Latest Cybersecurity News and Articles
27 October 2023
The high-severity flaw, tracked as CVE-2023-46747, could be exploited by an unauthenticated attacker with network access. The issue is related to the configuration utility component and does not expose data but impacts control plane operations.
27 October 2023
Nigerian police have shut down a cybercrime recruitment and training center in Abuja, arresting six suspects involved in various cybercrimes including business email compromise and romance scams.
27 October 2023
Spotify confirmed the incident and stated that they have fixed the issue, although some affected profiles may still show altered or missing profile pictures due to caching.
27 October 2023
The HTTP/2 Rapid Reset vulnerability was exploited in 89 attacks that exceeded 100 million requests per second, with the largest attack reaching 201 million requests per second.
27 October 2023
Hackers had unauthorized access to Philadelphia city email accounts for at least three months, potentially compromising health information stored in them. Suspicious activity was initially detected in May but residents were only notified in October.
27 October 2023
F5 has alerted customers of a critical security vulnerability impacting BIG-IP that could result in unauthenticated remote code execution.
The issue, rooted in the configuration utility component, has been assigned the CVE identifier CVE-2023-46747, and carries a CVSS score of 9.8 out of a maximum of 10.
"This vulnerability may allow an unauthenticated attacker with network access to the BIG-IP
26 October 2023
Online platforms, mobile phone networks, and social media are commonly used by scammers to target victims and initiate APP fraud, emphasizing the importance of collaboration across sectors to fight against fraud.
26 October 2023
Mirth Connect versions prior to 4.4.1 are vulnerable to CVE-2023-43208, a bypass for an RCE vulnerability.
The post Critical Mirth Connect Vulnerability Could Expose Sensitive Healthcare Data appeared first on SecurityWeek.
26 October 2023
The Cybersecurity Toolkit for Healthcare and Public Health provides valuable resources and guidance to help healthcare organizations enhance their security posture and reduce the risk of cyberattacks.
26 October 2023
The newly released SEC cyber incident disclosure rules have raised concerns about whether public companies are prepared to fully define operational risk and disclose material business risk from cyber incidents.
26 October 2023
The updates patch multiple flaws, including an insufficient activation-delay bug in Firefox and a use-after-free issue in Chrome, but there is no evidence of these vulnerabilities being exploited in the wild.
26 October 2023
A group of academics has devised a novel side-channel attack dubbed iLeakage that exploits a weakness in the A- and M-series CPUs running on Apple iOS, iPadOS, and macOS devices, enabling the extraction of sensitive information from the Safari web browser.
"An attacker can induce Safari to render an arbitrary webpage, subsequently recovering sensitive information present within it using
26 October 2023
The public perception of AI was analyzed in a recent report by IONOS, finding that 75% of respondents want some form of government oversight.
26 October 2023
This attack bypasses standard side-channel protections implemented by browser vendors and can retrieve data from Safari, as well as other browsers like Firefox, Tor, and Edge on iOS.
26 October 2023
Smart speakers, printers, routers, NAS devices, and mobile phones were hacked on the second day at Pwn2Own Toronto 2023.
The post Hackers Earn $350k on Second Day at Pwn2Own Toronto 2023 appeared first on SecurityWeek.
26 October 2023
The Australian government is introducing standards to address the cybersecurity vulnerabilities of internet-connected solar inverters amid concerns of potential Chinese state-sponsored hacking.
26 October 2023
AI cybersecurity firm Cranium has raised $25 million in Series A funding, which brings the total investment in the company to $32 million.
The post AI Security Firm Cranium Raises $25 Million appeared first on SecurityWeek.
26 October 2023
Cisco Talos has disclosed multiple vulnerabilities in popular VPN software, including a critical heap-based buffer overflow vulnerability, posing a significant risk to users' connections and allowing for arbitrary code execution.
26 October 2023
Octo Tempest, a financially motivated threat group known for extensive social engineering campaigns and SIM-swapping techniques, has become a major concern for businesses worldwide. It has been affiliated with ALPHV/BlackCat and began deploying ransomware payloads as well. Given Octo Tempest's relentless evolution and aggressive approach, organizations must be proactive in their defense strategies.
26 October 2023
There are key steps every organization should take to leverage threat and event data across the lifecycle of a cyber incident.
The post Key Learnings from “Big Game” Ransomware Campaigns appeared first on SecurityWeek.