Latest Cybersecurity News and Articles


VMware vCenter Flaw So Critical, Patches Released for End-of-Life Products

25 October 2023
VMware described the bug as an out-of-bounds write issue in its implementation of the DCE/RPC protocol. CVSS severity score of 9.8/10. The post VMware vCenter Flaw So Critical, Patches Released for End-of-Life Products appeared first on SecurityWeek.

White House Official Says New Global Initiatives Will Include Information Sharing, Ransom Payment Tracking

25 October 2023
The White House aims to establish a global norm against paying ransoms to cybercriminals and may seek a UN process or an international partnership to achieve this objective.

Cybersecurity Regulations for Passenger and Freight Railroads Renewed by TSA

25 October 2023
The TSA directives require operators to test their cybersecurity incident response plans annually, submit updated cybersecurity assessment plans, and report on the effectiveness of their efforts.

Critical Infrastructure Stakeholders Gather for Day 2 of SecurityWeek’s 2023 ICS Cybersecurity Conference

25 October 2023
SecurityWeek’s 2023 ICS Cybersecurity Conference continues in Atlanta, as hundreds of industrial cybersecurity stakeholders gather for Day 2 of the annual industrial cybersecurity conference. The post Critical Infrastructure Stakeholders Gather for Day 2 of SecurityWeek’s 2023 ICS Cybersecurity Conference appeared first on SecurityWeek.

Hackers Backdoor Russian State, Industrial Organizations for Data Theft

25 October 2023
Russian state organizations and industrial sectors have been targeted with a custom Go-based backdoor. The backdoor, distributed through phishing emails, steals data, including passwords from popular web browsers and the Thunderbird email client.

Censys Lands New Cash to Grow Its Threat-Detecting Cybersecurity Service

25 October 2023
Censys aims to offer customers insights into the historical and real-time status of their data, enabling them to identify how long their data has been vulnerable and what changes have made it exploitable.

The Rise of S3 Ransomware: How to Identify and Combat It

25 October 2023
In today's digital landscape, around 60% of corporate data now resides in the cloud, with Amazon S3 standing as the backbone of data storage for many major corporations.  Despite S3 being a secure service from a reputable provider, its pivotal role in handling vast amounts of sensitive data (customer personal information, financial data, intellectual property, etc.), provides a juicy target for

French Basketball Team ASVEL Confirms Data Breach After Ransomware Attack

25 October 2023
ASVEL has reported the incident to the national data protection authority and law enforcement authorities, while also assessing the potential impact on third parties, including fans who made purchases on the club's official website.

Report: GenAI Can Save Phishers Two Days of Work

25 October 2023
Although humans currently outperform AI in terms of click rates and detection, the advancing sophistication of AI suggests it may eventually surpass human capabilities in the phishing industry.

How Passkeys are Changing the Face of Authentication

25 October 2023
Passkeys are digital credentials that can only be used by authorized users and require biometric or unique factor authentication. Tech giants like Apple, Google, and Microsoft have embraced passkeys in their products.

Act Now: VMware Releases Patch for Critical vCenter Server RCE Vulnerability

25 October 2023
VMware has released security updates to address a critical flaw in the vCenter Server that could result in remote code execution on affected systems. The issue, tracked as CVE-2023-34048 (CVSS score: 9.8), has been described as an out-of-bounds write vulnerability in the implementation of the DCE/RPC protocol. "A malicious actor with network access to vCenter Server may trigger an out-of-bounds

Samsung Galaxy S23 Hacked Twice on First Day of Pwn2Own 2023 in Toronto

25 October 2023
Researchers also targeted other devices such as smartphones, printers, smart speakers, and surveillance cameras, demonstrating the wide range of potential targets for hackers.

Defending Federal Networks Requires More Than Money, CSIS Study Finds

25 October 2023
Additional resources and funding, along with harmonized authorities and improved coordination, are necessary to enhance the cybersecurity measures of federal executive agencies.

Malvertising Campaign Targets Brazil's PIX Payment System with GoPIX Malware

25 October 2023
The popularity of Brazil's PIX instant payment system has made it a lucrative target for threat actors looking to generate illicit profits using a new malware called GoPIX. Kaspersky, which has been tracking the active campaign since December 2022, said the attacks are pulled off using malicious ads that are served when potential victims search for "WhatsApp web" on search engines. "The

US Energy Firm Shares How Akira Ransomware Hacked its Systems

25 October 2023
The Akira ransomware gang breached BHI Energy's network through a stolen VPN credential and stole a significant amount of data, including the personal information of employees.

Email innovation simplifies takedown of cyber scams

25 October 2023
Scam emails can be sent directly to SERS via a new button organisations can add to their Microsoft Office 365 accounts.

Report: Only a Fraction of Risk Leaders are Prepared for GenAI Threats

25 October 2023
New research by Riskonnect highlights a significant gap in AI risk management, with only 17% of risk and compliance leaders formally training their organizations on the risks of generative AI.

Citrix Urges NetScaler ADC, Gateway Customers to Patch

25 October 2023
Citrix is urging its customers to upgrade to the latest versions of NetScaler ADC and NetScaler Gateway due to reports of targeted attacks and session hijacking. The company released patches to address a critical vulnerability, CVE-2023-4966.

Alleged Covert Wiretap on Russian Messaging Service Blown by Expired TLS Certificate

25 October 2023
The wiretap is believed to have lasted up to 6 months, allowing the attacker to execute actions on compromised accounts without the need for passwords, potentially altering messages and accessing unencrypted data.

Report: September was a Record Month for Ransomware Attacks in 2023

25 October 2023
Ransomware activity reached an all-time high in September, with 514 attacks recorded. The previous record was in March 2023, but this new surge was led by different threat groups. LockBit 3.0, LostTrust, and BlackCat were the top attackers.