Latest Cybersecurity News and Articles
31 October 2023
The vulnerability, rated 9.1 out of 10 on the CVSS scoring system, is an improper authorization vulnerability and affects all versions of Confluence Data Center and Server.
31 October 2023
The top-level domain for the United States -- .US -- is home to thousands of newly-registered domains tied to a malicious link shortening service that facilitates malware and phishing scams, new research suggests. The findings come close on the heels of a report that identified .US domains as among the most prevalent in phishing attacks over the past year.
31 October 2023
The SlashNext State of Phishing Report 2023 reveals a significant surge in malicious phishing emails and credential phishing attacks, with a 1265% and 967% increase respectively.
31 October 2023
The breach, discovered on June 7, was the result of business email compromise. While the total number of individuals impacted was not disclosed, only three residents of Maine were affected.
31 October 2023
Meta, the parent company of Facebook and Instagram, has announced plans to offer an ad-free subscription option for users in the European Union (EU), European Economic Area (EEA), and Switzerland.
31 October 2023
Cybersecurity researchers have uncovered a new set of malicious packages published to the NuGet package manager using a lesser-known method for malware deployment.
Software supply chain security firm ReversingLabs described the campaign as coordinated and ongoing since August 1, 2023, while linking it to a host of rogue NuGet packages that were observed delivering a remote access trojan called
31 October 2023
One of the main reasons why ZTNA fails is that most ZTNA implementations tend to focus entirely on securing remote access.
The post Extending ZTNA to Protect Against Insider Threats appeared first on SecurityWeek.
31 October 2023
LastPass previously disclosed a breach in August 2022, where an attacker obtained customer information and encrypted vault data, leading to the theft of over $35 million worth of crypto from around 150 victims.
31 October 2023
Contact key verification uses a verifiable log-backed map data structure to ensure user privacy and allow audits. It also enables users to manually verify contacts using a protocol called Vaudenay SAS.
31 October 2023
In the ever-evolving cybersecurity landscape, the game-changers are those who adapt and innovate swiftly.
Pen test solutions not only supercharge productivity but also provide a crucial layer of objectivity, ensuring efficiency and exceptional accuracy. The synergy between a skilled penetration tester and the precision of pen testing solutions are crucial for staying on top of today’s high
31 October 2023
Atlassian has warned of a critical security flaw in Confluence Data Center and Server that could result in "significant data loss if exploited by an unauthenticated attacker."
Tracked as CVE-2023-22518, the vulnerability is rated 9.1 out of a maximum of 10 on the CVSS scoring system. It has been described as an instance of "improper authorization vulnerability."
All versions of Confluence Data
31 October 2023
The suspected Hamas-affiliated threat actor, Arid Viper, employs social engineering and phishing attacks to deploy custom malware for cyber espionage activities against high-profile targets in Israel and Palestine.
31 October 2023
A new malvertising campaign has been observed capitalizing on a compromised website to promote spurious versions of PyCharm on Google search results by leveraging Dynamic Search Ads.
"Unbeknownst to the site owner, one of their ads was automatically created to promote a popular program for Python developers, and visible to people doing a Google search for it," Jérôme Segura, director of threat
31 October 2023
SolarWinds and its CISO Timothy Brown have been charged by the SEC for fraud and internal control failures related to misleading investors about their cybersecurity practices leading up to the Sunburst attack.
31 October 2023
Canada has banned the messaging app WeChat and cybersecurity platform Kaspersky from government smartphones and mobile devices due to privacy and security concerns. This follows Canada's previous ban on TikTok in February.
31 October 2023
A security researcher has discovered two vulnerabilities in Wyze Cam v3 firmware and released a proof-of-concept exploit that can be used to gain remote code execution and take over vulnerable devices.
31 October 2023
The lawsuits claim that Costco's data collection and disclosure practices violate HIPAA, the Federal Trade Act, and federal and state wiretapping and other laws, as well as warnings from government agencies.
31 October 2023
Canada on Monday announced a ban on the use of apps from Tencent and Kaspersky on government mobile devices, citing an "unacceptable level of risk to privacy and security."
"The Government of Canada is committed to keeping government information and networks secure," the Canadian government said. "We regularly monitor potential threats and take immediate action to address risks."
To that end,
31 October 2023
Despite patches being available, thousands of Cisco IOS XE devices remain compromised, with major telecommunications and internet providers being particularly affected by such attacks.
31 October 2023
The acquisition aligns with Proofpoint's vision of securing the human layer in cybersecurity and aims to improve email security, reduce the risk of data breaches, and ease the workload on security teams.