Latest Cybersecurity News and Articles
01 November 2023
MITRE announces the release of ATT&CK v14, which brings enhancements related to detections, ICS, and mobile.
The post MITRE Releases ATT&CK v14 With Improvements to Detections, ICS, Mobile appeared first on SecurityWeek.
01 November 2023
Employee and consumer data continue to be the most affected categories in data breaches, leading to negative impacts such as lost revenue, customer trust, and employee turnover.
01 November 2023
The targeted system, Mir, is a homegrown alternative to international payment brands and has seen increased usage in Russia following the country's invasion of Ukraine and the departure of international payment services.
01 November 2023
There has been an ongoing debate in the security industry over the last decade or so about whether or not deep packet inspection (DPI) is dead.
The post DPI: Still Effective for the Modern SOC? appeared first on SecurityWeek.
01 November 2023
The browser has become the main work interface in modern enterprises. It’s where employees create and interact with data, and how they access organizational and external SaaS and web apps. As a result, the browser is extensively targeted by adversaries. They seek to steal the data it stores and use it for malicious access to organizational SaaS apps or the hosting machine. Additionally,
01 November 2023
Over one-third of companies lack a comprehensive ransomware strategy, highlighting the need for a holistic approach that prioritizes both prevention and recovery, according to a survey by Zerto.
01 November 2023
Private torrent trackers like WiHD, known for their exclusivity, can still suffer from data breaches, highlighting the importance of robust security measures in protecting user data.
01 November 2023
Threat actors are constantly publishing malicious NuGet packages to automatically execute code on developers’ machines.
The post Malicious NuGet Packages Abuse MSBuild Integrations for Code Execution appeared first on SecurityWeek.
01 November 2023
A threat actor affiliated with Iran's Ministry of Intelligence and Security (MOIS) has been observed waging a sophisticated cyber espionage campaign targeting financial, government, military, and telecommunications sectors in the Middle East for at least a year.
Israeli cybersecurity firm Check Point, which discovered the campaign alongside Sygnia, is tracking the actor under the name Scarred
01 November 2023
Recovery efforts should prioritize patching vulnerabilities, removing malicious artifacts, and strengthening protective and detective controls to enhance cyber resilience and reduce the risk of follow-up attacks.
01 November 2023
F5 has issued a warning about active exploitation of a critical security flaw in its BIG-IP software. The vulnerability, known as CVE-2023-46747, allows attackers to execute arbitrary system commands.
01 November 2023
Many people are raising the alarm about AI’s as-yet-unknown dangers and calling for safeguards to protect people from its existential threats.
The post Cutting-Edge AI Raises Fears About Risks to Humanity. Are Tech and Political Leaders Doing Enough? appeared first on SecurityWeek.
01 November 2023
Graylog secured $39 million in funding to accelerate product development and scale its go-to-market operations.
The post SIEM and Log Management Provider Graylog Raises $39 Million appeared first on SecurityWeek.
01 November 2023
The use of the Forked IcedID variant, which removes banking functionality and focuses on payload delivery, highlights a shift in malware tactics toward prioritizing ransomware delivery.
01 November 2023
Former British cyberespionage agency employee was sentenced in a London court for attempted murder, will have to serve at least 13 years in prison.
The post Former British Cyberespionage Agency Employee Gets Life in Prison for Stabbing an American Spy appeared first on SecurityWeek.
01 November 2023
State-sponsored threat actors from the Democratic People's Republic of Korea (DPRK) have been found targeting blockchain engineers of an unnamed crypto exchange platform via Discord with a novel macOS malware dubbed KANDYKORN.
Elastic Security Labs said the activity, traced back to April 2023, exhibits overlaps with the infamous adversarial collective Lazarus Group, citing an analysis of the
01 November 2023
The .US domain has been plagued by phishing activity and illicit content, with thousands of malicious link shortener domains registered, despite regulations aimed at verifying the identity and location of registrants.
01 November 2023
The acquisition will integrate Dig's capabilities into Palo Alto's Prisma Cloud platform. Financial details were not disclosed, but reports suggest the deal is valued at $400 million.
01 November 2023
The latest variant of Kazuar features significant improvements in code structure and functionality, including comprehensive system profiling, credential theft, an extended set of commands, and enhanced task automation.
01 November 2023
The rise of hardware- and firmware-related attacks and supply chain threats has fundamentally changed the cybersecurity landscape, requiring a deeper understanding of these areas in the context of the MITRE ATT&CK framework.