Explore industry moves and significant changes in the industry for the week of January 6, 2025. Stay updated with the latest industry trends and shifts.
Close to $500 million in cryptocurrency from over 332,000 addresses was stolen in 2024 using wallet drainer malware.
The post Wallet Drainer Malware Used to Steal $500 Million in Cryptocurrency in 2024 appeared first on SecurityWeek.
A vulnerability in Nuclei's template signature verification system could have allowed attackers to execute arbitrary code.
The post Code Execution Flaw Found in Nuclei Vulnerability Scanner appeared first on SecurityWeek.
Roundup of the thirty-seven cybersecurity-related merger and acquisition (M&A) deals announced in December 2024.
The post Cybersecurity M&A Roundup: 37 Deals Announced in December 2024 appeared first on SecurityWeek.
Tenable has disabled two Nessus scanner agent versions after a differential plugin update caused the agents to go offline.
The post Tenable Disables Nessus Agents Over Faulty Updates appeared first on SecurityWeek.
Many cars know where you’ve been and where you are going, and also often have access to your contacts, call logs, texts and other sensitive information thanks to cell phone syncing.
The post Is Your Car Spying on You? What It Means That Tesla Shared Data in the Las Vegas Explosion appeared first on SecurityWeek.
The US Treasury has sanctioned Chinese company Integrity Technology for supporting state-sponsored group Flax Typhoon in hacking US critical infrastructure.
The post US Sanctions Chinese Firm Linked to Flax Typhoon Attacks on Critical Infrastructure appeared first on SecurityWeek.
IT services giant Atos has responded to the data breach claims made by a ransomware group named Space Bears.
The post IT Giant Atos Responds to Ransomware Group’s Data Theft Claims appeared first on SecurityWeek.
Tenable CEO and cybersecurity industry veteran Amit Yoran has passed away at the age of 54 after a battle with cancer.
The post Tenable CEO Amit Yoran Dead at 54 appeared first on SecurityWeek.
Noteworthy stories that might have slipped under the radar: location data of 800,000 electric Volkswagen cars leaked, DoubleClickjacking attack, China denies hacking US Treasury.
The post In Other News: Volkswagen Data Leak, DoubleClickjacking, China Denies Hacking US Treasury appeared first on SecurityWeek.
Teixeira pleaded guilty in March to six counts of the willful retention and transmission of national defense information under the Espionage Act.
The post Pentagon Secrets Leaker Jack Teixeira Sentenced to 15 Years in Prison by a Federal Judge appeared first on SecurityWeek.
Patch Tuesday: Microsoft patches 90 security flaws across the Windows ecosystem and warns of zero-day exploitation and code execution risks.
The post Microsoft Confirms Zero-Day Exploitation of Task Scheduler Flaw appeared first on SecurityWeek.
Adobe patches critical-severity bugs in multiple products, including the Adobe Commerce and Magento Open Source platforms.
The post Patch Tuesday: Critical Flaws in Adobe Commerce, Photoshop, InDesign, Illustrator appeared first on SecurityWeek.
GoIssue is a new tool for cybercriminals that allows attackers to extract email addresses from GitHub profiles and send bulk emails to users.
The post GitLoker Strikes Again: New “Goissue” Tool Targets GitHub Developers and Corporate Supply Chains appeared first on SecurityWeek.
Cybersecurity incident impacts Giant Food, Hannaford, and other Ahold Delhaize USA brands, including pharmacies and e-commerce services.
The post Ahold Delhaize Cybersecurity Incident Impacts Giant Food, Hannaford appeared first on SecurityWeek.
SAP has released eight new security notes on November 2024 patch day, including one addressing a high-severity vulnerability in Web Dispatcher.
The post SAP Patches High-Severity Vulnerability in Web Dispatcher appeared first on SecurityWeek.
The impact of a data breach suffered by Form I-9 Compliance is growing, with the number of affected individuals reaching 190,000.
The post Form I-9 Compliance Data Breach Impacts Over 190,000 People appeared first on SecurityWeek.
Hot Topic has suffered a data breach impacting approximately 57 million unique email addresses and the personal information of roughly 25 million.
The post Millions of Hot Topic Customers Impacted by Data Breach appeared first on SecurityWeek.
Amazon has confirmed that some employee data was compromised as a result of a MOVEit hack last year.
The post Amazon Employee Data Leaked by Hacker appeared first on SecurityWeek.
Explore industry moves and significant changes in the industry for the week of November 11, 2024. Stay updated with the latest industry trends and shifts.
Explore industry moves and significant changes in the industry for the week of September 30, 2024. Stay updated with the latest industry trends and shifts.
The New York late-stage startup banks $70 million in a new funding round led by Evolution Equity Partners.
The post Torq Secures $70M Series C for HyperSOC appeared first on SecurityWeek.
Microsoft reboots controversial Windows Recall with proof-of-presence encryption, anti-tampering checks, and secure enclave data management.
The post Controversial Windows Recall AI Search Tool Returns With Proof-of-Presence Encryption, Data Isolation appeared first on SecurityWeek.
Five Eyes cybersecurity agencies have released joint guidance on identifying Active Directory compromises.
The post Five Eyes Agencies Release Guidance on Detecting Active Directory Intrusions appeared first on SecurityWeek.
Incubated at Cambridge University’s engineering department, Featurespace's algorithmic-based solutions analyze transaction data to detect fraud cases.
The post Visa to Acquire Fraud Protection Firm Featurespace appeared first on SecurityWeek.
Meta fined more than $100 million by a European Union privacy regulator over a security lapse involving Facebook passwords.
The post Meta Hit With $102 Million Privacy Fine From European Union Over 2019 Password Security Lapse appeared first on SecurityWeek.
Noteworthy stories that might have slipped under the radar: China’s Salt Typhoon has hacked US ISPs, China has doxed Taiwanese hackers, and Bishop Fox has a new tool for AI attacks.
The post In Other News: Salt Typhoon Hacks US ISPs, China Doxes Hackers, New Tool for AI Attacks appeared first on SecurityWeek.
US offers up to $10 million for information on Timur Shakhmametov, charging him with running the carding website Joker’s Stash.
The post US Announces Charges, Sanctions Against Russian Administrator of Carding Website appeared first on SecurityWeek.
Experts believe schemes like this will become more common now that the technical barriers that once existed around generative artificial intelligence have decreased.
The post Sophistication of AI-Backed Operation Targeting Senator Points to Future of Deepfake Schemes appeared first on SecurityWeek.
The Tor Project announced that it has merged operations with the security-focused operating system Tails.
The post Tor Merges With Security-Focused OS Tails appeared first on SecurityWeek.
Users continue to flame Kaspersky and Pango Group as the automatic, forced transition to UltraAV gradually progresses.
The post Kaspersky, Pango Respond to User Backlash as Transition to UltraAV Nearly Complete appeared first on SecurityWeek.
A researcher has disclosed the details of an unpatched vulnerability that was expected to pose a serious threat to many Linux systems.
The post Highly Anticipated Linux Flaw Allows Remote Code Execution, but Less Serious Than Expected appeared first on SecurityWeek.
Social media platform X published its first transparency report since the company was purchased by Elon Musk.
The post X Releases Its First Transparency Report Since Elon Musk’s Takeover appeared first on SecurityWeek.
Join the webinar to gain insights and learn actionable steps to enhance your organization's data security and resilience.
The post Watch Now: Shield Your Data, Secure Your Future: A Multi-Layered Approach to Operational Resilience appeared first on SecurityWeek.
Nvidia confirms risk of code execution, denial of service, escalation of privileges, information disclosure, and data tampering. CVSS 9/10.
The post Critical Nvidia Container Flaw Exposes Cloud AI Systems to Host Takeover appeared first on SecurityWeek.
Critical and high-severity vulnerabilities that can be exploited for DoS attacks and remote code execution have been patched in OpenPLC.
The post Remote Code Execution, DoS Vulnerabilities Patched in OpenPLC appeared first on SecurityWeek.
Cisco has released patches for seven high-severity vulnerabilities affecting products running IOS and IOS XE software.
The post Cisco Patches High-Severity Vulnerabilities in IOS Software appeared first on SecurityWeek.
Memory safety bugs in Android have decreased significantly as old code matures and new code uses memory-safe languages.
The post Google Sees Drop in Memory Safety Bugs in Android as Code Matures appeared first on SecurityWeek.
An investigation has been launched into a Wi-Fi service hack that has impacted many train stations in the United Kingdom.
The post Police Are Probing a Cyberattack on Wi-Fi Networks at UK Train Stations appeared first on SecurityWeek.
Explore industry moves and significant changes in the industry for the week of September 23, 2024. Stay updated with the latest industry trends and shifts.
Explore industry moves and significant changes in the industry for the week of September 2, 2024. Stay updated with the latest industry trends and shifts.
Redmond's threat intel team said exploitation of CVE-2024-7971 can be attributed to a North Korean APT targeting the cryptocurrency sector for financial gain.
The post Microsoft Says North Korean Cryptocurrency Thieves Behind Chrome Zero-Day appeared first on SecurityWeek.
Noteworthy stories that might have slipped under the radar: automotive CTF with $100k in prizes, deepfake scams, and Singapore’s OT security masterplan for 2024.
The post In Other News: Automotive CTF, Deepfake Scams, Singapore’s OT Security Masterplan appeared first on SecurityWeek.
Cisco Talos has a blog post on the BlackByte ransomware group’s continuing evolution and new TTPs.
The post BlackByte Ransomware Gang Believed to Be More Active Than Leak Site Suggests appeared first on SecurityWeek.
Efforts in California to establish first-in-the-nation safety measures for the largest artificial intelligence systems cleared an important vote.
The post California Advances Landmark Legislation to Regulate Large AI Models appeared first on SecurityWeek.
Fortra limits access to FileCatalyst Workflow database after vendor knowledgebase article leaks default credentials.
The post Fortra Patches Critical Vulnerability in FileCatalyst Workflow appeared first on SecurityWeek.
The RansomHub ransomware group, which has made at least 210 victims, is believed to be behind the attack on oil giant Halliburton.
The post US Government Issues Advisory on Ransomware Group Blamed for Halliburton Cyberattack appeared first on SecurityWeek.
A former US president and several members of Congress were targets of a plot carried out by two European men to intimidate and threaten dozens of people by calling in bogus reports of police emergencies at their homes.
The post 2 Men From Europe Charged With ‘Swatting’ Plot Targeting Former US President and Members of Congress appeared first on SecurityWeek.
Censys warns of over 1,200 internet-accessible WhatsUp Gold instances potentially exposed to malicious attacks.
The post Critical Flaws in Progress Software WhatsUp Gold Expose Systems to Full Compromise appeared first on SecurityWeek.
The sporting goods retail chain said the incident exposed portions of the its IT systems containing confidential information.
The post Dick’s Sporting Goods Says Sensitive Data Exposed in Cyberattack appeared first on SecurityWeek.
Explore industry moves and significant changes in the industry for the week of August 19, 2024. Stay updated with the latest industry trends and shifts.
Security researchers at Palo Alto Networks discover a threat actor extorting organizations after compromising their cloud environments using inadvertently exposed environment variables.
The post Cloud Misconfigurations Expose 110,000 Domains to Extortion in Widespread Campaign appeared first on SecurityWeek.
Noteworthy stories that might have slipped under the radar: there are 400 CVE Numbering Authorities, crash reports can be a valuable source of information, and Schlatter was hit by a cyberattack.
The post In Other News: 400 CNAs, Crash Reports, Schlatter Cyberattack appeared first on SecurityWeek.
Security leaders are facing big decisions about how they use their monetary and people resources to better secure their environments.
The post Consolidation vs. Optimization: Which Is More Cost-Effective for Improved Security? appeared first on SecurityWeek.
Multiple Russian, Belarusian, and Western entities perceived as Russia’s enemies have been targeted in two recent spear-phishing campaigns.
The post Western, Russian Civil Society Targeted in Sophisticated Phishing Attacks appeared first on SecurityWeek.
Russian cybercriminals are advertising a new macOS malware, Banshee Stealer, capable of stealing passwords, browser data, and crypto wallets.
The post New Banshee Stealer macOS Malware Priced at $3,000 Per Month appeared first on SecurityWeek.
The US cybersecurity agency CISA warns that a recent SolarWinds Web Help Desk vulnerability has been exploited in the wild.
The post SolarWinds Web Help Desk Vulnerability Possibly Exploited as Zero-Day appeared first on SecurityWeek.
ZDI details a zero-day named Copy2Pwn and tracked as CVE-2024-38213, which cybercriminals exploited to bypass MotW protections in Windows.
The post Copy2Pwn Zero-Day Exploited to Bypass Windows Protections appeared first on SecurityWeek.
Security experts are ratcheting up the urgency for Windows admins to patch a wormable, pre-auth remote code execution vulnerability in the Windows TCP/IP stack.
The post Zero-Click Exploit Concerns Drive Urgent Patching of Windows TCP/IP Flaw appeared first on SecurityWeek.
Misconfigurations and security bugs lead to GitHub Actions artifacts exposing tokens for third party cloud services and GitHub repositories.
The post GitHub Actions Artifacts Leak Tokens and Expose Cloud Services and Repositories appeared first on SecurityWeek.
Azure Health Bot Service vulnerabilities found by Tenable could have been exploited for lateral movement and may have allowed customer data exposure.
The post Azure Health Bot Service Vulnerabilities Possibly Exposed Sensitive Data appeared first on SecurityWeek.
SecurityWeek spoke with Mike Britton, CISO at Abnormal Security, to understand what the company has learned about current social engineering and phishing attacks.
The post Unlocking the Front Door: Phishing Emails Remain a Top Cyber Threat Despite MFA appeared first on SecurityWeek.
Secure data sharing solutions provider Kiteworks has raised $456 million in growth equity investment from Insight Partners and Sixth Street Growth.
The post Secure Data Sharing Company Kiteworks Raises $456 Million appeared first on SecurityWeek.
Fortinet and Zoom have released patches for multiple vulnerabilities in their products, including high-severity bugs.
The post Fortinet, Zoom Patch Multiple Vulnerabilities appeared first on SecurityWeek.
Many hackers trace their origin to an interest in, and early exposure to, computers. Tom Anthony is no different.
The post Hacker Conversations: Tom Anthony and Scratching an Itch Without Doing Harm appeared first on SecurityWeek.
Intel and AMD have each informed customers about dozens of vulnerabilities found and patched in their products.
The post Chipmaker Patch Tuesday: Intel, AMD Address Over 110 Vulnerabilities appeared first on SecurityWeek.
Ivanti has released patches for multiple vulnerabilities in Neurons for ITSM, Avalanche, and Virtual Traffic Manager, including critical bugs.
The post Ivanti Patches Critical Vulnerabilities in Neurons for ITSM, Virtual Traffic Manager appeared first on SecurityWeek.
Kootenai Health says the personal and health information of over 460,000 individuals was stolen in a ransomware attack.
The post 460k Impacted by Kootenai Health Ransomware Attack appeared first on SecurityWeek.
ICS Patch Tuesday advisories have been published by Siemens, Schneider Electric, Rockwell Automation, Aveva and CISA.
The post ICS Patch Tuesday: Advisories Released by Siemens, Schneider, Rockwell, Aveva appeared first on SecurityWeek.
Explore industry moves and significant changes in the industry for the week of August 12, 2024. Stay updated with the latest industry trends and shifts.
AWS says a massive neural network graph model with 3.5 billion nodes and 48 billion edges is speeding up the prediction and detection of malicious domains.
The post AWS Deploying ‘Mithra’ Neural Network to Predict and Block Malicious Domains appeared first on SecurityWeek.
The introduction of AI can bring benefits to the enterprise while not introducing additional risk that is beyond acceptable levels.
The post AI in the Enterprise: Cutting Through the Hype and Assessing Real Risks appeared first on SecurityWeek.
Chinese group StormBamboo spotted delivering Windows and macOS malware by compromising an ISP and using DNS poisoning.
The post Chinese Hackers Deliver Malware via ISP-Level DNS Poisoning appeared first on SecurityWeek.
Nakasone will assess the firm’s investments and offer strategic support to portfolio companies in the fight against adversarial advances in the cyber domain.
The post Former NSA Director Paul Nakasone Joins Ballistic Ventures as Strategic Advisor appeared first on SecurityWeek.
A new Linux kernel exploitation technique named SLUBStick makes heap vulnerabilities more dangerous.
The post New SLUBStick Attack Makes Linux Kernel Vulnerabilities More Dangerous appeared first on SecurityWeek.
Organizations are being warned of a newly discovered Apache OFBiz vulnerability as exploitation of another recent flaw is observed.
The post Apache OFBiz Users Warned of New and Exploited Vulnerabilities appeared first on SecurityWeek.
The US Justice Department has sued TikTok, accusing the company of illegally collecting children’s data and violating an online privacy law.
The post Justice Department Sues TikTok, Accusing the Company of Illegally Collecting Children’s Data appeared first on SecurityWeek.
Explore industry moves and significant changes in the industry for the week of August 5, 2024. Stay updated with the latest industry trends and shifts.
Keytronic says the recent ransomware attack resulted in expenses and lost revenue totaling more than $17 million.
The post Ransomware Attack Cost Keytronic Over $17 Million appeared first on SecurityWeek.
Einstein has led CISA’s AI efforts since 2023 as CISA’s Senior Advisor for AI.
The post CISA Names Lisa Einstein as First Chief AI Officer appeared first on SecurityWeek.
Explore industry moves and significant changes in the industry for the week of July 29, 2024. Stay updated with the latest industry trends and shifts.
TechOperators leads a $6 million Series A funding round for Evo Security, a provider of IAM solutions for MSPs.
The post IAM for MSPs Provider Evo Security Raises $6 Million appeared first on SecurityWeek.
Progress Software calls attention to a critical remote code execution flaw in the Telerik Report Server product.
The post Progress Patches Critical Telerik Report Server Vulnerability appeared first on SecurityWeek.
Threat actors have started exploiting critical-severity vulnerabilities in ServiceNow shortly after public disclosure.
The post Threat Actors Exploit Fresh ServiceNow Vulnerabilities in Attacks appeared first on SecurityWeek.
Noteworthy stories that might have slipped under the radar: FBI article on agency’s Cyber Action Team, data of Pentagon IT provider Leidos leaked, Nigerian cybercriminal sentenced to 12 years in prison.
The post In Other News: FBI Cyber Action Team, Pentagon IT Firm Leak, Nigerian Gets 12 Years in Prison appeared first on SecurityWeek.
The US is offering a reward of up to $10 million for information on Rim Jong Hyok, a member of the North Korean hacking group APT45.
The post US Offers $10 Million Reward for Information on North Korean Hacker appeared first on SecurityWeek.
A vulnerability dubbed PKfail can allow attackers to run malicious code during the boot process, which can be used to deliver UEFI bootkits.
The post PKfail Vulnerability Allows Secure Boot Bypass on Hundreds of Computer Models appeared first on SecurityWeek.
CrowdStrike says 97% of Windows systems impacted by its bad update are back online, just as an insurer predicts billions in losses for major companies.
The post 97% of Devices Disrupted by CrowdStrike Restored as Insurer Estimates Billions in Losses appeared first on SecurityWeek.
A man who allegedly carried out attacks for a North Korean military intelligence agency has been indicted in a conspiracy to hack healthcare firms, NASA, military bases and other entities.
The post North Korean Charged in Cyberattacks on US Hospitals, NASA and Military Bases appeared first on SecurityWeek.
Software supply chain security startup Chainguard raises a $140 million Series C round that values the company at $1.2 billion.
The post Chainguard Raises $140 Million, Expands Tech to Secure AI Workloads appeared first on SecurityWeek.
Stargazer Goblin has created a network of over 3,000 GitHub accounts to distribute malware through phishing repositories.
The post Network of 3,000 GitHub Accounts Used for Malware Distribution appeared first on SecurityWeek.
A fresh Mandiant report documents North Korea's APT45 as a distinct hacking team conducting cyberespionage and ransomware operations.
The post Mandiant Shines Spotlight on APT45 Behind North Korea’s Digital Military Machine appeared first on SecurityWeek.
Google has announced improved protections for Chrome users when downloading files from the internet.
The post Google Boosts Chrome Protections Against Malicious Files appeared first on SecurityWeek.
Phone lines down in multiple courts across California after ransomware attack on state’s largest trial court in Los Angeles County.
The post Phone Lines Down in Multiple Courts Across California After Ransomware Attack appeared first on SecurityWeek.
Nvidia has patched high-severity vulnerabilities in its Jetson, Mellanox OS, OnyX, Skyway, and MetroX products.
The post Nvidia Patches High-Severity Vulnerabilities in AI, Networking Products appeared first on SecurityWeek.
The vulnerability, tagged as CVE-2024-41110 with a CVSS severity score of 10/10, was originally found and fixed in 2018.
The post Docker Patches Critical AuthZ Plugin Bypass Vulnerability Dating Back to 2018 appeared first on SecurityWeek.
Zest Security emerged from stealth with $5 million funding and an AI-powered platform that resolves the root source of risk in the cloud.
The post Zest Security Aims to Resolve, Not Just Mitigate Cloud Risks appeared first on SecurityWeek.
The new financing brings the total raised by Dazz to $110 million as investors double down on bets in the cloud security remediation space.
The post Dazz Scores Hefty $50M Investment for AI-Powered Risk Remediation Tech appeared first on SecurityWeek.
Sygnia discovered what it believes to be a variant of the GhostEmperor infection chain leading to the Demodex rootkit – which was first seen and described in 2021.
The post Is GhostEmperor Back? Sygnia Finds Clues in Recent Cyber Incident appeared first on SecurityWeek.
Explore industry moves and significant changes in the industry for the week of July 22, 2024. Stay updated with the latest industry trends and shifts.
Explore industry moves and significant changes in the industry for the week of July 15, 2024. Stay updated with the latest industry trends and shifts.
Vyacheslav Igorevich Penchukov was sentenced to nine years in prison for his role in the Zeus and IcedID malware operations.
The post Ukrainian Sentenced to Prison in US for Role in Zeus, IcedID Malware Operations appeared first on SecurityWeek.
Google's parent company Alphabet is reportedly in advanced talks to acquire the hotshot Israeli data security startup.
The post Google in Advanced Talks to Buy Wiz for $23B: WSJ Report appeared first on SecurityWeek.
Noteworthy stories that might have slipped under the radar: Apple's spyware warning, CDK Global's ransom payment, Platinum giant Sibanye hit by cyberattack.
The post In Other News: Apple’s Spyware Warning, CDK Global Ransom Payment, Sibanye Cyberattack appeared first on SecurityWeek.
Successful exploitation could allow attackers to deliver executable attachments to inboxes.
The post Critical Exim Flaw Allows Attackers to Deliver Malicious Executables to Mailboxes appeared first on SecurityWeek.
Advance Auto Parts says the personal information of 2.3 million was compromised after hackers accessed its Snowflake account.
The post Millions Impacted by Breach at Advance Auto Parts Linked to Snowflake Incident appeared first on SecurityWeek.
CISA says a SILENTSHIELD red team assessment found gaping holes in the security posture of a federal civilian executive branch organization.
The post CISA Red Team Exercise Finds Critical Vulnerabilities in Federal Civilian Agency appeared first on SecurityWeek.
Data breach exposed records of call and text interactions for nearly all AT&T’s wireless customers and has been linked to the recent attacks targeting Snowflake customers.
The post AT&T Data Breach: ‘Nearly All’ Wireless Customers Exposed in Massive Hack appeared first on SecurityWeek.
Akira and EstateRansomware cybercrime gangs have been exploiting a year-old Veeam Backup & Replication vulnerability in recent attacks.
The post Year-Old Veeam Vulnerability Exploited in Fresh Ransomware Attacks appeared first on SecurityWeek.
London startup Tracebit has raised $5 million in seed funding for its cloud-native threat detection and deception solution.
The post Tracebit Raises $5 Million for Threat Deception Solution appeared first on SecurityWeek.
Patch Tuesday: Microsoft patches more than 140 security vulnerabilities in the Windows ecosystem, including a pair of exploited zero-days.
The post Microsoft Warns of Windows Hyper-V Zero-Day Being Exploited appeared first on SecurityWeek.
Adobe documents at least seven code execution bugs affecting Adobe Premiere Pro, Adobe InDesign and Adobe Bridge on Windows and macOS.
The post Adobe Issues Critical Patches for Multiple Products, Warns of Code Execution Risks appeared first on SecurityWeek.
Security vendor InkBridge Networks calls urgent attention to the discovery of a decades-old design flaw in the widely used RADIUS protocol.
The post BlastRADIUS Attack Exposes Critical Flaw in 30-Year-Old RADIUS Protocol appeared first on SecurityWeek.
Command Zero has emerged from stealth mode with $21 million in a seed funding round led by Andreessen Horowitz.
The post Command Zero Emerges From Stealth Mode to Speed Up Cyber Investigations appeared first on SecurityWeek.
Patch Tuesday: Enterprise software vendor SAP releases patches for high-severity vulnerabilities in multiple products and tools.
The post SAP Patches High-Severity Vulnerabilities in PDCE, Commerce appeared first on SecurityWeek.
Evolve Bank says personal information of more than 7.6 million individuals was compromised in a ransomware attack.
The post Evolve Bank Data Breach Impacts 7.6 Million People appeared first on SecurityWeek.
The Ransomhub ransomware gang has claimed the theft of 100GB of data from the Florida Department of Health.
The post Ransomware Gang Leaks Data Allegedly Stolen from Florida Department of Health appeared first on SecurityWeek.
Seven nations are backing Australia in calling out a China-linked hacking group for compromising government networks.
The post Global Coalition Blames China’s APT40 for Hacking Government Networks appeared first on SecurityWeek.
Moving from a state of indifference about security to a place where users actively champion it can be transformed through a focused effort.
The post How to Fix a Dysfunctional Security Culture appeared first on SecurityWeek.
Starting in September, Microsoft will mandate the the use of Apple’s iPhones to authenticate identities when logging into work machines.
The post Microsoft Banning Android Phones for Staff in China appeared first on SecurityWeek.
On the eve of NATO’s 75th anniversary summit in Washington DC, Mandiant outlines the current state of cyberthreats facing NATO and aligned countries.
The post Mandiant Highlights Russian and Chinese Cyber Threats to NATO on Eve of 75th Anniversary Summit appeared first on SecurityWeek.
A threat actor sent over 35,000 phishing emails after hacking into Ethereum Foundation's account on a mailing list platform.
