Latest Cybersecurity News and Articles
14 November 2023
According to a recent ThreatX report, 97% of consumers are concerned that cyberattacks will continue to grow in volume over the next year.
14 November 2023
A targeted campaign against the gaming community exploits Discord channels and fake download sites to distribute types of information-stealing malware. Multiple information stealer families, including BBy Stealer, Nova Sentinel, Doenerium, and Epsilon Stealer, were identified. To counter similar threats, online gamers are urged to download software exclusively from official and trustworthy websites.
14 November 2023
Patch Tuesday: Redmond’s security response team flags two vulnerabilities -- CVE-2023-36033 and CVE-2023-36036 -- already being exploited in the wild.
The post Microsoft Warns of Critical Bugs Being Exploited in the Wild appeared first on SecurityWeek.
14 November 2023
A group of academics has disclosed a new "software fault attack" on AMD's Secure Encrypted Virtualization (SEV) technology that could be potentially exploited by threat actors to infiltrate encrypted virtual machines (VMs) and even perform privilege escalation.
The attack has been codenamed CacheWarp (CVE-2023-20592) by researchers from the CISPA Helmholtz Center for Information Security. It
14 November 2023
The Royal ransomware gang, now known as BlackSuit, has undergone a strategic rebranding, unveiled in a joint advisory by CISA and the FBI. This shift, observed since November 2022, involves advanced encryption methods and sophisticated attack vectors, emphasizing the exploitation of vulnerabilities in public-facing applications and remote desktop protocols.
14 November 2023
According to a recent zero trust and data protection report, one of six organizations experienced multiple losses of data in the past 12 months.
14 November 2023
Adobe patches 72 security bugs and calls special attention to code-execution defects in the widely deployed Acrobat and Reader software.
The post Adobe Patch Tuesday: Critical Bugs in Acrobat, Reader, ColdFusion appeared first on SecurityWeek.
14 November 2023
CacheWarp is a new attack method affecting a security feature present in AMD processors that can pose a risk to virtual machines.
The post Protected Virtual Machines Exposed to New ‘CacheWarp’ AMD CPU Attack appeared first on SecurityWeek.
14 November 2023
New York City and Washington DC-based startup Zip Security raised $7.7 million seed financing led by General Catalyst, co-led by Human Capital, and with participation from Box Group.
The post Zip Raises $7.7 Million to Expand SMB Cybersecurity Business appeared first on SecurityWeek.
14 November 2023
Britain’s cybersecurity agency said that artificial intelligence poses a threat to the country’s next election, and cyberattacks by hostile countries and their proxies are getting harder to track.
The post UK Cybersecurity Center Says ‘Deepfakes’ and Other AI Tools Pose a Threat to the Next Election appeared first on SecurityWeek.
14 November 2023
According to a recent ThreatQuotient survey, 75% of security professionals say cybersecurity automation is important, up from 68% last year.
14 November 2023
TA402 has recently employed a new initial access downloader called IronWind, using various infection chains and delivery methods such as Dropbox links, XLL and RAR file attachments, in order to evade detection.
14 November 2023
The attackers utilize deceptive tactics, such as sending archive files disguised as PDFs, to trick victims into launching malicious executables and gain unauthorized access to their accounts.
14 November 2023
The Medusa ransomware gang demanded a $6 million ransom, but Moneris stated that its security team stopped access to critical data and no ransom request was made. The company didn't disclose when the breach was attempted or whether it paid a ransom.
14 November 2023
Researchers warn attackers are targeting MySQL servers and Docker hosts to plant malware capable of launching distributed DDoS attacks.
The post MySQL Servers, Docker Hosts Infected With DDoS Malware appeared first on SecurityWeek.
14 November 2023
CISA says Royal ransomware has targeted 350 organizations to date, demanding over $275 million in ransoms.
The post Royal Ransomware Possibly Rebranding After Targeting 350 Organizations Worldwide appeared first on SecurityWeek.
14 November 2023
Hackers linked to the Russian GRU targeted Danish critical infrastructure, exploiting vulnerabilities in Zyxel firewalls and demonstrating meticulous planning and coordination.
14 November 2023
Radiant Security gets $15 million in new financing as investors double down on early stage companies experimenting with AI technology.
The post Radiant Snags $15 Million for AI-Powered SOC Technology appeared first on SecurityWeek.
14 November 2023
Siemens and Schneider Electric’s Patch Tuesday advisories for November 2023 address 90 vulnerabilities affecting their products.
The post ICS Patch Tuesday: 90 Vulnerabilities Addressed by Siemens and Schneider Electric appeared first on SecurityWeek.
14 November 2023
DP World is working to restore normal operations and investigate the possibility of data access and theft, engaging with cybersecurity experts and the Office of the Australian Information Commissioner.