Latest Cybersecurity News and Articles


Cisco Patches 27 Vulnerabilities in Network Security Products

02 November 2023
Cisco has released software updates to address 27 vulnerabilities in Cisco ASA, FMC, and FTD software. The post Cisco Patches 27 Vulnerabilities in Network Security Products appeared first on SecurityWeek.

Healthcare's Ransomware Attackers are Addicted to Encryption

02 November 2023
According to a report by security firm Sophos, 75% of ransomware attacks on healthcare organizations involve the malicious encryption of data. This reflects the increasing skill level of hackers in the healthcare sector.

Update: Boeing Admits Cyberattack on Parts and Distribution Business

02 November 2023
“We are aware of a cyber incident impacting elements of our parts and distribution business,” Boeing told The Register. At the time of writing, the company’s parts and distribution website was “down due to technical issues.”

SaaS Security is Now Accessible and Affordable to All

02 November 2023
This new product offers SaaS discovery and risk assessment coupled with a free user access review in a unique “freemium” model Securing employees' SaaS usage is becoming increasingly crucial for most cloud-based organizations. While numerous tools are available to address this need, they often employ different approaches and technologies, leading to unnecessary confusion and complexity. Enter

Iran's MuddyWater Targets Israel in New Spear-Phishing Cyber Campaign

02 November 2023
The Iranian nation-state actor known as MuddyWater has been linked to a new spear-phishing campaign targeting two Israeli entities to ultimately deploy a legitimate remote administration tool from N-able called Advanced Monitoring Agent. Cybersecurity firm Deep Instinct, which disclosed details of the attacks, said the campaign "exhibits updated TTPs to previously reported MuddyWater activity,"

Probe of School Surveillance Software Finds Privacy Abuses, Inaccurate Results

02 November 2023
The investigation by the Electronic Frontier Foundation (EFF) found that innocent content related to education, therapy, and LGBTQ+ issues was consistently flagged as potentially harmful, leading to a "stunning invasion of privacy."

Mozi Botnet Put in its Grave Using Kill Switch

02 November 2023
The activation of the kill switch disabled various system services, replaced the original malware, and maintained persistence, suggesting a deliberate dismantling of the botnet.

Researchers Find 34 Windows Drivers Vulnerable to Full Device Takeover

02 November 2023
As many as 34 unique vulnerable Windows Driver Model (WDM) and Windows Driver Frameworks (WDF) drivers could be exploited by non-privileged threat actors to gain full control of the devices and execute arbitrary code on the underlying systems. "By exploiting the drivers, an attacker without privilege may erase/alter firmware, and/or elevate [operating system] privileges," Takahiro Haruyama, a

Update: Toronto Public Library Outages Caused by Black Basta Ransomware Attack

02 November 2023
The library has stated that there is no evidence of compromised personal information, and they are actively working with cybersecurity experts and law enforcement to investigate the incident.

Update: Dallas County ‘Interrupted’ Data Exfiltration, Prevented Encryption After Attack

02 November 2023
Dallas County in Texas has provided an update on a ransomware attack that was reported earlier this week. The county was able to stop the hackers before they could encrypt files or systems.

FIRST Announces CVSS 4.0 - New Vulnerability Scoring System

02 November 2023
The Forum of Incident Response and Security Teams (FIRST) has officially announced CVSS v4.0, the next generation of the Common Vulnerability Scoring System standard, more than eight years after the release of CVSS v3.0 in June 2015. "This latest version of CVSS 4.0 seeks to provide the highest fidelity of vulnerability assessment for both industry and the public," FIRST said in a statement.

HelloKitty Ransomware Group Exploiting Apache ActiveMQ Vulnerability

02 November 2023
Cybersecurity researchers are warning of suspected exploitation of a recently disclosed critical security flaw in the Apache ActiveMQ open-source message broker service that could result in remote code execution. "In both instances, the adversary attempted to deploy ransomware binaries on target systems in an effort to ransom the victim organizations," cybersecurity firm Rapid7 disclosed in a

FIRST Releases CVSS 4.0 Vuln Scoring Standard

01 November 2023
The CVSS vulnerability scoring standard is refreshed to provide more data and remove ambiguities in rating the severity of downstream issues. The post FIRST Releases CVSS 4.0 Vuln Scoring Standard appeared first on SecurityWeek.

HHS settles data breach investigation

01 November 2023
The U.S. Department of Health and Human Services (HHS) settled healthcare data breach charges alongside the Office for Civil Rights (OCR).

Countries at a UK Summit Pledge to Tackle AI’s Potentially ‘Catastrophic’ Risks

01 November 2023
Delegates from 28 nations agreed to work together to contain the potentially “catastrophic” risks posed by galloping advances in artificial intelligence. The post Countries at a UK Summit Pledge to Tackle AI’s Potentially ‘Catastrophic’ Risks appeared first on SecurityWeek.

Chainguard Raises $61M in Series B Funding

01 November 2023
The Kirkland, Washington-based security company raised $61 million in Series B funding. The round was led by Spark Capital, with participation from existing investors Sequoia Capital, Amplify Partners, The Chainsmoker's Mantis VC, and Banana Capital.

Chrome 119 Patches 15 Vulnerabilities

01 November 2023
Out of the 15 vulnerabilities patched, 13 of which were reported by external researchers. Three of the bugs are rated as high severity, while the remaining ones are medium and low severity.

Log Analysis and Security Firm Graylog Raises $9M in Equity, $30M in Debt

01 November 2023
Graylog has raised $39 million in its Series C funding round co-led by Silver Lake Waterman, Piper Sandler Merchant Banking, and Harbert Growth Partners. It includes $9 million in equity and $30 million in a "flex debt" facility.

Latest RAT Attack Surge Bypasses Microsoft’s XLL Block

01 November 2023
Microsoft's block on Visual Basic for Applications (VBA) macros has led attackers to experiment with different file types, with XLL files now being used as a means to distribute malware.

NSA releases guidelines to mitigate phishing

01 November 2023
The National Security Agency (NSA) has partnered with other U.S. agencies to warn against phishing attacks and provide security strategies.