The post Hacked Ethereum Foundation Account Used to Send 35,000 Phishing Emails appeared first on SecurityWeek.
Kaspersky said the CloudSorcerer APT has been abusing public cloud services to exfiltrate data from Russian government entities.
The post Kaspersky Flags Cyberespionage APT ‘CloudSorcerer’ Targeting Russian Government appeared first on SecurityWeek.
The Supreme Court's striking down of the Chevron Doctrine will have a major effect on the determination and enforcement of cyber regulation in the US.
The post Supreme Court Ruling Threatens the Framework of Cybersecurity Regulation appeared first on SecurityWeek.
A class action lawsuit was filed against Geisinger for failing to properly secure patients’ personal and health information.
The post Former Nuance Employee Arrested After Geisinger Data Breach Exposed 1.2 Million Records appeared first on SecurityWeek.
Vulnerability in Ghostscript (CVE-2024-29510) allows attackers to bypass sandbox for remote code execution.
The post Attackers Exploiting Remote Code Execution Vulnerability in Ghostscript appeared first on SecurityWeek.
With Living Off the Cloud (LOTC) attacks, hackers abuse APIs of trusted cloud services to remotely control botnets but also to make malicious traffic appear as trusted cloud traffic.
The post Cloudy with a Chance of Cyberattack: Understanding LOTC Attacks and How ZTNA Can Prevent Them appeared first on SecurityWeek.
Baptiste Robert, a French cybersecurity expert, called on his government – and especially lawmakers – to prepare for the digital threats to come.
The post Russian-Linked Cybercampaigns put a Bull’s-Eye on France. Their Focus? The Olympics and Elections appeared first on SecurityWeek.
ChatGPT maker OpenAI was breached in 2023, but the company says source code and customer data were not accessed.
The post Hacker Stole Secrets From OpenAI appeared first on SecurityWeek.
The Olympic Games is only 29 days long, so set up and take down is a very intense period, where the threat actors can take advantage.
The post How Intelligence Sharing Can Help Keep Major Worldwide Sporting Events on Track appeared first on SecurityWeek.
Noteworthy stories that might have slipped under the radar: Microsoft details Rockwell HMI vulnerabilities, smart grills hacked, Predator spyware activity drops.
The post In Other News: Microsoft Details ICS Flaws, Smart Grill Hacking, Predator Spyware Activity appeared first on SecurityWeek.
OVHcloud says it mitigated the largest ever DDoS attack leveraging packet rate, which peaked at 840 Mpps.
The post OVHcloud Sees Record 840 Mpps DDoS Attack appeared first on SecurityWeek.
Alabama’s education superintendent said some data was breached during a hacking attempt at the State Department of Education.
The post Some Data Is ‘Breached’ During a Hacking Attack on the Alabama Education Department appeared first on SecurityWeek.
TeamViewer has confirmed that the Russian cyberespionage group APT29 appears to be behind the recent hack.
The post TeamViewer Hack Officially Attributed to Russian Cyberspies appeared first on SecurityWeek.
Shockwaves from the Russian government's hack of Microsoft's corporate infrastructure continue to spread as the victim pool widens.
The post Microsoft Alerts More Customers to Email Theft in Expanding Midnight Blizzard Hack appeared first on SecurityWeek.
Incubated for two years by Ballistic Ventures, GetReal Labs has launched to combat manipulated content and deepfakes.
The post GetReal Labs Emerges From Stealth to Tackle Deepfakes appeared first on SecurityWeek.
Permissions management technology startup AuthZed has raised $12 million in a Series A funding round led by General Catalyst.
The post AuthZed Raises $12 Million for Permissions Management Technology appeared first on SecurityWeek.
Noteworthy stories that might have slipped under the radar: Korean ISP delivers malware to customers, Temu sued for allegedly spying on users, Microsoft patches a critical Dataverse vulnerability.
The post In Other News: Malware Delivered by ISP, Temu Spying, Critical Dataverse Vulnerability appeared first on SecurityWeek.
Microsoft has tricked several gen-AI models into providing forbidden information using a jailbreak technique named Skeleton Key.
The post Microsoft Details ‘Skeleton Key’ AI Jailbreak Technique appeared first on SecurityWeek.
Fortra has patched a critical-severity vulnerability in FileCatalyst Workflow leading to the creation of administrator accounts.
The post Fortra Patches Critical SQL Injection in FileCatalyst Workflow appeared first on SecurityWeek.
Ann & Robert H. Lurie Children’s Hospital of Chicago says the recent data breach caused by a ransomware attack impacts 791,000 people.
The post Chicago Children’s Hospital Says 791,000 Impacted by Ransomware Attack appeared first on SecurityWeek.
Namecheap shut down polyfill.io amid reports of malicious activity, but the Chinese owner claims it has good intentions.
The post Polyfill Domain Shut Down as Owner Disputes Accusations of Malicious Activity appeared first on SecurityWeek.
TeamViewer’s corporate network was hacked and some reports say the Russian group APT29 is behind the attack.
The post Russian APT Reportedly Behind New TeamViewer Hack appeared first on SecurityWeek.
The US Justice Department has announced charges against Amin Stigal for conducting wiper cyberattacks on Ukraine in 2022.
The post US Announces Charges, Reward for Russian National Behind Wiper Attacks on Ukraine appeared first on SecurityWeek.
Healthcare services provider Designed Receivable Solutions says the number of individuals affected by a recent data breach has increased to 585,000.
The post Designed Receivable Solutions Data Breach Impacts 585,000 People appeared first on SecurityWeek.
GitLab CE and EE updates resolve 14 vulnerabilities, including a critical- and three high-severity bugs.
The post GitLab Security Updates Patch 14 Vulnerabilities appeared first on SecurityWeek.
Most critical open source software contains code written in a memory unsafe language, US, Australian, and Canadian government agencies warn.
The post US, Allies Warn of Memory Unsafety Risks in Open Source Software appeared first on SecurityWeek.
Inside the Mind of a CISO 2024 is a survey of 209 security leaders to understand the thinking and operational methods and motivations of CISOs.
The post Inside the Mind of a CISO: Survey and Analysis appeared first on SecurityWeek.
Critical vulnerabilities have been found in an Emerson gas chromatograph and Claroty warns that attacks could have a serious impact.
The post Gas Chromatograph Hacking Could Have Serious Impact: Security Firm appeared first on SecurityWeek.
CISA on Wednesday warned that three older flaws in GeoServer, Linux kernel, and Roundcube webmail are exploited in the wild.
The post CISA Warns of Exploited GeoServer, Linux Kernel, and Roundcube Vulnerabilities appeared first on SecurityWeek.
The LockBit ransomware group claimed to have hacked the US Federal Reserve, but leaked data from an Arkansas-based bank.
The post Evolve Bank Data Leaked After LockBit’s ‘Federal Reserve Hack’ appeared first on SecurityWeek.
Aqua Security shows that code in repositories remains accessible even after being deleted or overwritten, continuing to leak secrets.
The post ‘Phantom’ Source Code Secrets Haunt Major Organizations appeared first on SecurityWeek.
WikiLeaks founder Julian Assange returned to Australia, hours after pleading guilty to obtaining and publishing U.S. military secrets.
The post WikiLeaks Founder Julian Assange Returns to Australia a Free Man After US Legal Battle Ends appeared first on SecurityWeek.
A Mirai-like botnet has started exploiting a critical-severity vulnerability in discontinued Zyxel NAS products.
The post Recent Zyxel NAS Vulnerability Exploited by Botnet appeared first on SecurityWeek.
Indonesia’s national data center has been compromised by a hacking group asking for a $8 million ransom that the government won’t pay.
The post Indonesia Says a Cyberattack Has Compromised Its Data Center but It Won’t Pay the $8 Million Ransom appeared first on SecurityWeek.
CoinStats says North Korean hackers drained $2 million in virtual assets from 1,590 cryptocurrency wallets.
The post Hackers Steal Over $2 Million in Cryptocurrency From CoinStats Wallets appeared first on SecurityWeek.
Five WordPress plugins were injected with malicious code that creates a new administrative account.
The post Several Plugins Compromised in WordPress Supply Chain Attack appeared first on SecurityWeek.
Researcher shows how hackers could use social engineering to deliver ransomware and other malware to Meta’s Quest 3 VR headset.
The post Meta’s Virtual Reality Headset Vulnerable to Ransomware Attacks: Researcher appeared first on SecurityWeek.
Car dealerships in North America are still wrestling with major disruptions that started last week with cyberattacks on a company whose software is used widely in the auto retail sales sector.
The post Car Dealerships in North America Revert to Pens and Paper After Cyberattacks on Software Provider appeared first on SecurityWeek.
Employees of the Any.Run malware analysis service were recently targeted in a phishing attack that was part of a BEC campaign.
The post Malware Sandbox Any.Run Targeted in Phishing Attack appeared first on SecurityWeek.
Neiman Marcus has disclosed a data breach impacting 64,000 people just as a hacker announced the sale of customer data.
The post Neiman Marcus Data Breach Disclosed as Hacker Offers to Sell Stolen Information appeared first on SecurityWeek.
Google has released a Chrome security update to resolve four high-severity use-after-free vulnerabilities.
The post Chrome 126 Update Patches Memory Safety Bugs appeared first on SecurityWeek.
Assange will plead guilty to an Espionage Act charge of conspiring to unlawfully obtain and disseminate classified national defense information, the Justice Department said.
The post WikiLeaks Founder Julian Assange Will Plead Guilty in Deal With US and Return to Australia appeared first on SecurityWeek.
A suspected Chinese state-sponsored hacking group has stepped up its targeting of Taiwanese organizations, particularly those in sectors such as government, education, technology and diplomacy.
The post Chinese Hackers Have Stepped Up Attacks on Taiwanese Organizations, Cybersecurity Firm Says appeared first on SecurityWeek.
SecurityWeek’s AI Risk Summit + CISO Forum brings together business and government stakeholders to provide meaningful guidance on risk management and cybersecurity in the age of artificial intelligence.
The post Tech Leaders Gather This Week for AI Risk Summit + CISO Forum at the Ritz-Carlton, Half Moon Bay appeared first on SecurityWeek.
New attack named SnailLoad allows a remote attacker to infer websites and videos viewed by a user without direct access to network traffic.
The post New SnailLoad Attack Relies on Network Latency Variations to Infer User Activity appeared first on SecurityWeek.
The EFF has issued a warning over the use of automated license plate readers following the discovery of serious vulnerabilities.
The post EFF Issues New Warning After Discovery of Automated License Plate Reader Vulnerabilities appeared first on SecurityWeek.
LivaNova USA says the personal and medical information of 130,000 individuals was compromised in an October 2023 data breach.
The post LivaNova USA Discloses Data Breach Impacting 130,000 Individuals appeared first on SecurityWeek.
The US has announced charges against four Vietnamese nationals for hacking businesses and causing $71 million in losses.
The post Vietnamese Members of FIN9 Hacking Group Charged in US appeared first on SecurityWeek.
The Los Angeles County Department of Health Services discloses a data breach caused by push notification spamming attack.
The post Push Notification Fatigue Leads to LA County Health Department Data Breach appeared first on SecurityWeek.
The US has imposed sanctions on 12 individuals who have leadership roles at Kaspersky in Russia and the UK.
The post US Sanctions 12 Kaspersky Executives appeared first on SecurityWeek.
A hacker claims to have stolen the information of 30 million users from TEG subsidiary Ticketek.
The post Hacker Claims Theft of 30M User Records From Australia Ticketing Company TEG appeared first on SecurityWeek.
Japan’s space agency has suffered a series of cyberattacks, but sensitive information related to rockets and satellites was not affected.
The post Japan’s Space Agency Was Hit by Multiple Cyberattacks, but Officials Say No Sensitive Data Was Taken appeared first on SecurityWeek.
Facial recognition startup Clearview AI has reached a settlement in an Illinois lawsuit alleging its massive photographic collection of faces violated the subjects’ privacy rights.
The post Facial Recognition Startup Clearview AI Settles Privacy Suit appeared first on SecurityWeek.
Hundreds of operations and appointments are still being canceled more than two weeks after the June 3 cyberattack on NHS provider Synnovis.
The post Investigation of Russian Hack on London Hospitals May Take Weeks Amid Worries Over Online Data Dump appeared first on SecurityWeek.
Santander US is notifying over 12,000 employees that their personal information was compromised in a data breach.
The post Santander Employee Data Breach Linked to Snowflake Attack appeared first on SecurityWeek.
A recently patched Vision Pro vulnerability was classified by Apple as a DoS issue, but a researcher has shown that it’s ‘scary’.
The post Spatial Computing Hack Exploits Apple Vision Pro Flaw to Fill Room With Spiders, Bats appeared first on SecurityWeek.
Noteworthy stories that might have slipped under the radar: Microsoft email spoofing vulnerability, Snowflake hack victims get ransom demands, LogoFail still around.
The post In Other News: Microsoft Email Spoofing, Snowflake Hack Ransoms, LogoFail Follow-Up appeared first on SecurityWeek.
Threat actors are exploiting a recent path traversal vulnerability in SolarWinds Serv-U using public PoC code.
The post Recent SolarWinds Serv-U Vulnerability Exploited in the Wild appeared first on SecurityWeek.
CISA says CFATS program data was likely accessed after an Ivanti Connect Secure appliance was hacked in January.
The post Personal and Chemical Facility Information Potentially Accessed in CISA Hack appeared first on SecurityWeek.
The US government announced a ban on the sale of Kaspersky software over fears that the company is controlled by the Russian government.
The post US Bans Kaspersky Software appeared first on SecurityWeek.
Car dealership software provider CDK Global was in the process of restoring services impacted by a cyberattack when it discovered an additional hack.
The post Disruptions at Many Car Dealerships Continue as CDK Hack Worsens appeared first on SecurityWeek.
Change Healthcare is starting to notify hospitals, insurers and other customers that they may have had patient information exposed in a massive cyberattack.
The post Change Healthcare to Start Notifying Customers Who Had Data Exposed in Cyberattack appeared first on SecurityWeek.
A years-long espionage campaign has targeted telecoms companies in Asia with tools associated with Chinese groups.
The post Decade-Long Cyber Assault on Asian Telecoms Traced to Chinese State Hackers appeared first on SecurityWeek.
Ilya Sutskever's new company is focused on safely developing “superintelligence” - a reference to AI systems that are smarter than humans.
The post OpenAI Co-Founder Sutskever Sets up New AI Company Devoted to ‘Safe Superintelligence’ appeared first on SecurityWeek.
Pomerium raises $13.75 million in Series A funding for dynamic user identity verification and access management platform.
The post Access Management Startup Pomerium Raises $13.75 Million appeared first on SecurityWeek.
LockBit appears to once again be the most active ransomware group, but experts believe the hackers may just be inflating their numbers.
The post LockBit Ransomware Again Most Active – Real Attack Surge or Smokescreen? appeared first on SecurityWeek.
Hundreds of PC and server models may be affected by CVE-2024-0762, a privilege escalation and code execution flaw in Phoenix SecureCore UEFI firmware.
The post Hundreds of PC, Server Models Possibly Affected by Serious Phoenix UEFI Vulnerability appeared first on SecurityWeek.
AI model weights govern outputs from the system, but altered or ‘poisoned’, they can make the output erroneous and, in extremis, useless and dangerous.
The post AI Weights: Securing the Heart and Soft Underbelly of Artificial Intelligence appeared first on SecurityWeek.
Enterprise identity company raises new capital from JP Morgan and Hercules Capital as it prepares for an IPO exit.
The post Semperis Eyes IPO With $125 Million in Growth Financing appeared first on SecurityWeek.
A threat actor targeting Chinese-speaking victims has been using the SquidLoader malware loader in recent attacks.
The post Highly Evasive SquidLoader Malware Targets China appeared first on SecurityWeek.
Atlassian has released Confluence, Crucible, and Jira updates to address multiple high-severity vulnerabilities.
The post Atlassian Patches High-Severity Vulnerabilities in Confluence, Crucible, Jira appeared first on SecurityWeek.
Post-quantum cryptography (PQC) company PQShield has raised $37 million in Series B funding for its quantum-safe cryptography solutions.
The post Post-Quantum Cryptography Firm PQShield Raises $37 Million appeared first on SecurityWeek.
Sagar Steven Singh and Nicholas Ceraolo pleaded guilty to hacking a database maintained by a US federal law enforcement agency.
The post Two Men Plead Guilty to Hacking Law Enforcement Database for Doxing appeared first on SecurityWeek.
The BadSpace backdoor is being distributed via drive-by attacks involving infected websites and JavaScript downloaders.
The post New BadSpace Backdoor Deployed in Drive-By Attacks appeared first on SecurityWeek.
Entro’s platform is designed to bring order to the increasingly chaotic management of non-human identities.
The post Non-human Identity Lifecycle Firm Entro Security Raises $18 Million appeared first on SecurityWeek.
Researchers have targeted the MTE security feature in Arm CPUs and showed how attackers could bypass protections.
The post New TikTag Attack Targets Arm CPU Security Feature appeared first on SecurityWeek.
China-linked threat actor Velvet Ant leveraged a legacy F5 BIG-IP appliance for three-year access to a victim’s network.
The post Chinese Hackers Leveraged Legacy F5 BIG-IP Appliance for Persistence appeared first on SecurityWeek.
Serious vulnerabilities that can allow remote code execution and privilege escalation have been patched in VMware vCenter Server.
The post Critical Code Execution Vulnerabilities Patched in VMware vCenter Server appeared first on SecurityWeek.
Blackbaud was ordered to pay $6.75 million to the California Attorney General’s Office over the 2020 data breach.
The post Blackbaud Settles With California for $6.75 Million Over 2020 Data Breach appeared first on SecurityWeek.
SecurityWeek’s AI Risk Summit + CISO Forum bring together business and government stakeholders to provide meaningful guidance on risk management and cybersecurity in the age of artificial intelligence.
The post Tech Leaders to Gather for AI Risk Summit at the Ritz-Carlton, Half Moon Bay June 25-26, 2024 appeared first on SecurityWeek.
The US cybersecurity agency CISA has conducted a tabletop exercise with the private sector focused on AI cyber incident response.
The post CISA Conducts First AI Cyber Incident Response Exercise appeared first on SecurityWeek.
Keytronic confirms that personal information was compromised after a ransomware group leaked allegedly stolen data.
The post Keytronic Says Personal Information Stolen in Ransomware Attack appeared first on SecurityWeek.
US insurance company Globe Life is investigating a data breach involving unauthorized access to consumer and policyholder information.
The post Insurance Company Globe Life Investigating Data Breach appeared first on SecurityWeek.
Aim Security has raised a total of $28 million to date and is on a mission to help companies to implement AI products with confidence.
The post Aim Security Raises $18M to Secure Customers’ Implementation of AI Apps appeared first on SecurityWeek.
The LA County’s Department of Public Health says the personal information of 200,000 was compromised in a data breach.
The post 200,000 Impacted by Data Breach at Los Angeles County Public Health Agency appeared first on SecurityWeek.
A British man has been arrested in Spain for allegedly being the ringleader of the notorious Scattered Spider cybercrime group.
The post UK Man Suspected of Being ‘Scattered Spider’ Leader Arrested appeared first on SecurityWeek.
Nigerian national Ebuka Raphael Umeti was convicted in the US for operating a business email compromise (BEC) scheme.
The post Nigerian Faces Prison in US After BEC Fraud Conviction appeared first on SecurityWeek.
Republican Gov. Phil Scott said the legislation would have made Vermont “a national outlier and more hostile than any other state to many businesses and non-profits.”
The post Vermont Governor Vetoes Data Privacy Bill, Saying State Would be Most Hostile to Businesses appeared first on SecurityWeek.
Security researchers at Cisco Talos and Volexity flag two Pakistani espionage campaigns targeting Indian government entities.
The post Pakistani Threat Actors Caught Targeting Indian Gov Entities appeared first on SecurityWeek.
Retired U.S. Army General Paul M. Nakasone brings cybersecurity experience to OpenAI's Board of Directors and Safety and Security Committee.
The post OpenAI Appoints Former NSA Director Paul Nakasone to Board of Directors appeared first on SecurityWeek.
The increase in mass exploitation involving edge services and devices is likely to worsen.
The post Edge Devices: The New Frontier for Mass Exploitation Attacks appeared first on SecurityWeek.
Ascension says patient information was stolen in an early-May ransomware attack that involved an employee downloading malware.
The post Ascension Says Personal, Health Information Stolen in Ransomware Attack appeared first on SecurityWeek.
Noteworthy stories that might have slipped under the radar: Overview of the ICS malware Fuxnet, Google accused of tracking users, scammers impersonate CISA staff.
The post In Other News: Fuxnet ICS Malware, Google User Tracking, CISA Employee Scams appeared first on SecurityWeek.
Rockwell Automation has patched three high-severity vulnerabilities in its FactoryTalk View SE HMI software.
The post Rockwell Automation Patches High-Severity Vulnerabilities in FactoryTalk View SE appeared first on SecurityWeek.
CISA urges federal agencies to apply mitigations for an exploited Progress Telerik vulnerability as soon as possible.
The post CISA Warns of Progress Telerik Vulnerability Exploitation appeared first on SecurityWeek.
Microsoft is not rolling out Recall with Copilot+ PCs as it’s seeking additional feedback and working on improving security.
The post Microsoft Delaying Recall Feature to Improve Security appeared first on SecurityWeek.
YesWeHack has raised more than $52 million to date to build and market a crowdsourced vulnerability reporting platform.
The post French Bug Bounty Platform YesWeHack Raises $28 Million appeared first on SecurityWeek.
Mandiant says it has no evidence to suggest that unauthorized access to Snowflake customer accounts stemmed from a breach of Snowflake's enterprise environment.
The post Snowflake Attacks: Mandiant Links Data Breaches to Infostealer Infections appeared first on SecurityWeek.
Fortinet announces plans to acquire Lacework, a late-stage cloud security startup that was once listed as a “unicorn” company valued north of $1 billion.
The post Fortinet Expands Cloud Security Portfolio with Lacework Acquisition appeared first on SecurityWeek.
A critical vulnerability in the PyTorch distributed RPC framework could be exploited for remote code execution.
The post Critical PyTorch Vulnerability Can Lead to Sensitive AI Data Theft appeared first on SecurityWeek.
PHP has released patches for CVE-2024-4577, a critical vulnerability that could lead to arbitrary code execution on remote servers.
The post PHP Patches Critical Remote Code Execution Vulnerability appeared first on SecurityWeek.
The New York Times has issued a statement after someone leaked source code allegedly belonging to the news giant.
The post New York Times Responds to Source Code Leak appeared first on SecurityWeek.
Nvidia patches multiple high-severity vulnerabilities in GPU display drivers and virtual GPU software.
The post Nvidia Patches High-Severity GPU Driver Vulnerabilities appeared first on SecurityWeek.
Cisco Talos researchers have found over a dozen vulnerabilities in AutomationDirect PLCs, including flaws that could be valuable to attackers.
The post Cisco Finds 15 Vulnerabilities in AutomationDirect PLCs appeared first on SecurityWeek.
A Zambian court has sentenced 22 Chinese nationals to long prison terms for cybercrimes that included internet fraud and online scams targeting Zambians and other people.
The post 22 Chinese Nationals Sentenced to Long Prison Terms in Zambia for Multinational Cybercrimes appeared first on SecurityWeek.
Auction house Christie's says the data breach caused by the recent ransomware attack impacts the information of 45,000 individuals.
The post Christie’s Says Ransomware Attack Impacts 45,000 People appeared first on SecurityWeek.
Amidst public pressure, Microsoft changes the set-up experience of Copilot+ PCs to disable the controversial Windows Recall feature by default.
The post Microsoft Bows to Public Pressure, Disables Controversial Windows Recall by Default appeared first on SecurityWeek.
Tenable goes shopping again in Israel with plans to buy early stage startup Eureka Security to boost data security posture management tooling.
The post Tenable to Acquire Eureka Security to Boost DSPM Capabilities appeared first on SecurityWeek.
Noteworthy stories that might have slipped under the radar: TikTok patches account hijacking zero-day, $300 million DMM Bitcoin hack, free Android VPN apps analyzed.
The post In Other News: TikTok Zero-Day, DMM Bitcoin Hack, Free VPN App Analysis appeared first on SecurityWeek.
Mozilla has announced a 0Day Investigative Network (0Din) bug bounty program for LLMs and other deep learning tech.
The post Mozilla Launches 0Din Gen-AI Bug Bounty Program appeared first on SecurityWeek.
The FCC proposes that broadband providers plan for BGP security and provide quarterly reports on implemented risk mitigations.
The post FCC Proposes BGP Security Reporting for Broadband Providers appeared first on SecurityWeek.
AI-powered MDR startup AirMDR has raised $5 million in seed funding from Foundation Capital and Storm Ventures.
The post AirMDR Raises $5 Million for AI-Powered Managed Detection and Response appeared first on SecurityWeek.
SolarWinds has released patches for high-severity vulnerabilities in Serv-U and the SolarWinds Platform.
The post SolarWinds Patches High-Severity Vulnerability Reported by NATO Pentester appeared first on SecurityWeek.
Frontier Communications has started notifying over 750,000 individuals that their personal information was stolen in a recent data breach. The telecommunications giant says it identified the incident on April 14, when it was forced to shut down certain systems to contain it. By mid-May, the company had restored all impacted systems. Right from the start, […]
The post 750k Impacted by Frontier Communications Data Breach appeared first on SecurityWeek.
To comply with new UK government regulations, Apple has specified that iPhones will get at least 5 years of security updates.
The post Apple Says iPhones Will Get Security Updates for at Least 5 Years appeared first on SecurityWeek.
Akamai warns that a Chinese threat actor is exploiting years-old remote code execution vulnerabilities in ThinkPHP in new attacks.
The post Chinese Hackers Exploit Old ThinkPHP Vulnerabilities in New Attacks appeared first on SecurityWeek.
The US government is trying to recover more than $5.3 million stolen by cybercriminals through a BEC scheme from a workers union.
The post US Authorities Attempting to Recover $5.3 Million Stolen in BEC Scam appeared first on SecurityWeek.
Log tampering is an almost inevitable part of a compromise. Why and how do cybercriminals target logs, and what can be done to protect them?
The post Why Hackers Love Logs appeared first on SecurityWeek.
Google and Microsoft warn of elevated risks of cyber threats facing the 2024 Paris Olympics, especially from Russian threat actors.
