0

Law Firms & Legal Departments Singled Out for Cyberattacks

Thứ Năm, 30 tháng 11, 2023
Cybercriminals use legal search terms to ensnare unwitting victims, then launch ransomware or business email compromise attacks.
0

A New, Spookier Gh0st RAT Malware Haunts Global Cyber Targets

A decade and a half after Gh0st RAT first appeared, the "SugarGh0st RAT" variant aims to make life sweeter for cybercriminals.
0

Siemens PLCs Still Vulnerable to Stuxnet-like Cyberattacks

Security updates are tedious and difficult, so users continue to use a weak version of a core protocol and remain exposed to major attacks on critical infrastructure.
0

Feds Seize 'Sinbad' Crypto Mixer Used by North Korea's Lazarus

The prolific threat actor has laundered hundreds of millions of dollars in stolen virtual currency through the service.
0

Google Patches Another Chrome Zero-Day as Browser Attacks Mount

Thứ Tư, 29 tháng 11, 2023
The vulnerability is among a rapidly growing number of zero-day bugs that major browser vendors have reported recently.
0

Thought GDPR Compliance Was Hard? Buckle Up

The days of a one-size-fits-all consent strategy are gone. Consider a two-pronged approach and use smart consent management technology to adapt to differing regulations.
0

Why Ransomware Could Surge in the Middle East & Africa

Organizations from the Middle East and Africa have typically escaped public ransoms, but that's changing amid heightened geopolitical conflicts and digitalization initiatives.
0

Name That Toon: Slam Dunk

Thứ Ba, 28 tháng 11, 2023
Feeling creative? Submit your caption and our panel of experts will reward the winner with a $25 Amazon gift card.
0

Attacks Against South African ICS and IoT Systems Steadily Decrease

All African nations saw a reduced number of cyberattacks on industrial and IoT systems in the third quarter of 2023 compared with earlier this year.
0

Egyptian E-Payment Vendor Recovering From LockBit Ransomware Attack

Fawry confirms addresses, phone numbers, and dates of birth, leaked online.
0

CISA, NCSC Offer a Road Map, Not Rules, in New Secure AI Guidelines

Thứ Hai, 27 tháng 11, 2023
US and UK authorities issued new recommendations for companies that build and rely on AI, but they stop short of laying down the law.
0

Ardent Health Hospitals Disrupted After Ransomware Attack

More than two dozen hospitals have been impacted by the breach and are diverting emergency care for patients to other healthcare facilities.
0

General Electric, DARPA Hack Claims Raise National Security Concerns

Weapons systems data, AI research, and other classified information may be up for sale, not to mention access to other government agencies.
0

Hamas-Linked APT Wields New SysJoker Backdoor Against Israel

Gaza Cybergang is using a version of the malware rewritten in the Rust programming language.
0

Data De-Identification: Balancing Privacy, Efficacy & Cybersecurity

Companies must do a delicate dance between consumer privacy protection, upholding their product's efficacy, and de-risking cyber breaches to run the business.
0

Balancing Simplicity and Security in the Digital Experience

New data shows consumer preferences for security in digital experiences and indicates ways businesses can best protect digital identity in today's digital world.
0

Proof of Concept Exploit Publicly Available for Critical Windows SmartScreen Flaw

Thứ Tư, 22 tháng 11, 2023
Threat actors were actively exploiting CVE-2023-36025 before Microsoft patched it in November.
0

Mideast Oil & Gas Facilities Could Face Cyber-Related Energy Disruptions

The Israel-Gaza conflict could expose the region's oil and gas operations to renewed cyberattacks, with global ramifications.
0

3 Ways to Stop Unauthorized Code From Running in Your Network

As organizations increasingly rely on AI-developed code, they must put guardrails in place to prevent major cybersecurity risks related to malicious code.
0

Idaho National Nuclear Lab Targeted in Major Data Breach

The laboratory operates a major test reactor, tests advanced nuclear energy concepts, and conducts research involving hydrogen production and bioenergy.
0

