Our collection of the most relevant reporting and industry perspectives for those guiding cybersecurity strategies and focused on SecOps.
0
CISO Corner: The NYSE & the SEC; Ransomware Negotiation Tips
Thứ Sáu, 28 tháng 6, 2024
Việt Nam Hacker
0
CISA's Flags Memory-Unsafe Code in Major Open Source Projects
Việt Nam Hacker
Despite more than 50% of all open source code being written in memory-unsafe languages like C++, we are unlikely to see a massive overhaul to code bases anytime soon.
0
Hundreds of Thousands Impacted in Children's Hospital Cyberattack
Việt Nam Hacker
Though the Chicago-area hospital did not pay a ransom, a host of sensitive medical information is now at risk.
0
Authenticator for X, TikTok Exposes Personal User Info for 18 Months
Thứ Năm, 27 tháng 6, 2024
Việt Nam Hacker
With many popular apps, users must hand over personal information to prove their identity, and the big downside is they have no control over how that information gets processed and stored.
0
Dark Reading Confidential: Meet the Ransomware Negotiators
Việt Nam Hacker
Episode 2: Incident response experts-turned-ransomware negotiators Ed Dubrovsky, COO and managing partner of CYPFER, and Joe Tarraf, chief delivery officer of Surefire Cyber, explain how they interact with cyber threat actors who hold victim organizations' systems and data for ransom. Among their fascinating stories: how they negotiated with cybercriminals to restore operations in a hospital NICU where lives were at stake, and how they helped a church, where the attackers themselves "got a little religion."
0
Your Phone's 5G Connection is Vulnerable to Bypass, DoS Attacks
Việt Nam Hacker
Wireless service providers prioritize uptime and lag time, occasionally at the cost of security, allowing attackers to take advantage, steal data, and worse.
0
Dangerous AI Workaround: 'Skeleton Key' Unlocks Malicious Content
Thứ Tư, 26 tháng 6, 2024
Việt Nam Hacker
Microsoft, OpenAI, Google, Meta genAI models could be convinced to ditch their guardrails, opening the door to chatbots giving unfettered answers on building bombs, creating malware, and much more.
0
Apple AirPods Bug Allows Eavesdropping
Việt Nam Hacker
The vulnerability affects not only AirPods, but also AirPods Max, Powerbeats Pro, Beats Fit Pro, and all models of AirPods Pro.
0
Polyfill.io Supply Chain Attack Smacks Down 100K+ Websites
Việt Nam Hacker
The site is supplying malicious code that delivers dynamically generated payloads and can lead to other attacks, after a Chinese organization bought it earlier this year.
0
Neiman Marcus Customers Impacted by Snowflake Data Breach
Việt Nam Hacker
The high-end retailer is the latest company to confirm it was impacted by the wide-ranging Snowflake data breach, which impacted more than 165 organizations.
0
'ChamelGang' APT Disguises Espionage Activities With Ransomware
Việt Nam Hacker
The China-nexus cyberthreat actor has been operating since at least 2019 and has notched victims in multiple countries.
0
Fresh MOVEit Bug Under Attack Mere Hours After Disclosure
Thứ Ba, 25 tháng 6, 2024
Việt Nam Hacker
The high-severity CVE-2024-5806 allows cyberattackers to authenticate to the file-transfer platform as any valid user, with accompanying privileges.
0
Indonesia Refuses to Pay $8M Ransom After Cyberattack
Việt Nam Hacker
More than 200 regional and national government agencies have been impacted by the ransomware attack, and few of them are once again operational.
0
Threat Actor May Have Accessed Sensitive Info on CISA Chemical App
Việt Nam Hacker
An unknown adversary compromised a CISA app containing the data via a vulnerability in the Ivanti Connect Secure appliance this January.
0
China-Linked Cyber-Espionage Teams Target Asian Telecoms
Thứ Hai, 24 tháng 6, 2024
Việt Nam Hacker
In the latest breaches, threat groups compromised telecommunications firms in at least two Asian nations, installing backdoors and possibly eavesdropping or pre-positioning for a future attack.
0
CDK Attack: Why Contingency Planning Is Critical for SaaS Customers
Việt Nam Hacker
Daily operations at some 15,000 automotive dealers remain impacted as CDK works to restore its dealer management system, following what appears to be a ransomware attack last week.
0
What Building Application Security Into Shadow IT Looks Like
Việt Nam Hacker
AppSec is hard for traditional software development, let alone citizen developers. So how did two people resolve 70,000 vulnerabilities in three months?