The post Google, Microsoft: Russian Threat Actors Pose High Risk to 2024 Paris Olympics appeared first on SecurityWeek.
A Russian cyber gang is believed to be behind a ransomware attack that disrupted London hospitals and led to operations and appointments being canceled.
The post A Russian Cyber Gang Is Thought to Be Behind a Ransomware Attack That Hit London Hospitals appeared first on SecurityWeek.
GreyNoise has observed a rapid increase in the number of exploitation attempts targeting a recent Check Point VPN zero-day.
The post Exploitation of Recent Check Point VPN Zero-Day Soars appeared first on SecurityWeek.
It took code security firm Kiuwan nearly two years to patch several serious vulnerabilities found in its SAST products.
The post Vulnerabilities Patched in Kiuwan Code Security Products After Long Disclosure Process appeared first on SecurityWeek.
A multinational operation by Interpol and the FBI cracked down on attempts in Moldova to sabotage one of the international police agency’s key tools, the Red Notice system.
The post Interpol and FBI Break Up a Cyber Scheme in Moldova to Get Asylum for Wanted Criminals appeared first on SecurityWeek.
Gone are the days when cyberattacks were deemed concerns solely by corporate giants.
The post Upleveling the State of SMB Cybersecurity appeared first on SecurityWeek.
Multiple Chinese state-sponsored groups have targeted a Southeast Asian government in a years-long cyberespionage campaign.
The post Multiple Chinese APTs Targeted Southeast Asian Government for Two Years appeared first on SecurityWeek.
The FBI has obtained more than 7,000 LockBit ransomware decryption keys and is urging victims to get in touch with its IC3.
The post FBI Says It Has 7,000 LockBit Ransomware Decryption Keys appeared first on SecurityWeek.
Passwordless authentication provider Hypr has received a $30 million investment from Silver Lake Waterman.
The post Hypr Raises $30 Million for Passwordless Authentication appeared first on SecurityWeek.
Cybersecurity researchers are demonstrating how malware could steal data collected by the new Windows Recall feature.
The post Researchers Show How Malware Could Steal Windows Recall Data appeared first on SecurityWeek.
Critical vulnerabilities in discontinued Zyxel NAS products allow unauthenticated attackers to execute arbitrary code and OS commands.
The post ‘NsaRescueAngel’ Backdoor Account Again Discovered in Zyxel Products appeared first on SecurityWeek.
Mandiant saw an increase in ransomware activity in 2023 compared to 2022, including a 75% increase in posts on data leak sites.
The post Resurgence of Ransomware: Mandiant Observes Sharp Rise in Criminal Extortion Tactics appeared first on SecurityWeek.
There are 1.2 million cybersecurity workers in the US, but 225,000 more are needed to close the talent gap, according to new data.
The post 225,000 More Cybersecurity Workers Needed in US: CyberSeek appeared first on SecurityWeek.
Cisco has released a security advisory after researchers discovered that the German government’s Webex meetings were exposed.
The post Cisco Patches Webex Bugs Following Exposure of German Government Meetings appeared first on SecurityWeek.
Several hospitals in London have canceled operations and appointments after being hit in a ransomware attack.
The post London Hospitals Cancel Operations and Appointments After Being Hit in Ransomware Attack appeared first on SecurityWeek.
The BianLian ransomware gang has leaked data allegedly stolen from Australian mining company Northern Minerals.
The post Ransomware Gang Leaks Data From Australian Mining Company appeared first on SecurityWeek.
A group of OpenAI’s current and former workers is calling for AI firms to protect whistleblowing employees who flag safety risks about AI technology.
The post Former OpenAI Employees Lead Push to Protect Whistleblowers Flagging Artificial Intelligence Risks appeared first on SecurityWeek.
SonicWall has shared technical details on a recently addressed high-severity remote code execution flaw in Confluence.
The post Details of Atlassian Confluence RCE Vulnerability Disclosed appeared first on SecurityWeek.
A critical vulnerability in the Progress Telerik Report Server could allow unauthenticated attackers to access restricted functionality.
The post Progress Patches Critical Vulnerability in Telerik Report Server appeared first on SecurityWeek.
CISA has added an old Oracle WebLogic flaw tracked as CVE-2017-3506 to its known exploited vulnerabilities catalog.
The post CISA Warns of Attacks Exploiting Old Oracle WebLogic Vulnerability appeared first on SecurityWeek.
The RansomHub ransomware group claims to have stolen the information of over 2 million Frontier Communications customers.
The post Ransomware Group Claims Cyberattack on Frontier Communications appeared first on SecurityWeek.
Roundup of the more than two dozen cybersecurity-related merger and acquisition (M&A) deals announced in May 2024.
The post Cybersecurity M&A Roundup: 28 Deals Announced in May 2024 appeared first on SecurityWeek.
Cox recently patched a series of vulnerabilities that could have allowed hackers to remotely take control of millions of modems.
The post Vulnerabilities Exposed Millions of Cox Modems to Remote Hacking appeared first on SecurityWeek.
Android’s June 2024 security update resolves 37 vulnerabilities, including high-severity flaws in Framework and System.
The post 37 Vulnerabilities Patched in Android appeared first on SecurityWeek.
Law enforcement reveals the identities of eight cybercriminals linked to recently disrupted malware loaders.
The post Identities of Cybercriminals Linked to Malware Loaders Revealed appeared first on SecurityWeek.
PoC code targeting a recent Check Point VPN zero-day has been released as Censys identifies 14,000 internet-accessible appliances.
The post PoC Published for Exploited Check Point VPN Vulnerability appeared first on SecurityWeek.
Ticketmaster and other organizations have been affected by a data breach at cloud AI data platform Snowflake.
The post Snowflake Data Breach Impacts Ticketmaster, Other Organizations appeared first on SecurityWeek.
AI tool development platform Hugging Face has detected a Spaces hack that resulted in the exposure of secrets.
The post Secrets Exposed in Hugging Face Hack appeared first on SecurityWeek.
Noteworthy stories that might have slipped under the radar: Apple WPS can be abused for surveillance, Canadian government wants backdoors, NIST launches AI program.
The post In Other News: Apple WPS Surveillance, Canadian Gov Wants Backdoors, NIST AI Program appeared first on SecurityWeek.
The email addresses and other information of hundreds of British, French and EU politicians have been found on the dark web.
The post Information of Hundreds of European Politicians Found on Dark Web appeared first on SecurityWeek.
Over 600,000 SOHO routers belonging to a single ISP and infected with the Chalubo trojan were rendered inoperable.
The post Mysterious Threat Actor Used Chalubo Malware to Brick 600,000 Routers appeared first on SecurityWeek.
CISA instructs federal agencies to mitigate CVE-2024-1086, a Linux kernel flaw leading to privilege escalation.
The post CISA Warns of Exploited Linux Kernel Vulnerability appeared first on SecurityWeek.
Altman spent part of his virtual appearance fending off thorny questions about governance, an AI voice controversy and criticism from ousted board members.
The post OpenAI’s Altman Sidesteps Questions About Governance, Johansson at UN AI Summit appeared first on SecurityWeek.
The ShinyHunters hacking group has claimed the theft of 560 million Ticketmaster users’ data on a fresh BreachForums portal.
The post Hackers Boast Ticketmaster Breach on Relaunched BreachForums appeared first on SecurityWeek.
The BBC has disclosed a data breach impacting over 25,000 current and former employees, but the incident did not involve ransomware.
The post BBC Data Breach Impacts 25,000 Employees appeared first on SecurityWeek.
Cloudlfare acquires Boston seed-stage startup BastionZero to bolster its Zero Trust Network Access technology portfolio.
The post Cloudflare Expands Zero Trust Capabilities with Acquisition of BastionZero appeared first on SecurityWeek.
SecurityWeek editor-at-large Ryan Naraine examines the broad tension between tech innovation and privacy rights at a time when ChatGPT-like bots and generative-AI apps are starting to dominate the landscape.
The post Microsoft’s Windows Recall: Cutting-Edge Search Tech or Creepy Overreach? appeared first on SecurityWeek.
Malicious campaign exploits high-severity XSS flaws in three WordPress plugins to backdoor websites.
The post Critical WordPress Plugin Flaws Exploited to Inject Malicious Scripts and Backdoors appeared first on SecurityWeek.
NIST is receiving support to get the NVD and CVE processing back on track within the next few months.
The post NIST Getting Outside Help for National Vulnerability Database appeared first on SecurityWeek.
The TrickBot botnet and other malware droppers have been targeted by international law enforcement in Operation Endgame.
The post TrickBot and Other Malware Droppers Disrupted by Law Enforcement appeared first on SecurityWeek.
The data breach at debt collection agency Financial Business and Consumer Solutions (FBCS) impacts 3.2 million individuals.
The post FBCS Data Breach Impact Grows to 3.2 Million Individuals appeared first on SecurityWeek.
Okta raises the alarm on credential stuffing attacks targeting endpoints used for cross-origin authentication.
The post Okta Warns of Credential Stuffing Attacks Targeting Cross-Origin Authentication appeared first on SecurityWeek.
Assembling a diverse team, outlining clear objectives, and meticulously assessing your network landscape can enable organizations to successfully navigate SASE migration without hiccups and pitfalls.
The post 8 Degrees of Secure Access Service Edge appeared first on SecurityWeek.
The US announced that the 911 S5 (Cloud Router) botnet, likely the world’s largest, has been dismantled and its administrator arrested.
The post Massive 911 S5 Botnet Dismantled, Chinese Mastermind Arrested appeared first on SecurityWeek.
The Seattle Public Library is scrambling to bring systems online after shutting them down to contain a ransomware attack.
The post Ransomware Attack Disrupts Seattle Public Library Services appeared first on SecurityWeek.
The recently disclosed Check Point VPN attacks involve the zero-day vulnerability CVE-2024-24919, which allows hackers to obtain passwords.
The post Check Point VPN Attacks Involve Zero-Day Exploited Since April appeared first on SecurityWeek.
San Francisco data privacy startup Transcend secures 40 million in a Series B funding round that brings the total raised to $90 million.
The post Transcend Raises $40 Million for Data Privacy Platform appeared first on SecurityWeek.
Vulnerabilities in the real-time IoT operating system Eclipse ThreadX before version 6.4 could lead to denial-of-service and code execution.
The post Vulnerabilities in Eclipse ThreadX Could Lead to Code Execution appeared first on SecurityWeek.
The US government has announced sanctions against three Chinese nationals accused of creating and operating the 911 S5 proxy botnet.
The post US Sanctions Three Chinese Men for Operating 911 S5 Botnet appeared first on SecurityWeek.
Data security and AI governance company Zendata has emerged from stealth mode with $2 million in seed funding.
The post Zendata Emerges From Stealth With Data Security, AI Governance Solutions appeared first on SecurityWeek.
Microsoft dives into the tactics, techniques, and procedures of North Korean threat actor Moonstone Sleet.
The post New North Korean Threat Actor Engaging in Espionage, Revenue Generation Attacks appeared first on SecurityWeek.
Disruptive digital attacks – many traced to Russia-backed groups – have doubled in the European Union in 2024 and are also targeting election-related services, according to the EU’s top cybersecurity official.
The post Europe’s Cybersecurity Chief Says Disruptive Attacks Have Doubled in 2024, Sees Russia Behind Many appeared first on SecurityWeek.
The two primary components to the solution are to encrypt company data at all times, and to decrypt only when the file is required for use.
The post New Endpoint Protection Platform by Cigent Blocks Ransomware at the Data Level appeared first on SecurityWeek.
First American will notify 44,000 individuals that their personal information was stolen in a December 2023 ransomware attack.
The post Personal Information of 44,000 Compromised in First American Cyberattack appeared first on SecurityWeek.
Netflix has paid out more than $1 million for vulnerabilities found in its products since the launch of its bug bounty program in 2016.
The post Netflix Paid Out Over $1 Million via Bug Bounty Program appeared first on SecurityWeek.
While reintegration of formerly incarcerated people into the workforce is important, the government should be cautious about what positions those with a criminal history are put into.
The post Congresswomen Advocate for Cybersecurity Jobs for Formerly Incarcerated appeared first on SecurityWeek.
OpenAI is setting up a new safety and security committee and has begun training a new artificial intelligence model to supplant the GPT-4 system that underpins its ChatGPT chatbot.
The post OpenAI Forms Safety Committee as It Starts Training Latest Artificial Intelligence Model appeared first on SecurityWeek.
ABN Amro discloses data breach after third-party services provider AddComm suffers a ransomware attack.
The post ABN Amro Client Data Possibly Stolen in AddComm Ransomware Attack appeared first on SecurityWeek.
A look int the traditional pillars of security community culture and how they are being weakened and compromised, and even peek at where this all could go in a world of deepfakes and AI-fueled bias and hallucination.
The post Social Distortion: The Threat of Fear, Uncertainty and Deception in Creating Security Risk appeared first on SecurityWeek.
Auction house Christie’s has confirmed suffering a data breach following a ransomware attack launched earlier this month.
The post Christie’s Confirms Data Breach After Ransomware Group Claims Attack appeared first on SecurityWeek.
Private equity company Hg has acquired audit, compliance and risk management firm AuditBoard for over $3 billion.
The post Private Equity Firm Hg Acquires AuditBoard for $3 Billion appeared first on SecurityWeek.
A threat actor is asking $50,000 for data allegedly stolen from Australian digital prescription services provider MediSecure.
The post Data Stolen From MediSecure for Sale on Dark Web appeared first on SecurityWeek.
Pharmacy prescription services provider Sav-Rx says the personal information of 2.8 million was stolen in a cyberattack.
The post 2.8 Million Impacted by Data Breach at Prescription Services Firm Sav-Rx appeared first on SecurityWeek.
Check Point is warning customers that threat actors are targeting insecure VPN instances for initial access to enterprise networks.
The post Check Point VPN Targeted for Initial Access in Enterprise Attacks appeared first on SecurityWeek.
Only one of seven bills aimed at preventing AI’s penchant to discriminate when making consequential decisions — including who gets hired, money for a home or medical care — has passed.
The post Attempts to Regulate AI’s Hidden Hand in Americans’ Lives Flounder in US Statehouses appeared first on SecurityWeek.
Backdoored JAVS courtroom recording and management software installer puts thousands at risk of complete takeover.
The post JAVS Courtroom Audio-Visual Software Installer Serves Backdoor appeared first on SecurityWeek.
Averson secures seed funding to build technology that uses AI to identify cloud security weaknesses and counter cyberattacks.
The post Averlon Emerges From Stealth Mode With $8 Million in Funding appeared first on SecurityWeek.
Noteworthy stories that might have slipped under the radar: Chinese repair ships might be spying on undersea communications, spyware found at hotel check-ins, UK not ready for China threat.
The post In Other News: China’s Undersea Spying, Hotel Spyware, Iran’s Disruptive Attacks appeared first on SecurityWeek.
Exploited in the wild, Chrome vulnerability CVE-2024-5274 is a high-severity flaw described as a type confusion in the V8 JavaScript and WebAssembly engine.
The post Google Patches Fourth Chrome Zero-Day in Two Weeks appeared first on SecurityWeek.
U.S. intelligence agencies are scrambling to embrace the AI revolution, believing they’ll be smothered by exponential data growth as sensor-generated surveillance tech further blankets the planet.
The post US Intelligence Agencies’ Embrace of Generative AI Is at Once Wary and Urgent appeared first on SecurityWeek.
MITRE has shared information on how China-linked hackers abused VMware for persistence and detection evasion in the recent hack.
The post VMware Abused in Recent MITRE Hack for Persistence, Evasion appeared first on SecurityWeek.
Bolster has raised $14 million in Series B funding for technology integrations for its AI-powered phishing protection platform.
The post Bolster Raises $14 Million for AI-Powered Phishing Protection appeared first on SecurityWeek.
The Association of California School Administrators (ACSA) is informing nearly 55,000 individuals that they have been impacted by a ransomware attack.
The post 55,000 Impacted by Cyberattack on California School Association appeared first on SecurityWeek.
Under the new U.S. Cyber Trust Mark Initiative, manufacturers can affix the label on their products if they meet federal cybersecurity standards.
The post Cybersecurity Labeling for Smart Devices Aims to Help People Choose Items Less Likely to be Hacked appeared first on SecurityWeek.
Attackers are getting more sophisticated, better armed, and faster. Nothing in Rapid7's 2024 Attack Intelligence Report suggests that this will change.
The post Zero-Day Attacks and Supply Chain Compromises Surge, MFA Remains Underutilized: Rapid7 Report appeared first on SecurityWeek.
It will be interesting to see how AI continues to evolve and how it is used by defenders as they attempt to leapfrog attackers and protect the organization against new forms of AI attacks.
The post Why We Need to Get a Handle on AI appeared first on SecurityWeek.
Unfading Sea Haze has been targeting military and government entities in South China Sea countries since 2018.
The post Newly Detected Chinese Group Targeting Military, Government Entities appeared first on SecurityWeek.
The personal information of 400,000 individuals was compromised in a data breach at El Centro Del Barrio (CentroMed).
The post 400,000 Impacted by CentroMed Data Breach appeared first on SecurityWeek.
Intercontinental Exchange, the company that operates NYSE and other exchanges, has agreed to pay a $10 million fine related to a 2021 hack.
The post NYSE Operator Intercontinental Exchange Gets $10M SEC Fine Over 2021 Hack appeared first on SecurityWeek.
Mastercard is integrating AI into its fraud-prediction technology that it expects will be able to see patterns in stolen cards faster and allow banks to replace them before they are used by criminals.
The post Using AI, Mastercard Expects to Find Compromised Cards Quicker, Before They Get Used by Criminals appeared first on SecurityWeek.
Delaware startup secures a $25 million Series B funding round from PeakSpan Capital and Oxx. SOCRadar has raised to $30.2 million to date.
The post SOCRadar Raises $25M Series B for Threat Intel Tech appeared first on SecurityWeek.
ARPA-H has announced a $50 million investment in tools to help IT teams better secure hospital environments.
The post US to Invest $50 Million in Securing Hospitals Against Cyber Threats appeared first on SecurityWeek.
Rockwell Automation is concerned about internet-exposed ICS due to heightened geopolitical tensions and adversarial cyber activity globally.
The post Rockwell Automation Urges Customers to Disconnect ICS From Internet appeared first on SecurityWeek.
Veeam Backup Enterprise Manager update resolves multiple vulnerabilities, including a critical authentication bypass.
The post Critical Veeam Vulnerability Leads to Authentication Bypass appeared first on SecurityWeek.
Critical vulnerability in GitHub Enterprise Server allows unauthenticated attackers to obtain administrative privileges.
The post Critical Authentication Bypass Resolved in GitHub Enterprise Server appeared first on SecurityWeek.
Ivanti has released product updates to resolve multiple vulnerabilities, including critical code execution flaws in Endpoint Manager.
The post Ivanti Patches Critical Code Execution Vulnerabilities in Endpoint Manager appeared first on SecurityWeek.
SecurityWeek’s Threat Detection and Incident Response (TDIR) Summit takes place on Wednesday, May 22nd as a fully immersive virtual summit.
The post Virtual Event Today: Threat Detection and Incident Response (TDIR) Summit appeared first on SecurityWeek.
Claroty shows how Honeywell ControlEdge Virtual UOC vulnerability can be exploited for unauthenticated remote code execution.
The post Critical Vulnerability in Honeywell Virtual Controller Allows Remote Code Execution appeared first on SecurityWeek.
Google released a Chrome 125 update to resolve four high-severity vulnerabilities reported by external researchers.
The post Chrome 125 Update Patches High-Severity Vulnerabilities appeared first on SecurityWeek.
As chatbots become more adventurous, the dangers will increase.
The post Beware – Your Customer Chatbot is Almost Certainly Insecure: Report appeared first on SecurityWeek.
Leading artificial intelligence companies made pledge to develop AI safely, while world leaders agreed to build a network of publicly backed safety institutes to advance research and testing of the technology.
The post AI Companies Make Fresh Safety Promise at Seoul Summit, Nations Agree to Align Work on Risks appeared first on SecurityWeek.
QNAP rolls out patches for multiple vulnerabilities after proof-of-concept exploit published for a remote code execution vulnerability.
The post QNAP Rushes Patch for Code Execution Flaw in NAS Devices appeared first on SecurityWeek.
Zoom is announcing post-quantum end-to-end encryption on Meetings, with Phone and Rooms coming soon.
The post Zoom Adding Post-Quantum End-to-End Encryption to Products appeared first on SecurityWeek.
CIA Director William Burns says AI tech will augment humans, not replace them. The agency’s first chief technology officer, Nand Mulchandani, is marshaling the tools.
The post Insider Q&A: CIA’s Chief Technologist’s Cautious Embrace of Generative AI appeared first on SecurityWeek.
CISA has added CVE-2023-43208, an unauthenticated remote code execution vulnerability, to its KEV catalog.
The post CISA Warns of Attacks Exploiting NextGen Healthcare Mirth Connect Flaw appeared first on SecurityWeek.
The EPA has issued an enforcement alert, outlining the steps needed to comply with the Safe Drinking Water Act.
The post EPA Issues Alert After Finding Critical Vulnerabilities in Drinking Water Systems appeared first on SecurityWeek.
Semiconductor giant OmniVision Technologies says personal information was stolen in a September 2023 ransomware attack.
The post OmniVision Says Personal Information Stolen in Ransomware Attack appeared first on SecurityWeek.
Google is invoking the 'monoculture' word in response to a scathing U.S. government report on Microsoft's inadequate cybersecurity practices.
The post Google Cites ‘Monoculture’ Risks in Response to CSRB Report on Microsoft appeared first on SecurityWeek.
Linguistic Lumberjack (CVE-2024-4323) is a critical vulnerability in the Fluent Bit logging utility that can allow DoS, information disclosure and possibly RCE.
The post Vulnerability Found in Fluent Bit Utility Used by Major Cloud, Tech Companies appeared first on SecurityWeek.
CyberArk agreed to acquire machine identity management Venafi from Thoma Bravo for $1.54 billion.
The post CyberArk to Acquire Machine Identity Firm Venafi for $1.54 Billion appeared first on SecurityWeek.
CISA executive assistant director for cybersecurity Eric Goldstein is leaving the agency after more than three years.
The post Eric Goldstein Leaving CISA for Private Sector Role appeared first on SecurityWeek.
Health insurance firm WebTPA says the personal information of 2.4 million individuals was compromised in a data breach.
The post 2.4 Million Impacted by WebTPA Data Breach appeared first on SecurityWeek.
Roundup of the cybersecurity-related merger and acquisition (M&A) deals announced in the first half of May 2024.
The post Cybersecurity M&A Roundup for First Half of May 2024 appeared first on SecurityWeek.
These strategies can help cybersecurity startups navigate the current market dynamics, focusing on modern buyer behavior, updated KPIs, brand awareness, and effective sales and marketing alignment.
The post Start-Ups: 10 Tips for Navigating the Headwinds Against High-Growth appeared first on SecurityWeek.
MediSecure says data related to prescriptions distributed until November 2023 was compromised in a ransomware attack.
The post MediSecure Data Breach Impacts Patient and Healthcare Provider Information appeared first on SecurityWeek.
The American Radio Relay League (ARRL) has been targeted in a cyberattack that resulted in disruption and possibly a data breach.
The post American Radio Relay League Hit by Cyberattack appeared first on SecurityWeek.
Jan Leike, who ran OpenAI’s “Super Alignment” team, believes there should be more focus on preparing for the next generation of AI models, including on things like safety.
The post A Former OpenAI Leader Says Safety Has ‘Taken a Backseat to Shiny Products’ at the AI Company appeared first on SecurityWeek.
Slack reveals it has been training AI/ML models on customer data, including messages, files and usage information. It's opt-in by default.
The post User Outcry as Slack Scrapes Customer Data for AI Model Training appeared first on SecurityWeek.
Noteworthy stories that might have slipped under the radar: FBI is targeting Scattered Spider, Australia’s MediSecure hacked, new Wi-Fi attack.
The post In Other News: MediSecure Hack, Scattered Spider Targeted by FBI, New Wi-Fi Attack appeared first on SecurityWeek.
CISA has added two vulnerabilities in discontinued D-Link products to its KEV catalog, including a decade-old flaw.
The post CISA Warns of Exploited Vulnerabilities in EOL D-Link Products appeared first on SecurityWeek.
A critical vulnerability tracked as CVE-2024-34359 and dubbed Llama Drama can allow hackers to target AI product developers.
The post Critical Flaw in AI Python Package Can Lead to System and Data Compromise appeared first on SecurityWeek.
The Antidot Android banking trojan snoops on users and steals their credentials, contacts, and SMS messages.
The post New ‘Antidot’ Android Trojan Allows Cybercriminals to Hack Devices, Steal Data appeared first on SecurityWeek.
The Black Basta group abuses remote connection tool Quick Assist in vishing attacks leading to ransomware deployment.
The post Microsoft Quick Assist Tool Abused for Ransomware Delivery appeared first on SecurityWeek.
The US government has announced charges, seizures, arrests and rewards as part of an effort to disrupt a scheme that generates revenue for North Korea.
The post Woman Accused of Helping North Korean IT Workers Infiltrate Hundreds of US Firms appeared first on SecurityWeek.
C/side has emerged from stealth mode with $1.7 million in pre-seed funding from Scribble Ventures and angel investors
The post C/side Emerges From Stealth Mode With $1.7 Million Investment appeared first on SecurityWeek.
Network infrastructure as-a-service Alkira has raised $100 million in a Series C funding round led by Tiger Global Management.
The post Alkira Raises $100 Million for Secure Network Infrastructure Platform appeared first on SecurityWeek.
Google has announced patches for another Chrome vulnerability that has been exploited in attacks. This is the second zero-day addressed by the company in one week and the third flaw leveraged in malicious attacks in 2024. The new zero-day, tracked as CVE-2024-4761, has been described as a high-severity out-of-bounds write issue in the V8 JavaScript […]
The post Google Patches Second Chrome Zero-Day in One Week appeared first on SecurityWeek.
The City of Helsinki says usernames, email addresses, and personal information was stolen in a recent cyberattack.
The post Student, Personnel Information Stolen in City of Helsinki Cyberattack appeared first on SecurityWeek.
MITRE announced the public availability of the EMB3D threat model for embedded devices used in critical infrastructure.
The post MITRE EMB3D Threat Model Officially Released appeared first on SecurityWeek.
The FCC has issued a public notice on robocall scammer group ‘Royal Tiger’, the first designated threat actor.
