Latest Cybersecurity News and Articles
25 October 2023
The threat actor attempts to disguise their origin by hosting infrastructure in Azerbaijan and using the Azerbaijani language in their operations, despite not being fluent in Azerbaijani.
25 October 2023
Smokeloader malware is a highly complex tool that can perform various malicious functions, such as stealing credentials and executing DDoS attacks, with prices ranging from $400 to $1,650 depending on the package.
25 October 2023
The breach, which occurred on August 7, 2023, was discovered a day later and the cybercriminals were removed from CoinFlip's systems with the assistance of their IT team.
25 October 2023
Mandiant's Chief analyst urges critical infrastructure defenders to work on finding and removing traces of Volt Typhoon, a Chinese government-backed hacking team caught in a series of eyebrow-raising attacks against targets in Guam and the United States.
The post Mandiant Intelligence Chief Raises Alarm Over China’s ‘Volt Typhoon’ Hackers in US Critical Infrastructure appeared first on SecurityWeek.
25 October 2023
NAS devices, printers, IP cameras, speakers, and mobile phones were hacked on the first day at Pwn2Own Toronto 2023.
The post Hackers Earn $400k on First Day at Pwn2Own Toronto 2023 appeared first on SecurityWeek.
25 October 2023
Russian APT Winter Vivern exploits a zero-day in the Roundcube webmail server in attacks targeting European governments.
The post Russian Hackers Caught Exploiting Roundcube Webmail Zero-Day appeared first on SecurityWeek.
25 October 2023
The vulnerability, assigned CVE-2023-5631, allowed attackers to execute arbitrary JavaScript code in the context of a Roundcube user's browser window through a specially crafted email.
25 October 2023
The two exposed environment files contained sensitive information such as database credentials, SMTP server login details, and payment processing information, according to Cybernews researchers.
25 October 2023
Ransomware groups are likely to leverage AI-enabled tools, such as chatbots and voice cloning, to enhance their social engineering tactics and technical skills, posing a greater threat to public and private organizations.
25 October 2023
In Episode 17 of the Cybersecurity & Geopolitical Discussion from Security magazine, Ian Thornton-Trump, Philip Ingram and Lisa Forte analyze the Russia-Ukraine and Israel-Hamas wars.
25 October 2023
The updated plan will involve collaboration with industry stakeholders, government agencies, and critical infrastructure organizations, recognizing the private sector's role as the first responder to many cyber incidents.
25 October 2023
A new project aims to make it easier for PLC programmers to implement secure coding practices by cataloging useful files and functions from each vendor.
The post New Project Analyzes and Catalogs Vendor Support for Secure PLC Coding appeared first on SecurityWeek.
25 October 2023
MNEMO Mexico's expertise in advanced cyber defense, generative AI-powered cyber intelligence, and a 24/7 security operations center will enhance Accenture's capabilities in helping organizations build cyber-resilient businesses.
25 October 2023
With the investment from Sixth Street Growth, Keyfactor aims to continue its trajectory of hypergrowth, leveraging their experience, financial prowess, and strategic network to empower the company in the next chapter of its development.
25 October 2023
Michigan startup raises $75 million in new funding as venture capital investors bet big on attack surface management technologies.
The post Censys Banks $75M for Attack Surface Management Technology appeared first on SecurityWeek.
25 October 2023
Criminals are hijacking business accounts on Facebook and running their own advertising campaigns, causing financial damage and reputational harm to legitimate account holders.
25 October 2023
The threat actor known as Winter Vivern has been observed exploiting a zero-day flaw in Roundcube webmail software on October 11, 2023, to harvest email messages from victims' accounts.
"Winter Vivern has stepped up its operations by using a zero-day vulnerability in Roundcube," ESET security researcher Matthieu Faou said in a new report published today. Previously, it was using known
25 October 2023
The escalating reliance on information operations by these groups aims to influence the global perception of the conflict, with strategic campaigns designed to manipulate social media platforms and influence media outlets.
25 October 2023
The Cybersecurity Resilience Quotient empowers organizations to assess their security posture comprehensively, considering asset exposure, vulnerabilities, and criticality alongside process and network architecture and disaster recovery plans.
The post The Cybersecurity Resilience Quotient: Measuring Security Effectiveness appeared first on SecurityWeek.
25 October 2023
Critical security flaws have been disclosed in the Open Authorization (OAuth) implementation of popular online services such as Grammarly, Vidio, and Bukalapak, building upon previous shortcomings uncovered in Booking[.]com and Expo.
The weaknesses, now addressed by the respective companies following responsible disclosure between February and April 2023, could have allowed malicious actors to