0
30M Potentially Affected in Tickettek Australia Cloud Breach
Việt Nam Hacker
In an incident with direct parallels to the recent Ticketmaster compromise, an Aussie live events giant says it was breached via a third-party cloud provider, as ShinyHunters takes credit.
0
The NYSE's $10M Wake-up Call
Việt Nam Hacker
The settlement between the SEC and the owner of the New York Stock Exchange is a critical reminder of the vulnerabilities within financial institutions' cybersecurity frameworks as well as the importance of regulatory oversight.
0
VicOne Solutions for Detection of Zero-Day Vulnerabilities and Contextualized Attack Paths
Thứ Sáu, 21 tháng 6, 2024
Việt Nam Hacker
0
Legal Defense Fund Covers Crypto Research
Việt Nam Hacker
The nonprofit Security Alliance provided funding to protect those who illegally access crypto assets with the aim of improving security.
0
Multifactor Authentication Is Not Enough to Protect Cloud Data
Việt Nam Hacker
Ticketmaster, Santander Bank, and other large firms have suffered data leaks from a large cloud-based service, underscoring that companies need to pay attention to authentication.
0
Consumer Privacy Bill Fails in Vermont
Thứ Năm, 20 tháng 6, 2024
Việt Nam Hacker
The bill, if it had successfully become law, would have given consumers the right to sue companies that violate their privacy.
0
Thousands of Car Dealerships Stalled Out After Software Provider Cyberattack
Việt Nam Hacker
CDK Global, which makes software for car dealers, experienced a cyber incident that halted vehicle sales and service across the US.
0
High-Risk Overflow Bug in Intel Chips Likely Impacts 100s of PC Models
Việt Nam Hacker
The old, but newly disclosed, vulnerability is buried deep inside personal computers, servers, and mobile devices, and their supply chains, making remediation a headache.
0
CHERI Alliance Aims to Secure Hardware Memory
Việt Nam Hacker
The consortium of private companies and academia will focus on ways to protect hardware memory from attacks.
0
How Cybersecurity Can Steer Organizations Toward Sustainability
Việt Nam Hacker
By integrating environmental initiatives, social responsibility, and governance into their strategies, security helps advance ESG goals.
0
'ONNX' MFA Bypass Targets Microsoft 365 Accounts
Thứ Tư, 19 tháng 6, 2024
Việt Nam Hacker
The service, likely a rebrand of a previous operation called 'Caffeine,' mainly targets financial institutions in the Americas and EMEA and uses malicious QR codes and other advanced evasion tactics.
0
France Seeks to Protect National Interests With Bid for Atos Cybersec
Việt Nam Hacker
By offering to buy Atos's big data and cybersecurity operations. Paris is trying to make sure key technologies do not fall under foreign control.
0
Hackers Derail Amtrak Guest Rewards Accounts in Breach
Thứ Ba, 18 tháng 6, 2024
Việt Nam Hacker
The US passenger rail giant said attackers used previously compromised credentials to crack accounts and access a freight train of personal data.
0
Blackbaud Fined $6.75M After 2020 Ransomware Attack
Việt Nam Hacker
Threat actors were able to breach Blackbaud's systems and compromise sensitive data, largely because of the company's poor cybersecurity practices and lack of encrypted data, the AG said.
0
Cut & Paste Tactics Import Malware to Unwitting Victims
Việt Nam Hacker
"ClearFake" and "ClickFix" attackers are tricking people into cutting and pasting malicious PowerShell scripts to infect their own machines with RATs and infostealers.
0
LA County Dept. of Public Health Data Breach Impacts 200K
Thứ Hai, 17 tháng 6, 2024
Việt Nam Hacker
Threat actors were able to breach the department using the credentials accessed through phishing emails.
0
Addressing Misinformation in Critical Infrastructure Security
Việt Nam Hacker
As the lines between the physical and digital realms blur, widespread understanding of cyber threats to critical infrastructure is of paramount importance.
0
China's 'Velvet Ant' APT Nests Inside Multiyear Espionage Effort
Việt Nam Hacker
The campaign is especially notable for the remarkable lengths to which the threat actor went to maintain persistence on the target environment.
0
Name That Toon: Future Shock
Việt Nam Hacker
Feeling creative? Submit your caption and our panel of experts will reward the winner with a $25 Amazon gift card.
0
MITRE: US Government Needs to Focus on Critical Infrastructure
Việt Nam Hacker
With the presidential election this year and increase in cyberattacks and conflict around the world, MITRE has outlined four important areas the incoming presidential administration should focus on next year.
