Latest Cybersecurity News and Articles


UK Opposition Leader Targeted by AI-Generated Fake Audio Smear

11 October 2023
An audio clip of UK opposition leader Keir Starmer verbally abusing his staff, which gained significant traction on social media, has been debunked as AI-generated by private-sector and government analysis.

Microsoft Releases October 2023 Patches for 103 Flaws, Including 2 Active Exploits

11 October 2023
Microsoft has released its Patch Tuesday updates for October 2023, addressing a total of 103 flaws in its software, two of which have come under active exploitation in the wild. Of the 103 flaws, 13 are rated Critical and 90 are rated Important in severity. This is apart from 18 security vulnerabilities addressed in its Chromium-based Edge browser since the second Tuesday of September. The two

Microsoft Warns of Nation-State Hackers Exploiting Critical Atlassian Confluence Vulnerability

11 October 2023
Microsoft has linked the exploitation of a recently disclosed critical flaw in Atlassian Confluence Data Center and Server to a nation-state actor it tracks as Storm-0062 (aka DarkShadow or Oro0lxy). The tech giant's threat intelligence team said it observed in-the-wild abuse of the vulnerability since September 14, 2023. "CVE-2023-22515 is a critical privilege escalation vulnerability in

Communicating cybersecurity risks with non-security personnel

11 October 2023
Listen to the new episode of The Security Podcasts featuring Grayson Milbourne, Security Intelligence Director at OpenText Cybersecurity.

Microsoft Blames Nation-State Threat Actor for Confluence Zero-Day Attacks

10 October 2023
Microsoft says an APT group tracked as Storm-0062 has been hacking Confluence installations since mid-September, three weeks before Atlassian’s disclosure. The post Microsoft Blames Nation-State Threat Actor for Confluence Zero-Day Attacks appeared first on SecurityWeek.

Patch Tuesday, October 2023 Edition

10 October 2023
Microsoft today issued security updates for more than 100 newly-discovered vulnerabilities in its Windows operating system and related software, including four flaws that are already being exploited. In addition, Apple recently released emergency updates to quash a pair of zero-day bugs in iOS.

54% of IT leaders believe advances AI systems pose incoming risks

10 October 2023
IT leaders were surveyed on incoming security risks within the next one to three years, including generative AI, data privacy and third parties. 

Threat actors exploit HTTP/2 vulnerability

10 October 2023
In late August 2023, Cloudflare discovered a zero-day vulnerability, developed by an unknown threat actor that exploits the standard HTTP/2 protocol.

Microsoft Fixes Exploited Zero-Days in WordPad, Skype for Business

10 October 2023
Microsoft patches more than 100 vulnerabilities across the Windows ecosystem and warned that three are already being exploited in the wild. The post Microsoft Fixes Exploited Zero-Days in WordPad, Skype for Business appeared first on SecurityWeek.

Beyond the Front Lines: How the Israel-Hamas War Impacts the Cybersecurity Industry

10 October 2023
The war with Hamas will inevitably absorb manpower and focus from the cybersecurity sector. The post Beyond the Front Lines: How the Israel-Hamas War Impacts the Cybersecurity Industry appeared first on SecurityWeek.

IZ1H9 Campaign Enhances Its Arsenal with Scores of Exploits

10 October 2023
The campaign leverages multiple vulnerabilities, including command injection, remote code execution, and arbitrary command execution, to gain control of targeted devices and incorporate them into the botnet.

90% of CISOs faced at least one cyberattack in 2022

10 October 2023
The security practices of Chief Information Security Officers and Chief Security Officers were analyzed in a recent report by Splunk Inc.

Previously Unseen Grayling APT Targets Multiple Organizations in Taiwan

10 October 2023
Grayling employs a combination of custom malware and publicly available tools like Havoc, Cobalt Strike, and NetSpy to carry out its attacks, using DLL sideloading techniques and exploiting vulnerabilities like CVE-2019-0803.

Patch Tuesday: Code Execution Flaws in Adobe Commerce, Photoshop

10 October 2023
Adobe Commerce customers exposed to code execution, privilege escalation, arbitrary file system read, and security feature bypass attacks. The post Patch Tuesday: Code Execution Flaws in Adobe Commerce, Photoshop appeared first on SecurityWeek.

HTTP/2 Rapid Reset Zero-Day Vulnerability Exploited to Launch Record DDoS Attacks

10 October 2023
Amazon Web Services (AWS), Cloudflare, and Google on Tuesday said they took steps to mitigate record-breaking distributed denial-of-service (DDoS) attacks that relied on a novel technique called HTTP/2 Rapid Reset. The layer 7 attacks were detected in late August 2023, the companies said in a coordinated disclosure. The cumulative susceptibility to this attack is being tracked as CVE-2023-44487,

Mirai Variant IZ1H9 Adds 13 Exploits to Arsenal

10 October 2023
A Mirai botnet variant tracked as IZ1H9 has updated its arsenal with 13 exploits targeting various routers, IP cameras, and other IoT devices. The post Mirai Variant IZ1H9 Adds 13 Exploits to Arsenal appeared first on SecurityWeek.

Air Europa Customers Urged to Cancel Cards Following Hack on Payment System

10 October 2023
Air Europa suffered a cyberattack on its online payment system. While there is no evidence of fraudulent use, customers are warned to replace their bank cards as a precautionary measure.

Gutsy Launches With Huge $51M Seed to Bring Process Mining to Security

10 October 2023
Gutsy, a cybersecurity startup founded by the team behind Twistlock, has emerged from stealth with a $51 million seed round led by YL Ventures and Mayfield. The company applies process mining, a data science technique, to cybersecurity.

SAP Releases 7 New Notes on October 2023 Patch Day

10 October 2023
SAP has released seven new notes as part of its October 2023 Security Patch Day, all rated ‘medium severity’. The post SAP Releases 7 New Notes on October 2023 Patch Day appeared first on SecurityWeek.

SecurityWeek to Host 2023 ICS Cybersecurity Conference October 23-26 in Atlanta

10 October 2023
SecurityWeek will host its 2023 Industrial Control Systems (ICS) Cybersecurity Conference from October 23 – 26, 2023 at the InterContinental Atlanta Buckhead. The post SecurityWeek to Host 2023 ICS Cybersecurity Conference October 23-26 in Atlanta appeared first on SecurityWeek.