Source: www.securityweek.com – Author: Eduard Kovacs The US Cybersecurity and Infrastructure Security Agency (CISA) warns that a recently patched critical vulnerability affecting some of the network-attached...
Author:
Ransomware Group Starts Naming Victims of MOVEit Zero-Day Attacks – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs The Cl0p ransomware group has made public the names of more than two dozen organizations that appear to have been...
Barracuda Zero-Day Attacks Attributed to Chinese Cyberespionage Group – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs The recent attacks exploiting a zero-day vulnerability in a Barracuda Networks email security appliance have been attributed by Mandiant to...
Fake Security Researcher Accounts Pushing Malware Disguised as Zero-Day Exploits – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs Exploit and vulnerability intelligence provider VulnCheck has issued a warning over fake security researcher accounts distributing malware disguised as zero-day...
Threat Intelligence Firm Silent Push Launches With $10 Million in Seed Funding – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs Silent Push, a startup that describes itself as a detection-focused threat intelligence company, launched on Wednesday with $10 million in...
ICS Patch Tuesday: Siemens Addresses Over 180 Third-Party Component Vulnerabilities – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs Siemens and Schneider Electric on Tuesday released a total of 16 advisories addressing well over 200 vulnerabilities affecting their industrial...
CosmicEnergy ICS Malware Poses No Immediate Threat, but Should Not Be Ignored – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs The recently discovered CosmicEnergy malware, which is designed to target industrial control systems (ICS), does not pose an immediate threat...
New Research Shows Potential of Electromagnetic Fault Injection Attacks Against Drones – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs New research shows the potential of electromagnetic fault injection (EMFI) attacks against unmanned aerial vehicles, with experts showing how drones...
Fortinet Warns Customers of Possible Zero-Day Exploited in Limited Attacks – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs Fortinet warned customers on Monday that the recently patched vulnerability tracked as CVE-2023-27997 could be a zero-day flaw that has...
New MOVEit Vulnerabilities Found as More Zero-Day Attack Victims Come Forward – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs Progress Software has released another round of patches for its MOVEit products after researchers discovered new vulnerabilities while analyzing the...
Fortinet Patches Critical FortiGate SSL VPN Vulnerability – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs Fortinet has patched a critical FortiGate vulnerability that can be exploited by an unauthenticated attacker for remote code execution, according...
In Other News: AI Regulation, Layoffs, US Aerospace Attacks, Post-Quantum Encryption – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs SecurityWeek is publishing a weekly cybersecurity roundup that provides a concise compilation of noteworthy stories that might have slipped under...
Evidence Suggests Ransomware Group Knew About MOVEit Zero-Day Since 2021 – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs Newly uncovered evidence suggests that cybercriminals have known about the recently patched MOVEit Transfer zero-day vulnerability since mid-2021. The zero-day...
Vulnerabilities in Honda eCommerce Platform Exposed Customer, Dealer Data – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs A researcher has disclosed the details of serious vulnerabilities discovered in a Honda ecommerce platform used for equipment sales. Exploitation...
Barracuda Urges Customers to Replace Hacked Email Security Appliances – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs Barracuda Networks is telling customers to immediately replace hacked Email Security Gateway (ESG) appliances, even if they have installed all...
ChatGPT Hallucinations Can Be Exploited to Distribute Malicious Code Packages – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs It’s possible for threat actors to manipulate artificial intelligence chatbots such as ChatGPT to help them distribute malicious code packages...
AntChain, Intel Create New Privacy-Preserving Computing Platform for AI Training – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs AntChain has teamed up with Intel to create a privacy-preserving computing platform designed for machine learning. The new AntChain Massive...
Several Major Organizations Confirm Being Impacted by MOVEit Attack – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs Several major organizations have confirmed being impacted by the recent MOVEit Transfer zero-day attack, just as a known ransomware group...
Verizon 2023 DBIR: Human Error Involved in Many Breaches, Ransomware Cost Surges – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs Verizon on Tuesday published its 16th annual Data Breach Investigations Report (DBIR) to provide organizations with useful information collected from...
Google Patches Third Chrome Zero-Day of 2023 – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs Google on Monday released a Chrome 114 security update that patches the third zero-day vulnerability found in the web browser...
Ransomware Group Used MOVEit Exploit to Steal Data From Dozens of Organizations – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs The recent MOVEit zero-day attack has been linked to a known ransomware group, which has reportedly exploited the vulnerability to...
Cybersecurity M&A Roundup: 36 Deals Announced in May 2023 – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs Thirty-six cybersecurity-related merger and acquisition (M&A) deals were announced in May 2023. An analysis conducted by SecurityWeek shows that more...
In Other News: Government Use of Spyware, New Industrial Security Tools, Japan Router Hack – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs SecurityWeek is publishing a weekly cybersecurity roundup that provides a concise compilation of noteworthy stories that might have slipped under...
Apple Denies Helping US Government Hack Russian iPhones – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs Apple has denied working with any government to add backdoors to its products after Russia accused the company of helping...
Zero-Day in MOVEit File Transfer Software Exploited to Steal Data From Organizations – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs A zero-day vulnerability affecting Progress Software’s MOVEit Transfer product has been exploited to hack organizations and steal their data. Progress...
Russia Blames US Intelligence for iOS Zero-Click Attacks – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs Russian anti-malware vendor Kaspersky on Thursday said it discovered an APT actor launching zero-click iMessage exploits on iOS-powered devices in...
Cisco Acquiring Armorblox for Predictive and Generative AI Technology – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs Cisco on Wednesday announced that it’s acquiring California-based cybersecurity firm Armorblox for its artificial intelligence (AI) technology. Armorblox specializes in...
Moxa Patches MXsecurity Vulnerabilities That Could Be Exploited in OT Attacks – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs Organizations using Moxa’s MXsecurity product have been informed about two potentially serious vulnerabilities that could be exploited by malicious hackers...
Organizations Warned of Salesforce ‘Ghost Sites’ Exposing Sensitive Information – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs Some organizations can expose sensitive personal and corporate information by failing to properly deactivate Salesforce Community websites that are no...
Organizations Warned of Backdoor Feature in Hundreds of Gigabyte Motherboards – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs Researchers at firmware and hardware security company Eclypsium discovered that hundreds of motherboard models made by Taiwanese computer components giant...