0
Hamas Hackers Sling Stealthy Spyware Across Egypt, Palestine
Chủ Nhật, 16 tháng 6, 2024
Việt Nam Hacker
The Arid Viper APT group is deploying AridSpy malware with Trojanized messaging applications and second-stage data exfiltration.
0
'Sleepy Pickle' Exploit Subtly Poisons ML Models
Thứ Sáu, 14 tháng 6, 2024
Việt Nam Hacker
A model can be perfectly innocent, yet still dangerous if the means by which it's packed and unpacked are tainted.
0
Panera Notifies Employees of Compromised Data
Việt Nam Hacker
Though the company is informing affected individuals of a breach, it's keeping the nature and scope of the cybersecurity incident that led to it under wraps.
0
Marsh Insurance: Volume of Cyber-Insurance Claims Reaches New Heights
Thứ Năm, 13 tháng 6, 2024
Việt Nam Hacker
More claims are being made across the US and Canada compared with previous years, with healthcare organizations leading the way.
0
PoC Exploit Emerges for Critical RCE Bug in Ivanti Endpoint Manager
Việt Nam Hacker
A new month, a new high-risk Ivanti bug for attackers to exploit — this time, an SQL injection issue in its centralized endpoint manager.
0
North Korea's Moonstone Sleet Widens Distribution of Malicious Code
Việt Nam Hacker
The recently identified threat actor uses public registries for distribution and has expanded capabilities to disrupt the software supply chain.
0
AI Chatbot Fools Scammers & Scores Money-Laundering Intel
Việt Nam Hacker
Experiment demonstrates how AI can turn the tables on cybercriminals, capturing bank account details of how scammers move stolen funds around the world.
0
Rockwell's ICS Directive Comes As Critical Infrastructure Risk Peaks
Thứ Tư, 12 tháng 6, 2024
Việt Nam Hacker
Critical infrastructure is facing increasingly disruptive threats to physical processes, while thousands of devices are online with weak authentication and riddled with exploitable bugs.
0
Scores of Biometrics Bugs Emerge, Highlighting Authentication Risks
Việt Nam Hacker
Face scans stored like passwords inevitably will be compromised, like passwords are. But there's a crucial difference between the two that organizations can rely on when their manufacturers fail.
0
Cleveland City Hall Shuts Down After Cyber Incident
Việt Nam Hacker
As city officials continue to investigate, it's unclear which systems were affected and whether it was a ransomware attack.
0
LockBit & Conti Ransomware Hacker Busted in Ukraine
Việt Nam Hacker
Accused cybercriminal has special skills that helped Conti and LockBit ransomware evade detection, according to law enforcement.
0
Canada & UK Partner in Joint 23andMe Data Breach Investigation
Thứ Ba, 11 tháng 6, 2024
Việt Nam Hacker
The two jurisdictions will work together to investigate the credential-stuffing attack that put the personal data of millions at risk.
0
Process to Verify Software Was Built Securely Begins Today
Việt Nam Hacker
The US government launched a self-attestation form asking software developers to affirm their software was developed securely. Compliance starts today for software used in critical infrastructure.
0
Blood Shortages Hit London Hospitals After Ransomware Attack
Việt Nam Hacker
Operations at Synnovis medical labs have been disrupted for more than a week, prompting the NHS to implore the public to donate blood.
0
Tokenization Moves Beyond Payments to Personal Privacy
Thứ Hai, 10 tháng 6, 2024
Việt Nam Hacker
Pseudonymous masking has made credit card transactions more secure, but Visa has even greater plans for tokenization: giving users control of their data.
0
New York Times Internal Data Nabbed From GitHub
Việt Nam Hacker
The tranche of data, lifted from underprotected GitHub repositories, reportedly includes source code, though the country's paper of record has not yet confirmed the nature of the data accessed.
0
Smishers Stand Up Fake Phone Tower to Blast Malicious Texts
Việt Nam Hacker
London cops make arrests in connection with scam SMS messages, purportedly from official organizations, being sent out from bespoke phone mast.
0
Is a US Nationwide Privacy Law Really Coming?
Việt Nam Hacker
0
Making Choices for Stronger Vulnerability Management
Việt Nam Hacker
The threat environment will continue to grow in complexity. Now is the time for organizations to streamline how they manage and mitigate overlooked vulnerabilities.
0
Governments, Businesses Tighten Cybersecurity Around Hajj Season
Chủ Nhật, 9 tháng 6, 2024
Việt Nam Hacker
While cyberattacks drop slightly during the week of the Islamic pilgrimage, organizations in Saudi Arabia and other countries with large Muslim populations see attacks on the rise.
