Category: SecurityWeek RSS Feed

International Arrests Over ‘Criminal’ Crypto Exchange

The owner of China-based cryptocurrency exchange Bitzlato was arrested in Miami on Wednesday, along with five associates in Europe, during an international operation against “darknet” markets. read more This article has been indexed from SecurityWeek RSS Feed Read the original…

Free Decryptors Released for BianLian, MegaCortex Ransomware

Avast and Bitdefender have released decryptors to help victims of BianLian and MegaCortex ransomware recover their data for free. Written in Golang, BianLian emerged in August 2022 and has been used in targeted attacks against entertainment, healthcare, media, and manufacturing…

CircleCI Hacked via Malware on Employee Laptop

Software development service CircleCI has revealed that a recently disclosed data breach was the result of information stealer malware being deployed on an engineer’s laptop. The incident was initially disclosed on January 4, when CircleCI urged customers to rotate their…

NSA Director Pushes Congress to Renew Surveillance Powers

A top U.S. intelligence official on Thursday urged Congress to renew sweeping powers granted to American spy agencies to surveil and examine communications, saying they were critical to stopping terrorism, cyberattacks and other threats. read more This article has been…

Most Cacti Installations Unpatched Against Exploited Vulnerability

Most internet-exposed Cacti installations have not been patched against a critical-severity command injection vulnerability that is being exploited in attacks. read more This article has been indexed from SecurityWeek RSS Feed Read the original article: Most Cacti Installations Unpatched Against…

Tesla Returns as Pwn2Own Hacker Takeover Target

Electric car maker Tesla is using the annual Pwn2Own hacker contest to incentivize security researchers to showcase complex exploit chains that can lead to complete vehicle compromise. read more This article has been indexed from SecurityWeek RSS Feed Read the…

Threema Under Fire After Downplaying Security Research

The developers of the open source secure messaging app Threema have come under fire over their public response to a security analysis conducted by researchers at the Swiss university ETH Zurich. read more This article has been indexed from SecurityWeek…

Severe Vulnerabilities Allow Hacking of Asus Gaming Router

Cisco’s Talos security researchers have published technical information on three severe vulnerabilities impacting Asus RT-AX82U routers. A Wi-Fi 6 gaming router, the RT-AX82U can be configured via an HTTP server that is running on the local network, but also supports…

Chrome 109 Patches 17 Vulnerabilities

Google on Tuesday announced the release of Chrome 109 in the stable channel with patches for 17 vulnerabilities, including 14 bugs reported by external researchers. read more This article has been indexed from SecurityWeek RSS Feed Read the original article:…

Unpatchable Hardware Vulnerability Allows Hacking of Siemens PLCs

Researchers at firmware security company Red Balloon Security have discovered a potentially serious vulnerability affecting many of Siemens’ programmable logic controllers (PLCs). read more This article has been indexed from SecurityWeek RSS Feed Read the original article: Unpatchable Hardware Vulnerability…

EU Tells TikTok Chief To Respect Data Privacy Laws

The European Union warned online giant TikTok on Tuesday to respect EU law and ensure the safety of European users’ data, as the video-sharing app’s CEO met with top officials in Brussels. read more This article has been indexed from…

How Will a Recession Will Affect CISOs?

Is the United States heading toward a recession? If we are, then profits will dip, and belts will be tightened while we wait for the government to turn things round. Most, but not all, businesses will survive; but all will…

Adobe Plugs Security Holes in Acrobat, Reader Software

Software maker Adobe has rolled out its first batch of security patches for 2023 with fixes for at least 29 security vulnerabilities in a range of enterprise-facing products. The most prominent update, for the widely deployed Adobe Acrobat and Reader…

Zoom Patches High Risk Flaws on Windows, MacOS Platforms

Video messaging giant Zoom has released patches for multiple security vulnerabilities that expose both Windows and macOS users to malicious hacker attacks. The vulnerabilities, in the enterprise-facing Zoom Rooms product, could be exploited in privilege escalation attacks on both Windows…