The post FCC Warns of ‘Royal Tiger’ Robocall Scammers appeared first on SecurityWeek.
Zscaler has completed its investigation into the recent hacking claims and found that only an isolated test environment was compromised.
The post Zscaler Confirms Only Isolated Test Server Was Hacked appeared first on SecurityWeek.
Apple documents another zero-day flaw being exploited on older iPhones and documents security problems in macOS, iOS and iPadOS.
The post Apple Patch Day: Code Execution Flaws in iPhones, iPads, macOS appeared first on SecurityWeek.
China’s official Xinhua news agency said the two sides would take up issues including the technological risks of AI and global governance.
The post China and US Envoys Will Hold First Top-Level Dialogue on Artificial Intelligence appeared first on SecurityWeek.
Europol is investigating a data breach, but says no core systems are impacted and no operational data has been compromised.
The post Europol Investigating Breach After Hacker Offers to Sell Classified Data appeared first on SecurityWeek.
Weakening liberal democracies and weakening the NATO alliance are conjoined in the hybrid war that Russia is conducting against Ukraine.
The post NATO Draws a Cyber Red Line in Tensions With Russia appeared first on SecurityWeek.
A critical vulnerability in the Cinterion cellular modems can be exploited for remote code execution via SMS messages.
The post Cinterion Modem Flaws Pose Risk to Millions of Devices in Industrial, Other Sectors appeared first on SecurityWeek.
One of the largest healthcare systems in the United States is scrambling to contain a hack that's causing disruption and “downtime procedures” at hospitals around the country.
The post Healthcare Giant Ascension Hacked, Hospitals Diverting Emergency Service appeared first on SecurityWeek.
Noteworthy stories that might have slipped under the radar: European Parliament application breached, DocGo hacked, VMware advisories moved to Broadcom portal.
The post In Other News: European Parliament Breach, DocGo Hack, VMware Advisories Moved appeared first on SecurityWeek.
A Chrome 124 update patches the second Chrome zero-day that has been found to be exploited in malicious attacks in 2024.
The post Exploited Chrome Zero-Day Patched by Google appeared first on SecurityWeek.
The Ohio Lottery cyberattack conducted by the DragonForce ransomware group has impacted more than 500,000 individuals.
The post 500,000 Impacted by Ohio Lottery Ransomware Attack appeared first on SecurityWeek.
Hundreds of companies are showcasing their products and services this week at the 2024 edition of the RSA Conference in San Francisco.
The post RSA Conference 2024 – Announcements Summary (Day 4) appeared first on SecurityWeek.
Accenture Federal Services wins $789 million U.S. Navy SHARKCAGE cybersecurity contract.
The post Accenture Lands $789 Million Contract to Bolster U.S. Navy Cybersecurity appeared first on SecurityWeek.
Tech giant notifies millions of customers that full names and physical mailing addresses were stolen during a security incident.
The post Dell Says Customer Names, Addresses Stolen in Database Breach appeared first on SecurityWeek.
When not scamming other criminals, criminals are concentrating on the use of mainstream AI products rather than developing their own AI systems.
The post Criminal Use of AI Growing, But Lags Behind Defenders appeared first on SecurityWeek.
The LockBit cybercrime group has taken credit for the recent ransomware attack that disrupted City of Wichita systems.
The post LockBit Takes Credit for City of Wichita Ransomware Attack appeared first on SecurityWeek.
CISA’s Vulnrichment project is adding important information to CVE records to help improve vulnerability management processes.
The post CISA Announces CVE Enrichment Project ‘Vulnrichment’ appeared first on SecurityWeek.
BetterHelp customers have started receiving refund notices from a $7.8 million data privacy settlement, the FTC says.
The post BetterHelp Customers Begin Receiving Refund Notices From $7.8M Data Privacy Settlement, FTC Says appeared first on SecurityWeek.
F5 has patched two potentially serious vulnerabilities in BIG-IP Next that could allow an attacker to take full control of a device.
The post F5 Patches Dangerous Vulnerabilities in BIG-IP Next Central Manager appeared first on SecurityWeek.
Hundreds of companies are showcasing their products and services this week at the 2024 edition of the RSA Conference in San Francisco.
The post RSA Conference 2024 – Announcements Summary (Day 3) appeared first on SecurityWeek.
Zscaler says its customer, production and corporate environments are not impacted after a notorious hacker offers to sell access.
The post Zscaler Investigates Hacking Claims After Data Offered for Sale appeared first on SecurityWeek.
Tel Aviv-based firm emerged from stealth with $7 million seed funding led by TLV Partners with participation from SNR and angel investors.
The post Token Security Raises $7 Million Seed Funding for Machine-First Identity Security appeared first on SecurityWeek.
Organizations need to look beyond preventive measures when it comes to dealing with today’s ransomware threats and invest in ransomware response.
The post Shields Up: How to Minimize Ransomware Exposure appeared first on SecurityWeek.
A new VPN bypass technique allows threat actors to snoop on victims’ traffic by forcing it off the VPN tunnel using built-in features of DHCP.
The post New ‘TunnelVision’ Technique Leaks Traffic From Any VPN System appeared first on SecurityWeek.
The UK Ministry of Defense said a breach at a third-party payroll system exposed as many as 272,000 armed forces personnel and veterans.
The post The UK Says a Huge Payroll Data Breach by a ‘Malign Actor’ Has Exposed Details of Military Personnel appeared first on SecurityWeek.
Charges and sanctions announced against Dimitry Yuryevich Khoroshev, the alleged developer and operator of LockBit ransomware.
The post LockBit Ransomware Mastermind Unmasked, Charged appeared first on SecurityWeek.
ICS and OT security startup TXOne Networks secures $51 million in a Series B extension and adds new investors from Taiwan.
The post TXOne Networks Scores $51M Series B Extension appeared first on SecurityWeek.
Niobium has raised $5.5 million in seed funding for a fully homomorphic encryption (FHE) hardware accelerator designed for zero trust computing.
The post Niobium Raises $5.5M for Zero Trust Computing Hardware Acceleration appeared first on SecurityWeek.
Cloud security giant Wiz has raised $1 billion, which brings the total funding to $1.9 billion, at a valuation of $12 billion.
The post Wiz Raises $1 Billion at $12 Billion Valuation appeared first on SecurityWeek.
Akamai has announced plans to acquire Noname Security to enhance its API protection offering.
The post Akamai to Acquire API Protection Startup Noname Security for $450 Million appeared first on SecurityWeek.
Hundreds of companies are showcasing their products and services this week at the 2024 edition of the RSA Conference in San Francisco.
The post RSA Conference 2024 – Announcements Summary (Day 1) appeared first on SecurityWeek.
LevelBlue, a new WillJam Ventures and AT&T joint venture, provides various managed cybersecurity services.
The post AT&T Launches New Managed Cybersecurity Services Business LevelBlue appeared first on SecurityWeek.
As cyber threats grow more sophisticated, America cannot afford complacency. The time for decisive action and enhanced cyber resilience is now.
The post From Warnings to Action: Preparing America’s Infrastructure for Imminent Cyber Threats appeared first on SecurityWeek.
The US calls for international engagement towards building an open, inclusive, resilient, safe, and equitable digital space.
The post US Releases International Cyberspace Strategy appeared first on SecurityWeek.
MITRE has shared more details on the recent hack, including the new malware involved in the attack and a timeline of the attacker’s activities.
The post MITRE Hack: China-Linked Group Breached Systems in December 2023 appeared first on SecurityWeek.
Google rolls out new threat-intel and security operations products and looks to the magic of AI to tap into the booming cybersecurity market.
The post Google Debuts New Security Products, Hyping AI and Mandiant Expertise appeared first on SecurityWeek.
Synopsys is selling its Software Integrity Group to private equity firms Clearlake Capital and Francisco Partners in a $2.1 billion deal.
The post Synopsys Sells Software Integrity Business in $2.1 Billion Deal appeared first on SecurityWeek.
Iranian state-sponsored group APT42 is targeting NGOs, government, and intergovernmental organizations with two new backdoors.
The post Iranian Cyberspies Hit Targets With New Backdoors appeared first on SecurityWeek.
CyberNut has emerged from stealth mode with a K-12-focused security awareness training solution and $800k in pre-seed funding.
The post CyberNut Emerges From Stealth With K-12 Security Awareness Training Solution appeared first on SecurityWeek.
Identity management startup Anetac has emerged from stealth mode with a $16 million investment led by Liberty Global.
The post Anetac Emerges From Stealth Mode With $16 Million in Funding appeared first on SecurityWeek.
United States Cyber Command (USCYBERCOM) has named Ms. Morgan M. Adamski as Executive Director effective June 2024.
The post US Cyber Command Appoints Morgan Adamski as Executive Director appeared first on SecurityWeek.
Thirty-three cybersecurity-related merger and acquisition (M&A) deals were announced in April 2024.
The post Cybersecurity M&A Roundup: 33 Deals Announced in April 2024 appeared first on SecurityWeek.
The City of Wichita, Kansas, has shut down its network after falling victim to a file-encrypting ransomware attack.
The post City of Wichita Shuts Down Network Following Ransomware Attack appeared first on SecurityWeek.
Permira has agreed to acquire a majority of BioCatch shares, primarily from Bain Capital Tech Opportunities and Maverick Ventures.
The post Permira to Acquire Majority Stake in BioCatch at $1.3 Billion Valuation appeared first on SecurityWeek.
Vincent Strubel, who heads France’s national cybersecurity agency, called the cyberthreats level facing the Olympic Games unprecedented.
The post French Cyberwarriors Ready to Test Their Defense Against Hackers and Malware During the Olympics appeared first on SecurityWeek.
Germany accused Russian military agents of hacking the top echelons of Chancellor Olaf Scholz’s party and other government and industrial targets.
The post German Foreign Minister Says Russia will Face Consequences for Monthslong Cyber Espionage appeared first on SecurityWeek.
Microsoft security chief Charlie Bell pledges significant reforms and a strategic shift to prioritize security above all other product features.
The post Microsoft Overhauls Cybersecurity Strategy After Scathing CSRB Report appeared first on SecurityWeek.
Israeli startup LayerX Security banks $25 million in new financing as investors continue to pour money into secure web browsing technologies.
The post LayerX Raises $26 Million for Browser Security Platform appeared first on SecurityWeek.
The US government warns of a North Korean threat actor abusing weak email DMARC settings to hide spear-phishing attacks.
The post US Says North Korean Hackers Exploiting Weak DMARC Settings appeared first on SecurityWeek.
Noteworthy stories that might have slipped under the radar: 4,000 take part in Locked Shields 2024 exercise, Qantas and JP Morgan hit by data exposure bugs, NVIDIA patches critical flaw.
The post In Other News: Locked Shields 2024, Data Exposure Bugs, NVIDIA Patches appeared first on SecurityWeek.
A botnet dismantled in January and used by Russia-linked APT28 consisted of more than just Ubiquiti Edge OS routers.
The post Botnet Disrupted by FBI Still Used by Russian Spies, Cybercriminals appeared first on SecurityWeek.
CISA and the FBI warn of threat actors abusing path traversal software vulnerabilities in attacks targeting critical infrastructure.
The post CISA, FBI Urge Organizations to Eliminate Path Traversal Vulnerabilities appeared first on SecurityWeek.
An analysis of IoCs suggests that a Chinese threat group may be behind the recent ArcaneDoor espionage campaign targeting Cisco firewalls.
The post ArcaneDoor Espionage Campaign Targeting Cisco Firewalls Linked to China appeared first on SecurityWeek.
SaaS-based, AI-assisted penetration service allows proactive defensive action against exploitation of new vulnerabilities.
The post Horizon3.ai Introduces AI-Assisted Service to Prioritize and Patch Vulnerabilities Faster appeared first on SecurityWeek.
Microsoft has uncovered a new type of attack called Dirty Stream that impacted Android apps with billions of installations.
The post Microsoft Warns of ‘Dirty Stream’ Vulnerability in Popular Android Apps appeared first on SecurityWeek.
The White House has published a national security memorandum focusing on critical infrastructure security and resilience.
The post White House Issues National Security Memorandum for Critical Infrastructure appeared first on SecurityWeek.
A new Silicon Valley startup called Mimic is coming out of the shadows with a hefty $27 million seed-stage funding round led by Ballistic Ventures.
The post Ransomware Defense Startup Mimic Raises Hefty $27M Seed Round appeared first on SecurityWeek.
As you look to navigate RSA Conference, with so many vendors, approaches and solutions, how do you know what solutions you should be investing in?
The post Building the Right Vendor Ecosystem – a Guide to Making the Most of RSA Conference appeared first on SecurityWeek.
Israeli AI security firm Apex has received $7 million in seed funding for its detection, investigation, and response platform.
The post AI Security Startup Apex Emerges From Stealth With Funding From OpenAI CEO appeared first on SecurityWeek.
Cybersecurity startups Insane Cyber, Resonance Security, RunReveal and StepSecurity announce pre-seed, early-stage, and seed funding rounds.
The post Startup Dealflow: New Investments at Resonance, RunReveal, StepSecurity, Insane Cyber appeared first on SecurityWeek.
Network detection and response (NDR) provider Corelight has raised $150 million in a Series D funding round led by Accel.
The post Network Security Firm Corelight Raises $150 Million appeared first on SecurityWeek.
Verizon’s 2024 DBIR shows that vulnerability exploitation increased three times and confirmed data breaches doubled compared to the previous year.
The post Verizon DBIR 2024 Shows Surge in Vulnerability Exploitation, Confirmed Data Breaches appeared first on SecurityWeek.
Japan's Prime Minister unveiled an international framework for regulation and use of generative AI, adding to global efforts on governance for the rapidly advancing technology.
The post Japan’s Kishida Unveils a Framework for Global Regulation of Generative AI appeared first on SecurityWeek.
CISA says a critical GitLab password reset flaw is being exploited in attacks and roughly 1,400 servers have not been patched.
The post 1,400 GitLab Servers Impacted by Exploited Vulnerability appeared first on SecurityWeek.
Government agencies are sharing recommendations following attacks claimed by pro-Russian hacktivists on ICS/OT systems.
The post Russian Hackers Target Industrial Systems in North America, Europe appeared first on SecurityWeek.
Dropbox says hackers breached its Sign production environment and accessed customer email addresses and hashed passwords.
The post Hackers Compromised Dropbox eSignature Service appeared first on SecurityWeek.
UnitedHealth CEO Andrew Witty said in a U.S. Senate hearing that his company is still trying to understand why the server did not have the additional protection.
The post Change Healthcare Cyberattack Was Due to a Lack of Multifactor Authentication, UnitedHealth CEO says appeared first on SecurityWeek.
Everyone — not just politicians and celebrities — should be concerned about this increasingly powerful deep-fake technology, experts say.
The post Deepfake of Principal’s Voice Is the Latest Case of AI Being Used for Harm appeared first on SecurityWeek.
New York startup Oasis Security banks $35 million in a Series A extension round led by Accel, Cyberstarts, and Sequoia Capital.
The post Oasis Security Raises $35 Million to Tackle Non-Human Identity Management appeared first on SecurityWeek.
Traceable AI has raised $110 million since launching in 2018 with ambitious plans in the competitive API security and observability space.
The post Traceable AI Raises $30 Million to Safeguard Cloud APIs appeared first on SecurityWeek.
Researchers can earn as much as $450,000 for a single vulnerability report as Google boosts its mobile vulnerability rewards program.
The post Google Boosts Bug Bounty Payouts Tenfold in Mobile App Security Push appeared first on SecurityWeek.
Adobe is providing incentives for bug bounty hackers to report security flaws in its implementation of Content Credentials and Adobe Firefly.
The post Adobe Adds Content Credentials and Firefly to Bug Bounty Program appeared first on SecurityWeek.
Cuttlefish malware platform roaming around enterprise SOHO routers capable of covertly harvesting public cloud authentication data from internet traffic.
The post Cuttlefish Malware Targets Routers, Harvests Cloud Authentication Data appeared first on SecurityWeek.
Venafi introduced a 90-Day TLS Readiness solution to help enterprises prepare for Google’s proposed 90-day limit for the lifecycle of a digital certificate.
The post Machine Identity Firm Venafi Readies for the 90-day Certificate Lifecycle appeared first on SecurityWeek.
AI-Native Trust, Risk, and Security Management (TRiSM) startup DeepKeep raises $10 million in seed funding.
The post DeepKeep Launches AI-Native Security Platform With $10 Million in Seed Funding appeared first on SecurityWeek.
SecurityWeek interviews Geoff Belknap, CISO at LinkedIn, and Guy Rosen, CISO at Facebook parent company Meta.
The post CISO Conversations: LinkedIn’s Geoff Belknap and Meta’s Guy Rosen appeared first on SecurityWeek.
UnitedHealth Group’s CEO Andrew Witty shares details on the damaging cyberattack in testimony before a US Congress committee set for May 1, 2024.
The post UnitedHealth CEO Says Hackers Lurked in Network for Nine Days Before Ransomware Strike appeared first on SecurityWeek.
In February 2023, French police arrested well-known Finnish hacker Aleksanteri Kivimäki, who was living under a false identity near Paris. He was deported to Finland. His trial ended last month.
The post Finnish Hacker Gets Prison for Accessing Thousands of Psychotherapy Records and Demanding Ransoms appeared first on SecurityWeek.
JFrog raises an alarm after finding three large-scale malware campaigns targeting Docker Hub with imageless repositories.
The post Docker Hub Users Targeted With Imageless, Malicious Repositories appeared first on SecurityWeek.
Three vulnerabilities in the Judge0 open source service could allow attackers to escape the sandbox and obtain root privileges on the host.
The post Critical Vulnerabilities in Judge0 Lead to Sandbox Escape, Host Takeover appeared first on SecurityWeek.
Mainsail Partners leads a $15 million financing round for end-to-end cybersecurity compliance platform company Apptega.
The post Apptega Raises $15 Million for Cybersecurity Compliance Platform appeared first on SecurityWeek.
Despite competitive pressures from industry behemoths like Microsoft and Google, investors are still betting big on startups in the specialized enterprise browser space.
The post Island Secures $175M Investment as Enterprise Browser Startups Defy Tech Giants appeared first on SecurityWeek.
While China-linked Muddling Meerkat’s operations look like DNS DDoS attacks, it seems unlikely that denial of service is their goal, at least in the near term.
The post Chinese Hackers Have Been Probing DNS Networks Globally for Years: Report appeared first on SecurityWeek.
The Federal Communications Commission leveraged nearly $200 million in fines against wireless carriers AT&T, Sprint, T-Mobile and Verizon for illegally sharing customers’ location data.
The post FCC Fines Wireless Carriers for Sharing User Locations Without Consent appeared first on SecurityWeek.
SafeBase has raised north of $50 million since launching in 2020 with plans to simplify vendor risk assessment disclosures.
The post SafeBase Scores $33M Series B Investment appeared first on SecurityWeek.
A vulnerability (CVE-2024-27322) in the R programming language implementation can be exploited to execute arbitrary and be used as part of a supply chain attack.
The post Vulnerability in R Programming Language Could Fuel Supply Chain Attacks appeared first on SecurityWeek.
CEOs of major tech companies are joining a new artificial intelligence safety board to advise the federal government on how to protect the nation’s critical services from “AI-related disruptions.”
The post Tech CEOs Altman, Nadella, Pichai and Others Join Government AI Safety Board Led by DHS’ Mayorkas appeared first on SecurityWeek.
New CISA guidelines categorize AI risks into three significant types and pushes a four-part mitigation strategy.
The post CISA Rolls Out New Guidelines to Mitigate AI Risks to US Critical Infrastructure appeared first on SecurityWeek.
History of TikTok and how it many view it as a national security threat.
The post How TikTok Grew From a Fun App for Teens Into a Potential National Security Threat appeared first on SecurityWeek.
In 2023, Google said it blocked 2.28 million bad applications from being published on Google Play and banned 333,000 developer accounts.
The post Google Says it Blocked 2.28 Million Apps from Google Play Store appeared first on SecurityWeek.
The majority opinion is that a cybersecurity professional body is long overdue and would benefit cybersecurity and cybersecurity practitioners.
The post Should Cybersecurity Leadership Finally be Professionalized? appeared first on SecurityWeek.
US healthcare giant is warning millions of current and former patients that their personal information was exposed to third-party advertisers.
The post Kaiser Permanente Data Breach Impacts 13.4 Million Patients appeared first on SecurityWeek.
Jennifer Leggio makes the case for more alcohol-free networking events at conferences, and community-building opportunities for sober individuals working in cybersecurity.
The post Beyond the Buzz: Rethinking Alcohol as a Cybersecurity Bonding Ritual appeared first on SecurityWeek.
An analysis conducted by Honeywell shows that much of the USB-borne malware targeting industrial organizations can still cause OT disruption.
The post Honeywell: USB Malware Attacks on Industrial Orgs Becoming More Sophisticated appeared first on SecurityWeek.
Okta warned of a spike in credential stuffing attacks using anonymizing services such as Tor, DataImpulse, Luminati, and NSocks.
The post Okta Warns of Credential Stuffing Attacks Using Tor, Residential Proxies appeared first on SecurityWeek.
Financial Business and Consumer Solutions (FBCS) says compromised information may include names, dates of birth, Social Security numbers, and account information.
The post Collection Agency FBCS Says Data Breach Exposed Nearly 2 million People appeared first on SecurityWeek.
A Belarusian hacker activist group claims to have infiltrated the network of the country’s main KGB security agency and accessed personnel files of over 8,600 employees.
The post Hackers Claim to Have Infiltrated Belarus’ Main Security Service appeared first on SecurityWeek.
A new Android trojan named Brokewell can steal user’s sensitive information and allows attackers to take over devices.
The post Powerful ‘Brokewell’ Android Trojan Allows Attackers to Takeover Devices appeared first on SecurityWeek.
More than 1,400 CrushFTP servers remain vulnerable to an actively exploited zero-day for which PoC has been published.
The post Over 1,400 CrushFTP Instances Vulnerable to Exploited Zero-Day appeared first on SecurityWeek.
More than 90,000 unique IPs are still infected with a PlugX worm variant that spreads via infected flash drives.
The post Self-Spreading PlugX USB Drive Malware Plagues Over 90k IP Addresses appeared first on SecurityWeek.
Noteworthy stories that might have slipped under the radar: Volkswagen hacked by Chinese threat group, DDoS service shut down, Rubrik IPO.
The post In Other News: China Hacked Volkswagen, DDoS Service Shutdown, Rubrik IPO appeared first on SecurityWeek.
UK cybersecurity firm Darktace has agreed to sell itself to private equity giant Thoma Bravo for approximately $5.32 million in cash.
The post Darktrace to be Taken Private in $5.3 Billion Sale to Thoma Bravo appeared first on SecurityWeek.
A vulnerability in the WordPress Automatic plugin is being exploited to inject backdoors and web shells into websites.
The post Critical WordPress Automatic Plugin Vulnerability Exploited to Inject Backdoors appeared first on SecurityWeek.
Predictive attack intelligence and risk protection startup BforeAI has raised $15 million in a Series A funding round led by SYN Ventures.
The post Predictive Security Startup BforeAI Raises $15 Million appeared first on SecurityWeek.
Palo Alto Networks has shared remediation instructions for organizations whose firewalls have been hacked via CVE-2024-3400.
The post Palo Alto Networks Shares Remediation Advice for Hacked Firewalls appeared first on SecurityWeek.
A new phishing campaign abuses compromised email accounts and targets corporate users with PDF files hosted on Autodesk Drive.
The post Autodesk Drive Abused in Phishing Attacks appeared first on SecurityWeek.
The FTC is sending a total of $5.6 million in refunds to over 117,000 Ring customers as result of a 2023 settlement.
The post FTC Sending $5.6 Million in Refunds to Ring Customers Over Security Failures appeared first on SecurityWeek.
Maryland startup scores $8.5 million in seed-stage funding to compete in the Identity Threat Detection and Response (ITDR) category.
The post AuthMind Scores $8.5M Seed Funding for ITDR Tech appeared first on SecurityWeek.
The US Department of Energy gives $39 million in funding for nine projects to advance the cybersecurity of distributed energy resources.
The post Distributed Energy Resources Get Cybersecurity Boost with $39M DOE Funding appeared first on SecurityWeek.
Boards often complain they receive overly-technical reports from management teams that fail to put governance in business and financial terms.
The post CISOs and Board Reporting – an Ongoing Problem appeared first on SecurityWeek.
CISA, FBI and NSA have published a cybersecurity report on deepfakes and recommendations for identifying and responding to such threats.
The post US Agencies Publish Cybersecurity Report on Deepfake Threats appeared first on SecurityWeek.
Cybercriminals are increasingly trying to find ways to get around security, detection, intelligence and controls as APTs start to merge with conventional cybercrime.
The post How Next-Gen Threats Are Taking a Page From APTs appeared first on SecurityWeek.
CISA details its plan to support the open source software ecosystem and secure the use of open source software within the federal government.
The post CISA Releases Open Source Software Security Roadmap appeared first on SecurityWeek.
China said it was following media reports about suspected security issues with iPhones but insisted there was no ban on its officials using the devices
The post China Says No Law Banning iPhone Use in Govt Agencies appeared first on SecurityWeek.
The MetaStealer macOS information stealer has been targeting businesses to exfiltrate keychain and other valuable information.
The post macOS Info-Stealer Malware ‘MetaStealer’ Targeting Businesses appeared first on SecurityWeek.
Airbus has launched an investigation after a hacker claimed to have breached the company’s systems and leaked some business documents.
The post Airbus Launches Investigation After Hacker Leaks Data appeared first on SecurityWeek.
Virtual conference will explore cybersecurity use-cases for AI technology and the race to protect LLM algorithms from adversarial use.
The post SecurityWeek to Host Cyber AI & Automation Summit appeared first on SecurityWeek.
CISA is offering a free vulnerability scanning service to water utilities to help them protect drinking water and wastewater systems against cyberattacks.
The post CISA Offering Free Vulnerability Scanning Service to Water Utilities appeared first on SecurityWeek.
SAP has released patches for a critical vulnerability impacting multiple enterprise applications, including NetWeaver and S/4HANA.
The post SAP Patches Critical Vulnerability Impacting NetWeaver, S/4HANA appeared first on SecurityWeek.
After Apple and Google, Mozilla has also patched an image processing-related zero-day vulnerability exploited by spyware.
The post After Apple and Google, Mozilla Also Patches Zero-Day Exploited for Spyware Delivery appeared first on SecurityWeek.
