Latest Cybersecurity News and Articles
17 October 2023
Cisco is warning customers that a new IOS XE zero-day vulnerability tracked as CVE-2023-20198 is being exploited to hack devices.
The post Cisco Devices Hacked via IOS XE Zero-Day Vulnerability appeared first on SecurityWeek.
17 October 2023
A critical vulnerability in the Royal Elementor WordPress plugin has been exploited as a zero-day since August 30.
The post WordPress Websites Hacked via Royal Elementor Plugin Zero-Day appeared first on SecurityWeek.
17 October 2023
Void Rabisu has been found deploying the new RomCom 4.0 backdoor against participants of the Women Political Leaders (WPL) Summit in Brussels. According to researchers, the latest variant has undergone some significant changes in its architecture, making it lighter and stealthier. Organizations are advised to stay protected by staying updated on the RomCom attack trends and making use of the IoCs shared by Trend Micro.
17 October 2023
Air Vice-Marshal Tim Neal-Hopes has been appointed as the new commander of the United Kingdom's National Cyber Force (NCF). He joins the NCF from Strategic Command, where he served as the director for cyber, intelligence, and information integration.
17 October 2023
The vendor has released a patch (version 1.3.79) to fix the flaw (CVE-2023-5360), and users are recommended to upgrade as soon as possible, but a website cleanup may be necessary to remove any infections or malicious files.
17 October 2023
The company conducted a thorough investigation and found no indication that the vulnerability is real. Signal also reached out to the US government, which provided no information to support the claim.
17 October 2023
The recently disclosed flaw (CVE-2023-22515) in Atlassian Confluence Data Center and Server allows malicious actors to create unauthorized administrator accounts, leading to widespread exploitation and the need for immediate application of upgrades.
17 October 2023
The agreement between the US and the UAE comes ahead of the International Counter Ransomware Initiative summit, where governments are expected to pledge not to pay ransoms to cybercriminals.
17 October 2023
The vulnerability affects enterprise networking gear with the Web UI feature enabled and exposed to the internet or untrusted networks, and it is recommended to disable the HTTP server feature as a mitigation.
17 October 2023
The Computer Emergency Response Team of Ukraine (CERT-UA) has revealed that threat actors "interfered" with at least 11 telecommunication service providers in the country between May and September 2023.
The agency is tracking the activity under the name UAC-0165, stating the intrusions led to service interruptions for customers.
The starting point of the attacks is a reconnaissance phase in
17 October 2023
Cisco has warned of a critical, unpatched security flaw impacting IOS XE software that’s under active exploitation in the wild.
Rooted in the web UI feature, the zero-day vulnerability is assigned as CVE-2023-20198 and has been assigned the maximum severity rating of 10.0 on the CVSS scoring system.
It’s worth pointing out that the shortcoming only affects enterprise networking gear that have
16 October 2023
Henry Schein announced that a part of the company's manufacturing and distribution business suffered a data breach on October 14, 2023.
16 October 2023
Dozens of vulnerabilities in the Squid caching and forwarding web proxy, a widely used open-source proxy, remain unpatched two years after being discovered by researcher Joshua Rogers.
16 October 2023
Generative artificial intelligence use within the workplace was analyzed in a recent report, finding 9% of organizations feel prepared for the threat.
16 October 2023
The US EPA has withdrawn cybersecurity rules for public water systems due to lawsuits filed by states and non-profit water associations, citing concerns about financial burden and cybersecurity vulnerabilities.
16 October 2023
The vulnerability exposes system log files containing passwords, which can be used by attackers to gain unauthorized access. Security firm VulnCheck discovered evidence of small-scale exploitation of the vulnerability.
16 October 2023
Users should carefully review app permissions and ensure they are using the latest version of the app to minimize the risk of being targeted by spyware or fake notifications.
16 October 2023
The attackers exploit a recent flaw in WinRAR to execute malicious code and gain remote access to compromised systems. They also use a PowerShell script to steal data, including login credentials, from Google Chrome and Microsoft Edge browsers.
16 October 2023
A recent report found that 55% of IT leaders surveyed feel they need more education on how passwordless technology works and/or how to deploy it.
16 October 2023
The ransomware group demanded an $80 million ransom, but CDW only offered $1 million. CDW states that the affected servers are isolated and not customer-facing, and its systems remain fully operational.