Iowa’s Largest City Cancels Classes Due to Cyber Attack

Iowa’s largest school district cancelled classes for Tuesday after determining there was a cyber attack on its technology network. Des Moines Public Schools announced Monday that classes would be cancelled for its 33,000 students after being “alerted to a cyber…

PyPI Users Targeted With PoweRAT Malware

Software supply chain security firm Phylum has identified a malicious attack targeting Python Package Index (PyPI) users with the PoweRAT backdoor and information stealer. read more This article has been indexed from SecurityWeek RSS Feed Read the original article: PyPI…

GitHub Introduces Automatic Vulnerability Scanning Feature

Microsoft-owned code hosting platform GitHub is now providing developers with the option to have their code repositories automatically scanned for vulnerabilities. Available as a ‘default setup’ option, the new feature is meant to help code builders find and resolve vulnerabilities…

How a Recession Will Affect CISOs?

Is the United States heading toward a recession? If we are, then profits will dip, and belts will be tightened while we wait for the government to turn things round. Most, but not all, businesses will survive; but all will…

Microsoft Flags Ransomware Problems on Apple’s macOS Platform

Security researchers at Microsoft are flagging ransomware attacks on Apple’s flagship macOS operating system, warning that financially motivated cybercriminals are abusing legitimate macOS functionalities to exploit vulnerabilities, evade defenses, or coerce users to infect their devices. read more This article…

Microsoft Flags Ransomware Problems on Apple macOS Platform

Security researchers at Microsoft are flagging ransomware attacks on Apple’s flagship macOS platform, warning that financially motivated cybercriminals are abusing legitimate macOS functionalities to exploit vulnerabilities, evade defenses, or coerce users to infect their devices. read more This article has…

AWS Enables Default Server-Side Encryption for S3 Objects

AWS has announced that server-side encryption (SSE-S3) is now enabled by default for all Simple Storage Service (S3) buckets. read more This article has been indexed from SecurityWeek RSS Feed Read the original article: AWS Enables Default Server-Side Encryption for…

XDR and the Age-old Problem of Alert Fatigue

XDR’s fully loaded value to threat detection, investigation and response will only be realized when it is viewed as an architecture read more This article has been indexed from SecurityWeek RSS Feed Read the original article: XDR and the Age-old…

SASE Company Netskope Raises $401 Million

Secure access service edge (SASE) provider Netskope on Thursday announced that it has raised $401 million in an oversubscribed financing round. To date, the company has raised close to $1.5 billion. read more This article has been indexed from SecurityWeek…

Rackspace Completes Investigation Into Ransomware Attack

Cloud company Rackspace has completed its investigation into the recent ransomware attack and found that the hackers did access some customer resources. read more This article has been indexed from SecurityWeek RSS Feed Read the original article: Rackspace Completes Investigation…

France Regulator Raps Apple Over App Store Ads

France’s data regulator said Wednesday that it had fined Apple eight million euros ($8.5 million) for breaching privacy laws on its App Store. The CNIL said the US tech giant had installed trackers on the devices of French users without…

Slack Says Hackers Stole Private Source Code Repositories

Enterprise communication and collaboration platform Slack has informed customers that hackers have stolen some of its private source code repositories, but claims impact is limited. read more This article has been indexed from SecurityWeek RSS Feed Read the original article:…

The Impact of Geopolitics on CPS Security

The world changed fundamentally during the pandemic. Businesses were affected profoundly as they were forced to undergo digital transformation quickly to survive. And for organizations that were able to truly excel at it, digital transformation became a differentiating advantage. Of…

Critical Vulnerabilities Patched in Synology Routers

Taiwan-based networking and storage solutions provider Synology has informed customers about the availability of patches for several critical vulnerabilities, including flaws likely exploited recently at the Pwn2Own hacking contest. read more This article has been indexed from SecurityWeek RSS Feed…

Google to Pay Indiana $20 Million to Resolve Privacy Suit

Google will pay Indiana $20 million to resolve the state’s lawsuit against the technology giant over allegedly deceptive location tracking practices, state Attorney General Todd Rokita announced. read more This article has been indexed from SecurityWeek RSS Feed Read the…