Microsoft’s struggles with zero-day exploits rolled into a new month with a fresh Patch Tuesday warning about malware attacks in the wild.
The post Zero Day Summer: Microsoft Warns of Fresh New Software Exploits appeared first on SecurityWeek.
Israeli security startup Zenity banks $16.5 million in new venture capital funding to work on ‘low-code/no-code’ security technology.
The post Intel Capital Bets on Zenity for Low-Code/No-Code Security appeared first on SecurityWeek.
Adobe raises an alarm for new in-the-wild zero-day attacks hitting users of its widely deployed Adobe Acrobat and Reader product.
The post Adobe Says Critical PDF Reader Zero-Day Being Exploited appeared first on SecurityWeek.
Despite GitHub’s efforts to prevent repository hijacking, researchers continue finding new attack methods, and thousands of code packages.
The post Thousands of Code Packages Vulnerable to Repojacking Attacks appeared first on SecurityWeek.
Vector embeddings – data stored in a vector database – can be used to minimize hallucinations from a GPT-style large language model AI system (such as ChatGPT) and perform automated triaging on anomaly alerts.
The post Vector Embeddings – Antidote to Psychotic LLMs and a Cure for Alert Fatigue? appeared first on SecurityWeek.
Iran-linked cyberespionage group Charming Kitten has infected at least 34 victims in Brazil, Israel, and UAE with a new backdoor.
The post Iranian Cyberspies Deployed New Backdoor to 34 Organizations appeared first on SecurityWeek.
ICS Patch Tuesday: Siemens has released 7 new advisories and Schneider Electric has released 1 new advisory.
The post ICS Patch Tuesday: Critical CodeMeter Vulnerability Impacts Several Siemens Products appeared first on SecurityWeek.
Symantec warns that the Redfly APT appears to be focusing exclusively on targeting critical national infrastructure organizations.
The post China-Linked ‘Redfly’ Group Targeted Power Grid appeared first on SecurityWeek.
The next time you see CNAPP, CASB, WAAS, CSPM or many of the other phrases, it will be helpful to take a deep breath and realize enterprise security has never been a binary one or zero.
The post Finding Your Way in Cloud Security appeared first on SecurityWeek.
Real-time online banking fraud prevention firm Cleafy has raised €10 million ($10.7 million) in a funding round led by United Ventures.
The post Cleafy Raises €10 Million for Online Banking Fraud Prevention Platform appeared first on SecurityWeek.
Portuguese hacker behind “Football Leaks” convicted by a Lisbon court of nine crimes and given a suspended prison sentence of four years.
The post Court Convicts Portuguese Hacker in Football Leaks Trial and Gives Him a 4-Year Suspended Sentence appeared first on SecurityWeek.
Google has released a Chrome 116 security update to patch CVE-2023-4863, the fourth Chrome zero-day vulnerability documented in 2023.
The post Google Patches Chrome Zero-Day Reported by Apple, Spyware Hunters appeared first on SecurityWeek.
MGM Resorts confirms "cybersecurity incident" led to the shutdown of web sites and IT systems of hotels throughout the United States.
The post MGM Resorts Confirms ‘Cybersecurity Issue’, Shuts Down Systems appeared first on SecurityWeek.
One organization is hoping to transform the anniversary of 9/11 into a day of doing good.
The post US Marks 22 Years Since 9/11 Terrorist Attacks appeared first on SecurityWeek.
Anonymous Sudan launches a DDoS attack against Telegram in retaliation for the suspension of their primary account on the platform.
The post After Microsoft and X, Hackers Launch DDoS Attack on Telegram appeared first on SecurityWeek.
The personal information of more than 800,000 individuals was stolen from bookstore chain Dymocks in a cyberattack last week.
The post Bookstore Chain Dymocks Discloses Data Breach Possibly Impacting 800k Customers appeared first on SecurityWeek.
Cybercriminals breached an AP Stylebook website and obtained information on customers who were then targeted in phishing attacks.
The post Associated Press Stylebook Users Targeted in Phishing Attack Following Data Breach appeared first on SecurityWeek.
FBI says North Korean hacking group Lazarus has stolen $41 million in cryptocurrency from online betting platform Stake.com.
The post FBI Blames North Korean Hackers for $41 Million Stake.com Heist appeared first on SecurityWeek.
Some of the ways China has worked to spy on the West in recent years.
The post Spies, Hackers, Informants: How China Snoops on the West appeared first on SecurityWeek.
A researcher has found 7 vulnerabilities in Socomec UPS products that can be exploited to hijack and disrupt devices.
The post Vulnerabilities Allow Hackers to Hijack, Disrupt Socomec UPS Devices appeared first on SecurityWeek.
One of Myanmar’s biggest and most powerful ethnic minority militias arrested and repatriated more than 1,200 Chinese nationals allegedly involved in criminal online scam operations.
The post Powerful Ethnic Militia in Myanmar Repatriates 1,200 Chinese Suspected of Involvement in Cybercrime appeared first on SecurityWeek.
Cisco is warning of a zero-day vulnerability in Cisco ASA and FTD that can be exploited remotely, without authentication, in brute force attacks.
The post Cisco ASA Zero-Day Exploited in Akira Ransomware Attacks appeared first on SecurityWeek.
Check Point has observed a wave of phishing attacks launched via Google Looker Studio to steal credentials and funds from intended victims.
The post New Phishing Campaign Launched via Google Looker Studio appeared first on SecurityWeek.
Noteworthy stories that might have slipped under the radar: LastPass vault hacking, Russia targets energy facility in Ukraine, NXP data breach.
The post In Other News: LastPass Vault Hacking, Russia Targets Ukraine Energy Facility, NXP Breach appeared first on SecurityWeek.
Emsisoft urges its users to update anti-malware and other security products after signing them with an improperly issued digital certificate.
The post Emsisoft Tells Users to Update Products, Reboot Systems Due to Certificate Mishap appeared first on SecurityWeek.
The US and UK have announced sanctions against 11 more alleged members of the Russian cybercrime group Trickbot.
The post US, UK Sanction More Members of Trickbot Russian Cybercrime Group appeared first on SecurityWeek.
APTs exploited vulnerabilities in Zoho ManageEngine and Fortinet VPNs to hack an aerospace organization in early January 2023.
The post US Aeronautical Organization Hacked via Zoho, Fortinet Vulnerabilities appeared first on SecurityWeek.
Apple pushes out an urgent point-update to its flagship iOS and macOS platforms to fix a pair of security defects being exploited in the wild.
The post Apple Patches Actively Exploited iOS, macOS Zero-Days appeared first on SecurityWeek.
Google again catches a North Korean APT actor targeting security researchers with zero-days and rigged software tools.
The post Rigged Software and Zero-Days: North Korean APT Caught Hacking Security Researchers appeared first on SecurityWeek.
Vladislav Klyushin was sentenced to nine years in prison for his role in a nearly $100M stock market cheating scheme that relied on information stolen by hacking.
The post Wealthy Russian With Kremlin Ties Gets 9 Years in Prison for Hacking and Insider Trading Scheme appeared first on SecurityWeek.
Team8, a VC organization with added sauce, queried more than 130 CISOs from its own ‘CISO Village’ to discover the concerns of existing cybersecurity practitioners, and the technologies they are seeking for the future.
The post The Team8 Foundry Method for Selecting Investable Startups appeared first on SecurityWeek.
See Tickets is informing 300,000 individuals that their payment card information was stolen in a new web skimmer attack.
The post See Tickets Alerts 300,000 Customers After Another Web Skimmer Attack appeared first on SecurityWeek.
CISA has released new guidance to help federal agencies decide upon and prioritize DDoS mitigations based on mission and reputational impact.
The post CISA Releases Guidance on Adopting DDoS Mitigations appeared first on SecurityWeek.
A malware named Atomic macOS Stealer (AMOS) has been delivered to users via a malvertising campaign.
The post ‘Atomic macOS Stealer’ Malware Delivered via Malvertising Campaign appeared first on SecurityWeek.
Cisco has released patches for CVE-2023-20238, a critical authentication bypass vulnerability in the BroadWorks Application Delivery Platform.
The post Cisco Patches Critical Vulnerability in BroadWorks Platform appeared first on SecurityWeek.
Tenable is set to acquire cloud security firm Ermetic for $240 million as it looks to expand the capabilities of its exposure management platform.
The post Tenable to Acquire Cloud Security Firm Ermetic for $240 Million appeared first on SecurityWeek.
Vulnerabilities identified in the OAS Platform could be exploited to bypass authentication, leak sensitive information, and overwrite files.
The post Cisco Finds 8 Vulnerabilities in OAS Industrial IoT Data Platform appeared first on SecurityWeek.
IBM has disclosed a data breach involving a Janssen healthcare platform that last year helped more than 1 million patients.
The post IBM Discloses Data Breach Impacting Janssen Healthcare Platform appeared first on SecurityWeek.
Microsoft reveals how a crash dump from 2021 inadvertently exposed a key that Chinese cyberspies later leveraged to hack US government emails.
The post Crash Dump Error: How a Chinese Espionage Group Exploited Microsoft’s Mistakes appeared first on SecurityWeek.
It appears to be the end of the road for IronNet, the once-promising network security play founded by former NSA director General Keith Alexander.
The post Cash-Strapped IronNet Faces Bankruptcy Options appeared first on SecurityWeek.
Upwind raises a total of $80 million in just 10 months as investors pour cash into startups in the cloud and data security categories.
The post Investors Betting Big on Upwind for CNAPP Tech appeared first on SecurityWeek.
Join Microsoft and Finite State for a webinar that will introduce a new strategy for securing the software supply chain.
The post Webinar Tomorrow: Unpacking the Secure Supply Chain Consumption Framework (S2C2F) appeared first on SecurityWeek.
Truffle Security has discovered thousands of popular websites leaking their secrets, including .git directories and AWS and GitHub keys.
The post Thousands of Popular Websites Leaking Secrets appeared first on SecurityWeek.
Dozens of vulnerabilities have been found in widely used security cameras made by defunct Chinese company Zavio.
The post Dozens of Unpatched Flaws Expose Security Cameras Made by Defunct Company Zavio appeared first on SecurityWeek.
Academic researchers design a Chrome extension to steal passwords from input fields and publish it to the Chrome webstore.
The post Password-Stealing Chrome Extension Demonstrates New Vulnerabilities appeared first on SecurityWeek.
Mozilla has analyzed the privacy and security of 25 major car brands and found that they collect a lot of data and can share it or sell it to third parties.
The post 25 Major Car Brands Get Failing Marks From Mozilla for Security and Privacy appeared first on SecurityWeek.
Android’s September 2023 security update resolves a high-severity elevation of privilege vulnerability exploited in malicious attacks.
The post Android Zero-Day Patched With September 2023 Security Updates appeared first on SecurityWeek.
SecurityWeek talks to Alex Ionescu, a world-renowned cybersecurity expert who has combined a career as a business executive with that of a security researcher.
The post Hacker Conversations: Alex Ionescu appeared first on SecurityWeek.
Google has released another weekly Chrome update, to address four high-severity vulnerabilities reported by external researchers.
The post Chrome 116 Update Patches High-Severity Vulnerabilities appeared first on SecurityWeek.
AtlasVPN developers are working on a patch for an IP leak vulnerability after a researcher publicly disclosed the flaw due to being ignored.
The post AtlasVPN to Patch IP Leak Vulnerability After Public Disclosure appeared first on SecurityWeek.
United Airlines flights were halted nationwide on Sept. 5, because of an “equipment outage,” according to the FAA.
The post United Airlines Says the Outage That Held Up Departing Flights Was Not a Cybersecurity Issue appeared first on SecurityWeek.
Peiter ‘Mudge’ Zatko joins the US government's cybersecurity agency to preach the gospel of security-by-design and secure-by-default development principles.
The post CISA Hires ‘Mudge’ to Work on Security-by-Design Principles appeared first on SecurityWeek.
MITRE and CISA introduce Caldera for OT, a new extension to help security teams emulate attacks targeting operational technology systems.
The post MITRE and CISA Release Open Source Tool for OT Attack Emulation appeared first on SecurityWeek.
Nine vulnerabilities patched in SEL electric power management products, adding to the 19 other flaws fixed earlier this year.
The post 9 Vulnerabilities Patched in SEL Power System Management Products appeared first on SecurityWeek.
Freecycle.org is prompting millions of users to reset their passwords after their credentials were compromised in a data breach.
The post 7 Million Users Possibly Impacted by Freecycle Data Breach appeared first on SecurityWeek.
Norfolk Southern believes a software defect — not a hacker — was the cause of the widespread computer outage that forced the railroad to park all of its trains.
The post Norfolk Southern Says a Software Defect — Not a Hacker — Forced It to Park Its Trains This Week appeared first on SecurityWeek.
Okta says some of its US-based customers have been targeted in social engineering attacks whose goal was to disable MFA and obtain high privileges.
The post Okta Says US Customers Targeted in Sophisticated Attacks appeared first on SecurityWeek.
Malicious packages uploaded to PyPI, NPM, and Ruby repositories are targeting macOS users with information stealing malware.
The post Developers Warned of Malicious PyPI, NPM, Ruby Packages Targeting Macs appeared first on SecurityWeek.
Forty cybersecurity-related merger and acquisition (M&A) deals were announced in August 2023.
The post Cybersecurity M&A Roundup: 40 Deals Announced in August 2023 appeared first on SecurityWeek.
British mesh fencing systems maker Zaun discloses LockBit ransomware attack potentially impacting data related to UK military and intelligence sites.
The post Ransomware Attack on Fencing Systems Maker Zaun Impacts UK Military Data appeared first on SecurityWeek.
Exploit code and root-cause analysis released by SinSinology documents the problem as a case where VMWare “forgot to regenerate” SSH keys.
The post Exploit Code Published for Critical-Severity VMware Security Defect appeared first on SecurityWeek.
Weekly cybersecurity news roundup providing a summary of noteworthy stories that might have slipped under the radar.
The post In Other News: Hacking Encrypted Linux Computers, Android Fuzzing, Skype Leaking IPs appeared first on SecurityWeek.
EclecticIQ has released a free decryption tool to help victims of the Key Group ransomware recover their data without paying a ransom.
The post Free Decryptor Available for ‘Key Group’ Ransomware appeared first on SecurityWeek.
Twitter has updated its privacy policies, which will allow for the collection of biometric data and employment history, among other information.
The post Elon Musk Says X, Formerly Twitter, Will Have Voice and Video Calls, Updates Privacy Policy appeared first on SecurityWeek.
Industry professionals comment on the law enforcement operation targeting the Qakbot botnet and its implications.
The post Industry Reactions to Qakbot Botnet Disruption: Feedback Friday appeared first on SecurityWeek.
Cisco has observed multiple threat actors adopting the SapphireStealer information stealer after its source code was released on GitHub.
The post Threat Actors Adopt, Modify Open Source ‘SapphireStealer’ Information Stealer appeared first on SecurityWeek.
Sourcegraph says customer information was breached after an engineer accidentally leaked an admin access token.
The post Sourcegraph Discloses Data Breach Following Access Token Leak appeared first on SecurityWeek.
ZDI is offering more than $1 million at the Pwn2Own Automotive hacking contest, hosted in January at the Automotive World conference in Tokyo.
The post Over $1 Million Offered at New Pwn2Own Automotive Hacking Contest appeared first on SecurityWeek.
Small electric utilities in the US offered $9 million as part of a competition whose goal is to help them boost their cybersecurity posture.
The post Energy Department Offering $9M in Cybersecurity Competition for Small Electric Utilities appeared first on SecurityWeek.
A vulnerability in the All-in-One WP Migration plugin’s extensions exposes WordPress websites to attacks leading to sensitive information disclosure.
The post Vulnerability in WordPress Migration Plugin Exposes Websites to Attacks appeared first on SecurityWeek.
Apple is inviting security researchers to apply for the 2024 iPhone Security Research Device Program (SRDP) to receive hackable iPhones.
The post Apple Preparing iPhone 14 Pro Phones for 2024 Security Research Device Program appeared first on SecurityWeek.
Five Eyes report details 'Infamous Chisel' malware used by Russian state-sponsored hackers to target the Ukrainian military’s Android devices.
The post Five Eyes Report: New Russian Malware Targeting Ukrainian Military Android Devices appeared first on SecurityWeek.
Splunk has released patches for multiple high-severity vulnerabilities impacting Splunk Enterprise and IT Service Intelligence.
The post Splunk Patches High-Severity Flaws in Enterprise, IT Service Intelligence appeared first on SecurityWeek.
A lawsuit filed on behalf of a former student and former employee at the University of Minnesota accuses the university of not doing enough to protect personal information from a recent data breach.
The post Lawsuit Accuses University of Minnesota of Not Doing Enough to Prevent Data Breach appeared first on SecurityWeek.
Fashion retailer Forever 21 says that the personal information of more than 500,000 individuals was compromised in a data breach.
The post 500k Impacted by Data Breach at Fashion Retailer Forever 21 appeared first on SecurityWeek.
Dangling DNS records were abused by researchers to hijack subdomains belonging to major organizations, warning that thousands of entities are impacted.
The post Dangling DNS Used to Hijack Subdomains of Major Organizations appeared first on SecurityWeek.
Earth Estries, a cyberspy group possibly linked to China, has targeted governments and tech firms in the US, Germany, South Africa and Asia.
The post ‘Earth Estries’ Cyberespionage Group Targets Government, Tech Sectors appeared first on SecurityWeek.
Roughly 78% of the healthcare organizations in North America, South America, the APAC region, and Europe experienced a cyberattack over the past year, according to a new report.
The post Healthcare Organizations Hit by Cyberattacks Last Year Reported Big Impact, Costs appeared first on SecurityWeek.
Four recent vulnerabilities in the J-Web component of Junos OS have started being chained in malicious attacks after PoC exploit code was published.
The post Recent Juniper Flaws Chained in Attacks Following PoC Exploit Publication appeared first on SecurityWeek.
GitHub Enterprise Server 3.10 released with additional security capabilities, including support for custom deployment rules.
The post GitHub Enterprise Server Gets New Security Capabilities appeared first on SecurityWeek.
Serious flaw affecting major BGP implementations can be exploited to cause prolonged internet outages, but several vendors have not patched it.
The post BGP Flaw Can Be Exploited for Prolonged Internet Outages appeared first on SecurityWeek.
While quantum-based attacks are still in the future, organizations must think about how to defend data in transit when encryption no longer works.
The post How Quantum Computing Will Impact Cybersecurity appeared first on SecurityWeek.
The DreamBus botnet has resurfaced and it has been exploiting a recently patched Apache RocketMQ vulnerability to deliver a Monero miner.
The post DreamBus Botnet Exploiting RocketMQ Vulnerability to Delivery Cryptocurrency Miner appeared first on SecurityWeek.
Mozilla and Google have released stable updates for the Firefox and Chrome browsers to address several memory corruption vulnerabilities.
The post High-Severity Memory Corruption Vulnerabilities Patched in Firefox, Chrome appeared first on SecurityWeek.
Fianu Labs has emerged from stealth mode with a software governance automation solution and $2 million in seed funding.
The post Fianu Labs Emerges From Stealth With $2 Million in Seed Funding appeared first on SecurityWeek.
U.S. law enforcement announce the disruption of the notorious Qakbot cybercrime operation and the release of an auto-disinfection tool to 700,000 infected machines.
The post Qakbot Botnet Disrupted in Operation ‘Duck Hunt’ appeared first on SecurityWeek.
VWware patches critical flaws that allow hackers to bypass SSH authentication and gain access to the Aria Operations for Networks command line interface.
The post VMware Patches Major Security Flaws in Network Monitoring Product appeared first on SecurityWeek.
The newly identified MMRat Android trojan has been targeting users in Southeast Asia to remotely control devices and perform bank fraud.
The post New ‘MMRat’ Android Trojan Targeting Users in Southeast Asia appeared first on SecurityWeek.
ChatGPT Enterprise is a corporate edition of ChatGPT that promises “enterprise-grade security” and a commitment not to use prompts and company data to train AI models.
The post OpenAI Turns to Security to Sell ChatGPT Enterprise appeared first on SecurityWeek.
If an organization decides to include cyberinsurance within its total cyber risk management posture, that cyberinsurance must be fully integrated with the organization’s cybersecurity posture.
The post The Reality of Cyberinsurance in 2023 appeared first on SecurityWeek.
NEWS ANALYSIS: Redmond plants its feet firmly in the enterprise browser space, sending major ripples through Silicon Valley's bustling venture-backed startup ecosystem.
The post Did Microsoft Just Upend the Enterprise Browser Market? appeared first on SecurityWeek.
A new report sheds light on cybercrime scams that have become a major issue in Asia, with many workers trapped in virtual slavery.
The post UN Warns Hundreds of Thousands in Southeast Asia Roped Into Online Scams appeared first on SecurityWeek.
Chinese threat actor exploiting Barracuda ESG appliances deployed persistence mechanisms in preparation for remediation efforts.
The post Chinese APT Was Prepared for Remediation Efforts in Barracuda ESG Zero-Day Attack appeared first on SecurityWeek.
Meta has purged thousands of Facebook accounts that were part of a widespread online Chinese spam operation trying to covertly boost China and criticize the West.
The post Meta Fights Sprawling Chinese ‘Spamouflage’ Operation appeared first on SecurityWeek.
PurFoods says the personal and protected health information of over 1.2 million individuals was stolen in a February 2023 ransomware attack.
The post Personal, Health Information of 1.2 Million Stolen in PurFoods Ransomware Attack appeared first on SecurityWeek.
Just as a professional football team needs coordination, strategy and adaptability to secure a win on the field, a well-rounded cybersecurity strategy must address specific challenges and threats.
The post Security Team Huddle: Using the Full NIST Cybersecurity Framework for the Win appeared first on SecurityWeek.
Cybersecurity vendors SentinelOne and BlackBerry have been separately named in public acquisition chatter with a surprise suitor emerging.
The post Acquisition Chatter Swirls Around SentinelOne, BlackBerry appeared first on SecurityWeek.
The personal information of roughly 10 million individuals might have been compromised in a data breach at French unemployment agency Pole Emploi.
The post 10 Million Likely Impacted by Data Breach at French Unemployment Agency appeared first on SecurityWeek.
The Crates.io Rust package registry was targeted in preparation of a malware attack aimed at developers, according to Phylum.
The post Signs of Malware Attack Targeting Rust Developers Found on Crates.io appeared first on SecurityWeek.
QakBot, SocGholish, and Raspberry Robin are the three most popular malware loaders, accounting for 80% of the observed incidents.
The post 3 Malware Loaders Detected in 80% of Attacks: Security Firm appeared first on SecurityWeek.
Polish police have arrested two men suspected of illegally hacking into the national railway's communications network, causing disruption to 20 trains.
The post Two Men Arrested Following Poland Railway Hacking appeared first on SecurityWeek.
Dutch cloud company Leaseweb shut down some critical systems last week due to a cyberattack.
The post Leaseweb Reports Cloud Disruptions Due to Cyberattack appeared first on SecurityWeek.
Personal information stolen in ransomware attack at Ohio History Connection posted online after organization refuses to pay ransom.
The post Ohio History Organization Says Personal Information Stolen in Ransomware Attack appeared first on SecurityWeek.
Three bankrupt cryptocurrency companies — FTX, BlockFi and Genesis — suffered data breaches following a SIM swapping attack at Kroll.
The post 3 Cryptocurrency Firms Suffer Data Breach After Kroll SIM Swapping Attack appeared first on SecurityWeek.
Weekly cybersecurity news roundup that provides a summary of noteworthy stories that might have slipped under the radar for the week of August 21, 2023.
The post In Other News: Africa Cybercrime Crackdown, Unpatched macOS Flaw, Investor Disclosures appeared first on SecurityWeek.
North Korea-linked Lazarus Group exploited a ManageEngine vulnerability to compromise an internet backbone infrastructure provider.
The post North Korean APT Hacks Internet Infrastructure Provider via ManageEngine Flaw appeared first on SecurityWeek.
Israeli startup Cypago raises $13 million in funding and launches a governance, risk management and compliance (GRC) automation platform.
The post Cypago Raises $13 Million for GRC Automation Platform appeared first on SecurityWeek.
Congresswoman Nancy Mace has introduced a bill that would require federal contractors to have a Vulnerability Disclosure Policy (VDP).
The post Lawmaker Wants Federal Contractors to Have Vulnerability Disclosure Policies appeared first on SecurityWeek.
The Digital Services Act aims to protect European users when it comes to privacy, transparency and removal of harmful or illegal content.
The post Europe is Cracking Down on Big Tech. This Is What Will Change When You Sign On appeared first on SecurityWeek.
Google has announced new AI-powered zero trust, digital sovereignty, and threat defense controls for Workspace customers.
The post Google Workspace Introduces New AI-Powered Security Controls appeared first on SecurityWeek.
Nearly 1,000 organizations and 60 million individuals are impacted by the MOVEit hack, and the Cl0p ransomware gang is leaking stolen data.
The post Nearly 1,000 Organizations, 60 Million Individuals Impacted by MOVEit Hack appeared first on SecurityWeek.
Microsoft warns that Chinese spies are hacking into Taiwanese organizations with minimal use of malware and by abusing legitimate software.
The post Chinese-backed APT ‘Flax Typhoon’ Hacks Taiwan with Minimal Malware Footprint appeared first on SecurityWeek.
University of Minnesota confirms data was stolen from its systems, says no malware infection or file encryption has been identified.
The post University of Minnesota Confirms Data Breach, Says Ransomware Not Involved appeared first on SecurityWeek.
Cisco has released patches for three high-severity vulnerabilities in NX-OS and FXOS software that could lead to denial-of-service (DoS) conditions.
The post Cisco Patches Vulnerabilities Exposing Switches, Firewalls to DoS Attacks appeared first on SecurityWeek.
Mysterious Whiffy Recon malware scans for nearby Wi-Fi access points to obtain the location of the infected device.
The post Mysterious Malware Uses Wi-Fi Scanning to Get Location of Infected Device appeared first on SecurityWeek.
The FBI says that the patches Barracuda released in May for an exploited ESG zero-day vulnerability (CVE-2023-2868) were not effective.
The post FBI: Patches for Recent Barracuda ESG Zero-Day Ineffective appeared first on SecurityWeek.
Rockwell Automation ThinManager ThinServer vulnerabilities could allow remote attackers to take control of servers and hack HMIs.
