Latest Cybersecurity News and Articles
21 November 2023
Business logic attacks, which exploit the intended functionality of applications and APIs, have increased in the past year, making up 42.6% of attacks on retail sites and highlighting the vulnerability of the e-commerce industry.
21 November 2023
Interview with Craig Martell, Chief Digital and AI Officer (CDAO) for the U.S. Department of Defense, about AI use in the military.
The post Insider Q&A: Pentagon AI Chief on Network-Centric Warfare, Generative AI Challenges appeared first on SecurityWeek.
21 November 2023
Over the past ten years, Microsoft has handed out $63 million in rewards as part of its bug bounty programs.
The post Microsoft Paid Out $63 Million Since Launch of First Bug Bounty Program 10 Years Ago appeared first on SecurityWeek.
21 November 2023
Sumo Logic has completed its investigation into the recent security breach and found no evidence of impact to customer data.
The post Sumo Logic Completes Investigation Into Recent Security Breach appeared first on SecurityWeek.
21 November 2023
Wireshark 4.2.0 introduces notable improvements, such as enhanced packet list sorting and smarter display filter autocomplete. It supports a wide range of new protocols, including HTTP/3, SAP protocols, Zigbee TLV, and VMware HeartBeat.
21 November 2023
Phishing attacks are steadily becoming more sophisticated, with cybercriminals investing in new ways of deceiving victims into revealing sensitive information or installing malicious software. One of the latest trends in phishing is the use of QR codes, CAPTCHAs, and steganography. See how they are carried out and learn to detect them.
Quishing
Quishing, a phishing technique resulting from the
21 November 2023
Threat actors are targeting the education, government, and business services sectors with a remote access trojan called NetSupport RAT. The malware is typically downloaded onto a victim's computer through deceptive websites and fake browser updates.
21 November 2023
The Kinsing threat actors are actively exploiting a critical security flaw in vulnerable Apache ActiveMQ servers to infect Linux systems with cryptocurrency miners and rootkits.
"Once Kinsing infects a system, it deploys a cryptocurrency mining script that exploits the host's resources to mine cryptocurrencies like Bitcoin, resulting in significant damage to the infrastructure and a negative
21 November 2023
The CISA is pushing for manufacturers and vendors to take responsibility for the security of their products. CISA wants detailed data and logs from technology companies to prove they are incorporating security measures.
21 November 2023
The use of the ZPAQ compression format by threat actors in this malware campaign highlights the need for improved security measures and awareness regarding lesser-known archive tools.
21 November 2023
Researchers from the Electronic Frontier Foundation have discovered that the Dragon Touch KidzPad Y88X 10 tablet, sold on Amazon, contains malware and preinstalled riskware. The tablet also comes with an outdated parental control app called KIDOZ.
21 November 2023
The Rhysida ransomware gang, responsible for the attack, has leaked data stolen from the library's internal HR files, prompting the library to advise users to change their passwords as a precautionary measure.
21 November 2023
Android smartphone users in India are the target of a new malware campaign that employs social engineering lures to install fraudulent apps that are capable of harvesting sensitive data.
“Using social media platforms like WhatsApp and Telegram, attackers are sending messages designed to lure users into installing a malicious app on their mobile device by impersonating legitimate organizations,
21 November 2023
The China-linked Mustang Panda actor has been linked to a cyber attack targeting a Philippines government entity amid rising tensions between the two countries over the disputed South China Sea.
Palo Alto Networks Unit 42 attributed the adversarial collective to three campaigns in August 2023, primarily singling out organizations in the South Pacific.
"The campaigns leveraged legitimate software
20 November 2023
The Royal Mail has revealed the financial impact of a ransomware attack it suffered earlier this year. The attack caused severe disruption to its international services and resulted in a decline in revenue and parcel volumes.
20 November 2023
The investigator's victims included high-profile climate change activists, and their hacked communications were leaked to media outlets to undermine investigations into Exxon's knowledge about climate change risks.
20 November 2023
Access-as-a-service (AaaS) is a new underground business model in cybercrime where threat actors steal enterprise user credentials and sell them to other attack groups, leading to the exfiltration of confidential data.
20 November 2023
Johnson Controls has released patches for a critical vulnerability found in some of its industrial refrigeration products. The flaw, known as CVE-2023-4804, could allow unauthorized access to debug features.
20 November 2023
The funding opportunity includes investments in technologies, tools, training, and processes to strengthen cybersecurity, as well as increasing access to technical assistance and training for organizations with limited resources.
20 November 2023
FortiGuard Labs has identified a Russian-language Word document with a malicious macro in the ongoing Konni campaign. The campaign uses a remote access trojan (RAT) to gain control of infected systems.