Nikesh Arora on Palo Alto's Approach to Supply Chain DefenseThe $250 million acquisition of Cider Security will allow Palo Alto Networks to secure a piece of...
Day: December 15, 2022
Combating Ransomware Attacks: Which Strategies Hold Promise?
Combating Ransomware Attacks: Which Strategies Hold Promise?Defenders have made strides in disrupting ransomware, but assessing the effectiveness of countermeasures is tough due to a scarcity of...
Assessing Cyber Risk, Maturity in Healthcare M&As
Assessing Cyber Risk, Maturity in Healthcare M&AsWhen healthcare organizations come together through mergers or acquisitions, it is critical for the entities to carefully assess the cyber...
Patch Tuesday December 2022 – Microsoft Fixes Spoofing and Elevation of Privilege Vulnerabilities
Patch Tuesday December 2022 – Microsoft Fixes Spoofing and Elevation of Privilege VulnerabilitiesThe end of the year is here, and with it, Microsoft is trying to...
How Criminals Extort Healthcare Victims With Ransomware
How Criminals Extort Healthcare Victims With RansomwareVictims Urged to Prepare Rather Than Pay, Especially for False Data-Wiping PromisesRansomware operations have become expert at finding ways to...
Dental Practice Hit With HIPAA Fine for Posting PHI on Yelp
Dental Practice Hit With HIPAA Fine for Posting PHI on YelpHHS Settlement Is Latest Involving Similar Social Media BlundersA California dental practice that for years revealed...
Indian Ministry of External Affairs Platform Leaked Expats’ Passport Information
Indian Ministry of External Affairs Platform Leaked Expats’ Passport InformationSensitive information, such as names and passport numbers, was exposed through the Global Pravasi Rishta Portal, India’s...
Microsoft Patches Zero-Day Magniber Ransomware Hackers Used
Microsoft Patches Zero-Day Magniber Ransomware Hackers UsedSecureScreen Treated Malformed Signature the Same as a Valid SignatureMicrosoft's last monthly dump of patches for 2022 includes a fix...
New Actively Exploited Zero-Day Vulnerability Discovered in Apple Products
New Actively Exploited Zero-Day Vulnerability Discovered in Apple ProductsEarlier this week, Apple released updates to reinforce their security against a new zero-day vulnerability that could lead...
EmoLoad: Loading Emotet Modules without Emotet
EmoLoad: Loading Emotet Modules without EmotetOur latest report exposing Emotet’s supply chain would not have been possible without custom-made tools, tailored to analyze the core Emotet...
Hacker Reportedly Breaches US FBI Cybersecurity Forum
Hacker Reportedly Breaches US FBI Cybersecurity ForumBureau Ushered a Phony CEO Who Stole Emails Into a Seat at InfraGardA hacker selling a data set purportedly containing...
K35253541: Java vulnerabilities CVE-2020-14779, CVE-2020-14781, CVE-2020-14782, CVE-2020-14797
K35253541: Java vulnerabilities CVE-2020-14779, CVE-2020-14781, CVE-2020-14782, CVE-2020-14797Java vulnerabilities CVE-2020-14779, CVE-2020-14781, CVE-2020-14782, CVE-2020-14797 Security Advisory Security Advisory Description CVE-2020-14779 Vulnerability in the Java SE, Java SE Embedded...
K71522481: Java vulnerability CVE-2021-2163
K71522481: Java vulnerability CVE-2021-2163Java vulnerability CVE-2021-2163 Security Advisory Security Advisory Description Vulnerability in the Java SE, Java SE Embedded, Oracle GraalVM Enterprise Edition product of Oracle...
Microsoft: Windows 10 21H1 has reached end of servicing
Microsoft: Windows 10 21H1 has reached end of servicingMultiple editions of Windows 10 21H1 have reached their end of service (EOS) on this month's Patch Tuesday,...