The post Rockwell ThinManager Vulnerabilities Could Expose Industrial HMIs to Attacks appeared first on SecurityWeek.
Account takeover and fraud protection firm SpyCloud has raised $110 million in a growth funding round led by Riverwood Capital.
The post Digital Identity Protection Firm SpyCloud Raises $110 Million appeared first on SecurityWeek.
A financially motivated cybercrime group has exploited a WinRAR zero-day to deliver malware to traders and steal their money.
The post Traders Targeted by Cybercriminals in Attack Exploiting WinRAR Zero-Day appeared first on SecurityWeek.
Danish cloud hosting provider CloudNordic says most customers lost all data after ransomware shut down all its systems and servers.
The post Hosting Provider CloudNordic Loses All Customer Data in Ransomware Attack appeared first on SecurityWeek.
A UK court has found a teenager responsible for a hacking campaign that included one of the biggest breaches in the history of the video game industry.
The post UK Court Concludes Teenager Behind Huge Hacking Campaign appeared first on SecurityWeek.
The private equity firm merges the newly acquired ForgeRock with Ping Identity, combining two of the biggest names in enterprise IAM market.
The post Thoma Bravo Merges ForgeRock with Ping Identity appeared first on SecurityWeek.
As smart cities evolve with more and more integrated connected services, cybersecurity concerns will increase dramatically.
The post Smart Cities: Utopian Dream, Security Nightmare, or Political Gimmick? appeared first on SecurityWeek.
The FBI has published information on six crypto wallets in which North Korean hackers moved roughly 1,580 Bitcoin from various heists.
The post FBI Finds 1,580 Bitcoin in Crypto Wallets Linked to North Korean Hackers appeared first on SecurityWeek.
Cybersecurity companies have released a dozen ransomware reports in recent weeks and most of them show a surge in attacks.
The post Cybersecurity Companies Report Surge in Ransomware Attacks appeared first on SecurityWeek.
As the SEC cyber incident disclosure rules come into effect, organizations will be forced to seriously consider giving security leaders a seat at the table.
The post The End of “Groundhog Day” for the Security in the Boardroom Discussion? appeared first on SecurityWeek.
More than 3,000 Openfire servers are not patched against a recent vulnerability and are exposed to attacks employing a new exploit.
The post 3,000 Openfire Servers Exposed to Attacks Targeting Recent Vulnerability appeared first on SecurityWeek.
CISA, NSA, and NIST urge organizations to create quantum-readiness roadmaps and prepare for post-quantum cryptography migration.
The post US Government Publishes Guidance on Migrating to Post-Quantum Cryptography appeared first on SecurityWeek.
Google has released the first weekly Chrome security update, which patches five memory safety vulnerabilities, including four rated ‘high severity’.
The post First Weekly Chrome Security Update Patches High-Severity Vulnerabilities appeared first on SecurityWeek.
While initially it was unclear if the Ivanti Sentry vulnerability CVE-2023-38035 has been exploited, the vendor and CISA have now confirmed it.
The post Exploitation of Ivanti Sentry Zero-Day Confirmed appeared first on SecurityWeek.
Vulnerabilities in the TP-Link Tapo L530E smart bulb and accompanying mobile application can be exploited to obtain the local Wi-Fi password.
The post TP-Link Smart Bulb Vulnerabilities Expose Households to Hacker Attacks appeared first on SecurityWeek.
Cris Thomas, also known as Space Rogue, was a founding member of the Lopht Heavy Industries hacker collective.
The post Hacker Conversations: Cris Thomas (AKA Space Rogue) From Lopht Heavy Industries appeared first on SecurityWeek.
The threat actor behind HiatusRAT was seen performing reconnaissance against a US military procurement system in June 2023.
The post US Military Targeted in Recent HiatusRAT Attack appeared first on SecurityWeek.
The BlackCat/ALPHV ransomware group has started publishing data allegedly stolen from Japanese watchmaking giant Seiko.
The post Ransomware Group Starts Leaking Data From Japanese Watchmaking Giant Seiko appeared first on SecurityWeek.
Energy One, an Australian company that provides software products and services to the energy sector, has been hit by a cyberattack.
The post Australian Energy Software Firm Energy One Hit by Cyberattack appeared first on SecurityWeek.
A new APT group called Carderbee has been observed deploying the PlugX backdoor via a supply chain attack targeting organizations in Hong Kong.
The post New ‘Carderbee’ APT Targeted Chinese Security Software in Supply Chain Attack appeared first on SecurityWeek.
Israeli startup Grip Security has banked $41 million in new financing from a group of investors led by Third Point Ventures.
The post Grip Security Lands $41 Million Series B Financing appeared first on SecurityWeek.
Cerby has raised $17 million in Series A funding for its access management platform for applications not supported by identity providers.
The post Cerby Raises $17 Million for Access Management Platform for Nonstandard Applications appeared first on SecurityWeek.
CISA warns that CVE-2023-26359, an Adobe ColdFusion vulnerability patched in March, has been exploited in the wild.
The post CISA Warns of Another Exploited Adobe ColdFusion Vulnerability appeared first on SecurityWeek.
A critical-severity vulnerability in the Ivanti Sentry (formerly MobileIron Sentry) product exposes sensitive API data and configurations.
The post Ivanti Ships Urgent Patch for API Authentication Bypass Vulnerability appeared first on SecurityWeek.
Cyfirma security researchers uncover the real identity of the CypherRAT and CraxsRAT malware developer and MaaS operator.
The post Researchers Uncover Real Identity of CypherRAT and CraxsRAT Malware Developer appeared first on SecurityWeek.
Australian lender Latitude Financial said the recent ransomware attack has cost it AU$76 million (roughly US$50 million).
The post Australian Lender Latitude Financial Reports AU$76 Million Cyberattack Costs appeared first on SecurityWeek.
The FBI, NCSC, and AFOSI warn US space industry organizations of foreign intelligence targeting and exploitation, including cyberattacks.
The post US Gov Warns of Foreign Intelligence Cyberattacks Against US Space Industry appeared first on SecurityWeek.
Join Cloudflare and SecurityWeek for a webinar to discuss “VPN Replacement: Other ZTNA Superpowers CISOs Should Know”
The post Webinar Tomorrow: ZTNA Superpowers CISOs Should Know appeared first on SecurityWeek.
A Brazilian hacker claims former president Bolsonaro asked him to hack into the voting system ahead of the 2022 election.
The post Brazilian Hacker Claims Bolsonaro Asked Him to Hack Into the Voting System Ahead of 2022 Vote appeared first on SecurityWeek.
Juniper Networks has released Junos OS updates to address J-Web vulnerabilities that can be combined to achieve unauthenticated, remote code execution.
The post Flaws in Juniper Switches and Firewalls Can Be Chained for Remote Code Execution appeared first on SecurityWeek.
Tesla has disclosed a data breach impacting 75,000 people, but it’s a result of a whistleblower leak, not a malicious cyberattack.
The post Tesla Discloses Data Breach Related to Whistleblower Leak appeared first on SecurityWeek.
North Korea-linked "Kimsuky" hackers carried out "continuous malicious email attacks" on contractors working at the war simulation centre.
The post Suspected N. Korean Hackers Target S. Korea-US Drills appeared first on SecurityWeek.
Weekly cybersecurity news roundup that provides a summary of noteworthy stories that might have slipped under the radar for the week of August 14, 2023.
The post In Other News: US Hacking China, Unfixed PowerShell Gallery Flaws, Free Train Tickets appeared first on SecurityWeek.
Jenkins has announced patches for high and medium-severity vulnerabilities impacting several of the open source automation tool’s plugins.
The post Jenkins Patches High-Severity Vulnerabilities in Multiple Plugins appeared first on SecurityWeek.
The ‘LabRat’ cryptomining and proxyjacking operation relies on signature-based tools and stealthy cross-platform malware, and abuses TryCloudflare to hide its C&Cs.
The post Stealthy ‘LabRat’ Campaign Abuses TryCloudflare to Hide Infrastructure appeared first on SecurityWeek.
Several major companies have published advisories in response to the Downfall vulnerability affecting Intel CPUs.
The post Companies Respond to ‘Downfall’ Intel CPU Vulnerability appeared first on SecurityWeek.
Israel and US government agencies have announced plans to invest close to $4 million in projects to improve the security of critical infrastructure systems.
The post Israel, US to Invest $4 Million in Critical Infrastructure Security Projects appeared first on SecurityWeek.
The National Credit Union Administration is requiring all federally insured credit unions to report cyber incidents within 72 hours of discovery.
The post Federally Insured Credit Unions Required to Report Cyber Incidents Within 3 Days appeared first on SecurityWeek.
San Francisco startup ProjectDiscovery has banked $25 million in early-stage financing as investors continue bet on cloud security vendors.
The post ProjectDiscovery Lands $25M Investment for Cloud Security Tech appeared first on SecurityWeek.
Google sprinkles magic of generative-AI into its open source fuzz testing infrastructure and finds immediate success with code coverage.
The post Google Brings AI Magic to Fuzz Testing With Eye-Opening Results appeared first on SecurityWeek.
A new report from Rapid7 says a ransomware gang like Cl0p would easily be able to afford a bevy of zero-day exploits for vulnerable enterprise software.
The post Rapid7 Says ROI for Ransomware Remains High; Zero-Day Usage Expands appeared first on SecurityWeek.
A widespread phishing campaign utilizing malicious QR codes has hit organizations in various industries, including a major energy company in the US.
The post Malicious QR Codes Used in Phishing Attack Targeting US Energy Company appeared first on SecurityWeek.
Cisco has patched high-severity vulnerabilities in enterprise applications that could lead to privilege escalation, SQL injection, and denial-of-service.
The post Cisco Patches High-Severity Vulnerabilities in Enterprise Applications appeared first on SecurityWeek.
Threat actors have been observed deploying a proxy application on Windows and macOS systems that were infected with malware.
The post Thousands of Systems Turned Into Proxy Exit Nodes via Malware appeared first on SecurityWeek.
CISA has published a cyber defense plan outlining strategies to help critical infrastructure organizations reduce the risks associated with RMM software.
The post CISA Releases Cyber Defense Plan to Reduce RMM Software Risks appeared first on SecurityWeek.
Twenty-five cybersecurity-related M&A deals were announced in the first half of August 2023.
The post Cybersecurity M&A Roundup for August 1-15, 2023 appeared first on SecurityWeek.
Exploitation of a Citrix ShareFile vulnerability tracked as CVE-2023-24489 has spiked as CISA added it to its ‘must patch’ catalog.
The post Exploitation of Citrix ShareFile Vulnerability Spikes as CISA Issues Warning appeared first on SecurityWeek.
Google has released the first quantum-resilient FIDO2 security key implementation as part of its OpenSK project.
The post Google Releases Security Key Implementation Resilient to Quantum Attacks appeared first on SecurityWeek.
Ivanti has patched critical- and high-severity vulnerabilities with the latest release of Avalanche, its enterprise mobile device management solution.
The post Ivanti Patches Critical Vulnerability in Avalanche Enterprise MDM Solution appeared first on SecurityWeek.
Cleaning products manufacturer and marketer Clorox Company has taken certain systems offline after falling victim to a cyberattack.
The post Cleaning Products Giant Clorox Takes Systems Offline Following Cyberattack appeared first on SecurityWeek.
GitHub says it paid out more than $1.5 million in bug bounties for 364 vulnerabilities in 2022, reaching a total of nearly $4 million since 2016.
The post GitHub Paid Out $1.5 Million in Bug Bounties in 2022 appeared first on SecurityWeek.
Google has released Chrome 116 with patches for 26 vulnerabilities and plans to ship weekly security updates for the popular web browser.
The post Chrome 116 Patches 26 Vulnerabilities appeared first on SecurityWeek.
A threat actor has exploited a recent Citrix vulnerability (CVE-2023-3519) to infect roughly 2,000 NetScaler instances with a backdoor.
The post 2,000 Citrix NetScaler Instances Backdoored via Recent Vulnerability appeared first on SecurityWeek.
SecurityWeek talks to Billy Spears, CISO at Teradata (a multi-cloud analytics provider), and Lea Kissner, CISO at cloud security firm Lacework.
The post CISO Conversations: CISOs in Cloud-based Services Discuss the Process of Leadership appeared first on SecurityWeek.
Hudson Rock security researchers have identified credentials for hacker forums on roughly 120,000 computers infected with information stealers.
The post Hacker Forum Credentials Found on 120,000 PCs Infected With Info-Stealer Malware appeared first on SecurityWeek.
The personal information of 1.5 million individuals was compromised in a ransomware attack at Alberta Dental Service Corporation (ADSC).
The post 1.5 Million Impacted by Ransomware Attack at Canadian Dental Service appeared first on SecurityWeek.
Threat detection and response firm SecureWorks is laying off 15% of its staff (roughly 300 people) in the second round of firings this year.
The post SecureWorks Laying Off 15% of Employees appeared first on SecurityWeek.
Colorado’s health programs administrator says the personal information of 4 million individuals was compromised in the recent MOVEit hack.
The post Colorado Health Agency Says 4 Million Impacted by MOVEit Hack appeared first on SecurityWeek.
Working remotely is here to stay and businesses should continue to make sure their basic forms of communication are properly configured and secured.
The post Email – The System Running Since 71’ appeared first on SecurityWeek.
The US government's CSRB will conduct a review of cloud security to provide recommendations on improving identity management and authentication.
The post US Cyber Safety Board to Review Cloud Attacks appeared first on SecurityWeek.
Vulnerabilities in CyberPower and Dataprobe power management products could be exploited in data center attacks, including to cause damage and for spying.
The post Power Management Product Flaws Can Expose Data Centers to Damaging Attacks, Spying appeared first on SecurityWeek.
US authorities have announced charges against a Polish national who allegedly operated the LolekHosted.net bulletproof hosting service.
The post US Shuts Down Bulletproof Hosting Service LolekHosted, Charges Its Polish Operator appeared first on SecurityWeek.
Ford says a critical vulnerability in the TI Wi-Fi driver of the SYNC 3 infotainment system on certain vehicle models does not pose a safety risk.
The post Ford Says Wi-Fi Vulnerability Not a Safety Risk to Vehicles appeared first on SecurityWeek.
Several vulnerabilities discovered in Iagona ScrutisWeb ATM fleet monitoring software could be exploited to remotely hack ATMs.
The post Iagona ScrutisWeb Vulnerabilities Could Expose ATMs to Remote Hacking appeared first on SecurityWeek.
Security in current AI models was an afterthought in their training as data scientists amassed breathtakingly complex collections of images and text.
The post Don’t Expect Quick Fixes in ‘Red-Teaming’ of AI Models. Security Was an Afterthought appeared first on SecurityWeek.
Weekly cybersecurity news roundup that provides a summary of noteworthy stories that might have slipped under the radar for the week of August 7, 2023.
The post In Other News: macOS Security Reports, Keyboard Spying, VPN Vulnerabilities appeared first on SecurityWeek.
Over a dozen Codesys vulnerabilities discovered by Microsoft researchers can be exploited to shut down industrial processes or deploy backdoors.
The post Microsoft Discloses Codesys Flaws Allowing Shutdown of Industrial Operations, Spying appeared first on SecurityWeek.
Northern Ireland’s top police officer apologized for what he described as an “industrial scale” data breach in which the personal information of more than 10,000 officers and staff was released to the public.
The post Northern Ireland’s Top Police Officer Apologizes for ‘Industrial Scale’ Data Breach appeared first on SecurityWeek.
Hundreds of companies and organizations showcased their products and services this week at the 2023 edition of the Black Hat conference in Las Vegas.
The post Black Hat USA 2023 – Announcements Summary appeared first on SecurityWeek.
Indian lawmakers approved a data protection legislation that “seeks to better regulate big tech firms and penalize companies for data breaches” as several groups expressed concern over citizens’ privacy rights.
The post India Passes Data Protection Legislation in Parliament. Critics Fear Privacy Violation appeared first on SecurityWeek.
MoustachedBouncer is a cyberespionage group that targets foreign diplomats in Belarus via ISP adversary-in-the-middle attacks.
The post MoustachedBouncer: Foreign Embassies in Belarus Likely Targeted via ISPs appeared first on SecurityWeek.
Check Point will acquire SASE and ZTNA cybersecurity firm Perimeter 81 for $490 million, a big discount to its $1 billion valuation in 2022.
The post Check Point to Acquire SASE Security Firm Perimeter 81 for $490 Million appeared first on SecurityWeek.
The complexity and challenge of distributed cloud environments often necessitate managing multiple infrastructure, technology, and security stacks, multiple policy engines, multiple sets of controls, and multiple asset inventories.
The post Managing and Securing Distributed Cloud Environments appeared first on SecurityWeek.
Symmetry Systems has raised $17.7 million for its AI-powered Data Security Posture Management (DSPM) platform.
The post Symmetry Systems Raises $17.7M for Data Security Posture Management Platform appeared first on SecurityWeek.
Norway-based startup Pistachio has raised €3.25 million ($3.5 million) for its AI-based cybersecurity training platform.
The post European Startup Pistachio Raises €3.25 Million for Cybersecurity Training Platform appeared first on SecurityWeek.
CISA has added CVE-2023-38180, a zero-day vulnerability affecting .NET and Visual Studio, to its Known Exploited Vulnerabilities Catalog.
The post CISA Warns Organizations of Exploited Vulnerability Affecting .NET, Visual Studio appeared first on SecurityWeek.
The White House launched an Artificial Intelligence Cyber Challenge competition for creating new AI systems that can defend critical software from hackers.
The post White House Offers Prize Money for Hacker-Thwarting AI appeared first on SecurityWeek.
Critical vulnerabilities discovered in WD and Synology NAS devices could have exposed the files of millions of users.
The post Western Digital, Synology NAS Vulnerabilities Exposed Millions of Users’ Files appeared first on SecurityWeek.
Israeli startup emerged from stealth with $12 million in Seed funding and launched a Cloud Runtime Security Suite.
The post Sweet Security Emerges From Stealth With $12 Million Seed Funding and a Cloud Runtime Solution appeared first on SecurityWeek.
For the fourth consecutive year, Microsoft has paid out more than $13 million through its bug bounty programs.
The post Microsoft Paid Out $13 Million via Bug Bounty Programs for Fourth Consecutive Year appeared first on SecurityWeek.
Australian cybersecurity startup Kivera raised $3.5 million in seed funding from General Advance, Round 13 Capital and angel investors.
The post Cloud Security Firm Kivera Raises $3.5 Million in Seed Funding appeared first on SecurityWeek.
Intel has addressed 80 vulnerabilities affecting its products, including 18 high-severity privilege escalation and DoS flaws.
The post Intel Addresses 80 Firmware, Software Vulnerabilities appeared first on SecurityWeek.
Automated Security Control Assessment enhances security posture by verifying proper, consistent configurations of security controls, rather than merely confirming their existence.
The post Automated Security Control Assessment: When Self-Awareness Matters appeared first on SecurityWeek.
SAP has fixed over a dozen new vulnerabilities with its Patch Tuesday updates, including a critical flaw in its PowerDesigner product.
The post SAP Patches Critical Vulnerability in PowerDesigner Product appeared first on SecurityWeek.
Researchers have disclosed the details of a new side-channel attack targeting AMD CPUs named Inception.
The post New ‘Inception’ Side-Channel Attack Targets AMD Processors appeared first on SecurityWeek.
40 vulnerabilities have been patched by Google in the Android operating system with the release of the August 2023 security updates.
The post 40 Vulnerabilities Patched in Android With August 2023 Security Updates appeared first on SecurityWeek.
Google researcher discloses the details of an Intel CPU attack method named Downfall that may be remotely exploitable.
The post Downfall: New Intel CPU Attack Exposing Sensitive Information appeared first on SecurityWeek.
Restructuring plan will result in an 18% reduction in employee headcount and closing of some Rapid7 office locations.
The post Rapid7 Announces Layoffs, Office Closings Under Restructuring Plan appeared first on SecurityWeek.
Patch Tuesday: A month after confirming active exploitation of Office code execution flaws, Microsoft has shipped patches for multiple affected products.
The post Patch Tuesday: Microsoft (Finally) Patches Exploited Office Zero-Days appeared first on SecurityWeek.
Adobe rolls out a big batch of security updates to fix at least 30 Acrobat and Reader vulnerabilities affecting Windows and macOS users.
The post Patch Tuesday: Adobe Patches 30 Acrobat, Reader Vulns appeared first on SecurityWeek.
CISA will step up training for the K-12 sector and technology providers, including Amazon Web Services and Cloudflare, will offer grants and free software.
The post White House Holds First-Ever Summit on the Ransomware Crisis Plaguing the Nation’s Public Schools appeared first on SecurityWeek.
Horizon3.ai, a provider of autonomous security testing solutions, raised $40 million through a Series C funding round.
The post Horizon3 AI Raises $40 Million to Expand Automated Pentesting Platform appeared first on SecurityWeek.
Context helps complete the picture and results in actionable intelligence that security teams can use to make informed decisions more quickly.
The post Protection is No Longer Straightforward – Why More Cybersecurity Solutions Must Incorporate Context appeared first on SecurityWeek.
Identity-based attacks have soared in the past year, according to CrowdStrike’s 2023 Threat Hunting Report.
The post Identity-Based Attacks Soared in Past Year: Report appeared first on SecurityWeek.
ICS Patch Tuesday: Siemens releases a dozen advisories covering over 30 vulnerabilities, but Schneider Electric has only published one advisory.
The post ICS Patch Tuesday: Siemens Fixes 7 Vulnerabilities in Ruggedcom Products appeared first on SecurityWeek.
The Royal United Services Institute (RUSI) examined the relationship between cyberinsurance and ransomware, and proposes greater reporting from victims to government, enforced through insurance policies.
The post UK Think Tank Proposes Greater Ransomware Reporting From Cyberinsurance to Government appeared first on SecurityWeek.
The cybersecurity industry heads to Las Vegas this week for Black Hat in a state of economic contraction, confusion and excitement. Can the promise of AI overcome the hype cycle to truly solve security problems?
The post Black Hat Preview: The Business of Cyber Takes Center Stage appeared first on SecurityWeek.
Microsoft has shared guidance and resources from its AI Red Team program to help organizations and individuals with AI security.
The post Microsoft Shares Guidance and Resources for AI Red Teams appeared first on SecurityWeek.
Resilience Cyber Insurance Solutions has raised $100 million through a Series D funding round to support global expansion of its cyber risk platform that was launched earlier this year.
The post Cyberinsurance Firm Resilience Raises $100 Million to Expand Its Cyber Risk Platform appeared first on SecurityWeek.
A sanctioned Russian missile maker appears to have been targeted by two important North Korean hacking groups.
The post North Korean Hackers Targeted Russian Missile Developer appeared first on SecurityWeek.
A new vulnerability in the PaperCut MF/NG print management software can be exploited for unauthenticated, remote code execution.
The post New PaperCut Vulnerability Allows Remote Code Execution appeared first on SecurityWeek.
CISA has unveiled its Cybersecurity Strategic Plan for the next 3 years, focusing on addressing immediate threats, hardening the terrain, and driving security.
The post CISA Unveils Cybersecurity Strategic Plan for Next 3 Years appeared first on SecurityWeek.
Colorado Department of Higher Education targeted in a ransomware attack that resulted in a data breach impacting many students and teachers.
The post Colorado Department of Higher Education Discloses Ransomware Attack, Data Breach appeared first on SecurityWeek.
A cyberattack has disrupted hospital computer systems in several states, forcing some emergency rooms to close and ambulances to be diverted.
The post A Cyberattack Has Disrupted Hospitals and Health Care in Five States appeared first on SecurityWeek.
Weekly cybersecurity news roundup that provides a summary of noteworthy stories that might have slipped under the radar for the week of July 31, 2023.
The post In Other News: Cybersecurity Funding Rebounds, Cloud Threats, BeyondTrust Vulnerability appeared first on SecurityWeek.
Threat actors have been observed abusing the open source Cloudflare Tunnel tool Cloudflared to maintain stealthy, persistent access to compromised systems.
The post Threat Actors Abuse Cloudflare Tunnel for Persistent Access, Data Theft appeared first on SecurityWeek.
A critical Microsoft Power Platform vulnerability exposed authentication data and other secrets, but the tech giant has been accused of handling it poorly.
The post Microsoft Criticized Over Handling of Critical Power Platform Vulnerability appeared first on SecurityWeek.
Multiple vulnerabilities in the airline and hotel rewards platform points.com could have led to personal information theft and unauthorized administrative access.
The post Points.com Vulnerabilities Allowed Customer Data Theft, Rewards Program Hacking appeared first on SecurityWeek.
A married couple from New York dubbed "Bitcoin Bonnie and Crypto Clyde" pleaded guilty to laundering billions of dollars in stolen bitcoin.
The post New York Couple Plead Guilty to Bitcoin Laundering appeared first on SecurityWeek.
Exploitation of the Ivanti EPMM flaw CVE-2023-35078 is picking up as a new critical vulnerability tracked as CVE-2023-35082 is disclosed.
The post Exploitation of Ivanti EPMM Flaw Picking Up as New Vulnerability Is Disclosed appeared first on SecurityWeek.
Five Eyes government agencies have published a list of the software vulnerabilities that were most frequently exploited in malicious attacks in 2022.
The post Five Eyes Agencies Call Attention to Most Frequently Exploited Vulnerabilities appeared first on SecurityWeek.
The US government's cybersecurity agency describes UEFI as "critical attack surface" that requires urgent security attention.
The post CISA Calls Urgent Attention to UEFI Attack Surfaces appeared first on SecurityWeek.
Jericho Security raises $3 million in a pre-seed funding round to help organizations defend against emerging generative AI-powered phishing attacks.
The post Jericho Security Raises $3 Million for Awareness Training Powered by Generative AI appeared first on SecurityWeek.
CISA disclosed 670 ICS vulnerabilities in the first half of 2023, but roughly one-third have no patches or mitigations from the vendor.
The post 670 ICS Vulnerabilities Disclosed by CISA in First Half of 2023: Analysis appeared first on SecurityWeek.
Cisco Talos researchers warn of dozens of critical- and high-severity vulnerabilities in the Milesight UR32L industrial router leading to code execution.
The post Dozens of RCE Vulnerabilities Impact Milesight Industrial Router appeared first on SecurityWeek.
Cloud security specialist Qualys has provided its view of the top five cloud security risks, drawing insights and data from its own platform and third parties.
The post These Are the Top Five Cloud Security Risks, Qualys Says appeared first on SecurityWeek.
