Latest Cybersecurity News and Articles
08 November 2023
The gang has posted allegedly stolen data and threatened to release more if there is no reaction. The county is investigating the incident and working with law enforcement and cybersecurity experts.
08 November 2023
SaaS applications make up 70% of total company software usage, and as businesses increase their reliance on SaaS apps, they also increase their reliance on those applications being secure. These SaaS apps store an incredibly large volume of data so safeguarding the organization's SaaS app stack and data within is paramount. Yet, the path to implementing an effective SaaS security program is not
08 November 2023
The malware is believed to be a late stage in a multi-stage attack delivered via social engineering, targeting companies in the cryptocurrency industry or those closely associated with it.
08 November 2023
Cybersecurity researchers have unmasked a prolific threat actor known as farnetwork, who has been linked to five different ransomware-as-a-service (RaaS) programs over the past four years in various capacities.
Singapore-headquartered Group-IB, which attempted to infiltrate a private RaaS program that uses the Nokoyawa ransomware strain, said it underwent a "job interview" process with the
08 November 2023
What challenges do aspiring cybersecurity leaders face? Answer this question and more with George Gerchow, Chief Security Officer at Sumo Logic.
08 November 2023
Financial institutions work to improve payment data security.
07 November 2023
A new survey found that fraud attacks on call centers are on the rise, based on growth from 2021 to 2022, with financial industry respondents noting an even more acute increase.
07 November 2023
This attack on the flour plant is part of a series of cyber attacks by the group on Israeli organizations, including a successful attack on the Ashalim Power Station and taking control of military servers and systems.
07 November 2023
Five Canadian hospitals have confirmed that patient and employee data stolen in a ransomware attack has been leaked online, impacting millions of patient visits and employee information.
07 November 2023
GootBot is designed to connect to compromised WordPress sites for command and control, making use of unique hard-coded C2 servers for each sample, posing a challenge for detection and prevention.
07 November 2023
Veeam Software has rolled out patches to cover code execution vulnerabilities in its Veeam ONE IT monitoring product.
The post Critical Vulnerabilities Expose Veeam ONE Software to Code Execution appeared first on SecurityWeek.
07 November 2023
The November 2023 Android security update addresses high-severity vulnerabilities in the System component, with additional fixes for Arm, MediaTek, and Qualcomm components.
07 November 2023
Foreign threat actors can easily obtain sensitive information on US military members from data brokers, a Duke University study shows.
The post Data Brokers Expose Sensitive US Military Member Info to Foreign Threat Actors: Study appeared first on SecurityWeek.
07 November 2023
The database contained over 3.3 million orders from 2015 to 2020, many of which included uploaded copies of customers' government-issued identity cards. The vulnerability was addressed after a security researcher notified the store owners.
07 November 2023
These policies will also require MFA for per-user MFA users for all cloud apps and for high-risk sign-ins. The policies will be gradually added to eligible Microsoft tenants, and administrators will have 90 days to review and enable them.
07 November 2023
The Jupyter Infostealer malware has resurfaced with new techniques, including PowerShell command modifications and the use of signed certificates, to establish a persistent presence on compromised systems.
07 November 2023
SIM box fraud is a type of “interconnected bypass” scam, where threat actors intercept international calls and route them to a local device known as a SIM box. This device then routes the connection back into the network as a local call.
07 November 2023
Internet-exposed Apache ActiveMQ servers are being targeted by ransomware attacks exploiting a critical remote code execution vulnerability. Over 4,770 vulnerable Apache ActiveMQ servers are at risk of exploitation.
07 November 2023
New macOS malware, tracked by Jamf as ObjCShellz, is likely being used by North Korean hackers to target crypto exchanges
The post New MacOS Malware Linked to North Korean Hackers appeared first on SecurityWeek.
07 November 2023
The North Korea-linked nation-state group called BlueNoroff has been attributed to a previously undocumented macOS malware strain dubbed ObjCShellz.
Jamf Threat Labs, which disclosed details of the malware, said it's used as part of the RustBucket malware campaign, which came to light earlier this year.
"Based on previous attacks performed by BlueNoroff, we suspect that this malware was a late