Category: Cybersecurity News, Insights and Analysis | SecurityWeek

Chinese UEFI Rootkit Found on Gigabyte and Asus Motherboards

Security researchers with Kaspersky have analyzed a UEFI firmware rootkit that appears to target specific motherboard models from Gigabyte and Asus. read more This article has been indexed from Cybersecurity News, Insights and Analysis | SecurityWeek Read the original article:…

Data Stolen in Breach at Security Company Entrust

Entrust suffered a data breach last month and the security company has confirmed that the attackers have stolen some files. read more This article has been indexed from Cybersecurity News, Insights and Analysis | SecurityWeek Read the original article: Data…

SonicWall Warns of Critical GMS SQL Injection Vulnerability

Network security appliance vendor SonicWall late Thursday shipped urgent patches for a critical flaw in its Global Management System (GMS) software, warning that the issue exposes businesses to remote hacker attacks. read more This article has been indexed from Cybersecurity…

Microsoft Resumes Rollout of Macro Blocking Feature

Microsoft this week announced that it has resumed the rollout of an Office feature that will block by default macros in documents received from the internet. Macros are small snippets of code attached to Office documents to trigger specific behavior…

Code Execution and Other Vulnerabilities Patched in Drupal

Drupal developers have announced the release of updates that patch several vulnerabilities in the open source content management system (CMS). read more This article has been indexed from Cybersecurity News, Insights and Analysis | SecurityWeek Read the original article: Code…

USCYBERCOM Releases IoCs for Malware Targeting Ukraine

The United States Cyber Command (USCYBERCOM) this week released indicators of compromise (IoCs) associated with malware families identified in recent attacks targeting Ukraine. read more This article has been indexed from Cybersecurity News, Insights and Analysis | SecurityWeek Read the…

Cisco Patches Severe Vulnerabilities in Nexus Dashboard

Cisco on Wednesday announced the availability of patches for multiple vulnerabilities in Nexus Dashboard, including a critical-severity issue that could lead to the execution of arbitrary commands. read more This article has been indexed from Cybersecurity News, Insights and Analysis…

Apple Ships Urgent Security Patches for macOS, iOS

It’s a very busy Patch Wednesday for computer users running Apple’s flagship macOS and iOS devices. Apple’s security response team has pushed out software fixes for at least 39 software vulnerabilities haunting the macOS Catalina, iOS and iPadOS platforms. read…

Can Encryption Key Intercepts Solve The Ransomware Epidemic?

California-based Nubeva is building technology to recover encrypted data without making ransomware payments read more This article has been indexed from Cybersecurity News, Insights and Analysis | SecurityWeek Read the original article: Can Encryption Key Intercepts Solve The Ransomware Epidemic?

Google, EU Warn of Malicious Russian Cyber Activity

Russia-linked Turla threat actor spotted using Android malware for first time Google and the European Union have issued separate warnings this week over Russian cyberattacks and misinformation campaigns. read more This article has been indexed from Cybersecurity News, Insights and…

Google Introduces DNS-over-HTTP/3 in Android

Google this week announced the rollout of DNS-over-HTTP/3 (DoH3) for Android 11 and newer devices. An encrypted DNS protocol, DoH3 is expected to provide performance and safety improvements compared to alternatives, mainly through the QUIC transport layer network protocol. read…

Chrome 103 Update Patches High-Severity Vulnerabilities

Google this week announced a Chrome update that resolves a total of 11 vulnerabilities in the browser, including six reported by external researchers. Of these, five are use-after-free issues, including four that are considered “high severity.” Use-after-free flaws are triggered…

German Consumer Group Sues Tesla Over Privacy, Climate

A German consumer group on Tuesday said it had sued US electric vehicles manufacturer Tesla over data privacy concerns and claims that buying its cars reduces emissions. read more This article has been indexed from Cybersecurity News, Insights and Analysis…

Push Security Banks $4 Million Seed Funding

Push Security, a British startup building technology to help defenders manage cloud software sprawl and shadow IT, has banked $4 million in early-stage venture capital funding. read more This article has been indexed from Cybersecurity News, Insights and Analysis |…

US Disrupts North Korean Hackers That Targeted Hospitals

The FBI and Justice Department recently disrupted the activities of a hacking group that was sponsored by the North Korean government and that targeted U.S. read more This article has been indexed from Cybersecurity News, Insights and Analysis | SecurityWeek…

New ‘CloudMensis’ macOS Spyware Used in Targeted Attacks

Researchers at cybersecurity company ESET have analyzed a previously undocumented macOS malware that appears to have been used in targeted attacks to steal valuable information from compromised systems. read more This article has been indexed from Cybersecurity News, Insights and…

FBI Warns of Fraudulent Crypto Investment Applications

The Federal Bureau of Investigation (FBI) is warning financial institutions and investors of fraudulent cryptocurrency investment applications used to defraud victims of millions of dollars. read more This article has been indexed from Cybersecurity News, Insights and Analysis | SecurityWeek…

US Cybersecurity Agency CISA to Open London Office

The US Cybersecurity and Infrastructure Security Agency (CISA) announced on Monday that it’s set to open an office in the United Kingdom in an effort to boost international cooperation and collaboration. read more This article has been indexed from Cybersecurity…

New Deanonymization Attack Works on Major Browsers, Websites

Researchers with the New Jersey Institute of Technology have devised a new targeted deanonymization attack that relies on a cache side-channel and which they say is efficient on multiple architectures, operating systems, and browser versions, and works on major websites.…

PLC and HMI Password Cracking Tools Deliver Malware

Tools advertised as being capable of cracking passwords for HMIs, PLCs and other industrial products have been found to exploit a zero-day vulnerability, and threat actors are using these tools to deliver malware. read more This article has been indexed…

Researchers Say Thai Pro-Democracy Activists Hit by Spyware

Cybersecurity researchers reported details Monday of cases where Thai activists involved in the country’s pro-democracy protests had their cell phones or other devices infected and attacked with government-sponsored spyware. read more This article has been indexed from Cybersecurity News, Insights…

Supply Chain Attack Technique Spoofs GitHub Commit Metadata

Security researchers at Checkmarx are warning of a new supply chain attack technique that relies on spoofed commit metadata to add legitimacy to malicious GitHub repositories. read more This article has been indexed from Cybersecurity News, Insights and Analysis |…

Software Vendors Start Patching Retbleed CPU Vulnerabilities

Vendors have started rolling out software updates to address the recently disclosed Retbleed speculative execution attack targeting Intel and AMD processors. read more This article has been indexed from Cybersecurity News, Insights and Analysis | SecurityWeek Read the original article:…