Latest Cybersecurity News and Articles


In Other News: Ex-NSA Employee Spying for Russia, EU Threat Landscape, Cyber Education Funding

27 October 2023
Noteworthy stories that might have slipped under the radar: Ex-NSA employee spying for Russia, EU threat landscape report, cyber education funding The post In Other News: Ex-NSA Employee Spying for Russia, EU Threat Landscape, Cyber Education Funding appeared first on SecurityWeek.

Report: Consumers are Taking Action to Protect Their Privacy

27 October 2023
A recent survey conducted by Cisco reveals that younger consumers are more proactive in protecting their privacy, with 42% of those aged 18-24 exercising their Data Subject Access Rights.

Advanced ‘StripedFly’ Malware With 1 Million Infections Shows Similarities to NSA-Linked Tools

27 October 2023
The StripedFly malware has APT-like capabilities, but remained unnoticed for five years, posing as a cryptocurrency miner. The post Advanced ‘StripedFly’ Malware With 1 Million Infections Shows Similarities to NSA-Linked Tools appeared first on SecurityWeek.

F5 Warns of Critical Remote Code Execution Vulnerability in BIG-IP

27 October 2023
A critical-severity vulnerability in F5 BIG-IP CVE-2023-46747 allows unauthenticated attackers to execute code remotely. The post F5 Warns of Critical Remote Code Execution Vulnerability in BIG-IP appeared first on SecurityWeek.

Survey highlights 5 mounting pressures Chief Risk Officers face

27 October 2023
A recent survey reveals Chief Risk Officers (CROs) are facing five pressures that require the acceleration in the transformation of the risk function to adapt to change.

Cybersecurity Resilience Quotient Metric for Measuring Security Effectiveness

27 October 2023
The Cybersecurity Resilience Quotient (CRQ) metric goes beyond traditional approaches by considering factors such as asset exposure, vulnerability, criticality, architecture defensibility, and business process vulnerabilities.

In-Home Hospitality App Hello Alfred Exposes User Data

27 October 2023
The in-home hospitality app exposed almost 170,000 user records, including sensitive personal data and partial payment information, due to a passwordless and publicly accessible database.

Report: Security Not a Priority For a Third of SMBs

27 October 2023
A key point of contention is the shared responsibility model which is frequently misunderstood. While cloud providers like AWS secure the infrastructure, customers are responsible for safeguarding their sensitive data and other components.

Record-Breaking 100 Million RPS DDoS Attack Exploits HTTP/2 Rapid Reset Flaw

27 October 2023
Cloudflare has revealed that it mitigated thousands of hyper-volumetric HTTP distributed denial-of-service (DDoS) attacks exploiting the recently disclosed HTTP/2 Rapid Reset flaw.

Security Leaders Have Good Reasons to Fear AI-Generated Attacks

27 October 2023
According to Abnormal Security, the majority of security leaders are not adequately prepared to defend against AI-generated email attacks, relying on traditional solutions that lack effectiveness.

Android Adware Apps on Google Play Amass Two Million Installs

27 October 2023
These apps, associated with malware families such as 'FakeApp,' 'Joker,' and 'HiddenAds,' have been downloaded over 2 million times. The HiddenAds apps push intrusive ads to users while hiding their presence on the infected devices.

FakeUpdateRU: New Malware Camouflaged as Fake Chrome Update

27 October 2023
A new malware variant dubbed FakeUpdateRU was found targeting site visitors, attempting to trick them into downloading a fake Google Chrome update. The infection impacts WordPress websites as well as other CMS platforms. Google has blocked many domains associated with this malware, but attackers have adapted by linking directly to compromised websites.

New Project Analyzes and Catalogs Vendor Support for Secure PLC Coding

27 October 2023
While some secure coding practices apply to all PLCs, others are specific to each vendor, making it difficult to find relevant documentation. The project aims to provide this information in an easy-to-digest format.

France Says Russian State Hackers Breached Numerous Critical Networks

27 October 2023
The Russian APT28 hacking group, also known as 'Strontium' or 'Fancy Bear,' has been targeting government entities, businesses, universities, research institutes, and think tanks in France since the second half of 2021.

How to Keep Your Business Running in a Contested Environment

27 October 2023
When organizations start incorporating cybersecurity regulations and cyber incident reporting requirements into their security protocols, it's essential for them to establish comprehensive plans for preparation, mitigation, and response to potential threats. At the heart of your business lies your operational technology and critical systems. This places them at the forefront of cybercriminal

Google Expands Its Bug Bounty Program to Tackle Artificial Intelligence Threats

27 October 2023
Google has announced that it's expanding its Vulnerability Rewards Program (VRP) to reward researchers for finding attack scenarios tailored to generative artificial intelligence (AI) systems in an effort to bolster AI safety and security. "Generative AI raises new and different concerns than traditional digital security, such as the potential for unfair bias, model manipulation or

Rising Global Tensions Could Portend Destructive Hacks

27 October 2023
U.S. government agencies and private sector organizations should remain on high alert for cyberattacks targeting critical infrastructure and key sectors in light of escalating global conflicts.

UN Chief Appoints 39-Member Panel to Advise on International Governance of Artificial Intelligence

27 October 2023
U.N. Secretary-General António Guterres assembled a global advisory panel to report on international governance of artificial intelligence and its risks, challenges and key opportunities. The post UN Chief Appoints 39-Member Panel to Advise on International Governance of Artificial Intelligence appeared first on SecurityWeek.

Hackers Earn $350k on Second Day at Pwn2Own Toronto 2023

27 October 2023
The highest reward of $100,000 went to Chris Anastasio for exploits targeting a P-Link Omada Gigabit router and a Lexmark CX331adwe printer. Other successful exploits earned hackers rewards ranging from $50,000 to $10,000.

Cranium Announces $25 Million in Series A Funding to Secure AI

27 October 2023
The AI security and trust software firm has raised $25 million in Series A funding, bringing its total funding to $32 million, which will be used for innovation, R&D, and business expansion.