Latest Cybersecurity News and Articles
09 November 2023
Cloud adoption and cybersecurity spending for small and medium businesses (SMBs) was analyzed in a recent report by DigitalOcean Holdings.
09 November 2023
The threat actor known as Lace Tempest has been linked to the exploitation of a zero-day flaw in SysAid IT support software in limited attacks, according to new findings from Microsoft.
Lace Tempest, which is known for distributing the Cl0p ransomware, has in the past leveraged zero-day flaws in MOVEit Transfer and PaperCut servers.
The issue, tracked as CVE-2023-47246, concerns a path traversal
09 November 2023
A medical company has been fined $450,000 by the New York AG over a data breach that may have involved exploitation of a SonicWall vulnerability.
The post Medical Company Fined $450,000 by New York AG Over Data Breach appeared first on SecurityWeek.
09 November 2023
The Russia-linked hacker group Anonymous Sudan claimed responsibility for the DDoS attacks, targeting OpenAI due to its support for Israel and alleged bias in ChatGPT against Palestine.
09 November 2023
The Washington, DC startup is building a threat-informed defense platform that helps organizations automate detection and response work.
The post Tidal Cyber Raises $5 Million for Threat-Informed Defense Platform appeared first on SecurityWeek.
09 November 2023
As organizations increasingly use QR codes, it seems QR code phishing AKA "quishing" is also on the rise with a 51% increase in September.
09 November 2023
The breach exposed sensitive patient data, including names, birthdates, addresses, medical information, and potentially Social Security numbers, emphasizing the risk of identity theft and healthcare fraud.
09 November 2023
A report found that 70% of developers and 52% of chief information security officers view software supply chain security as a top priority.
09 November 2023
A new malvertising campaign has been observed wherein threat actors are copying a legitimate Windows news portal to promote a malicious installer for the popular processor tool CPU-Z. Based on the infrastructure, domain names, and cloaking templates used, researchers believe the incident is part of a larger malvertising campaign targeting other utilities such as Notepad++, Citrix, and VNC Viewer.
09 November 2023
A new set of malicious Python packages has been discovered on the Python Package Index (PyPI) repository. These packages masquerade as harmless obfuscation tools but contain a malware called BlazeStealer. The campaign started in January 2023 and includes eight packages. Developers must stay alert and thoroughly assess the reliability and safety of packages before incorporating them into their work.
09 November 2023
Checkmarx uncovers a malicious campaign targeting Python developers with malware that takes over their systems.
The post ‘BlazeStealer’ Malware Delivered to Python Developers Looking for Obfuscation Tools appeared first on SecurityWeek.
09 November 2023
The attack was not driven by military necessity but rather aimed to increase the psychological toll of the war, showcasing Russia's focus on disrupting and degrading military readiness through cyber means.
09 November 2023
ChatGPT and its API have experienced a major outage due to a DDoS attack apparently launched by Anonymous Sudan.
The post Major ChatGPT Outage Caused by DDoS Attack appeared first on SecurityWeek.
09 November 2023
A new malvertising campaign has been found to employ fake sites that masquerade as legitimate Windows news portal to propagate a malicious installer for a popular system profiling tool called CPU-Z.
"This incident is a part of a larger malvertising campaign that targets other utilities like Notepad++, Citrix, and VNC Viewer as seen in its infrastructure (domain names) and cloaking templates used
09 November 2023
The vulnerability, tracked as CVE-2023-47246, allows for arbitrary code execution and has been exploited by a threat actor known as Lace Tempest, who is associated with the deployment of Cl0p ransomware.
09 November 2023
The U.S. is still the first most breached country in Q3 2023 despite a decrease in breach count, according to a recent report.
09 November 2023
The vulnerability allows an unauthenticated, remote attacker to register services and use spoofed UDP traffic to conduct a DoS attack with a significant amplification factor, making it a serious threat to network and server security.
09 November 2023
MuddyC2Go allows the threat actors to automate the connection to their command-and-control server using an embedded PowerShell script, eliminating the need for manual execution.
09 November 2023
UK-based Risk Ledger has raised £6.25 million (~$7.65 million) in Series A funding to prevent supply chain attacks.
The post Risk Ledger Raises £6.25 Million for Supply Chain Security Solution appeared first on SecurityWeek.
09 November 2023
Japan Aviation Electronics confirms cyberattack as Alphv/BlackCat ransomware group publishes allegedly stolen data.
The post Japan Aviation Electronics Targeted in Ransomware Attack appeared first on SecurityWeek.