DPRK Hackers Masquerade as Tech Recruiters, Job Seekers

Thứ Ba, 21 tháng 11, 2023
No one has turned the job market into an attack surface quite like North Korea, which plays both sides for financial gain and, possibly, espionage.
0

The Role of the CISO in Digital Transformation

A successful CISO should play a leading role in digital transformation and cloud migration initiatives in their organization. The CISO is responsible for making sure technical security controls are designed and implemented appropriately, and changes are properly managed, with security in mind from the very start. 
0

Inside Job: Cyber Exec Admits to Hospital Hacks

Healthcare cyber services executive Vikas Singla admits to hobbling hospital operations, then using the incidents to try and gin up extra business.
0

Major Saudi University to Offer AI, Cybersecurity Studies

University of Jeddah partners with Resecurity to teach cybersecurity skills.
0

Amid Military Buildup, China Deploys Mustang Panda in the Philippines

Thứ Hai, 20 tháng 11, 2023
China pairs cyber and kinetic attacks in the South Pacific as it continues to wrangle control of the South China Sea.
0

CISA Launches Pilot Program to Address Critical Infrastructure Threats

CISA expects to extend this program to include up to 100 critical infrastructure entities in its first year.
0

Enterprise Generative AI Enters Its Citizen Development Era

Your business users are building Copilots and GPTs with your enterprise data. What can you do about it?
0

Saudi Arabia Arms Public Sector With Google Cloud Services

Chronicle CyberShield will be offered as a managed service with security monitoring and Mandiant incident response included.
0

How the Evolving Role of the CISO Impacts Cybersecurity Startups

CISOs and vendors must work together to keep up with emerging threats and find solutions, says a group of CISOs and security entrepreneurs.
0

A Detection and Response Benchmark Designed for the Cloud

Does your security operation center's performance meet the 5/5/5 benchmark for cloud threat detection and incident response?
0

British Library Confirms Ransomware Attack Caused Outages

Thứ Sáu, 17 tháng 11, 2023
The library said that it expects many of its services to be restored in the forthcoming weeks.
0

Scattered Spider Casino Hackers Evade Arrest in Plain Sight

The feds seem to know all about the hacking group brazenly breaking into corporate networks; so why are enterprise teams left on their own to stop their cybercrimes?
0

Shadowy Hack-for-Hire Group Behind Sprawling Web of Global Cyberattacks

For several years operators at New Delhi-based Appin hacked into, spied on, and stole data from targets around the world for clients that included private investigators, government agencies, law enforcement, and others.
0

Actions to Take to Defeat Initial Access Brokers

Initial access brokers (IAB) are often difficult to track. This Tech Tip spells out some countermeasures enterprises need to defend against stolen credentials.
0

'CacheWarp' AMD VM Bug Opens the Door to Privilege Escalation

Thứ Năm, 16 tháng 11, 2023
Academics in Germany figured out how to reverse time in AMD virtualization environments, then reap the spoils.
0

Consumer Software Security Assessment: Should We Follow NHTSA's Lead?

Vehicles are required to meet basic safety standards. Having similar requirements for software would give consumers greater control over their privacy and security.
0

'Randstorm' Bug: Millions of Crypto Wallets Open to Theft

The security vulnerability in a component of a widely used JavaScript implementation of Bitcoin makes passwords guessable via brute-force attacks.
0

Unpatched Critical Vulnerabilities Open AI Models to Takeover

The security holes can allow server takeover, information theft, model poisoning, and more.
0

Rackspace Ransomware Costs Soar to Nearly $12M

Thứ Tư, 15 tháng 11, 2023
Rackspace's 2022 ransomware attack only continue to mount, with lawsuits in the offing — and show the long-tail costs of a cyberattack.
0

'AlphaLock' Hacker Organization Launches Pen-Testing Training Group

With a two-pronged approach, the group trains its hackers in penetration testing, only to set them free to build a marketplace for pen-testing services.
0

