Our collection of the most relevant reporting and industry perspectives for those guiding cybersecurity strategies and focused on SecOps. Also included: fighting cybersecurity burnout; BlackSuit ransomware; the SEC breach rules and risk management.
0
CISO Corner: Federal Cyber Deadlines Loom; Private Chatbot Danger
Thứ Sáu, 31 tháng 5, 2024
Việt Nam Hacker
0
BBC Breach Puts 25K Pension Scheme Members at Risk
Việt Nam Hacker
Though information such as dates of birth, email addresses, and home addresses were compromised, "the Beeb" assures individuals that financial information is still protected.
0
OpenAI Disrupts 5 AI-Powered, State-Backed Influence Ops
Việt Nam Hacker
Most of the operations were feckless efforts with little impact, but they illustrate how AI is changing the game for inauthentic content on both the adversary and defense sides.
0
FlyingYeti APT Serves Up Cookbox Malware Using WinRAR
Việt Nam Hacker
The Russia-aligned FlyingYeti's phishing campaign exploited Ukrainian citizens' financial stress to spread Cookbox malware.
0
Data Privacy in the Age of GenAI
Việt Nam Hacker
Consumer data is still a prime target for threat actors, and organizational consumption of data must be aligned to protecting it. The new rights act seeks to do some of this, but it still needs tweaking.
0
Cops Swarm Global Cybercrime Botnet Infrastructure in 2 Massive Ops
Thứ Năm, 30 tháng 5, 2024
Việt Nam Hacker
Europol undertook dropper malware botnet takedown while US law enforcement dismantled a sprawling cybercrime botnet for hire.
0
Flawed AI Tools Create Worries for Private LLMs, Chatbots
Việt Nam Hacker
Companies are looking to large language models to help their employees glean information from unstructured data, but vulnerabilities could lead to disinformation and, potentially, data leaks.
0
BforeAI Launches PreCrime™ Guarantee Program for Seamless Cyber Risk Coverage
Thứ Tư, 29 tháng 5, 2024
Việt Nam Hacker
0
Microsoft: 'Moonstone Sleet' APT Melds Espionage, Financial Goals
Việt Nam Hacker
North Korea's newest threat actor uses every trick in the nation-state APT playbook, and most of cybercrime's tricks, too. It also developed a whole video game company to hide malware.
0
Exploit for Fortinet Critical RCE Bug Allows SIEM Root Access
Việt Nam Hacker
Corporate admins should patch the max-severity CVE-2024-23108 immediately, which allows unauthenticated command injection.
0
Making the Case for 'Reasonable' Cybersecurity
Thứ Ba, 28 tháng 5, 2024
Việt Nam Hacker
Reasonable cybersecurity is highly subjective and organizations need to plan carefully in order to quantify cyber risk and apply security controls.
0
CatDDOS Threat Groups Sharply Ramp Up DDoS Attacks
Việt Nam Hacker
In attacks over the past three months, threat actors have exploited more than 80 vulnerabilities to accelerate distribution of the Mirai variant.
0
OpenAI Forms Another Safety Committee After Dismantling Prior Team
Việt Nam Hacker
The committee is being set up as the ChatGPT creator begins to train its latest large language model, GPT-5, which will reach "a new level of capabilities."
0
90+ Malicious Apps Totaling 5.5M Downloads Lurk on Google Play
Việt Nam Hacker
The dangerous Anatsa banking Trojan is among the malware being spread to Android users via decoy mobile apps in recent months.
0
The SEC's New Take on Cybersecurity Risk Management
Việt Nam Hacker
0
Looking to Leverage Generative AI? Prep for Success With These 4 Tips
Việt Nam Hacker
There's plenty of upside to this emerging technology, especially if organizations smartly plan for GenAI's rollout and long-term management.
0
6 Facts About How Interpol Fights Cybercrime
Chủ Nhật, 26 tháng 5, 2024
Việt Nam Hacker
So you think you know Interpol? Here are some key details of how this international law enforcement entity disrupts cybercrime worldwide.
0
Microsoft's 'Recall' Feature Draws Criticism From Privacy Advocates
Thứ Sáu, 24 tháng 5, 2024
Việt Nam Hacker
Despite Microsoft's reassurances, multiple security researchers describe the technology as problematic for users and their organizations.
0
AI Voice Generator App Used to Drop Gipy Malware
Việt Nam Hacker
Users get duped into downloading malicious files disguised to look like an application that uses artificial intelligence to alter voices.