Medical infusion pumps available via secondary market sources contain Wi-Fi configuration settings from the original organization.
The post Decommissioned Medical Infusion Pumps Expose Wi-Fi Configuration Data appeared first on SecurityWeek.
Forty-two cybersecurity-related merger and acquisition (M&A) deals were announced in July 2023.
The post Cybersecurity M&A Roundup: 42 Deals Announced in July 2023 appeared first on SecurityWeek.
Google has paid out over $60,000 for three high-severity type confusion vulnerabilities in Chrome’s V8 engine.
The post Google Awards Over $60,000 for V8 Vulnerabilities Patched With Chrome 115 Update appeared first on SecurityWeek.
Threat actors have exploited a Salesforce email service zero-day vulnerability and abused Meta features in a sophisticated phishing campaign.
The post Salesforce Email Service Zero-Day Exploited in Phishing Campaign appeared first on SecurityWeek.
Endor Labs has closed a massive $70 million Series A round of financing to fuel ambitious plans to build a dependency lifecycle management platform.
The post Software Supply Chain Startup Endor Labs Scores Massive $70M Series A Round appeared first on SecurityWeek.
Microsoft says a Russian government-linked hacking group is using its Microsoft Teams chat app to phish for credentials at targeted organizations.
The post Microsoft Catches Russian Government Hackers Phishing with Teams Chat App appeared first on SecurityWeek.
Menlo Security introduced anti-phishing solutions that analyze what users see on a landing page rather than just analyzing the content of an email.
The post Shield and Visibility Solutions Target Phishing From Inside the Browser appeared first on SecurityWeek.
A new macOS-targeting hVNC malware family is being advertised on a prominent cybercrime forum.
The post New hVNC macOS Malware Advertised on Hacker Forum appeared first on SecurityWeek.
Threat intelligence firm Cyble has raised $24 million in a Series B funding round co-led by Blackbird Ventures and King River Capital.
The post Cyble Raises $24 Million for AI-Powered Threat Intelligence Platform appeared first on SecurityWeek.
Firefox 116 was released with patches for 14 CVEs, including nine high-severity vulnerabilities, some of which can lead to remote code execution or sandbox escapes.
The post Firefox 116 Patches High-Severity Vulnerabilities appeared first on SecurityWeek.
Threat actors are using Google AMP URLs in phishing campaigns as a new detection evasion tactic.
The post Google AMP Abused in Phishing Attacks Aimed at Enterprise Users appeared first on SecurityWeek.
The recently patched Ivanti EPMM zero-day CVE-2023-35078 has been exploited to hack the Norwegian government since at least April 2023.
The post Ivanti Zero-Day Exploited by APT Since at Least April in Norwegian Government Attack appeared first on SecurityWeek.
Forgepoint Capital makes another investment in the cyber-insurance sector with a $15 million Series A investment in Converge Insurance.
The post Forgepoint Capital Places $15M Series A Bet on Converge Insurance appeared first on SecurityWeek.
A new power side-channel attack named Collide+Power can allow an attacker to obtain sensitive information and it works against nearly any modern CPU.
The post Nearly All Modern CPUs Leak Data to New Collide+Power Side-Channel Attack appeared first on SecurityWeek.
Researchers unmask an Iranian-run company providing command-and-control services to hacking groups, including state-sponsored APT actors.
The post Iran-Run ISP ‘Cloudzy’ Caught Supporting Nation-State APTs, Cybercrime Hacking Groups appeared first on SecurityWeek.
San Francisco startup Socket raises $20 million as investors continue to bet on companies in the open source software security category.
The post Socket Scores $20M as Investors Bet on Software Supply Chain Security Startups appeared first on SecurityWeek.
Silk Security raised $12.5 million in seed funding and is on a mission to break down the silos between security and development with an integrated ‘find and fix’ platform.
The post Silk Security Emerges from Stealth With $12.5 Million Seed Funding appeared first on SecurityWeek.
SpecterOps announces version 5.0 of BloodHound Active Directory mapping tool with
enterprise-grade deployment, usability, and UI.
The post SpecterOps Updates BloodHound Active Directory Mapping Tool appeared first on SecurityWeek.
Network-as-a-service (NaaS) solutions provider Nile has raised $175 million in a Series C funding round that brings the total raised by the firm to $300 million.
The post Nile Raises $175 Million for Secure NaaS Solutions appeared first on SecurityWeek.
SecurityWeek speaks to Youssef Sammouda about using cybersecurity research and bug bounties as a way of life and source of income.
The post Hacker Conversations: Youssef Sammouda, Bug Bounty Hunter appeared first on SecurityWeek.
The number of ransomware attacks targeting industrial organizations and infrastructure has doubled since the second quarter of 2022, according to Dragos.
The post Ransomware Attacks on Industrial Organizations Doubled in Past Year: Report appeared first on SecurityWeek.
Bedding products provider Tempur Sealy says it has shut down certain systems following a cyberattack.
The post Bedding Giant Tempur Sealy Takes Systems Offline Following Cyberattack appeared first on SecurityWeek.
China has implanted malware in key US power and communications networks in a "ticking time bomb" that could disrupt the military in event of a conflict
The post Possible Chinese Malware in US Systems a ‘Ticking Time Bomb’: Report appeared first on SecurityWeek.
Canon says more than 200 inkjet printer models fail to properly erase Wi-Fi configuration settings.
The post 200 Canon Printer Models May Expose Wi-Fi Connection Data appeared first on SecurityWeek.
The Biden administration on Monday announced a series of “generational investments” to address immediate and long-term cyber workforce needs.
The post US Gov Rolls Out National Cyber Workforce, Education Strategy appeared first on SecurityWeek.
To boost user privacy, Apple is requiring app developers to declare a reason to use specific APIs.
The post Apple Lists APIs That Developers Can Only Use for Good Reason appeared first on SecurityWeek.
Reddit hires a 20-year cybersecurity veteran to manage its privacy and security functions as it prepares for an IPO.
The post Reddit Taps Fredrick ‘Flee’ Lee for CISO Job appeared first on SecurityWeek.
Ivanti EPMM customers have been warned of CVE-2023-35081, a second zero-day vulnerability that has been exploited in targeted attacks.
The post Second Ivanti EPMM Zero-Day Vulnerability Exploited in Targeted Attacks appeared first on SecurityWeek.
CISA has shared analysis reports on three malware families obtained from an organization hacked via a recent Barracuda ESG vulnerability.
The post CISA Analyzes Malware Used in Barracuda ESG Attacks appeared first on SecurityWeek.
US and Australian government agencies provide guidance on addressing access control vulnerabilities in web applications.
The post US, Australia Issue Warning Over Access Control Vulnerabilities in Web Applications appeared first on SecurityWeek.
Weekly cybersecurity news roundup that provides a summary of noteworthy stories that might have slipped under the radar for the week of July 24, 2023.
The post In Other News: Data Breach Cost Rises, Russia Targets Diplomats, Tracker Alerts in Android appeared first on SecurityWeek.
The first attempts to exploit CVE-2023-24489, a recent critical Citrix ShareFile remote code execution vulnerability, have been observed.
The post Exploitation of Recent Citrix ShareFile RCE Vulnerability Begins appeared first on SecurityWeek.
Several industry professionals comment on the SEC’s new cybersecurity incident disclosure rules and their implications.
The post Industry Reactions to New SEC Cyber Incident Disclosure Rules: Feedback Friday appeared first on SecurityWeek.
Zimbra has released patches for a cross-site scripting (XSS) vulnerability that has been exploited in malicious attacks.
The post Zimbra Patches Exploited Zero-Day Vulnerability appeared first on SecurityWeek.
CoinsPaid says North Korean hacking group Lazarus is likely responsible for the recent theft of $37 million in cryptocurrency.
The post CoinsPaid Blames North Korean Hackers for $37 Million Cryptocurrency Heist appeared first on SecurityWeek.
Several vulnerabilities found in Weintek Weincloud could have allowed hackers to manipulate and damage ICS, including PLCs and field devices.
The post Weintek Weincloud Vulnerabilities Allowed Manipulation, Damaging of ICS Devices appeared first on SecurityWeek.
Redmond is accused of “negligent cybersecurity practices” that enabled a successful Chinese hack of the United States government.
The post US Senator Wyden Accuses Microsoft of ‘Cybersecurity Negligence’ appeared first on SecurityWeek.
Threat intelligence services provider QuoIntelligence has raised €5 million ($5.5 million) in seed funding.
The post European Threat Intelligence Firm QuoIntelligence Raises $5.5 Million in Seed Funding appeared first on SecurityWeek.
CISA Director Jen Easterly says more is needed to defend the integrity and resiliency of the election process ahead of the 2024 election.
The post Head of US Cybersecurity Agency Sees Progress on Election Security, With More Work Needed for 2024 appeared first on SecurityWeek.
The TSA has released updated cybersecurity requirements for pipeline owners and operators, instructing them to test assessment and incident response plans.
The post TSA Updates Pipeline Cybersecurity Requirements appeared first on SecurityWeek.
Internet-connected Peloton workout equipment is impacted by multiple security risks, such as having USB debugging enabled.
The post Multiple Security Issues Identified in Peloton Fitness Equipment appeared first on SecurityWeek.
Thinking through the good, the bad, and the ugly now is a process that affords us “the negative focus to survive, but a positive one to thrive."
The post The Good, the Bad and the Ugly of Generative AI appeared first on SecurityWeek.
Researchers discovered two vulnerabilities in the Ubuntu OverlayFS module: CVE-2023-2640 and CVE-2023-32629 (together dubbed ‘GameOver(lay)’).
The post Two New Vulnerabilities Could Affect 40% of Ubuntu Cloud Workloads appeared first on SecurityWeek.
Canadian medical software provider CardioComm has taken systems offline to contain a cyberattack.
The post CardioComm Takes Systems Offline Following Cyberattack appeared first on SecurityWeek.
An Axis network door controller vulnerability can be exploited to target facilities, exposing them to both physical and cyber threats.
The post Axis Door Controller Vulnerability Exposes Facilities to Physical, Cyber Threats appeared first on SecurityWeek.
Maximus Inc says that the personal information of 8 to 11 million individuals was stolen in the MOVEit cyberattack.
The post Up to 11 Million People Hit by MOVEit Hack at Government Services Firm Maximus appeared first on SecurityWeek.
The SEC has adopted new rules requiring public companies to disclose cybersecurity breaches that have a material impact within four days.
The post SEC Says Companies Must Disclose Cybersecurity Incidents Within 4 Days appeared first on SecurityWeek.
Researchers say a whopping 62 percent of AWS environments may be exposed to the newly documented AMD 'Zenbleed' information leak flaw.
The post Wiz Says 62% of AWS Environments Exposed to Zenbleed Exploitation appeared first on SecurityWeek.
The Biden administration has nominated former Navy commander Harry Coker to replace the retired Chris Inglis.
The post Ex-NSA Official Harry Coker Tapped for National Cyber Director Job appeared first on SecurityWeek.
Cyclops emerges from stealth mode with $6.4 million in seed funding and a generative AI-powered cybersecurity search platform.
The post Cyclops Emerges From Stealth With Security Search Platform Powered by Generative AI appeared first on SecurityWeek.
Fortinet has published details on a series of critical- and high-severity vulnerabilities in the Microsoft Message Queuing service.
The post Microsoft Message Queuing Vulnerabilities Allow Remote Code Execution, DoS Attacks appeared first on SecurityWeek.
The Akira ransomware operators claim to have compromised 63 organizations since March 2023, mostly SMBs.
The post Dozens of Organizations Targeted by Akira Ransomware appeared first on SecurityWeek.
Russia has sentenced Ilya Sachkov, co-founder of the Group-IB cybersecurity firm, to 14 years in prison on treason charges.
The post Russian Cybersecurity Firm Founder Jailed for 14 Years appeared first on SecurityWeek.
Over 900,000 devices are impacted by an arbitrary code execution vulnerability in MikroTik RouterOS.
The post Code Execution Vulnerability Impacts 900k MikroTik Devices appeared first on SecurityWeek.
SecurityWeek talks to Field CISOs, Fawaz Rasheed (VMware Carbon Black) and Nabil Hannan (NetSPI), about this emerging role.
The post CISO Conversations: Field CISOs From VMware Carbon Black and NetSPI appeared first on SecurityWeek.
Join SecurityWeek and TXOne Networks for this webinar as we expose common misconceptions surrounding the security of Operational Technology (OT) and dive into the evolving threat landscape.
The post Webinar Tomorrow: Exposing Common Myths of OT Cybersecurity appeared first on SecurityWeek.
The NHL Stenden University of Applied Sciences in the Netherlands has launched MCAD, the Maritime Cyber Attack Database.
The post Maritime Cyberattack Database Launched by Dutch University appeared first on SecurityWeek.
TETRA:BURST - vulnerabilities in widely used radio standard could threaten military and law enforcement communications, as well as ICS.
The post TETRA Radio Standard Vulnerabilities Can Expose Military Comms, Industrial Systems appeared first on SecurityWeek.
French aerospace, defense, and security giant Thales is acquiring cybersecurity firm Imperva from Thoma Bravo in a $3.6 billion deal.
The post Thales Acquiring Imperva From Thoma Bravo for $3.6 Billion appeared first on SecurityWeek.
AMD has released microcode patches to address Zenbleed, a vulnerability in its Zen 2 CPUs that can allow an attacker to access sensitive information.
The post AMD CPU Vulnerability ‘Zenbleed’ Can Expose Sensitive Information appeared first on SecurityWeek.
An Ivanti EPMM product zero-day vulnerability tracked as CVE-2023-35078 has been exploited in an attack aimed at the Norwegian government.
The post Ivanti Zero-Day Vulnerability Exploited in Attack on Norwegian Government appeared first on SecurityWeek.
Apple patches another zero-day flaw used in the 'Operation Triangulation' exploit chain. iOS and macOS-powered devices are affected.
The post Apple Patches Another Kernel Flaw Exploited in ‘Operation Triangulation’ Attacks appeared first on SecurityWeek.
100% key capture rate and successful ransomware decryption shows progress in ransomware defense capabilities.
The post Nubeva’s Ransomware Key Interception and Decryption Technology Validated in Third-Party Lab appeared first on SecurityWeek.
Privacy management solutions provider OneTrust raises $150 million at a $4.5 billion valuation.
The post OneTrust Raises $150 Million at $4.5 Billion Valuation appeared first on SecurityWeek.
Sharing threat information and cooperating with other threat intelligence groups helps to strengthen customer safeguards and boosts the effectiveness of the cybersecurity sector overall.
The post Cybersecurity Public-Private Partnership: Where Do We Go Next? appeared first on SecurityWeek.
Experts believe the Cl0p ransomware gang could earn as much as $100 million from the MOVEit hack, with the number of confirmed victims approaching 400.
The post MOVEit Hack Could Earn Cybercriminals $100M as Number of Confirmed Victims Grows appeared first on SecurityWeek.
Amir Golshan, of Los Angeles, pleaded guilty to perpetrating multiple cybercrime schemes using SIM swapping.
The post Los Angeles SIM Swapper Pleads Guilty to Cybercrime Charges appeared first on SecurityWeek.
Over 20,000 appliances are vulnerable to a new exploit technique targeting a recent Citrix ADC zero-day vulnerability CVE-2023-3519.
The post Over 20,000 Citrix Appliances Vulnerable to New Exploit appeared first on SecurityWeek.
Atlassian patches high-severity remote code execution vulnerabilities in Confluence and Bamboo products.
The post Atlassian Patches Remote Code Execution Vulnerabilities in Confluence, Bamboo appeared first on SecurityWeek.
Cybersecurity firm Perimeter81 appears to have botched the responsible disclosure process for a privilege escalation vulnerability found in its macOS application.
The post Perimeter81 Vulnerability Disclosed After Botched Disclosure Process appeared first on SecurityWeek.
The China-linked cyberspy group APT31 is believed to be behind a data-theft campaign targeting industrial organizations in Eastern Europe.
The post Industrial Organizations in Eastern Europe Targeted by Chinese Cyberspies appeared first on SecurityWeek.
Cloud security researcher warns that stolen Microsoft signing key was more powerful and not limited to Outlook.com and Exchange Online.
The post Microsoft Cloud Hack Exposed More Than Exchange, Outlook Emails appeared first on SecurityWeek.
Weekly cybersecurity news roundup that provides a summary of noteworthy stories that might have slipped under the radar for the week of July 17, 2023.
The post In Other News: Military Emails Leaked, Google Restricts Internet Access, Chinese Spyware appeared first on SecurityWeek.
A Russian prosecutor requested an 18-year prison sentence for Ilya Sachkov, founder of cybersecurity firm Group-IB.
The post Russia Seeks 18 Years in Jail for Founder of Cybersecurity Firm appeared first on SecurityWeek.
Google has created a dedicated AI Red Team tasked with carrying out complex technical attacks on artificial intelligence systems.
The post Google Creates Red Team to Test Attacks Against AI Systems appeared first on SecurityWeek.
Three vulnerabilities in Apache OpenMeetings could be exploited by attackers to take over an administrator account and execute arbitrary code remotely.
The post OpenMeetings Flaws Allow Hackers to Hijack Instances, Execute Code on Servers appeared first on SecurityWeek.
VirusTotal has provided clarifications on the recent data leak that resulted in the exposure of information on 5,600 of the threat analysis service’s customers.
The post VirusTotal Provides Clarifications on Data Leak Affecting Premium Accounts appeared first on SecurityWeek.
Amazon, Google, Meta, Microsoft, OpenAI and other tech firms have voluntary agreed to AI safeguards set by the White House.
The post Tech Titans Promise Watermarks to Expose AI Creations appeared first on SecurityWeek.
North Korean hackers are targeting employees at technology firms with repository invitations and malicious NPM packages.
The post GitHub Warns of North Korean Social Engineering Attacks Targeting Tech Firm Employees appeared first on SecurityWeek.
Tampa General Hospital has started informing patients that their personal information was stolen in a ransomware attack.
The post Tampa General Hospital Says Patient Information Stolen in Ransomware Attack appeared first on SecurityWeek.
CISA says the new Citrix zero day vulnerability tracked as CVE-2023-3519 has been exploited against a critical infrastructure organization.
The post Citrix Zero-Day Exploited Against Critical Infrastructure Organization appeared first on SecurityWeek.
Two new serious vulnerabilities in AMI BMC, which is used by millions of devices, can allow attackers to take control of systems and cause physical damage.
The post New AMI BMC Flaws Allowing Takeover and Physical Damage Could Impact Millions of Devices appeared first on SecurityWeek.
SentinelOne has linked the recent JumpCloud cyberattack to North Korean hackers, based on the published IoCs.
The post JumpCloud Cyberattack Linked to North Korean Hackers appeared first on SecurityWeek.
Estée Lauder has confirmed suffering a data breach just as two ransomware groups claimed to have targeted the company, both allegedly stealing vast amounts of information.
The post Cosmetics Giant Estée Lauder Targeted by Two Ransomware Groups appeared first on SecurityWeek.
While traditional security awareness teaches users how to recognize social engineering, new behavior changing trains the brain on the correct recognition and response to phishing.
The post Human Cyber-Risk Can Be Demonstrably Mitigated by Behavior Changing Training: Analysis appeared first on SecurityWeek.
Multiple DDoS botnets have been observed targeting CVE-2023-28771, a Zyxel firewall vulnerability patched in April.
The post Multiple DDoS Botnets Exploiting Recent Zyxel Vulnerability appeared first on SecurityWeek.
The Rust-based peer-to-peer worm ‘P2PInfect’ is targeting a Lua sandbox escape vulnerability in internet-accessible Redis servers.
The post P2PInfect: New Peer-to-Peer Worm Targeting Redis Servers appeared first on SecurityWeek.
Securing APIs is a noble, though complex journey. Security teams can leverage these 10 steps to help secure their APIs.
The post 10 Steps to Help Secure Your APIs appeared first on SecurityWeek.
The recently discovered SophosEncrypt ransomware is impersonating the cybersecurity firm Sophos.
The post New Ransomware With RAT Capabilities Impersonating Sophos appeared first on SecurityWeek.
Adobe releases a second round of patches for recent ColdFusion vulnerabilities, including flaws that have been exploited in attacks.
The post Adobe Releases New Patches for Exploited ColdFusion Vulnerabilities appeared first on SecurityWeek.
Famed hacker Kevin Mitnick has died after a battle with pancreatic cancer. At the time of his death, he was Chief Hacking Officer at security awareness training firm KnowBe4.
The post Famed Hacker Kevin Mitnick Dead at 59 appeared first on SecurityWeek.
Facing intense pressure after Chinese APT hack, Microsoft plans to expand logging defaults for lower-tier M365 customers.
The post Microsoft Bows to Pressure to Free Up Cloud Security Logs appeared first on SecurityWeek.
Norwegian recycling giant Tomra says internal systems have been taken offline to contain an extensive cyberattack.
The post Recycling Giant Tomra Takes Systems Offline Following Cyberattack appeared first on SecurityWeek.
Attackers are exploiting two path traversal vulnerabilities in the Stagil navigation for Jira – Menus & Themes plugin.
The post Two Jira Plugin Vulnerabilities in Attacker Crosshairs appeared first on SecurityWeek.
Register for the Cloud & Data Security Summit to learn how to utilize tools, controls, and design models needed to properly secure cloud environments.
The post Virtual Event Today: 2023 Cloud & Data Security Summit appeared first on SecurityWeek.
Over a dozen vulnerabilities patched by GE in its Cimplicity HMI/SCADA product are reminiscent of ICS attacks conducted by the Russian Sandworm group.
The post Recently Patched GE Cimplicity Vulnerabilities Reminiscent of Russian ICS Attacks appeared first on SecurityWeek.
Security awareness training isn’t working to the level it needs to. Social engineering, however, is getting better. Why doesn’t awareness training work, and how can we improve it?
The post Security Awareness Training Isn’t Working – How Can We Improve It? appeared first on SecurityWeek.
Oracle has released 508 new security patches as part of the July 2023 CPU, including more than 70 that address critical vulnerabilities
The post Oracle Releases 508 New Security Patches With July 2023 CPU appeared first on SecurityWeek.
Citrix has patched several vulnerabilities, including CVE-2023-3519, a critical remote code execution zero-day that has been exploited in attacks.
The post Exploitation of New Citrix Zero-Day Likely to Increase, Organizations Warned appeared first on SecurityWeek.
Chrome 115 released with patches for 20 vulnerabilities, including 11 reported by external researchers, who earned thousands of dollars in bug bounties.
The post Chrome 115 Patches 20 Vulnerabilities appeared first on SecurityWeek.
The two foreign companies are being sanctioned for “for trafficking in cyber exploits used to gain access to information systems.”
The post US Gov Mercenary Spyware Clampdown Hits Cytrox, Intellexa appeared first on SecurityWeek.
The NSA and CISA have published guidance on hardening 5G standalone network slices against potential threats.
The post NSA, CISA Issue Guidance on 5G Network Slicing Security appeared first on SecurityWeek.
Olalekan Jacob Ponle, a Nigerian national living in the UAE, was sentenced to 8 years in a US prison for his role in an $8 million BEC scheme.
The post Nigerian Man Sentenced to 8 Years in US Prison for $8 Million BEC Scheme appeared first on SecurityWeek.
A threat actor’s real identity was uncovered after they infected their own computer with an information stealer.
The post Black Hat Hacker Exposes Real Identity After Infecting Own Computer With Malware appeared first on SecurityWeek.
Attackers have started exploiting CVE-2023-28121, a recent critical vulnerability in the WooCommerce Payments WordPress plugin.
The post WordPress Sites Hacked via Critical Vulnerability in WooCommerce Payments Plugin appeared first on SecurityWeek.
New US cyber program will label smart devices that are considered safer and less vulnerable to attacks.
The post White House Unveils Cybersecurity Labeling Program for Smart Devices appeared first on SecurityWeek.
Daniel Kelley was just 18 years old when he was arrested and charged on thirty counts – most infamously for the 2015 hack of UK telecoms firm TalkTalk. In 2019 he was convicted and sentenced to four years in prison.
The post Hacker Conversations: Inside the Mind of Daniel Kelley, ex-Blackhat appeared first on SecurityWeek.
The British company secures $100 million in funding and announced the hiring of a new chief executive to pursue global expansion plans.
The post Netcraft Raises $100M, Hires New CEO for Global Expansion appeared first on SecurityWeek.
At least two new Adobe ColdFusion vulnerabilities have been exploited in the wild, including one that has not been completely patched by the software giant.
The post Two New Adobe ColdFusion Vulnerabilities Exploited in Attacks appeared first on SecurityWeek.
Norway's data protection agency wants to ban Facebook and Instagram owner Meta from using the personal information of users for targeted advertising, threatening a $100,000 daily fine if the company continues.
The post Norway Threatens $100,000 Daily Fine on Meta Over Data appeared first on SecurityWeek.
While silos pose significant dangers to an enterprise's cybersecurity posture, consolidation serves as a powerful solution to overcome these risks, offering improved visibility, efficiency, incident response capabilities, and risk management.
The post Embracing Consolidation and Squashing Silos appeared first on SecurityWeek.
Conor Brian Fitzpatrick, the owner of the infamous cybercrime website BreachForums, has pleaded guilty in a US court.
The post Owner of Cybercrime Website BreachForums Pleads Guilty appeared first on SecurityWeek.
JumpCloud says a sophisticated nation-state threat actor breached its systems, targeting specific customers.
The post JumpCloud Says Sophisticated Nation-State Targeted Specific Customers appeared first on SecurityWeek.
The number of entities impacted by the MOVEit hack — either directly or indirectly — reportedly exceeds 340 organizations and 18 million individuals.
The post MOVEit Hack: Number of Impacted Organizations Exceeds 340 appeared first on SecurityWeek.
An analysis conducted by SecurityWeek shows that more than 210 cybersecurity-related mergers and acquisitions were announced in the first half of 2022.
The post SecurityWeek Analysis: Over 210 Cybersecurity M&A Deals Announced in First Half of 2023 appeared first on SecurityWeek.
Adobe patches critical code execution vulnerability in ColdFusion for which a proof-of-concept (PoC) blog exists.
The post Exploitation of ColdFusion Vulnerability Reported as Adobe Patches Another Critical Flaw appeared first on SecurityWeek.
Weekly cybersecurity news roundup that provides a summary of noteworthy stories that might have slipped under the radar for the week of July 10, 2023.
