Latest Cybersecurity News and Articles
13 October 2023
CISA is now flagging vulnerabilities and misconfigurations that are known to be exploited in ransomware attacks.
The post CISA Now Flagging Vulnerabilities, Misconfigurations Exploited by Ransomware appeared first on SecurityWeek.
13 October 2023
A new vulnerability in the User Submitted Posts WordPress plugin (versions 20230902 and below) has been discovered by the Patchstack team. The vulnerability has been assigned CVE-2023-45603.
13 October 2023
Fact sheet released by CISA provides software security challenges and recommendations to improve security and risk management of OSS use.
13 October 2023
The State Department has undergone a significant cybersecurity overhaul, prioritizing a zero-trust security architecture and implementing key performance indicators and guidance from various federal agencies.
13 October 2023
Juniper Networks patches over 30 vulnerabilities in Junos OS and Junos OS Evolved, including nine high-severity bugs.
The post Juniper Networks Patches Over 30 Vulnerabilities in Junos OS appeared first on SecurityWeek.
13 October 2023
The Vietnamese government is suspected of being behind a targeted campaign using social media to spread links containing commercial spyware, with potential targets including members of the U.S. Congress and European officials.
13 October 2023
A new report sheds light on the distinctive cybersecurity risks facing financial services organizations.
13 October 2023
In Other
The post In Other News: Ex-Uber Security Chief Appeal, New Offerings From Tech Giants, Crypto Bounty appeared first on SecurityWeek.
13 October 2023
Cybersecurity has become a top concern for small and medium enterprises (SMEs) and nearly half (48%) of SMEs have experienced at least one cyber incident in the past year, according to a survey from Sage.
13 October 2023
The advanced persistent threat (APT) actor known as ToddyCat has been linked to a new set of malicious tools that are designed for data exfiltration, offering a deeper insight into the hacking crew's tactics and capabilities.
The findings come from Kaspersky, which first shed light on the adversary last year, linking it to attacks against high-profile entities in Europe and Asia for nearly three
13 October 2023
DarkGate is a commodity loader that has been increasingly used in initial entry attacks, offering various malicious capabilities such as keylogging, browser information theft, and privilege escalation.
13 October 2023
There were 2116 reported US data breaches and leaks in the first nine months of 2023, making it the worst year on record with a whole quarter left to go, according to the Identity Theft Resource Center (ITRC).
13 October 2023
Ransomware attacks have only increased in sophistication and capabilities over the past year. From new evasion and anti-analysis techniques to stealthier variants coded in new languages, ransomware groups have adapted their tactics to bypass common defense strategies effectively.
This article will cover just some of those new developments in Q3-2023 as well as give predictions on quarters to
13 October 2023
The FBI and the CISA recommend implementing application control mechanisms, limiting remote desktop services, and following best practices such as updating software and using strong passwords to defend against AvosLocker ransomware attacks.
13 October 2023
A piece of malware known as DarkGate has been observed being spread via instant messaging platforms such as Skype and Microsoft Teams.
In these attacks, the messaging apps are used to deliver a Visual Basic for Applications (VBA) loader script that masquerades as a PDF document, which, when opened, triggers the download and execution of an AutoIt script designed to launch the malware.
"It's
13 October 2023
Progress Software has received a subpoena from the SEC and faces multiple class action lawsuits and claims for indemnification due to the MOVEit vulnerability, resulting in significant costs.
13 October 2023
After nearly a week of intense speculation regarding the security issues in cURL, the latest version of this command-line transfer tool has been released with a fix. Vulnerable systems could allow potential attacks via a malicious HTTPS server redirect. Organizations are urged to promptly update and secure systems using cURL or libcurl.
13 October 2023
The AvosLocker ransomware gang has been linked to attacks against critical infrastructure sectors in the U.S., with some of them detected as recently as May 2023.
That's according to a new joint cybersecurity advisory released by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) detailing the ransomware-as-a-service (RaaS) operation's
13 October 2023
The Reichsadler Cybercrime Group attempted to deploy ransomware on unpatched WS_FTP servers using a stolen LockBit 3.0 builder. The attackers used the GodPotato tool to escalate privileges on the servers.
13 October 2023
Dozens of Squid caching proxy vulnerabilities remain unpatched two years after a researcher reported them to developers.
The post Dozens of Squid Proxy Vulnerabilities Remain Unpatched 2 Years After Disclosure appeared first on SecurityWeek.