0
MIT Brothers Charged With Exploiting Ethereum to Steal $25 Million
Thứ Năm, 23 tháng 5, 2024
Việt Nam Hacker
The two MIT graduates discovered a flaw in a common trading tool for the Ethereum blockchain. Does it presage problems ahead for cryptocurrency?
0
Stalkerware App With Security Bug Discovered on Hotel Systems
Việt Nam Hacker
The spyware is able to capture screenshots of a user's device every few seconds from any location globally.
0
New Gift Card Scam Targets Retailers, Not Buyers, to Print Endless $$$
Việt Nam Hacker
Microsoft researchers discover an old-timey scam with a facelift for the cloud era: hacking retailers' portals to make it rain gift cards.
0
GitHub Authentication Bypass Opens Enterprise Server to Attackers
Thứ Tư, 22 tháng 5, 2024
Việt Nam Hacker
0
Snowflake's Anvilogic Investment Signals Changes in SIEM Market
Việt Nam Hacker
Coming on the heels of Cisco buying Splunk, Palo Alto Networks acquiring IBM's QRadar, and LogRhythm merging with Exabeam, Snowflake's investment highlights the ongoing market pressure to improve SOC tools.
0
Trends at the 2024 RSA Startup Competition
Việt Nam Hacker
Startups at Innovation Sandbox 2024 brought clarity to artificial intelligence, protecting data from AI, and accomplishing novel security solutions with new models.
0
Iran APTs Tag Team Espionage, Wiper Attacks Against Israel & Albania
Thứ Ba, 21 tháng 5, 2024
Việt Nam Hacker
Scarred Manticore is the smart, sophisticated one. But when Iran needs something destroyed, it hands the keys over to Void Manticore.
0
YouTube Becomes Latest Battlefront for Phishing, Deepfakes
Việt Nam Hacker
Personalized phishing emails with fake collaboration opportunities and compromised video descriptions linking to malware are just some of the new tricks.
0
Name That Toon: Buzz Kill
Việt Nam Hacker
Feeling creative? Submit your caption and our panel of experts will reward the winner with a $25 Amazon gift card.
0
Critical Bug Allows DoS, RCE, Data Leaks in All Major Cloud Platforms
Thứ Hai, 20 tháng 5, 2024
Việt Nam Hacker
An on-by-default endpoint in ubiquitous logging service Fluent Bit contains an oversight that hackers can toy with to rattle most any cloud environment.
0
Students Spot Washing Machine App Flaw That Gives Out Free Cycles
Việt Nam Hacker
UCSC students say that after reporting the bug months ago they're still able to rack up unlimited free wash loads at their local laundromat.
0
What American Enterprises Can Learn From Europe's GDPR Mistakes
Việt Nam Hacker
As the US braces for a data privacy overhaul, companies need to update data practices, train staff, and ensuring compliance from the outset to avoid Europe's costly missteps.
0
Android Banking Trojan Antidot Disguised as Google Play Update
Việt Nam Hacker
0
CISO Corner: What Cyber Labor Shortage?; Trouble Meeting SEC Disclosure Deadlines
Thứ Sáu, 17 tháng 5, 2024
Việt Nam Hacker
Our collection of the most relevant reporting and industry perspectives for those guiding cybersecurity strategies and focused on SecOps. Also included: DR's podcast on the CISO & the SEC; breaking down CISA's Secure by Design Pledge; Singapore puts cloud providers on notice.
0
Intel Discloses Max Severity Bug in Its AI Model Compression Software
Việt Nam Hacker
The improper input validation issue in Intel Neural Compressor enables remote attackers to execute arbitrary code on affected systems.
0
10 Ways a Digital Shield Protects Apps and APIs
Việt Nam Hacker
Layers of protection can bring defense-in-depth practices to distributed clouds and other modern network architectures.
0
SEC Adds New Incident Response Rules for Financial Sector
Việt Nam Hacker
Financial firms covered under new regulations will be required to establish a clear response and communications plan for customer data breaches.
0
There Is No Cyber Labor Shortage
Thứ Năm, 16 tháng 5, 2024
Việt Nam Hacker
There are plenty of valuable candidates on the market. Hiring managers are simply looking in the wrong places.
0
US AI Experts Targeted in SugarGh0st RAT Campaign
Việt Nam Hacker
Researchers believe the attacker is likely China-affiliated, since a previous version of the malware was used by a China nation-state attack group.