EU Tightens Cybersecurity Requirements for Critical Infrastructure and Services

Organizations in "essential" sectors have until October 2024 to comply with the Network and Information Systems Directive 2022 (NIS2).
0

Cyber Resilience Requires Maturity, Persistence & Board Engagement

Women in Cyber Security Middle East highlight a requirement for resilience in the face of increased business and cyber challenges.
0

Google Goes After Scammers Abusing Its Bard AI Chatbot

Thứ Ba, 14 tháng 11, 2023
A pair of lawsuits are part of a wider strategy to establish guardrails preventing AI-powered scams, frauds, and harassment, Google's general counsel says.
0

HARmor Cleans, Sanitizes, Encrypts HAR Files

Okta's breach highlighted the importance of sanitizing the data logged in HAR files before sharing them.
0

Zero-Days in Edge Devices Become China's Cyber Warfare Tactic of Choice

While China is already among the world's most formidable threat actors, a focus on exploiting public-facing appliances makes its state-sponsored APTs more dangerous than ever.
0

21 Vulnerabilities Discovered in Crucial IT-OT Connective Routers

In this Black Hat Europe preview, devices bridging critical machinery with the wider Internet are exposed and subject to numerous supply chain-induced bugs.
0

Ducktail Malware Targets the Fashion Industry

Thứ Hai, 13 tháng 11, 2023
Threat actors distributed an archive containing images of new products by major clothing companies, along with a malicious executable disguised with a PDF icon.
0

A Closer Look at State and Local Government Cybersecurity Priorities

Complexity impedes the universal and consistent application of security policy, which is an obstacle to adequately securing government environments.
0

Azerbaijan Agencies Sign Cyber-Partner Deals

The country has signed fresh deals to boost cyber intelligence and preparedness capabilities.
0

SEC Suit Ushers in New Era of Cyber Enforcement

A federal push to enforce cybersecurity requirements is holding public companies and government contractors accountable as a matter of law and for national security.
0

Security Is a Process, Not a Tool

Process failures are the root cause of most serious cybersecurity incidents. We need to treat security as a process issue, not try to solve it with a collection of tools.
0

'CitrixBleed' Linked to Ransomware Hit on China's State-Owned Bank

Thứ Sáu, 10 tháng 11, 2023
Meanwhile, CISA joins the call to patch CVE-2023-4966 immediately amid reports of mass-exploit activity; at least 5,000 orgs remain exposed.
0

ChatGPT: OpenAI Attributes Regular Outages to DDoS Attacks

ChatGPT and the associated APIs have been affected by regular outages, citing DDoS attacks as the reason — the Anonymous Sudan group claimed responsibility.
0

Leaky DICOM Medical Standard Exposes Millions of Patient Records

A 30-year-old, rarely updated protocol for medical devices has exposed reams of highly personal data, thanks to a lack of proper security throughout owner environments.
0

What We Can Learn from Major Cloud Cyberattacks

Thứ Năm, 9 tháng 11, 2023
Analysis of six major cloud incidents shows how some common mistakes can lead to serious consequences.
0

When Good Security Awareness Programs Go Wrong

Avoid making these mistakes when crafting a security awareness strategy at your organization.
0

How to Outsmart Malware Attacks That Can Fool Antivirus Protection

One of the main challenges for Android users is protecting themselves malicious applications that can damage devices or perform other harmful actions.
0

Imperial Kitten APT Claws at Israeli Industry with Multiyear Spy Effort

The Iran-linked group uses redirected websites to compromise victims and exfiltrate data in a campaign that has lasted over 2022 and 2023.
0

Sandworm Cyberattackers Down Ukrainian Power Grid During Missile Strikes

A premier Russian APT used living-off-the-land techniques in a major OT hit, raising tough questions about whether or not we can defend against the attack vector.
0

Evasive Jupyter Infostealer Campaign Showcases Dangerous Variant

Thứ Tư, 8 tháng 11, 2023
The attacks are another manifestation of the concerning rise in information stealers for harvesting data and enabling persistent access to enterprise networks.
0

