Latest Cybersecurity News and Articles
13 July 2023
“There was no disruption of critical County services, such as 911 dispatch. Kent County's Information Technology team responded immediately and have received strong support from the State of Delaware and local governments,” county officials said.
13 July 2023
In a sign that cybersecurity researchers continue to be under the radar of malicious actors, a proof-of-concept (PoC) has been discovered on GitHub, concealing a backdoor with a "crafty" persistence method.
"In this instance, the PoC is a wolf in sheep's clothing, harboring malicious intent under the guise of a harmless learning tool," Uptycs researchers Nischay Hegde and Siddartha Malladi said.
13 July 2023
Wiz uncovered a fileless malware called PyLoose, specifically targeting cloud workloads. This attack involves Python code that utilizes the memfd technique to load an XMRig miner directly into memory. Around 200 instances of this technique were spotted being used for cryptomining. PyLoose was first detected on June 22, after it gained initial access through a publicly accessible Jupyter Notebook service.
13 July 2023
TikTok executives were unable to answer Liberal senator and chair of the committee James Paterson when he questioned them on how many times Australian user data had been accessed by TikTok staff in China, but the executives admitted it had happened.
13 July 2023
With at least 75% of organizations upgrading infrastructure and 78% increasing security budgets, a new report highlights disparity between infrastructure upgrades, spending and security improvements.
13 July 2023
According to the researchers, if these flaws are exploited, threat actors can easily access user databases of countless applications, putting millions of user records at risk of exposure and exploitation.
13 July 2023
The financially-motivated threat actor, known as Scarleteel, has been observed abusing Amazon Web Services (AWS) Fargate with the objective of stealing credentials and intellectual property. Additionally, it has expanded its arsenal to carry out distributed DDoS attacks and more. Organizations are advised to deploy multiple layers of defenses to stay safe.
13 July 2023
Nearly three-quarters (72%) of white hat hackers do not believe that generative AI can replace human creativity in security research and vulnerability management, according to Bugcrowd’s Inside the Mind of a Hacker – 2023 report.
13 July 2023
Microsoft and U.S. officials confirmed Wednesday that a threat actor based in China had hacked the Outlook email accounts of U.S. government agencies and at least 25 European governments for the purpose of espionage and data theft.
13 July 2023
Security leaders are concerned about attacks that leverage malware-exfiltrated authentication data, with 53% expressing extreme concern and less than 1% admitting they weren’t concerned at all, according to SpyCloud.
13 July 2023
SonicWall warned customers today to urgently patch multiple critical vulnerabilities impacting the company's Global Management System (GMS) firewall management and Analytics network reporting engine software suites.
13 July 2023
The Cyware Partner Advisory Marketplace provides a platform for security vendors to make intelligence feeds easily available to Cyware’s extensive network of direct customers, and members of ISACs, ISAOs, and other intelligence sharing communities.
13 July 2023
President Joe Biden has yet to officially nominate a new director to lead the Office of the National Cyber Director following Chris Inglis' retirement in February, leaving Acting Director Kemba Walden to fill the spot ever since.
13 July 2023
More than three-quarters of a million people may have had their social security numbers stolen in a data breach at Lansing Community College in late 2022 and early 2023, according to a law firm that says it's investigating the incident.
13 July 2023
Comparisons of vulnerability scans by the VA OIG inspectors showed that the VA Office of IT handling the Northern Arizona system did not identify all critical or high-risk vulnerabilities in the network or remediate flaws, the report said.
13 July 2023
Gamers should be cautious of downloading cheats or hacks from untrusted sources as they may unknowingly install malware that compromises their personal information and gaming experience.
13 July 2023
Apple fixed and re-released emergency security updates addressing a WebKit zero-day vulnerability exploited in attacks. The initial patches had to be withdrawn on Monday due to browsing issues on certain websites.
13 July 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has alerted of two security flaws impacting Rockwell Automation ControlLogix EtherNet/IP (ENIP) communication module models that could be exploited to achieve remote code execution and denial-of-service (DoS).
"The results and impact of exploiting these vulnerabilities vary depending on the ControlLogix system configuration, but
13 July 2023
The attacks, which commenced on May 15, 2023, entailed access to email accounts affecting approximately 25 entities and a small number of related individual consumer accounts.
13 July 2023
Kernel-mode drivers operate at the highest privilege level on Windows (Ring 0), allowing complete access to the target machine for stealthy persistence, undetectable data exfiltration, and the ability to terminate almost any process.