0
Asian Threat Actors Use New Techniques to Attack Familiar Targets
Việt Nam Hacker
Generative AI and software supply chain attacks are being exploited to disrupt, manipulate, and steal.
0
GE Ultrasound Gear Riddled With Bugs, Open to Ransomware & Data Theft
Việt Nam Hacker
Thankfully, GE ultrasounds aren't Internet-facing. Exploiting most of the bugs to cause serious damage to patients would require physical device access.
0
Alkira Raises $100M in Series C Funding to Simplify, Secure and Scale Critical Network Infrastructure
Thứ Tư, 15 tháng 5, 2024
Việt Nam Hacker
0
FBI, DoJ Shut Down BreachForums, Launch Investigation
Việt Nam Hacker
Instead of online contraband, the website now asks anyone with information that could help with the investigation to contact authorities.
0
Scammers Fake DocuSign Templates to Blackmail & Steal From Companies
Việt Nam Hacker
Cybercriminals are trafficking DocuSign assets that allow for easy extortion and business email compromise.
0
Microsoft Windows DWM Zero-Day Poised for Mass Exploit
Thứ Ba, 14 tháng 5, 2024
Việt Nam Hacker
CVE-2024-30051, under active exploit, is the most concerning out of this month's Patch Tuesday offerings, and already being abused by several QakBot actors.
0
Unprotected Session Tokens Can Undermine FIDO2 Security
Việt Nam Hacker
While the protocol has made passwordless authentication a reality, token-binding is key to prevent against token theft and reuse, security vendor says.
0
A Cost-Effective Encryption Strategy Starts With Key Management
Việt Nam Hacker
Key management is more complex than ever. Your choices are: Rely on your cloud provider or manage keys locally; Encrypt only the most critical data; Or encrypt everything.
0
There Is No Cyber Labor Shortage
Việt Nam Hacker
There are plenty of valuable candidates on the market. Hiring managers are simply looking in the wrong places.
0
Heartbleed: When Is It Good to Name a Vulnerability?
Việt Nam Hacker
Ten years have passed since Heartbleed was first identified, but the security industry is still grappling with the question of branded vulnerabilities and naming vulnerabilities appropriately.
0
500 Victims In, Black Basta Reinvents With Novel Vishing Strategy
Thứ Hai, 13 tháng 5, 2024
Việt Nam Hacker
Ransomware groups have always created problems for their victims that only they could solve. Black Basta is taking that core idea in a creative, new direction.
0
Ukrainian, Latvian TV Hijacked to Broadcast Russian Celebrations
Việt Nam Hacker
At least 15 television channels were interrupted in Ukraine alone, which, reportedly, is not out of the norm in this "information war."
0
IntelBroker Nabs Europol Info; Agency Investigating
Việt Nam Hacker
Europe's cross-border law enforcement agency says the well-known hacking outfit, contrary to claims, did not access operational data.
0
Why Tokens Are Like Gold for Opportunistic Threat Actors
Việt Nam Hacker
When setting authentication token expiry policies, always lean in to security over employee convenience.
0
Millions of IoT Devices at Risk from Flaws in Integrated Cellular Modem
Thứ Sáu, 10 tháng 5, 2024
Việt Nam Hacker
Researchers discovered seven vulnerabilities — including an unauthenticated RCE issue — in widely deployed Telit Cinterion modems.
0
Reality Defender Wins RSAC Innovation Sandbox Competition
Việt Nam Hacker
In a field thick with cybersecurity startups showing off how they use AI and LLMs, Reality Defender stood out for its tool for detecting and labeling deepfakes and other artificial content.
0
CyberProof Announces Strategic Partnership With Google Cloud
Thứ Năm, 9 tháng 5, 2024
Việt Nam Hacker
0
Aggressive Cloud-Security Player Wiz Scores $1B in Funding Round
Việt Nam Hacker
The latest round of investment prices the fast-growing cloud native application protection platform (CNAPP) at $12 billion with a simple mandate: Grow quickly through acquisition.
0
LockBit Claims Wichita as Its Victim 2 Days After Ransomware Attack
Việt Nam Hacker
The city is still investigating the attack, and neither the group nor city officials have offered details about the ransomware demands.
0
runZero Research Explores Unexpected Exposures in Enterprise Infrastructure
Thứ Tư, 8 tháng 5, 2024
Việt Nam Hacker
0
CISOs Are Worried About Their Jobs & Dissatisfied With Their Incomes
Việt Nam Hacker
The research shows a significant drop in the number of tech CISOs that got a base salary increase in the past year — roughly 18% year-over-year.