Ransomware Mastermind Uncovered After Oversharing on Dark Web

Meet "farnetwork," one of the most prolific RaaS operators around, who spilled too many details during an affiliate "job interview."
0

MGM and Caesars Attacks Highlight Social Engineering Risks

Relying on passwords to secure user accounts is a gamble that never pays off.
0

North Korea's BlueNoroff APT Debuts 'Dumbed Down' macOS Malware

Thứ Ba, 7 tháng 11, 2023
Kim Jong-Un's hackers are scraping the bottom of the barrel, using script kiddie-grade malware to steal devalued digital assets.
0

Crafting an AI Policy That Safeguards Data Without Stifling Productivity

Companies must recognize AI's utility, while setting clear boundaries to curtail unsafe utilization.
0

Iran-Linked Agrius APT Group Targets Israeli Education, Tech Sectors

The attackers also use custom wipers to cover their tracks and bypass EDR.
0

US Sanctions Ryuk Ransomware’s Russian Money Launderer

Thứ Hai, 6 tháng 11, 2023
Woman is accused of assisting Russian oligarchs and ransomware affiliates with schemes to evade sanctions.
0

Middle East's 5G Acceleration May Pose Serious Security Issues

Telcos across the Middle East are rapidly rolling out 5G networks. Will this accelerated adoption lead to higher security vulnerabilities?
0

Meet Your New Cybersecurity Auditor: Your Insurer

As cyber insurance gets more expensive and competitive, security decision-makers have actionable opportunities to strengthen their cyber defenses.
0

Keep Your Organization's APIs Protected This Holiday Season

Understanding API security risks isn't just a good idea — it's a business imperative. A single API breach can lead to financial losses and reputational damage.
0

Sky's the Limit, but What About API Security? Challenges in the Cloud-First Era

APIs enable cloud transformation but bring security risks, demanding robust, adaptive strategies to safeguard data and operations.
0

Ace Hardware Still Reeling From Weeklong Cyberattack

Thứ Sáu, 3 tháng 11, 2023
Cyberattackers downed a quarter of the hardware giant's entire IT apparatus. Now, before the company can recover, they're going after individual branches.
0

'KandyKorn' macOS Malware Lures Crypto Engineers

Posing as fellow engineers, the North Korean state-sponsored cybercrime group Lazarus tricked crypto-exchange developers into downloading the hard-to-detect malware.
0

Somebody Just Killed the Mozi Botnet

The once great botnet was nearly entirely eliminated in August. Why, who did it, and what comes next remain unclear.
0

How Do We Truly Make Security 'Everyone's Responsibility'?

Thứ Năm, 2 tháng 11, 2023
When everybody is responsible for a task, sometimes nobody takes ownership. Here are three steps to distribute cybersecurity throughout your organization.
0

Upgraded Kazuar Backdoor Offers Stealthy Power

The obscure Kazuar backdoor used by Russian attack group Turla has resurfaced, and it's more dangerous than ever.
0

Saudi Aramco CEO Warns of New Threat of Generative AI

Oil executive Amin H. Nasser calls for global cooperation and international standards to combat the dark side of artificial intelligence.
0

Middle East Advances in Generative AI Hold Promise

Gulf countries are heavily invested in GenAI, but security is still a concern.
0

One Ukraine Company Shares Lessons in Prepping for Wartime Cyber Resilience

Thứ Tư, 1 tháng 11, 2023
The CTO of MacPaw provides a case study in planning for cybersecurity and uptime in the face of armed conflict.
0

3 Ways to Close the Cybersecurity Skills Gap — Now

The future of the cybersecurity workforce will rely less on long-led legacy education models and more on skills-now training.
0

Atlassian Customers Should Patch Latest Critical Vuln Immediately

Atlassian CISO warns Confluence Data Center and Server customers they're vulnerable to "significant data loss" if all on-premises versions aren't patched.
0

FBI Director Warns of Increased Iranian Attacks

Christopher Wray tells the US Senate that more US infrastructure will be targeted for cyberattacks in the wake of the Gaza conflict.