Menu

Category Archives: All

Everything

Okta tells 5,000 of its own staff that their data was accessed in third-party breach
The state of API security in 2023
Boeing acknowledges cyberattack on parts and distribution biz
FBI boss: Taking away our Section 702 spying powers could be ‘devastating’
Smashing Security podcast #346: How hackers are breaching Booking.com, and the untrustworthy reviews
Ransomware crooks SIM swap medical research biz exec, threaten to leak stolen data

security update

security update

Mozi botnet murder mystery: China or criminal operators behind the kill switch?
Splunk cuts 7% of workforce ahead of Cisco acquisition
Critical vulnerability in F5 BIG-IP under active exploitation
Cybercrooks amp up attacks via macro-enabled XLL files
Get your very own ransomware empire on the cheap, while stocks last
Meeting the challenge of OT security
Indian politicians say Apple warned them of state-sponsored attacks
US officials close to persuading allies to not pay off ransomware crooks
‘Mass exploitation’ of Citrix Bleed underway as ransomware crews pile in

security update

security update

security update

security update

Now Russians accused of pwning JFK taxi system to sell top spots to cabbies
India’s biggest data breach? Hacking gang claims to have stolen 815 million people’s personal information
Ace holed: Hardware store empire felled by cyberattack
Finance orgs have 30 days to confess cyber sins under incoming FTC rules
Cybersecurity snafu sends British Library back to the Dark Ages
UK policing minister urges doubling down on face-scanning tech
Meta’s ad-free scheme dares you to buy your privacy back, one euro at a time
3 things for your 2024 cloud to-do list
Stop what you’re doing and patch this critical Confluence flaw, warns Atlassian
Florida man jailed after draining $1M from victims in crypto SIM swap attacks
Unpatched NGINX ingress controller bugs can be abused to steal Kubernetes cluster secrets
Cryptojackers steal AWS credentials from GitHub in 5 minutes
Stanford schooled in cybersecurity after Akira claims ransomware attack
LockBit alleges it boarded Boeing, stole ‘sensitive data’

security update

Roundcube Webmail servers under attack – Week in security with Tony Anscombe

The zero-day exploit deployed by the Winter Vivern APT group only requires that the target views a specially crafted message in a web browser

security update

security update

Protecting your intellectual property and AI models using Confidential Containers
Ask An OpenShift Admin episode 117: Security considerations while designing a CI/CD Pipeline
Apple Private Wi-Fi hasn’t worked for the past three years
F5 hurriedly squashes BIG-IP remote code execution bug
ESET APT Activity Report Q2–Q3 2023

An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q2 and Q3 2023

Microsoft unveils shady shenanigans of Octo Tempest and their cyber-trickery toolkit
Have you accidentally hired a North Korean IT worker who’s spying on your company?
King Charles III signs off on UK Online Safety Act, with unenforceable spying clause
Apple drops urgent patch against obtuse TriangleDB iPhone malware

security update

security update

Forget the outside hacker, the bigger threat is inside by the coffee machine
Phony Corsair job vacancy targets LinkedIn users with DarkGate malware
Side channel attacks take bite out of Apple silicon with iLeakage exploit
Winter Vivern exploits zero-day vulnerability in Roundcube Webmail servers

ESET Research recommends updating Roundcube Webmail to the latest available version as soon as possible

ServiceNow quietly addresses unauthenticated data exposure flaw from 2015

security update

security update

Canada goosed as attackers shutter hospitals and China deepfakes its politicians
Pro-Russia group exploits Roundcube zero-day in attacks on European government emails

Our annual analysis of the most notorious malware has arrived. As always, it covers the trends, malware groups, and tips for how to protect yourself and your organization. This post covers highlights of our analysis, including the rise of ransomware as a service (RaaS), the six nastiest malware groups, and the role of artificial intelligence […]

A fortified data vault to give you peace of mind
Hunters International leaks pre-op plastic surgery pics in negotiation no-no
VMware reveals critical vCenter vuln that you may have patched already without knowing it
Hot fuzz: Cascade finds dozens of RISC-V chip bugs using random data storm
Citrix urges ‘immediate; patch for critical NetScaler bug as exploit POC made public
Spanish police make 34 arrests, dismantling cybercriminal gang that stole 4 million people’s data
Ex-NSA techie pleads guilty to selling state secrets to Russia
1Password confirms attacker tried to pull list of admin users after Okta intrusion
Element users are asking for protection against government encryption busting
Irish cops data debacle exposes half a million motorist records
How to have encryption, computation, and compliance all at once
Helping you bridge the cloud security gap
Scammers use India’s real-time payment system to siphon off money, send it to China
Cisco fixes critical IOS XE bug but malware crew way ahead of them
DC elections agency warns entire voting roll may have been stolen
Microsoft opens early access to AI assistant for infosec, Security Copilot
Redefining united data protection

security update

security update

Spearphishing targets in Latin America – Week in security with Tony Anscombe

ESET’s analysis of cybercrime campaigns in Latin America reveals a notable shift from opportunistic crimeware to more complex threats, including those targeting enterprises and governments

Admin behind E-Root stolen creds souk extradited to US
CloudBees readies cloud-native devsecops platform
Strengthening the weakest link: top 3 security awareness topics for your employees

Knowledge is a powerful weapon that can empower your employees to become the first line of defense against threats

Runtime security deep dive: Ask An OpenShift Admin episode 116
Enterprise security challenges for CNI organizations: Technical solutions to address security challenges
Casio keyed up after data loss hits customers in 149 countries
Better safe than sorry: 10 tips to build an effective business backup strategy

How robust backup practices can help drive resilience and improve cyber-hygiene in your company

Europol knocks RagnarLocker offline in second major ransomware bust this year
Millions of new 23andMe genetic data profiles leak on cybercrime forum
Cybercrim claims fresh 23andMe batch takes leaked records to 5 million
Ex-Navy IT manager gets 5 years in slammer for 2018 database heist
Ex-Navy IT manager jailed for selling people’s data on the dark web
October Cybersecurity Awareness Month to target internal security risks
Smashing Security podcast #344: What’s cooking at Booking.com? And a podcast built by AI

security update

Plastic surgeries warned by the FBI that they are being targeted by cybercriminals
D-Link clears up ‘exaggerations’ around data breach
CIA exposed to potential intelligence interception due to X’s URL bug

security update

Israelis told to secure their home security cameras against hackers