Source: www.securityweek.com – Author: Eduard Kovacs German software giant SAP has fixed more than a dozen new vulnerabilities with its August 2023 Patch Tuesday updates, including...
Author:
New ‘Inception’ Side-Channel Attack Targets AMD Processors – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs Researchers on Tuesday disclosed the details of a new CPU side-channel attack named Inception that impacts AMD processors. The Inception...
40 Vulnerabilities Patched in Android With August 2023 Security Updates – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs Just over 40 vulnerabilities have been patched by Google in the Android operating system with the release of the August...
Downfall: New Intel CPU Attack Exposing Sensitive Information – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs The details of a new side-channel attack targeting Intel processors were disclosed on Tuesday. The attack, discovered by a researcher...
Identity-Based Attacks Soared in Past Year: Report – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs CrowdStrike on Tuesday released its 2023 Threat Hunting Report, warning that threat actors have doubled down on identity-based attacks over...
ICS Patch Tuesday: Siemens Fixes 7 Vulnerabilities in Ruggedcom Products – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs Siemens released a dozen advisories covering more than 30 vulnerabilities this Patch Tuesday, but Schneider Electric has only published one...
Microsoft Shares Guidance and Resources for AI Red Teams – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs Microsoft on Monday published a summary of its artificial intelligence (AI) red teaming efforts, and shared guidance and resources that...
North Korean Hackers Targeted Russian Missile Developer – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs A Russian defense industrial base organization specializing in missiles and military spacecraft appears to have been targeted by two important...
New PaperCut Vulnerability Allows Remote Code Execution – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs Organizations have been warned about a new potentially serious vulnerability affecting the PaperCut NG/MF print management software. The flaw, tracked...
CISA Unveils Cybersecurity Strategic Plan for Next 3 Years – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs The US Cybersecurity and Infrastructure Security Agency (CISA) has unveiled its Cybersecurity Strategic Plan for the next three years, focusing...
Colorado Department of Higher Education Discloses Ransomware Attack, Data Breach – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs The Colorado Department of Higher Education (CDHE) has been targeted in a ransomware attack that resulted in a data breach...
Microsoft Criticized Over Handling of Critical Power Platform Vulnerability – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs A critical Microsoft Power Platform vulnerability exposed organizations’ authentication data and other secrets, but the tech giant has been accused...
Exploitation of Ivanti EPMM Flaw Picking Up as New Vulnerability Is Disclosed – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs Exploitation of the recently disclosed Ivanti Endpoint Manager Mobile (EPMM) vulnerability has started to pick up, just as the vendor...
670 ICS Vulnerabilities Disclosed by CISA in First Half of 2023: Analysis – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs The US Cybersecurity and Infrastructure Security Agency (CISA) disclosed 670 vulnerabilities affecting industrial control systems (ICS) and other operational technology...
Cybersecurity M&A Roundup: 42 Deals Announced in July 2023 – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs Forty-two cybersecurity-related merger and acquisition (M&A) deals were announced in July 2023. The number of transactions has bounced back following...
Salesforce Email Service Zero-Day Exploited in Phishing Campaign – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs Threat actors have exploited a Salesforce zero-day vulnerability and abused Meta features in a sophisticated phishing campaign, according to web...
Ivanti Zero-Day Exploited by APT Since at Least April in Norwegian Government Attack – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs The recently patched zero-day vulnerability affecting Ivanti’s Endpoint Manager Mobile (EPMM) product has been exploited by an advanced persistent threat...
Nearly All Modern CPUs Leak Data to New Collide+Power Side-Channel Attack – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs A new side-channel attack method that can lead to data leakage works against nearly any modern CPU, but we’re unlikely...
Ransomware Attacks on Industrial Organizations Doubled in Past Year: Report – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs The number of ransomware attacks targeting industrial organizations and infrastructure has doubled since the second quarter of 2022, according to...
Second Ivanti EPMM Zero-Day Vulnerability Exploited in Targeted Attacks – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs Ivanti has warned customers about a second zero-day vulnerability in its Endpoint Manager Mobile (EPMM) product that has been exploited...
Industry Reactions to New SEC Cyber Incident Disclosure Rules: Feedback Friday – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs The US Securities and Exchange Commission (SEC) has adopted new cybersecurity incident disclosure rules for public companies, but there is...
Weintek Weincloud Vulnerabilities Allowed Manipulation, Damaging of ICS Devices – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs Several vulnerabilities discovered by a researcher from industrial cybersecurity firm TXOne Networks in a Weintek product could have been exploited...
TSA Updates Pipeline Cybersecurity Requirements – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs The Transportation Security Administration (TSA) announced on Wednesday an update to its cybersecurity requirements for oil and natural gas pipeline...
Axis Door Controller Vulnerability Exposes Facilities to Physical, Cyber Threats – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs A potentially serious vulnerability affecting a network door controller made by Swedish security solutions provider Axis Communications can expose facilities...
Maritime Cyberattack Database Launched by Dutch University – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs The NHL Stenden University of Applied Sciences in the Netherlands recently announced the launch of a database tracking cyberattacks and...
Thales Acquiring Imperva From Thoma Bravo for $3.6 Billion – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs French aerospace, defense, and security giant Thales (Euronext Paris: HO) announced on Tuesday that it has reached an agreement with...
AMD CPU Vulnerability ‘Zenbleed’ Can Expose Sensitive Information – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs AMD has started releasing microcode patches to address a Zen 2 processor vulnerability that can allow an attacker to access...
Ivanti Zero-Day Vulnerability Exploited in Attack on Norwegian Government – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs A new zero-day vulnerability affecting a product of US-based enterprise software provider Ivanti has been exploited in an attack aimed...
MOVEit Hack Could Earn Cybercriminals $100M as Number of Confirmed Victims Grows – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs Ransomware recovery company Coveware believes the Cl0p ransomware gang could earn as much as $100 million from the MOVEit hack,...
Perimeter81 Vulnerability Disclosed After Botched Disclosure Process – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs Network security company Perimeter81 apparently needs to improve its responsible disclosure process for vulnerabilities found in its products. Cybersecurity researcher...





