0
Chinese Hackers Deployed Backdoor Quintet to Down MITRE
Thứ Ba, 7 tháng 5, 2024
Việt Nam Hacker
MITRE's hackers made use of at least five different Web shells and backdoors as part of their attack chain.
0
Wiz Announces $1B Funding Round, Plans More M&A
Việt Nam Hacker
Much of the funding will be used for product development and talent acquisition to cover more ground as the cybersecurity industry continues to evolve.
0
Does CISA's KEV Catalog Speed Up Remediation?
Việt Nam Hacker
Vulnerabilities added to the CISA known exploited vulnerability (KEV) list do indeed get patched faster, but not fast enough.
0
What's the Future Path for CISOs?
Việt Nam Hacker
A panel of former CISOs will lead the closing session of this week's RSA Conference to discuss challenges and opportunities.
0
Introducing the NetBeacon Institute: Empowering a Safer Web
Thứ Hai, 6 tháng 5, 2024
Việt Nam Hacker
0
Microsoft Previews Feature to Block Malicious OAuth Apps
Việt Nam Hacker
Microsoft is previewing new AI and machine learning capabilities in Defender XDR that will help detect and block malicious OAuth applications.
0
AT&T Splits Cybersecurity Services Business, Launches LevelBlue
Việt Nam Hacker
The new company will focus on cybersecurity services as a top-10 managed security service provider, but must expand outside the low-margin managing of security into detection and response.
0
Anetac Targets Service Account Security
Việt Nam Hacker
The new startup's identity and access management platform uncovers poorly monitored service accounts and secures them from abuse.
0
Amnesty International Cites Indonesia as a Spyware Hub
Chủ Nhật, 5 tháng 5, 2024
Việt Nam Hacker
The growing amount of surveillance technology being deployed in the country is concerning due to Indonesia's increasing blows to citizens' civil rights.
0
Paris Olympics Cybersecurity at Risk via Attack Surface Gaps
Thứ Sáu, 3 tháng 5, 2024
Việt Nam Hacker
Though Olympics officials appear to have better secured their digital footprint than other major sporting events have, significant risks remain for the Paris Games.
0
GAO: NASA Faces 'Inconsistent' Cybersecurity Across Spacecraft
Việt Nam Hacker
The space agency needs to implement stricter policies and standards when it comes to its cybersecurity practices, but doing so the wrong way would put machinery at risk, a federal review found.
0
REvil Affiliate Off to Jail for Multimillion-Dollar Ransomware Scheme
Việt Nam Hacker
Charges against the ransomware gang member included damage to computers, conspiracy to commit fraud, and conspiracy to commit money laundering.
0
Hacker Sentenced After Years of Extorting Psychotherapy Patients
Thứ Năm, 2 tháng 5, 2024
Việt Nam Hacker
Two years after a warrant went out for his arrest, Aleksanteri Kivimäki finally has been found guilty of thousands of counts of aggravated attempted blackmail, among other charges.
0
The Psychological Underpinnings of Modern Hacking Techniques
Việt Nam Hacker
The tactics employed by hackers today aren't new; they're simply adapted for the digital age, exploiting the same human weaknesses that have always existed.
0
Dropbox Breach Exposes Customer Credentials, Authentication Data
Việt Nam Hacker
Threat actor dropped in to Dropbox Sign production environment and accessed emails, passwords, and other PII, along with APIs, OAuth, and MFA info.
0
Cobalt's 2024 State of Pentesting Report Reveals Cybersecurity Industry Needs
Thứ Tư, 1 tháng 5, 2024
Việt Nam Hacker
0
Shadow APIs: An Overlooked Cyber-Risk for Orgs
Việt Nam Hacker
Unmanaged and unknown Web services endpoints are just some of the challenges organizations must address to improve API security.
0
Qantas Customers' Boarding Passes Exposed in Flight App Mishap
Việt Nam Hacker
Some customers found that they had the ability to cancel a stranger's flight to another country after opening the app, which was showing other individuals' flight details.
0
'Cuttlefish' Zero-Click Malware Steals Private Cloud Data
Việt Nam Hacker
The newly discovered malware, which has so far mainly targeted Turkish telcos and has links to HiatusRat, infects routers and performs DNS and HTTP hijacking attacks on connections to private IP addresses.
Đăng ký:
Bài đăng (Atom)