Latest Cybersecurity News and Articles
06 October 2023
Businesses are investing more in cybersecurity resources and training, resulting in a decrease in phishing links clicked by workers and ransomware attacks, according to GetApp.
06 October 2023
The Node.js malware Lu0Bot uses unconventional programming languages and multi-layer obfuscation. Lu0Bot utilizes a unique approach to domain connection and assembles various parts into a single entity within the JavaScript code.
06 October 2023
GitHub has announced an improvement to its secret scanning feature that extends validity checks to popular services such as Amazon Web Services (AWS), Microsoft, Google, and Slack.
Validity checks, introduced by the Microsoft subsidiary earlier this year, alert users whether exposed tokens found by secret scanning are active, thereby allowing for effective remediation measures. It was first
06 October 2023
Clorox anticipates continued operational strain in the second quarter but hopes to benefit from restocking retailer inventory, while assessing the long-term impact on earnings.
06 October 2023
The scheme, known as BADBOX, deploys the Triada malware as a "backdoor" on various devices such as CTV boxes, smartphones, and tablets during the supply chain process in China.
06 October 2023
The Department of Homeland Security is investigating the attack to determine if sensitive physical security information was compromised, but it was not a breach of any DHS network or system.
06 October 2023
The United States, Canada, and Italy are the countries with the highest number of organizations with exposed ICSs, while sectors such as Education, Technology, and Government show the least secure ICS security.
06 October 2023
Multiple security vulnerabilities have been disclosed in the Intelligent Platform Management Interface (IPMI) firmware for Supermicro baseboard management controllers (BMCs) that could result in privilege escalation and execution of malicious code on affected systems.
The seven flaws, tracked from CVE-2023-40284 through CVE-2023-40290, vary in severity from High to Critical, according to Binarly
05 October 2023
Cisco warns that unauthenticated, remote attackers can log into devices using root account, which has default, static credentials that cannot be changed or deleted.
The post Cisco Plugs Gaping Hole in Emergency Responder Software appeared first on SecurityWeek.
05 October 2023
The GoldDigger trojan has been active since at least June 2023 and is currently targeting users of over 50 Vietnamese banking apps, as well as e-wallets and crypto-wallets.
05 October 2023
The organizations targeted by PLAY include Roof Management, Security Instrument Corp, Filtration Control Ltd, Cinépolis Cinemas, CHARMANT Group, and Stavanger Municipality.
05 October 2023
Attackers redirect victims to scams that involve QR codes and phishing websites promising to double their cryptocurrency investments, often using deep fake videos of Elon Musk to add credibility.
05 October 2023
Stream-jacking attacks on YouTube are increasing, targeting popular channels to spread deceptive content. Cybercriminals hijack these channels, often impersonating famous figures or brands like Elon Musk and Tesla, promoting scams like crypto doubling. Viewers should be cautious of videos with clickbait titles, especially those promoting financial opportunities.
05 October 2023
Really Simple Systems exposed a non-password-protected database with over 3 million records, including highly sensitive customer information such as medical records and tax documents.
05 October 2023
Despite the focus on cloud security, many organizations still have risk management lapses, such as not addressing disaster recovery and backup with their cloud service provider.
05 October 2023
While the specific APT group behind the campaign could not be identified, there is medium confidence that it is a China-aligned threat group based on the use of a variant of Korplug, which is commonly associated with such groups.
05 October 2023
GitHub beefs up its secret scanning feature, now allowing users to check the validity of exposed credentials for major cloud services.
The post GitHub Improves Secret Scanning Feature With Expanded Token Validity Checks appeared first on SecurityWeek.
05 October 2023
Dubbed “WebWyrm” by CloudSEK, the operation has already targeted more than 100,000 individuals across over 50 countries by impersonating over 1000 companies across 10 industries. It has already potentially netted the scammers over $100m.
05 October 2023
Phone call fraud and spam callers were analyzed in a recent report by Hiya, finding Amazon impersonation scams in the top scams of 2023.
05 October 2023
South Korea's National Intelligence Service said it is notifying shipbuilders of threats to their systems and networks and advising major shipyards to conduct independent security audits to plug security holes in digital infrastructure.