Latest Cybersecurity News and Articles


F5 Issues Warning Over BIG-IP Vulnerability That Allows Remote Code Execution

27 October 2023
The high-severity flaw, tracked as CVE-2023-46747, could be exploited by an unauthenticated attacker with network access. The issue is related to the configuration utility component and does not expose data but impacts control plane operations.

Nigerian Police Dismantle Major Cybercrime Hub

27 October 2023
Nigerian police have shut down a cybercrime recruitment and training center in Abuja, arresting six suspects involved in various cybercrimes including business email compromise and romance scams.

Russian Artists’ Spotify Accounts Defaced by Pro-Ukraine Hackers

27 October 2023
Spotify confirmed the incident and stated that they have fixed the issue, although some affected profiles may still show altered or missing profile pictures due to caching.

Novel Zero-Day Exploits Fuel Q3 Surge in DDoS Attacks

27 October 2023
The HTTP/2 Rapid Reset vulnerability was exploited in 89 attacks that exceeded 100 million requests per second, with the largest attack reaching 201 million requests per second.

Update: Hackers Spent Three Months Accessing Philadelphia City Government Email Accounts

27 October 2023
Hackers had unauthorized access to Philadelphia city email accounts for at least three months, potentially compromising health information stored in them. Suspicious activity was initially detected in May but residents were only notified in October.

F5 Issues Warning: BIG-IP Vulnerability Allows Remote Code Execution

27 October 2023
F5 has alerted customers of a critical security vulnerability impacting BIG-IP that could result in unauthenticated remote code execution. The issue, rooted in the configuration utility component, has been assigned the CVE identifier CVE-2023-46747, and carries a CVSS score of 9.8 out of a maximum of 10. "This vulnerability may allow an unauthenticated attacker with network access to the BIG-IP

UK: Purchase Scams Surge as Fraud Losses Hit $703m

26 October 2023
Online platforms, mobile phone networks, and social media are commonly used by scammers to target victims and initiate APP fraud, emphasizing the importance of collaboration across sectors to fight against fraud.

Critical Mirth Connect Vulnerability Could Expose Sensitive Healthcare Data

26 October 2023
Mirth Connect versions prior to 4.4.1 are vulnerable to CVE-2023-43208, a bypass for an RCE vulnerability. The post Critical Mirth Connect Vulnerability Could Expose Sensitive Healthcare Data appeared first on SecurityWeek.

CISA, HHS, and HSCC Jointly Release Cybersecurity Toolkit For Healthcare Sector

26 October 2023
The Cybersecurity Toolkit for Healthcare and Public Health provides valuable resources and guidance to help healthcare organizations enhance their security posture and reduce the risk of cyberattacks.

What Is Operational Risk and Why Should You Care? Assessing SEC Rule Readiness for OT and IoT

26 October 2023
The newly released SEC cyber incident disclosure rules have raised concerns about whether public companies are prepared to fully define operational risk and disclose material business risk from cyber incidents.

Firefox, Chrome Updates Patch High-Severity Vulnerabilities

26 October 2023
The updates patch multiple flaws, including an insufficient activation-delay bug in Firefox and a use-after-free issue in Chrome, but there is no evidence of these vulnerabilities being exploited in the wild.

iLeakage: New Safari Exploit Impacts Apple iPhones and Macs with A and M-Series CPUs

26 October 2023
A group of academics has devised a novel side-channel attack dubbed iLeakage that exploits a weakness in the A- and M-series CPUs running on Apple iOS, iPadOS, and macOS devices, enabling the extraction of sensitive information from the Safari web browser. "An attacker can induce Safari to render an arbitrary webpage, subsequently recovering sensitive information present within it using

75% of Americans want government regulations for AI

26 October 2023
The public perception of AI was analyzed in a recent report by IONOS, finding that 75% of respondents want some form of government oversight.

New iLeakage Attack Steals Emails, Passwords From Apple Safari

26 October 2023
This attack bypasses standard side-channel protections implemented by browser vendors and can retrieve data from Safari, as well as other browsers like Firefox, Tor, and Edge on iOS.

Hackers Earn $350k on Second Day at Pwn2Own Toronto 2023

26 October 2023
Smart speakers, printers, routers, NAS devices, and mobile phones were hacked on the second day at Pwn2Own Toronto 2023. The post Hackers Earn $350k on Second Day at Pwn2Own Toronto 2023 appeared first on SecurityWeek.

Australia Focuses on Threat of Chinese Attack on Solar Power

26 October 2023
The Australian government is introducing standards to address the cybersecurity vulnerabilities of internet-connected solar inverters amid concerns of potential Chinese state-sponsored hacking.

AI Security Firm Cranium Raises $25 Million

26 October 2023
AI cybersecurity firm Cranium has raised $25 million in Series A funding, which brings the total investment in the company to $32 million. The post AI Security Firm Cranium Raises $25 Million appeared first on SecurityWeek.

Nine Vulnerabilities Found in VPN Software, Including One Critical RCE Issue

26 October 2023
Cisco Talos has disclosed multiple vulnerabilities in popular VPN software, including a critical heap-based buffer overflow vulnerability, posing a significant risk to users' connections and allowing for arbitrary code execution.

The Rise and Tactics of Octo Tempest: A Cyber Threat Analysis

26 October 2023
Octo Tempest, a financially motivated threat group known for extensive social engineering campaigns and SIM-swapping techniques, has become a major concern for businesses worldwide. It has been affiliated with ALPHV/BlackCat and began deploying ransomware payloads as well. Given Octo Tempest's relentless evolution and aggressive approach, organizations must be proactive in their defense strategies.

Key Learnings from “Big Game” Ransomware Campaigns

26 October 2023
There are key steps every organization should take to leverage threat and event data across the lifecycle of a cyber incident. The post Key Learnings from “Big Game” Ransomware Campaigns appeared first on SecurityWeek.