Latest Cybersecurity News and Articles
12 October 2023
The building materials producer experienced a cybersecurity incident that has caused disruptions in its operations and is expected to continue, leading to a pause in business operations.
12 October 2023
The discontinuation of Internet Explorer, which came bundled with VBScript, eliminates a prevalent infection vector used by threat actors to distribute malware on Windows systems.
12 October 2023
ZTNA simplifies operational costs by centralizing policy controls and adapting to changing conditions, reducing the need for expensive and challenging-to-maintain traditional network security measures.
12 October 2023
High-profile government and telecom entities in Asia have been targeted as part of an ongoing campaign since 2021 that's designed to deploy basic backdoors and loaders for delivering next-stage malware.
Cybersecurity company Check Point is tracking the activity under the name Stayin' Alive. Targets include organizations located in Vietnam, Uzbekistan, Pakistan, and Kazakhstan.
"The simplistic
12 October 2023
Patches have been released for two security flaws impacting the Curl data transfer library, the most severe of which could potentially result in code execution.
The list of vulnerabilities is as follows -
CVE-2023-38545 (CVSS score: 7.5) - SOCKS5 heap-based buffer overflow vulnerability
CVE-2023-38546 (CVSS score: 5.0) - Cookie injection with none file
CVE-2023-38545 is the more severe of the
11 October 2023
A recent Deep Instinct report found that more victims were affected by ransomware in the first half of 2023 than in the entirety of 2022.
11 October 2023
FortiGuard Labs found that the IZ1H9 Mirai-based DDoS botnet campaign has strengthened its arsenal with 13 exploits for D-Link devices, Netis wireless routers, TOTOLINK routers, Zyxel devices, and others. As the botnet expands its arsenal with new exploit triggers, it underscores the importance of applying security patches on time.
11 October 2023
The "Five Families" of hacktivist gangs, including ThreatSec, GhostSec, Stormous, Blackforums, and SiegedSec, are collaborating to launch large-scale cyberattacks, causing disruptions and chaos.
11 October 2023
The letter from the lawmakers follows a recent fine of 345 million euros (~$366 million) imposed on TikTok by the Irish Data Protection Commissioner for failing to adequately protect children's privacy.
11 October 2023
A recent survey conducted by Enea reveals that 76% of cybersecurity professionals believe that malicious AI, capable of bypassing most cybersecurity measures, is a looming threat.
11 October 2023
Google has released Chrome 118 with fixes for 20 vulnerabilities, including a critical bug in Site Isolation that could allow for sandbox escape and arbitrary code execution.
11 October 2023
Symantec found a previously unidentified threat actor named Grayling conducting advanced persistent attacks targeting organizations in Taiwan, the Pacific Islands, Vietnam, and the U.S., with a focus on intelligence gathering. Grayling's modus operandi seems to revolve around exploiting public infrastructures for initial access. This demands a keen eye on network anomalies and a rigorous patch management flow in place.
11 October 2023
Flaw poses a direct threat to the SOCKS5 proxy handshake process in cURL and can be exploited remotely in some non-standard configurations.
The post Critical SOCKS5 Vulnerability in cURL Puts Enterprise Systems at Risk appeared first on SecurityWeek.
11 October 2023
Spanish airline Air Europa is informing customers that their payment card information has been stolen as a result of a hacker attack.
The post Payment Card Data Stolen in Air Europa Hack appeared first on SecurityWeek.
11 October 2023
Citrix has released patches for a critical information disclosure vulnerability in NetScaler ADC and NetScaler Gateway.
The post Citrix Patches Critical NetScaler ADC, Gateway Vulnerability appeared first on SecurityWeek.
11 October 2023
The lawsuit alleged that Crunchyroll had disclosed subscribers' personal information to third parties without proper consent. Initially denying the allegations, Crunchyroll ultimately chose to settle to avoid expenses and uncertainties.
11 October 2023
The vulnerability, CVE-2023-22515, allows remote attackers to create unauthorized administrator accounts and gain access to Confluence servers. Organizations using Confluence applications should upgrade to the latest versions and isolate them.
11 October 2023
More than 17,000 WordPress websites have been compromised in the month of September 2023 with malware known as Balada Injector, nearly twice the number of detections in August.
Of these, 9,000 of the websites are said to have been infiltrated using a recently disclosed security flaw in the tagDiv Composer plugin (CVE-2023-3169, CVSS score: 6.1) that could be exploited by unauthenticated users to
11 October 2023
Automation and AI are being used by cybercriminals to enhance the speed and effectiveness of attacks, particularly in areas like money laundering and credential stuffing.
11 October 2023
CISA, FBI, NSA, and US Treasury published new guidance on improving the security of open source software in OT and ICS.
The post US Government Releases Security Guidance for Open Source Software in OT, ICS appeared first on SecurityWeek.