Latest Cybersecurity News and Articles
18 October 2023
Attackers are using Starjacking and Typosquatting techniques to inject malicious code into open-source projects, compromising developers' systems and stealing sensitive data.
18 October 2023
The Malicious Packages Repository, which has already collected over 15,000 reports, provides a centralized database for shared intelligence, enabling early detection and prevention of malicious code in open-source projects.
18 October 2023
Government entities in the Asia-Pacific (APAC) region are the target of a long-running cyber espionage campaign dubbed TetrisPhantom.
"The attacker covertly spied on and harvested sensitive data from APAC government entities by exploiting a particular type of secure USB drive, protected by hardware encryption to ensure the secure storage and transfer of data between computer systems," Kaspersky
18 October 2023
AIDS Alabama has confirmed a data breach that occurred between October 2021 and August 2022. Sensitive personal information such as names, addresses, Social Security numbers, medical diagnoses, and more were compromised.
18 October 2023
Prove Identity, the smartphone-based identity verification startup formerly known as Payfone, has raised $40 million in funding co-led by MassMutual Ventures and Capital One Ventures.
18 October 2023
Two federal class action lawsuits have been filed against IBM and Johnson & Johnson, alleging negligence in protecting sensitive health information and seeking financial damages and improved data security practices.
18 October 2023
Hackers are targeting Israeli Android users by distributing a malicious version of the popular RedAlert – Rocket Alerts app, which acts as spyware and collects sensitive data from victims. To tackle the current threat, Android users are advised to avoid using internet URLs or third-party app stores to download the app.
18 October 2023
The vulnerability stems from the use of the insecure randomness of the JavaScript Math.random() method, which can be exploited to predict and access restricted functionality.
18 October 2023
A medium-severity flaw has been discovered in Synology's DiskStation Manager (DSM) that could be exploited to decipher an administrator's password and remotely hijack the account.
"Under some rare conditions, an attacker could leak enough information to restore the seed of the pseudorandom number generator (PRNG), reconstruct the admin password, and remotely take over the admin account,"
17 October 2023
Taiwanese networking equipment manufacturer D-Link has confirmed a data breach that led to the exposure of what it said is "low-sensitivity and semi-public information."
"The data was confirmed not from the cloud but likely originated from an old D-View 6 system, which reached its end of life as early as 2015," the company said.
"The data was used for registration purposes back then. So far, no
17 October 2023
Two critical security flaws in CasaOS personal cloud software allowed attackers to bypass authentication and gain full access to the system, posing a significant cyber threat.
17 October 2023
The threat group behind the SocGholish campaigns is likely responsible for the ClearFake malware delivery campaign, which uses compromised WordPress sites to push malicious fake browser updates.
17 October 2023
The US cybersecurity agency, CISA, has warned organizations about critical vulnerabilities found in a human-machine interface (HMI) product made by the Taiwan-based Weintek. The impacted product is used globally, including in critical manufacturing.
17 October 2023
According to a recent data recovery report, 63% of organizations successfully restore their data when they experience a ransomware attack.
17 October 2023
Amir Golestan, the 40-year-old CEO of the Charleston, S.C. based technology company Micfo LLC, has been sentenced to five years in prison for wire fraud. Golestan's sentencing comes nearly two years after he pleaded guilty to using an elaborate network of phony companies to secure more than 735,000 Internet Protocol (IP) addresses from the American Registry for Internet Numbers (ARIN), the nonprofit which oversees IP addresses assigned to entities in the U.S., Canada, and parts of the Caribbean.
17 October 2023
The Black Basta ransomware gang claimed responsibility for the attack, but the extent of the data stolen is unknown. The company confirmed the incident and stated that they are working with law enforcement to address the issue.
17 October 2023
Startup with roots in the ecommerce mobile payments space raises $40 million for digital identity verification and authentication technology.
The post Prove Identity Snags $40M Funding for ID Verification Tech appeared first on SecurityWeek.
17 October 2023
The attackers behind the XorDDoS campaign have migrated their offensive infrastructure to legitimate public hosting services, making it harder to block their command and control (C2) traffic.
17 October 2023
In what's the latest evolution of threat actors abusing legitimate infrastructure for nefarious ends, new findings show that nation-state hacking groups have entered the fray in leveraging the social platform for targeting critical infrastructure.
Discord, in recent years, has become a lucrative target, acting as a fertile ground for hosting malware using its content delivery network (CDN) as
17 October 2023
The feared ‘cryptopocalypse’ (the death of current encryption) might be sooner than expected – caused by in-memory computing ASICs rather than quantum computers.
The post Beyond Quantum: MemComputing ASICs Could Shatter 2048-bit RSA Encryption appeared first on SecurityWeek.