K50343021: Node-vm2 vulnerability CVE-2022-36067
K50343021: Node-vm2 vulnerability CVE-2022-36067Node-vm2 vulnerability CVE-2022-36067 Security Advisory Security Advisory Description vm2 is a sandbox that can run untrusted code with whitelisted Nodes built-in modules. In...
California State Finance Department, Lockbit Ransomware’s Latest Victim
California State Finance Department, Lockbit Ransomware’s Latest VictimLockbit, the notorius Russian-linked ransomware group, claims to have added nine new victims to its growing list of conquests....
Uber Hit By New Data Breach After Attack on Third-Party Vendor
Uber Hit By New Data Breach After Attack on Third-Party VendorCompany information was stolen from third-party vendor Teqtivity and posted on a dark web forumLeer másCompany...
GoTrim Botnet Goes After WordPress Admin Accounts
GoTrim Botnet Goes After WordPress Admin AccountsGoTrim, a new Go-based botnet malware, scans the internet for WordPress websites and attempts to brute force the administrator’s password and...
Russian Medibank hackers could be first targets of Australian sanctions against cyber-attackers
Russian Medibank hackers could be first targets of Australian sanctions against cyber-attackersDfat confirms it has provided advice to minister Penny Wong about using cyber-related powers introduced...
California Hit By Cyber-Attack, LockBit Claims Responsibility
California Hit By Cyber-Attack, LockBit Claims ResponsibilityAt the time of writing, the California Budget website remains offlineLeer másAt the time of writing, the California Budget website...
VMware fixes critical ESXi and vRealize security flaws
VMware fixes critical ESXi and vRealize security flawsVMware released security updates to address a critical-severity vulnerability impacting ESXi, Workstation, Fusion, and Cloud Foundation, and a critical-severity...
15 seasonal cyber security shopping tips, keep your celebrations bright
15 seasonal cyber security shopping tips, keep your celebrations brightEXECUTIVE SUMMARY: Many people are eager to celebrate the beauty of the holiday season with parties, parades,...
Citrix ADC and Gateway Zero Day Exploited by Hackers
Citrix ADC and Gateway Zero Day Exploited by HackersCitrix urgently advises administrators to install security updates for Citrix ADC and Gateway due to a “Critical” zero-day...
Twitter Addresses November Data Leak Claims
Twitter Addresses November Data Leak ClaimsNo passwords were reportedly exposed, but Twitter prompted users to enable 2FA to protect accountsLeer másNo passwords were reportedly exposed, but...
The New Deepfake Regulations in China Raise Multiple Issues
The New Deepfake Regulations in China Raise Multiple IssuesFrom January 20, 2023, new regulations regarding deepfake will be in place in China. Cyberspace Administration of China...
CISO Pete Nicoletti on first-of-their-kind operational necessities for SMBs
CISO Pete Nicoletti on first-of-their-kind operational necessities for SMBsBy Pete Nicoletti, Field CISO, Americas. Pete has 32 years of Security, Network, and MSSP experience and has been...
Microsoft patches Windows zero-day used to drop ransomware
Microsoft patches Windows zero-day used to drop ransomwareMicrosoft has fixed a security vulnerability used by threat actors to circumvent the Windows SmartScreen security feature and deliver...
Two Zero-Days Fixed in December Patch Tuesday
Two Zero-Days Fixed in December Patch TuesdayClose to 50 CVEs addressed this monthLeer másClose to 50 CVEs addressed this month
Experts detailed a previously undetected VMware ESXi backdoor
Experts detailed a previously undetected VMware ESXi backdoorA new Python backdoor is targeting VMware ESXi servers, allowing attackers to take over compromised systems. Juniper Networks researchers...
Malicious Windows Drivers Used in Ransomware Attacks
Malicious Windows Drivers Used in Ransomware AttacksThreat actors used drivers signed by Microsoft hardware developer profiles for launching ransomware attacks. On October 19, this year, cyber...