Latest Cybersecurity News and Articles


How Global Password Practices are Changing

07 November 2023
Password health and hygiene have improved globally over the past year, reducing the risk of account takeover. However, password reuse remains prevalent, making user accounts vulnerable to password-spraying attacks.

Free Tool Helps Industrial Organizations Find OPC UA Vulnerabilities

07 November 2023
A new free tool named OpalOPC helps industrial organizations find OPC UA misconfigurations and vulnerabilities. The post Free Tool Helps Industrial Organizations Find OPC UA Vulnerabilities appeared first on SecurityWeek.

Update: Critical Atlassian Bug Exploited in Ransomware Attacks

07 November 2023
The vulnerability, known as CVE-2023-22518, impacts all versions of Atlassian Confluence Data Center and Server, and users are strongly advised to update to the latest version to mitigate the risk.

The Roadblocks to Preventive Cybersecurity Success

07 November 2023
Cloud infrastructure poses the greatest exposure risk for organizations, requiring effective integration of user identity and access privileges into preventive cybersecurity practices.

37 Vulnerabilities Patched in Android With November 2023 Security Updates

07 November 2023
The Android security updates released this week resolve 37 vulnerabilities, including a critical information disclosure bug. The post 37 Vulnerabilities Patched in Android With November 2023 Security Updates appeared first on SecurityWeek.

Veeam Patches Two Critical Bugs in Veeam ONE

07 November 2023
In a security update yesterday, the firm revealed CVE-2023-38547, a CVSS 9.9-rated flaw in Veeam ONE 11, 11a, and 12. The second critical bug (CVE-2023-38548) affects Veeam ONE version 12 and has a CVSS score of 9.8.

New GootLoader Malware Variant Evades Detection and Spreads Rapidly

07 November 2023
A new variant of the GootLoader malware called GootBot has been found to facilitate lateral movement on compromised systems and evade detection. "The GootLoader group's introduction of their own custom bot into the late stages of their attack chain is an attempt to avoid detections when using off-the-shelf tools for C2 such as CobaltStrike or RDP," IBM X-Force researchers Golo Mühr and Ole

Myrror Security Emerges From Stealth Mode With $6 Million in Funding

07 November 2023
Myrror Security emerges from stealth mode to disrupt supply chain attacks with binary-to-source code analysis. The post Myrror Security Emerges From Stealth Mode With $6 Million in Funding appeared first on SecurityWeek.

Palo Alto Networks to Acquire Israeli Enterprise Browser Security Firm Talon

07 November 2023
The acquisition aims to strengthen security for unmanaged devices used by employees to access work-related material. Last week, Palo Alto Networks purchased cloud safety firm Dig Security.

Narrowing the Focus of AI in Security

07 November 2023
AI can truly disrupt all elements of the SOC and provide an analyst with 10x more data and save 10x more time than what currently exists. The post Narrowing the Focus of AI in Security appeared first on SecurityWeek.

Confidence in File Upload Security is Alarmingly Low. Why?

07 November 2023
Numerous industries—including technology, financial services, energy, healthcare, and government—are rushing to incorporate cloud-based and containerized web applications.  The benefits are undeniable; however, this shift presents new security challenges.  OPSWAT's 2023 Web Application Security report reveals: 75% of organizations have modernized their infrastructure this year. 78% have

Medusa Ransomware Group Claims Cyberattack on Canadian Psychological Association

07 November 2023
The Medusa ransomware group has demanded a ransom of $10,000 to delay the publication of compromised data by another day, and a staggering $200,000 for the complete deletion of the data.

Countries Pledge to Not Pay Ransoms, but Experts Question Impact

07 November 2023
While the pledge is a step in the right direction, legislative measures are needed to effectively deter organizations from paying ransoms and address the growing issue of ransomware attacks.

Researchers Find Data Brokers are Selling US Service Members’ Secrets

07 November 2023
A new report from Duke University reveals that data brokers are selling highly sensitive information on American military service members, posing a threat to national security.

Federal Push for Secure-by-Design: What It Means for Developers

07 November 2023
Secure-by-design is clearly important to the federal government, and there is a strong possibility that it will become a regulatory requirement for the critical industries enforced through an Executive Order. The post Federal Push for Secure-by-Design: What It Means for Developers appeared first on SecurityWeek.

Ransomware Gang Leaks Data Allegedly Stolen From Canadian Hospitals

07 November 2023
Five Canadian hospitals have confirmed a ransomware attack as data allegedly stolen from them was posted online. The post Ransomware Gang Leaks Data Allegedly Stolen From Canadian Hospitals appeared first on SecurityWeek.

Update: Microsoft Says Exchange ‘Zero Days’ Disclosed by ZDI Already Patched or Not Urgent

07 November 2023
As per Microsoft, the vulnerabilities do not meet the criteria of actual zero-days and require authentication for exploitation, reducing their chances of being used in malicious attacks.

Offensive and Defensive AI: Let’s Chat(GPT) About It

07 November 2023
ChatGPT: Productivity tool, great for writing poems, and… a security risk?! In this article, we show how threat actors can exploit ChatGPT, but also how defenders can use it for leveling up their game. ChatGPT is the most swiftly growing consumer application to date. The extremely popular generative AI chatbot has the ability to generate human-like, coherent and contextually relevant responses.

Fake Ledger Live App on Microsoft Store Leads to $800,000 Crypto Theft

07 November 2023
The scam involved a sophisticated tactic of replicating the look and features of the authentic app, making it challenging for users to differentiate between the real and fake versions.

Cybersecurity M&A Roundup: 31 Deals Announced in October 2023

07 November 2023
Thirty-one cybersecurity-related merger and acquisition (M&A) deals were announced in October 2023. The post Cybersecurity M&A Roundup: 31 Deals Announced in October 2023 appeared first on SecurityWeek.