Latest Cybersecurity News and Articles
30 October 2023
The threat actor behind the campaign quickly scans and clones GitHub repositories to capture exposed keys, highlighting the importance of promptly removing and revoking any compromised credentials.
30 October 2023
Researchers document the Wiki-Slack attack, a new technique that uses modified Wikipedia pages to target end users on Slack.
The post Attackers Can Use Modified Wikipedia Pages to Mount Redirection Attacks on Slack appeared first on SecurityWeek.
30 October 2023
The tool provides step-by-step installation instructions, prebuilt elastic security detection rules, and coding to reduce cost barriers, making it accessible for organizations aiming to implement basic logging and monitoring capabilities.
30 October 2023
A new report reveals a 967% increase in credential phishing attempts year-over-year, the number one access point to organizational breaches.
30 October 2023
Hackers have demonstrated 58 zero-days and earned more than $1 million in rewards at Pwn2Own Toronto 2023.
The post Hackers Earn Over $1 Million at Pwn2Own Toronto 2023 appeared first on SecurityWeek.
30 October 2023
The recent DDoS attacks by pro-Ukrainian hackers targeted Russian ISPs, including Miranda-media, Krimtelekom, and MirTelekom, affecting not only Crimea but also occupied parts of other regions.
30 October 2023
QR codes are particularly vulnerable to exploitation due to their ability to encode complex data and redirect users to malicious sites, making them an attractive target for hackers.
30 October 2023
Modern web app development relies on cloud infrastructure and containerization. These technologies scale on demand, handling millions of daily file transfers – it's almost impossible to imagine a world without them. However, they also introduce multiple attack vectors that exploit file uploads when working with public clouds, vulnerabilities in containers hosting web applications, and many other
30 October 2023
Earlier this week, ServiceNow announced on its support site that misconfigurations within the platform could result in “unintended access” to sensitive data. For organizations that use ServiceNow, this security exposure is a critical concern that could have resulted in major data leakage of sensitive corporate data. ServiceNow has since taken steps to fix this issue.
This article fully analyzes
30 October 2023
Parents have received emails from the threat actors, with leaked PDF documents containing student data, causing concerns about potential identity theft and phishing attacks.
30 October 2023
The new disclosure requirement aims to empower consumers by providing them with breach data and enabling them to make more informed decisions about which financial institutions to trust with their information.
30 October 2023
Are whistleblowers traitors to the company, a danger to corporate brand image, and a form of insider threat? Or are they an early warning safety valve that can be used to strengthen cybersecurity and compliance?
The post Whistleblowers: Should CISOs Consider Them a Friend or Foe? appeared first on SecurityWeek.
30 October 2023
The GHOSTPULSE malware employs multiple evasion techniques, such as DLL side-loading and module stomping, to load and execute various malware including SectopRAT, Rhadamanthys, Vidar, Lumma, and NetSupport RAT.
30 October 2023
A new ongoing campaign dubbed EleKtra-Leak has set its eyes on exposed Amazon Web Service (AWS) identity and access management (IAM) credentials within public GitHub repositories to facilitate cryptojacking activities.
"As a result of this, the threat actor associated with the campaign was able to create multiple AWS Elastic Compute (EC2) instances that they used for wide-ranging and
30 October 2023
Raven scans GitHub workflows, breaks them into components, and utilizes a knowledge base to identify vulnerabilities, making it easier for security teams to assess and address risks.
30 October 2023
President Joe Biden on Monday will sign a sweeping executive order to guide the development of artificial intelligence — requiring industry to develop safety and security standards, and introducing new consumer protections.
The post Biden Wants to Move Fast on AI Safeguards and Will Sign an Executive Order to Address His Concerns appeared first on SecurityWeek.
30 October 2023
According to GuidePoint Security, ransomware activity continued to surge in Q3 of 2023. There was a 15% increase in ransomware activity compared to Q2, with 10 new emerging groups tracked during this quarter.
30 October 2023
The complexity of OT environments, the convergence of IT and OT, insider attacks, and supply chain vulnerabilities contribute to the lack of success in defending against these attacks.
30 October 2023
Many chief information security officers (CISOs) are facing challenges when it comes to the purpose and value of security controls data in supporting critical business decisions, according to a report by Panaseer.
30 October 2023
The request for comment aims to establish uniform parameters for tracking critical information such as known vulnerabilities and approved software, enhancing software security.