Latest Cybersecurity News and Articles
17 October 2023
Two critical security flaws discovered in the open-source CasaOS personal cloud software could be successfully exploited by attackers to achieve arbitrary code execution and take over susceptible systems.
The vulnerabilities, tracked as CVE-2023-37265 and CVE-2023-37266, both carry a CVSS score of 9.8 out of a maximum of 10.
Sonar security researcher Thomas Chauchefoin, who discovered the bugs,
17 October 2023
The Knight group threatened to release stolen files and provided countdown links. However, the parent company, BMW, has not confirmed the attack. The website for BMW Munique Motors is still operational.
17 October 2023
The security concerns of generative artificial intelligence (AI) use within the workplace were analyzed in a recent report by ExtraHop.
17 October 2023
These include authenticated remote code execution via "zip slip" and WebDAV path traversal, session fixation on the remote administration server, information disclosure via path traversal on FTP, and information disclosure in the admin interface.
17 October 2023
Data transmission faces a looming threat from Harvest Now, Decrypt Later (HNDL) attacks, where encrypted data is collected and stored with the intention of decrypting it in the future using advancements in computing or quantum technologies.
17 October 2023
Anonybit has raised $3 million in seed funding extension for its biometric authentication and data protection solutions.
The post Anonybit Raises $3 Million for Biometric Authentication Platform appeared first on SecurityWeek.
17 October 2023
A new report by Trellix reveals that Discord, a popular communication platform, is being increasingly used by hackers, including advanced persistent threat (APT) groups, to target critical infrastructure.
17 October 2023
A recent survey by Hornetsecurity reveals that 60% of companies are highly concerned about ransomware attacks, highlighting the urgency for robust protection measures and the active involvement of leadership in preventing such incidents.
17 October 2023
Weintek has patched critical and high-severity vulnerabilities found in its cMT series HMIs by industrial cybersecurity firm TXOne.
The post Critical Vulnerabilities Expose Weintek HMIs to Attacks appeared first on SecurityWeek.
17 October 2023
The exact reason for the significant increase in affected individuals since July is unclear, but ongoing investigation and the discovery of additional compromised locations may be contributing factors.
17 October 2023
A recently released report reveals more than half of senior leaders have no involvement in their company's cyber cases.
17 October 2023
Security researchers discovered threat actors using the Discord platform to distribute Lumma Stealer, an information-stealing malware. The malware is designed to steal user credentials, cryptocurrency wallets, and browser data. Users need to exercise caution while clicking links or downloading files from unverified sources.
17 October 2023
The hackers used reconnaissance techniques to identify vulnerabilities in the telecom providers' networks and gained unauthorized access using compromised servers in the Ukrainian internet segment.
17 October 2023
Financial data is much more than just a collection of numbers; it is a crucial component of any business and a prime target for cybercriminals. It's important to understand that financial records can be a veritable treasure trove for digital pirates.
A security breach not only puts customers' personal information in jeopardy but also enables fraudsters to drain company funds and exploit clients.
17 October 2023
Researchers from Radware found that Israel endured 143 DDoS attacks between October 2 and October 10, making it the most targeted nation-state during that period. These attacks were all claimed by hacktivists on the messaging service Telegram.
17 October 2023
The Kansas Supreme Court and other district courts in the state are experiencing a disruption in their IT systems due to a security incident, leading to the suspension of electronic filing of documents.
17 October 2023
NSA has released Elitewolf, a repository of intrusion detection signatures and analytics for OT environments.
The post NSA Publishes ICS/OT Intrusion Detection Signatures and Analytics appeared first on SecurityWeek.
17 October 2023
Recently, the cybersecurity landscape has been confronted with a daunting new reality – the rise of malicious Generative AI, like FraudGPT and WormGPT. These rogue creations, lurking in the dark corners of the internet, pose a distinctive threat to the world of digital security. In this article, we will look at the nature of Generative AI fraud, analyze the messaging surrounding these creations,
17 October 2023
A severity flaw impacting industrial cellular routers from Milesight may have been actively exploited in real-world attacks, new findings from VulnCheck reveal.
Tracked as CVE-2023-43261 (CVSS score: 7.5), the vulnerability has been described as a case of information disclosure that affects UR5X, UR32L, UR32, UR35, and UR41 routers before version 35.3.0.7 that could enable attackers to access
17 October 2023
CISA, FBI, and MS-ISAC warn of potential widespread exploitation of CVE-2023-22515, a critical vulnerability in Atlassian Confluence.
The post US Gov Expects Widespread Exploitation of Atlassian Confluence Vulnerability appeared first on SecurityWeek.