting a vulnerability in Citrix's NetScaler web application control.
22 November 2023
The macOS information stealer known as Atomic is now being delivered to target via a bogus web browser update chain tracked as ClearFake.
"This may very well be the first time we see one of the main social engineering campaigns, previously reserved for Windows, branch out not only in terms of geolocation but also operating system," Malwarebytes' Jérôme Segura said in a Tuesday analysis.
Atomic
21 November 2023
Multiple threat actors, including LockBit ransomware affiliates, are actively exploiting a recently disclosed critical security flaw in Citrix NetScaler application delivery control (ADC) and Gateway appliances to obtain initial access to target environments.
The joint advisory comes from the U.S. Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI),
21 November 2023
The Information Commissioner’s Office (ICO) said that a complaint was first lodged back in June 2019, after a patient raised concerns that their records had been improperly accessed by Loretta Alborghetti, from Redditch.
21 November 2023
Play ransomware attacks have shown little variation, suggesting that affiliates are following predefined playbooks provided with the RaaS, using identical tactics and commands.