Latest Cybersecurity News and Articles
10 November 2023
The State of Maine says the personal information of 1.3 million individuals was compromised in the MOVEit attack.
The post 1.3 Million Maine Residents Impacted by MOVEit Hack appeared first on SecurityWeek.
10 November 2023
The LockBit ransomware gang claimed responsibility for the breach and leaked stolen data, including passport scans and financial documents, potentially exposing proprietary designs and patented information.
10 November 2023
A ransomware attack on China’s biggest bank, the Industrial and Commercial Bank of China Financial Services, disrupts Treasury market trades.
The post Ransomware Attack on China’s Biggest Bank Disrupts Treasury Market Trades, Reports Say appeared first on SecurityWeek.
10 November 2023
Cybersecurity company SentinelOne is acquiring advisory firm Krebs Stamos Group to create a new entity called PinnacleOne Strategic Advisory Group, with Christopher Krebs and Alex Stamos taking on key positions.
10 November 2023
Germany's National Security Strategy envisions the establishment of a dedicated entity for offensive cyber operations, although it rejects the use of hack-backs as a means of cyber defense.
10 November 2023
The use of a reverse proxy in this phishing campaign allows the attackers to bypass multi-factor authentication (MFA) and gain access to victims' Microsoft 365 accounts, leading to further distribution of phishing emails.
10 November 2023
MGM Resorts is investing $40 million in IT upgrades next year and is facing multiple class-action lawsuits and potential financial losses from legal proceedings related to the attack.
10 November 2023
The hacking tool is distributed through Telegram channels linked to hacking communities and focuses on facilitating web application attacks on commonly used technologies.
10 November 2023
The privacy feature builds upon previous measures such as "Silence Unknown Callers" to protect users from unwanted contact and minimize the risk of zero-click attacks and spyware.
10 November 2023
The group initially threatened victims with European data breach fines but later offered to sell the entire operation, including domain names, breached company access, and databases.
10 November 2023
GitHub is leveraging AI to enhance its secret scanning program, allowing code maintainers to create custom patterns for detecting organization-specific secrets and improving scanning accuracy.
10 November 2023
There is a seemingly never-ending quest to find the right security tools that offer the right capabilities for your organization.
SOC teams tend to spend about a third of their day on events that don’t pose any threat to their organization, and this has accelerated the adoption of automated solutions to take the place of (or augment) inefficient and cumbersome SIEMs.
With an estimated 80% of
10 November 2023
Cybersecurity researchers have discovered a stealthy backdoor named Effluence that's deployed following the successful exploitation of a recently disclosed security flaw in Atlassian Confluence Data Center and Server.
"The malware acts as a persistent backdoor and is not remediated by applying patches to Confluence," Aon's Stroz Friedberg Incident Response Services said in an analysis published
10 November 2023
While AI tools make fraud campaigns more convincing, users can still protect themselves by being cautious of phishing emails, recognizing warning signs, and following online shopping guidance provided by the NCSC.
10 November 2023
The London-based company offers a collaborative platform that helps organizations identify and mitigate supply chain security risks in real time. The funding will be used to advance product development and deepen partnerships in key industries.
10 November 2023
The breach was a result of the group failing to apply a firmware patch to fix a zero-day vulnerability in their SonicWall firewall, highlighting the importance of promptly updating and securing computer hardware and systems.
10 November 2023
Organizations should implement security measures such as regular backups, vendor security reviews, strong user account security, and network monitoring to mitigate the risk of ransomware attacks.
10 November 2023
A group with links to Iran targeted transportation, logistics, and technology sectors in the Middle East, including Israel, in October 2023 amid a surge in Iranian cyber activity since the onset of the Israel-Hamas war.
The attacks have been attributed by CrowdStrike to a threat actor it tracks under the name Imperial Kitten, and which is also known as Crimson Sandstorm (previously Curium),
10 November 2023
The attack generated one million requests per second (RPS), four times larger than any previous attack on the bank. Sberbank believes that new, highly skilled hackers are targeting major Russian resources.
10 November 2023
Urdu-speaking readers of a regional news website that caters to the Gilgit-Baltistan region have likely emerged as a target of a watering hole attack designed to deliver a previously undocumented Android spyware dubbed Kamran.
The campaign, ESET has discovered, leverages Hunza News (urdu.hunzanews[.]net), which, when opened on a mobile device, prompts visitors of the Urdu version to install its