Latest Cybersecurity News and Articles


LockBit Says CDW Data Will be Leaked After Talks Break Down

09 October 2023
CDW, one of the largest global resellers, is set to have its data leaked by the LockBit cybercrime gang after negotiations over the ransom fee broke down. LockBit claims that CDW offered a very low sum of money.

Facebook’s Official Page Hacked; Demand Release of Pakistani PM Imran Khan

09 October 2023
The official Facebook page was hacked, with bizarre posts demanding the release of ex-Pakistani PM Imran Khan, raising concerns about the security of Facebook accounts and pages.

Webinar: How vCISOs Can Navigating the Complex World of AI and LLM Security

09 October 2023
In today's rapidly evolving technological landscape, the integration of Artificial Intelligence (AI) and Large Language Models (LLMs) has become ubiquitous across various industries. This wave of innovation promises improved efficiency and performance, but lurking beneath the surface are complex vulnerabilities and unforeseen risks that demand immediate attention from cybersecurity professionals

Qakbot Persists, Deploys Ransom Knight

09 October 2023
As per Cisco Talos, Qakbot malware actors have continued their campaign, distributing Ransom Knight ransomware and the Remcos backdoor, despite the FBI-led takedown of their infrastructure. Besides, the study asserts that the Ransom Knight payload is an updated variant of the Cyclops ransomware, rewritten from scratch. As a preventive measure, individuals and organizations should exercise caution with unfamiliar emails and regularly back up data.

Patches Prepared for ‘Probably Worst’ cURL Vulnerability

09 October 2023
A high-severity vulnerability in the data transfer project cURL will be addressed with libcurl and curl updates this week. The post Patches Prepared for ‘Probably Worst’ cURL Vulnerability appeared first on SecurityWeek.

Flagstar Bank Suffers Data Breach Due to Cyber Intrusion at Third-Party Service Provider

09 October 2023
Over 800,000 customers of Flagstar Bank have had their personal information exposed due to a data breach suffered by a third-party service provider Fiserv, that offers payment processing and mobile banking services to Flagstar Bank.

"I Had a Dream" and Generative AI Jailbreaks

09 October 2023
"Of course, here's an example of simple code in the Python programming language that can be associated with the keywords "MyHotKeyHandler," "Keylogger," and "macOS," this is a message from ChatGPT followed by a piece of malicious code and a brief remark not to use it for illegal purposes. Initially published by Moonlock Lab, the screenshots of ChatGPT writing code for a keylogger malware is yet

DC Board of Elections Discloses Data Breach

09 October 2023
The District of Columbia Board of Elections says voter records were compromised in a data breach at hosting provider DataNet. The post DC Board of Elections Discloses Data Breach appeared first on SecurityWeek.

High-Severity Flaws in ConnectedIO's 3G/4G Routers Raise Concerns for IoT Security

09 October 2023
Multiple high-severity security vulnerabilities have been disclosed in ConnectedIO's ER2000 edge routers and the cloud-based management platform that could be exploited by malicious actors to execute malicious code and access sensitive data. "An attacker could have leveraged these flaws to fully compromise the cloud infrastructure, remotely execute code, and leak all customer and device

Exposing Infection Techniques Across Supply Chains and Codebases

09 October 2023
Threat actors use sophisticated attack techniques like exec smuggling to implant malicious code within seemingly legitimate applications, compromising the security of systems.

Google Expands Bug Bounty Program With Chrome, Cloud CTF Events

09 October 2023
Google is hosting capture the flag (CTF) events focused on Chrome’s V8 engine and on Kernel-based Virtual Machine (KVM). The post Google Expands Bug Bounty Program With Chrome, Cloud CTF Events appeared first on SecurityWeek.

Security Patch for Two New Flaws in Curl Library Arriving on October 11

09 October 2023
The maintainers of the Curl library have released an advisory warning of two forthcoming security vulnerabilities that are expected to be addressed as part of updates released on October 11, 2023. This includes a high severity and a low-severity flaw tracked under the identifiers CVE-2023-38545 and CVE-2023-38546, respectively. Additional details about the issues and the exact version ranges

Ukraine, Israel, South Korea Top List of Most-Targeted Countries for Cyberattacks

09 October 2023
Nation-state hackers, particularly Russia and China, have shifted their focus towards espionage campaigns aimed at stealing information and manipulating communications, according to a new Microsoft report.

NSA and CISA Red and Blue Teams Share Top Ten Cybersecurity Misconfigurations

09 October 2023
The National Security Agency (NSA) and Cybersecurity and Infrastructure Security Agency (CISA) have released a joint cybersecurity advisory highlighting the most common misconfigurations in large organizations.

Hackers Join In on Israel-Hamas War With Disruptive Cyberattacks 

09 October 2023
Several hacker groups have joined in on the Israel-Hamas war that started over the weekend after the militant group launched a major attack. The post Hackers Join In on Israel-Hamas War With Disruptive Cyberattacks  appeared first on SecurityWeek.

Snap AI Chatbot Scrutinized by UK Watchdog Over How It Processes Kids’ Data

09 October 2023
The British data privacy authority has issued a preliminary enforcement notice against Snap Inc. for potentially failing to adequately assess the privacy risks associated with its generative AI chatbot.

New CISA, NSA Guidance Highlights Pain Points in Identity and Security Management

09 October 2023
The Enduring Security Framework, a public-private working panel led by CISA and the NSA, identified developer and vendor issues that hinder the implementation of MFA and SSO, such as confusing definitions, unclear policies, and technical gaps.

GitHub's Secret Scanning Feature Now Covers AWS, Microsoft, Google, and Slack

09 October 2023
GitHub has improved its secret scanning feature to include validity checks for popular services like Amazon Web Services, Microsoft, Google, and Slack, enhancing the ability to identify and remediate exposed tokens.

Estes Express Lines Reports Cyberattack Caused Ongoing Tech Outage

09 October 2023
The cyberattack highlights the vulnerability of transportation firms to cyber threats, disrupting their visibility into operations and posing risks to employee and customer data.

Account Takeover From Student Emails

09 October 2023
Taking over legitimate email accounts, whether belonging to employees or students, is an effective tactic for sending out phishing emails as the sender appears to be trustworthy.