0
CISO Corner: Red Sox CloudSec; Deepfake Biz Risk; Ticketmaster Takeaways
Thứ Sáu, 7 tháng 6, 2024
Việt Nam Hacker
Our collection of the most relevant reporting and industry perspectives for those guiding cybersecurity strategies and focused on SecOps. Also included: Proactive playbooks, a US-Kenya partnership, and the trouble with shadow engineering.
0
Cybersecurity Job Hunting May Come Down to Certifications
Việt Nam Hacker
If current cybersecurity workers only fill 85% of the need in the US, why are so many people still looking for positions? The data from the private-public NIST partnership CyberSeek offers some insight.
0
SolarWinds Flaw Flagged by NATO Pen Tester
Việt Nam Hacker
The latest platform update from SolarWinds includes patches for three vulnerabilities, including two high-severity bugs.
0
Hotel Check-in Kiosks Expose Guest Data, Room Keys
Việt Nam Hacker
CVE-2024-37364 affects hospitality kiosks from Ariane Systems, which are used for self-check-in at more than 3,000 hotels worldwide.
0
'Commando Cat' Digs Its Claws into Exposed Docker Containers
Thứ Năm, 6 tháng 6, 2024
Việt Nam Hacker
Attackers are taking advantage of misconfigured containers to deploy cryptocurrency mining software.
0
Technology, Regulations Can't Save Orgs From Deepfake Harm
Việt Nam Hacker
Monetary losses, reputational damage, share price declines — it's hard to counter, much less try to stay ahead of, AI-based attacks.
0
Mallox Ransomware Variant Targets Privileged VMWare ESXi Environments
Việt Nam Hacker
Novel attack vector uses a custom shell for payload delivery and execution — and only goes after systems with administrative privileges.
0
EV Manufacturer BYD Selects Karamba Security to Meet Global Automotive Cybersecurity Regulations
Thứ Tư, 5 tháng 6, 2024
Việt Nam Hacker
0
Hijacking Scheme Takes Over High-Profile TikTok Accounts
Việt Nam Hacker
Hijacking malware gets spread through TikTok's direct messaging and doesn't require the victim to click links or download anything.
0
Chinese Threat Clusters Triple-Team a High-Profile Asia Government Org
Việt Nam Hacker
A trio of Chinese-affiliated clusters performed specialized tasks in a broader attack chain, likely under the watch of a single organization.
0
Africa Ranks Low on Phishing Cyber Resilience
Thứ Ba, 4 tháng 6, 2024
Việt Nam Hacker
As threats to Africa's cybersphere continue to grow, the continent faces high risks to its society and economy with a growing cyber skills gap and lack of preparedness.
0
Ukrainian Systems Hit by Cobalt Strike Via a Malicious Excel File
Việt Nam Hacker
The campaign uses a multistage payload-delivery process and various mechanisms for evasion and persistence.
0
'Fog' Ransomware Rolls in to Target Education, Recreation Sectors
Việt Nam Hacker
A new group of hackers is encrypting data in virtual machines, leaving ransom notes, and calling it a day.
0
Russia Aims Cyber Operations at Summer Olympics
Thứ Hai, 3 tháng 6, 2024
Việt Nam Hacker
As always, Russian APTs are hoping to foment unrest by stoking existing societal divides and fears, this time around the Olympics and EU politics; and, concerns remain around physical disruption.
0
Europol's Hunt Begins for Emotet Malware Mastermind
Việt Nam Hacker
International law enforcement Operation Endgame shifts its crackdown to focus on individual adversaries.
0
Ticketmaster Confirms Cloud Breach, Amid Murky Details
Việt Nam Hacker
Ticketmaster parent Live Nation has filed a voluntary SEC data breach notification, while one of its cloud providers, Snowflake, also confirmed targeted cyberactivity against some of its customers.
0
Name That Edge Toon: Zonked Out
Việt Nam Hacker
Feeling creative? Submit your caption and our panel of experts will reward the winner with a $25 Amazon gift card.
0
CISA's Secure by Design Initiative at 1: A Report Card
Việt Nam Hacker
0
As Allies, Kenya & US Aim to Bolster Digital Security in Africa
Chủ Nhật, 2 tháng 6, 2024
Việt Nam Hacker
Amid surging attacks, Kenya aims to expand its technology sector and improve cybersecurity to protect the country's fast-growing digital economy.
0
Lawyers Ask Forensics Investigators for Help Outside Cybersecurity
Việt Nam Hacker
Attorneys are increasingly realizing that forensics investigators have skills analyzing documents and uncovering digital clues that could help them in non-cybersecurity cases.
Đăng ký:
Bài đăng (Atom)