The post In Other News: Security Firm Hit by Investor Lawsuit, Satellite Hacking, Cloud Attacks appeared first on SecurityWeek.
SaaS management platform Zluri has raised $20 million in a Series B funding round led by Lightspeed.
The post Zluri Raises $20 Million for SaaS Management Platform appeared first on SecurityWeek.
Feedback Friday: industry professionals comment on the implications of the recently approved EU-US Data Privacy Framework.
The post Industry Reactions to EU-US Data Privacy Framework: Feedback Friday appeared first on SecurityWeek.
A critical vulnerability in the Cisco SD-WAN vManage software could allow unauthenticated attackers to retrieve information from vulnerable instances.
The post Critical Cisco SD-WAN Vulnerability Leads to Information Leaks appeared first on SecurityWeek.
Secure Code Warrior has raised $50 million in Series C funding to further empower developers to address code vulnerabilities.
The post Secure Code Warrior Raises $50 Million to Help Developers Write Secure Code appeared first on SecurityWeek.
Several instances of the Reddit alternative Lemmy were hacked in recent days by attackers who had exploited a zero-day vulnerability.
The post Hackers Target Reddit Alternative Lemmy via Zero-Day Vulnerability appeared first on SecurityWeek.
The Biden-Harris administration has laid out the plan for implementing the National Cybersecurity Strategy.
The post US Publishes Implementation Plan for National Cybersecurity Strategy appeared first on SecurityWeek.
Google researchers have discovered that a Zimbra zero-day vulnerability has been exploited in the wild, with users being advised to manually patch their installations.
The post Google Researchers Discover In-the-Wild Exploitation of Zimbra Zero-Day appeared first on SecurityWeek.
QuickBlox SDK and API vulnerabilities impact chat and video applications used by industries including telemedicine, smart IoT, and finance.
The post API Flaw in QuickBlox Framework Exposed PII of Millions of Users appeared first on SecurityWeek.
The planned Oort purchase is Cisco’s fourth acquisition of a cybersecurity company in the first half of 2023.
The post Cisco Shopping Spree Adds Oort ID Threat Detection Tech appeared first on SecurityWeek.
The source code for the BlackLotus UEFI bootkit has been leaked on GitHub and an expert has issued a warning over the risks.
The post BlackLotus UEFI Bootkit Source Code Leaked on GitHub appeared first on SecurityWeek.
Cybersecurity company Armis has identified several vulnerabilities in Honeywell ICS products that could expose industrial organizations to attacks.
The post Honeywell DCS Platform Vulnerabilities Can Facilitate Attacks on Industrial Organizations appeared first on SecurityWeek.
A group of congressional Democrats reported that three large tax preparation firms sent “extraordinarily sensitive” information on tens of millions of taxpayers to Facebook parent company Meta over the course of at least two years.
The post 3 Tax Prep Firms Shared ‘Extraordinarily Sensitive’ Data About Taxpayers With Meta, Lawmakers Say appeared first on SecurityWeek.
The All-In-One Security (AIOS) WordPress plugin was found to be writing plaintext passwords to log files.
The post Popular WordPress Security Plugin Caught Logging Plaintext Passwords appeared first on SecurityWeek.
Juniper Networks has patched multiple high-severity vulnerabilities in Junos OS, Junos OS Evolved, and Junos Space.
The post Juniper Networks Patches High-Severity Vulnerabilities in Junos OS appeared first on SecurityWeek.
Apple has re-released its Rapid Security Response updates for iOS and macOS after fixing a website access issue caused by the original patches.
The post Apple Re-Releases Urgent Zero-Day Patches With Fix for Website Access Issue appeared first on SecurityWeek.
SonicWall patches four critical-severity vulnerabilities in its Global Management System (GMS) and Analytics products.
The post SonicWall Patches Critical Vulnerabilities in GMS, Analytics Products appeared first on SecurityWeek.
Two Rockwell Automation product vulnerabilities have been used for a new exploit by an APT group that could use it to target critical infrastructure.
The post APT Exploit Targeting Rockwell Automation Flaws Threatens Critical Infrastructure appeared first on SecurityWeek.
Orca Security sues its main rival, claiming patent infringements, intellectual property theft and even marketing copycat behavior.
The post Orca Sues Wiz Over Alleged Cloud Security Patent Violations appeared first on SecurityWeek.
Multiple hardcoded accounts on the Technicolor TG670 DSL gateway router can be used to completely take over the impacted devices.
The post Hardcoded Accounts Allow Full Takeover of Technicolor Routers appeared first on SecurityWeek.
Bugcrowd’s Inside the Mind of the Hacker report shows the speed and efficiency of hackers adopting new technologies to assist their hunting
The post Inside the Mind of the Hacker: Report Shows Speed and Efficiency of Hackers in Adopting New Technologies appeared first on SecurityWeek.
Microsoft says a Chinese cyberespionage group tracked as Storm-0558 has used forged authentication tokens to access government emails.
The post Chinese Cyberspies Used Forged Authentication Tokens to Hack Government Emails appeared first on SecurityWeek.
SecurityWeek talks to Dennis Kallelis (CSO at Idemia) and Jason Kees (CISO at Ping), two of industry’s identity giants. The idea, as always, is to discuss the role of the modern CISO.
The post CISO Conversations: CISOs of Identity Giants IDEMIA and Ping appeared first on SecurityWeek.
Citrix has patched a critical-severity vulnerability in Secure Access client for Ubuntu that could lead to remote code execution (RCE).
The post Citrix Patches Critical Vulnerability in Secure Access Client for Ubuntu appeared first on SecurityWeek.
Fortinet patches a critical-severity vulnerability in FortiOS and FortiProxy that could lead to remote code execution.
The post Fortinet Patches Critical FortiOS Vulnerability Leading to Remote Code Execution appeared first on SecurityWeek.
Microsoft has revoked signed drivers used for post-exploitation activity, in many cases by Chinese cybercriminals.
The post Microsoft Revokes Many Signed Drivers Used by Chinese Cybercriminals appeared first on SecurityWeek.
The need for cyber resilience arises from the growing realization that traditional security measures are no longer enough to protect systems, data, and the network from compromise.
The post MOVEit: Testing the Limits of Supply Chain Security appeared first on SecurityWeek.
SAP on July 2023 Security Patch Day released 16 new security notes, including one addressing a critical vulnerability in ECC and S/4HANA (IS-OIL).
The post SAP Patches Critical Vulnerability in ECC and S/4HANA Products appeared first on SecurityWeek.
Former security engineer Shakeeb Ahmed has been arrested on charges related to the defrauding of decentralized crypto exchange Crema Finance.
The post Former Security Engineer Arrested for $9 Million Crypto Exchange Hack appeared first on SecurityWeek.
Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.
The post Microsoft Warns of Office Zero-Day Attacks, No Patch Available appeared first on SecurityWeek.
Apple has pulled its latest Rapid Security Response updates for iOS and macOS after users complained that they can no longer access websites.
The post Apple’s Rapid Security Response Patches Are Breaking Websites appeared first on SecurityWeek.
Savvy emerges from stealth mode with $30 million in funding, on path to secure the use of software-as-a-service (SaaS) applications.
The post SaaS Application Security Firm Savvy Exits Stealth Mode With $30 Million in Funding appeared first on SecurityWeek.
Software maker calls special attention to CVE-2023-29300, a deserialization of untrusted data bug with a CVSS severity score of 9.8/10.
The post Adobe Patch Tuesday: Critical Flaws Haunt InDesign, ColdFusion appeared first on SecurityWeek.
ICS Patch Tuesday: Siemens and Schneider Electric release nine new security advisories and fix 50 vulnerabilities in their industrial products.
The post ICS Patch Tuesday: Siemens, Schneider Electric Fix 50 Vulnerabilities appeared first on SecurityWeek.
Signing code is very important to defend against supply chain attacks, but it’s also one of the most cumbersome to implement for internal development.
The post Verifying Software Integrity With Sigstore appeared first on SecurityWeek.
HCA Healthcare says the personal information of roughly 11 million patients was stolen in a data breach.
The post Personal Information of 11 Million Patients Stolen in Data Breach at HCA Healthcare appeared first on SecurityWeek.
A recent RomCom cyber operation has been targeting NATO Summit guests and other entities supporting Ukraine.
The post Russia-Linked RomCom Hackers Targeting NATO Summit Guests appeared first on SecurityWeek.
Apple rolls out urgent iOS and iPadOS software updates and warned that zero-day exploitation has already been detected.
The post Apple Ships Urgent iOS Patch for WebKit Zero-Day appeared first on SecurityWeek.
VMware confirmed that exploit code for CVE-2023-20864 has been published, underscoring the urgency for enterprise network admins to apply available patches.
The post Exploit Code Published for Remote Root Flaw in VMware Logging Software appeared first on SecurityWeek.
The EU signed off on a new agreement over the privacy of people’s personal information that gets pinged across the Atlantic, aiming to ease European concerns about electronic spying by American intelligence agencies.
The post Europe Signs Off on a New Privacy Pact That Allows People’s Data to Keep Flowing to US appeared first on SecurityWeek.
Private equity giant plans to buy Forcepoint’s Global Governments and Critical Infrastructure (G2CI) business unit for $2.5 billion.
The post TPG to Acquire Forcepoint’s Government Cybersecurity Business Unit appeared first on SecurityWeek.
Critical infrastructure services provider Ventia has taken some systems offline following a cyberattack.
The post Critical Infrastructure Services Firm Ventia Takes Systems Offline Due to Cyberattack appeared first on SecurityWeek.
Assuming NATO can play a greater part in the cybersecurity of its members, possibly through a more formal NATO Cyber Command, the question then becomes ‘what should we hope for?’
The post A Cybersecurity Wish List Ahead of NATO Summit appeared first on SecurityWeek.
Industrial giant Honeywell wants to extend its OT cybersecurity portfolio with the acquisition of Israel-based OT/IoT security firm SCADAfence.
The post Honeywell Boosting OT Cybersecurity Offering With Acquisition of SCADAfence appeared first on SecurityWeek.
PoC exploit has been published for a recently patched Ubiquiti EdgeRouter vulnerability leading to arbitrary code execution.
The post PoC Exploit Published for Recent Ubiquiti EdgeRouter Vulnerability appeared first on SecurityWeek.
A critical vulnerability in the Mastodon social networking platform may allow attackers to take over target servers.
The post Critical Vulnerability Can Allow Takeover of Mastodon Servers appeared first on SecurityWeek.
Facing ransomware zero-days, Progress Software will release regular service packs to help customers mitigate critical security flaws.
The post After Zero-Day Attacks, MOVEit Turns to Security Service Packs appeared first on SecurityWeek.
Weekly cybersecurity news roundup that provides a summary of noteworthy stories that might have slipped under the radar for the week of July 3, 2023.
The post In Other News: Healthcare Product Flaws, Free Email Security Testing, New Attack Techniques appeared first on SecurityWeek.
Former contractor employee charged with hacking for accessing the systems of a water treatment facility in California to delete critical software.
The post Former Contractor Employee Charged for Hacking California Water Treatment Facility appeared first on SecurityWeek.
In May 2023, Iran-linked cyberespionage group Charming Kitten targeted a US-based think tank with new macOS malware.
The post Iranian Cyberspies Target US-Based Think Tank With New macOS Malware appeared first on SecurityWeek.
Potentially serious vulnerabilities discovered by researchers in a PiiGAB product could expose industrial organizations to remote hacker attacks.
The post Vulnerabilities in PiiGAB Product Could Expose Industrial Organizations to Attacks appeared first on SecurityWeek.
SwSec 5D framework aims to provide a roadmap for secure software development, and its use would help improve security in the software supply chain.
The post OWASP SwSec 5D Tool Provides SDLC Maturity Ratings, Aids Software Supply Chain appeared first on SecurityWeek.
Cyble has discovered more than 130,000 Photovoltaic monitoring and diagnostic solutions exposed to the internet.
The post Security Firm Finds Over 130k Internet-Exposed Photovoltaic Diagnostics Systems appeared first on SecurityWeek.
Two applications hosted on Google Play, with over 1.5 million combined downloads, were caught sending user data to servers in China.
The post Two Apps Hosted on Google Play Caught Sending User Data to Chinese Servers appeared first on SecurityWeek.
Hackers linked to the Truebot malware are exploiting a year-old Netwrix Auditor flaw to break into organizations in the U.S. and Canada.
The post Truebot Hackers Exploiting Netwrix Auditor Flaw: CISA, FBI Alert appeared first on SecurityWeek.
What a cloud migration strategy did for cloud adoption, an automation implementation strategy does for security automation adoption.
The post Now’s the Time for a Pragmatic Approach to New Technology Adoption appeared first on SecurityWeek.
JumpCloud is responding to an incident that has triggered a reset of all API keys in order to protect customers and their operations.
The post JumpCloud Says All API Keys Invalidated to Protect Customers appeared first on SecurityWeek.
Google’s July 2023 security updates for Android patches 43 vulnerabilities, including three exploited in the wild.
The post Android Security Updates Patch 3 Exploited Vulnerabilities appeared first on SecurityWeek.
The personal, financial, and health information of over 28,000 individuals stolen in data breach at Pepsi Bottling Ventures.
The post 28,000 Impacted by Data Breach at Pepsi Bottling Ventures appeared first on SecurityWeek.
Shell confirms that employee personal information has been stolen after the Cl0p ransomware group leaked data allegedly stolen from the energy giant.
The post Shell Confirms MOVEit-Related Breach After Ransomware Group Leaks Data appeared first on SecurityWeek.
A new Linux kernel vulnerability tracked as StackRot and CVE-2023-3269 shows the exploitability of use-after-free-by-RCU (UAFBR) bugs.
The post StackRot Linux Kernel Vulnerability Shows Exploitability of UAFBR Bugs appeared first on SecurityWeek.
Law enforcement authorities have arrested a suspected senior member of the French-speaking Opera1er cybercrime group.
The post Interpol: Key Member of Major Cybercrime Group Arrested in Africa appeared first on SecurityWeek.
Cisco says a high-severity vulnerability in Nexus 9000 series switches could allow attackers to intercept and modify encrypted traffic.
The post Vulnerability in Cisco Enterprise Switches Allows Attackers to Modify Encrypted Traffic appeared first on SecurityWeek.
Infisical banks $2.8 million in seed funding as investors continue to bet on companies in the software supply chain security space.
The post Infisical Snags $2.8M Seed Funding for Secrets Sprawl Security Tech appeared first on SecurityWeek.
Japan’s Port of Nagoya this week suspended cargo loading and unloading operations following a ransomware attack.
The post Japan’s Nagoya Port Suspends Cargo Operations Following Ransomware Attack appeared first on SecurityWeek.
An actively exploited vulnerability in the Contec SolarView solar power monitoring product can expose hundreds of energy organizations to attacks.
The post Exploited Solar Power Product Vulnerability Could Expose Energy Organizations to Attacks appeared first on SecurityWeek.
Sweden has ordered four companies to stop using a Google tool that measures and analyses web traffic as doing so transfers personal data to the United States, fining one company the equivalent of more than $1.1 million.
The post Sweden Orders Four Companies to Stop Using Google Tool appeared first on SecurityWeek.
Ransomware gangs are targeting schools, stealing confidential documents and then dumping them online.
The post Ransomware Criminals Are Dumping Kids’ Private Files Online After School Hacks appeared first on SecurityWeek.
Mozilla has released Firefox 115 to the stable channel with patches for two high-severity use-after-free vulnerabilities.
The post Firefox 115 Patches High-Severity Use-After-Free Vulnerabilities appeared first on SecurityWeek.
Twenty-three cybersecurity-related merger and acquisition (M&A) deals were announced in June 2023.
The post Cybersecurity M&A Roundup: 23 Deals Announced in June 2023 appeared first on SecurityWeek.
Facebook, Instagram and WhatsApp may need to overhaul how they collect the data of users in Europe after the top EU court ruled against Meta.
The post EU Court Deals Blow to Meta in German Data Case appeared first on SecurityWeek.
VMware partners with tech giants to accelerate the development of confidential computing applications.
The post VMware, Other Tech Giants Announce Push for Confidential Computing Standards appeared first on SecurityWeek.
Fears mount that UK Online Safety Bill may include a requirement for an encrypted message scanning capability.
The post Apple, Civil Liberty Groups Condemn UK Online Safety Bill appeared first on SecurityWeek.
Cait Conley will coordinate with federal, state and local officials responsible for ensuring elections are secure ahead of the 2024 presidential election.
The post Army Combat Veteran to Take Over Key Election Security Role Working With State, Local Officials appeared first on SecurityWeek.
Weekly cybersecurity news roundup that provides a summary of noteworthy stories that might have slipped under the radar for the week of June 26, 2023.
The post In Other News: Hospital Infected via USB Drive, EU Cybersecurity Rules, Free Security Tools appeared first on SecurityWeek.
Attackers exploit critical vulnerability in the Ultimate Member plugin to create administrative accounts on WordPress websites.
The post 200,000 WordPress Sites Exposed to Attacks Exploiting Flaw in ‘Ultimate Member’ Plugin appeared first on SecurityWeek.
CISA adds 6 Samsung mobile device flaws to its known exploited vulnerabilities catalog and they have likely been exploited by a spyware vendor.
The post Samsung Phone Flaws Added to CISA ‘Must Patch’ List Likely Exploited by Spyware Vendor appeared first on SecurityWeek.
Use-after-free and OS command injection vulnerabilities reach the top five most dangerous software weaknesses in the 2023 CWE Top 25 list.
The post MITRE Updates CWE Top 25 Most Dangerous Software Weaknesses appeared first on SecurityWeek.
Proton makes its open source Proton Pass password manager globally available for major browsers and mobile devices.
The post Proton Launches Open Source Password Manager appeared first on SecurityWeek.
LockBit ransomware group claims to have hacked TSMC and is asking for a $70 million ransom, but the chip giant says only a supplier was breached.
The post TSMC Says Supplier Hacked After Ransomware Group Claims Attack on Chip Giant appeared first on SecurityWeek.
New York startup $30 million in new financing to fuel plans to take advantage of the demand for AI-powered threat-intel security tools.
The post Cyware Snags $30M for Threat Intel Infrastructure Tech appeared first on SecurityWeek.
Rapid7 analyzes the Japan threat landscape and warns that attacks against the third-largest economy in the world have global consequences.
The post Rapid7: Japan Threat Landscape Takes on Global Significance appeared first on SecurityWeek.
IP Fabric raises $25 million in new financing to build technology in the enterprise network assurance space.
The post IP Fabric Raises $25 Million in Series B Funding appeared first on SecurityWeek.
Details have been disclosed for critical SAP vulnerabilities, including a wormable exploit chain, that can expose organizations to attacks.
The post Details Disclosed for Critical SAP Vulnerabilities, Including Wormable Exploit Chain appeared first on SecurityWeek.
Researchers publish PoC for a high-severity authentication bypass vulnerability in the Arcserve UDP data backup solution.
The post Serious Vulnerability Exposes Admin Interface of Arcserve UDP Backup Solution appeared first on SecurityWeek.
Ann Dunkin, CIO at the Department of Energy, is more concerned about cyberattack speed than attack type or source.
The post DOE CIO Talks to SecurityWeek About Cybersecurity, Digital Transformation appeared first on SecurityWeek.
Tel Aviv startup scores investment to build technology to secure in-house low-code/no-code custom applications.
The post Nokod Snags $8M to Secure Low Code/No-Code Custom Apps appeared first on SecurityWeek.
The framework helps evaluate the effectiveness of obfuscation side-channel mitigation schemes against data leaks.
The post New MIT Framework Evaluates Side-Channel Attack Mitigations appeared first on SecurityWeek.
The White House has released a memorandum outlining the cybersecurity investment priorities for government departments and agencies for fiscal year 2025.
The post White House Outlines Cybersecurity Budget Priorities for Fiscal 2025 appeared first on SecurityWeek.
New guidance from CISA and the NSA provides recommendations on securing CI/CD pipelines against malicious attacks.
The post CISA, NSA Share Guidance on Securing CI/CD Environments appeared first on SecurityWeek.
More victims of the MOVEit hack have come to light, with a total of over 130 organizations and 15 million people believed to be affected.
The post Over 130 Organizations, Millions of Individuals Believed to Be Impacted by MOVEit Hack appeared first on SecurityWeek.
New York startup scores early stage financing to build new technology to replace virtual desktop infrastructure.
The post Venn Software Snags $29M to build MDM for Laptops Technology appeared first on SecurityWeek.
The 8Base ransomware gang has hit roughly 30 small businesses over the past month, reaching a total of approximately 80 victims since March 2022.
The post Dozens of Businesses Hit Recently by ‘8Base’ Ransomware Gang appeared first on SecurityWeek.
Ask any three people to define cyberwar and you will get three different answers. But as global geopolitics worsen and aggressive cyberattacks increase, this becomes more than an academic question.
The post What is Cyberwar? appeared first on SecurityWeek.
Invary has raised $1.85 million in a pre-seed funding round led by Flyover Capital to launch its runtime integrity solution.
The post Invary Raises $1.85 Million in Pre-Seed Funding for Runtime Integrity Solution appeared first on SecurityWeek.
Astrix Security raises $25 million in Series A funding for its solution designed to help enterprises secure non-human identities.
The post Astrix Raises $25 Million to Help Enterprises Secure App-to-App Connections appeared first on SecurityWeek.
Recorded Future underlines threats to submarine telecommunication cables, such as the risk of intentional sabotage and spying by nation-state threat actors.
The post Submarine Cables at Risk of Nation-State Sabotage, Spying: Report appeared first on SecurityWeek.
The official Call for Presentations for SecurityWeek’s 2023 ICS Cybersecurity Conference, being held October 23-26, 2023 at the InterContinental Atlanta is open through Friday, June 30, 2023.
The post Reminder: CFP for ICS Cybersecurity Conference Closes June 30th appeared first on SecurityWeek.
Emails, phone numbers, calls logs, and collected messages stolen in data breach at Android stalkware LetMeSpy.
The post Sensitive Information Stolen in LetMeSpy Stalkerware Hack appeared first on SecurityWeek.
Energy giants Schneider Electric and Siemens Energy confirm being targeted by the Cl0p ransomware group in the campaign exploiting a MOVEit zero-day.
The post Siemens Energy, Schneider Electric Targeted by Ransomware Group in MOVEit Attack appeared first on SecurityWeek.
Malicious applications with over 30,000 installs in Google Play have infected Android devices with the Anatsa banking trojan.
The post Anatsa Banking Trojan Delivered via Google Play Targets Android Users in US, Europe appeared first on SecurityWeek.
Philippine police backed by commandos staged a massive raid and rescued more than 2,700 workers who were allegedly swindled into working for cybercrime groups.
The post 2,700 People Tricked Into Working for Cybercrime Syndicates Rescued in Philippines appeared first on SecurityWeek.
HashiCorp acquires BluBracket secrets-scanning technology to help businesses block accidental leaks and fight secret sprawl.
The post HashiCorp Buys BluBracket for Secrets Scanning Tech appeared first on SecurityWeek.
Cyera closes a massive $100 million round as investors continue to pour cash into the data security posture management (DSPM) space.
The post Data Security Firm Cyera Attracts $100M Investment appeared first on SecurityWeek.
BeeKeeperAI has raised $12.1 million in Series A funding for a secure collaboration platform designed for AI development on healthcare and other sensitive data.
The post BeeKeeperAI Platform for AI Development on Sensitive Data Receives $12M in Funding appeared first on SecurityWeek.
Patented.ai has raised $4 million in pre-seed funding to help organizations protect sensitive information from artificial intelligence.
The post Patented.ai Raises $4 Million for AI Data Privacy Solution appeared first on SecurityWeek.
Investigations triggered by the cracking of encrypted phones three years ago have led to more than 6,500 arrests worldwide and the seizure of hundreds of tons of drugs.
The post 3-Year Probe Into Encrypted Phones Led to Seizure of Hundreds of Tons of Drugs, Prosecutors Say appeared first on SecurityWeek.
Identity verification solutions provider Socure has acquired automated ID verification firm Berbix for roughly $70 million in cash and stock.
The post Socure Acquires ID Verification Company Berbix for $70 Million appeared first on SecurityWeek.
Censys identified hundreds of devices within US federal agencies’ networks that expose their management interface to the internet.
The post Hundreds of Devices With Internet-Exposed Management Interface Found in US Agencies appeared first on SecurityWeek.
CalypsoAI is building tools to help “accelerate trust and governance” in enterprise adoption of AI and machine learning technologies.
The post CalypsoAI Raises $23 Million for AI Security Tech appeared first on SecurityWeek.
Google says it handed out $35,000 in bug bounty rewards for three high-severity vulnerabilities in Chrome 114.
The post Chrome 114 Update Patches High-Severity Vulnerabilities appeared first on SecurityWeek.
Some services at Petro-Canada gas stations have been disrupted following a cyberattack on parent company Suncor, one of North America’s largest energy companies.
The post Gas Stations Impacted by Cyberattack on Canadian Energy Giant Suncor appeared first on SecurityWeek.
The personal information of American Airlines and Southwest Airlines pilots was exposed in a data breach at a third-party services provider.
The post American Airlines, Southwest Airlines Impacted by Data Breach at Third-Party Provider appeared first on SecurityWeek.
Fortinet releases patches for a critical FortiNAC vulnerability leading to remote code execution without authentication.
The post Fortinet Patches Critical RCE Vulnerability in FortiNAC appeared first on SecurityWeek.
UK national Joseph James O’Connor was sentenced to five years in a US prison for hacking into Twitter accounts and stealing cryptocurrency.
The post British Twitter Hacker Sentenced to Prison in US appeared first on SecurityWeek.
CISA has warned users of Zyxel NAS products that the recently patched critical vulnerability CVE-2023-27992 has been exploited in attacks.
The post CISA Says Critical Zyxel NAS Vulnerability Exploited in Attacks appeared first on SecurityWeek.
The latest BIND updates address three high-severity, remotely exploitable vulnerabilities leading to denial-of-service (DoS).
The post Remotely Exploitable DoS Vulnerabilities Patched in BIND appeared first on SecurityWeek.
The National Security Agency (NSA) has released mitigation guidance to help organizations stave off BlackLotus UEFI bootkit infections.
The post NSA Issues Guidance on Mitigating BlackLotus Bootkit Infections appeared first on SecurityWeek.
Weekly cybersecurity news roundup that provides a summary of noteworthy stories that might have slipped under the radar for the week of June 19, 2023.
The post In Other News: Microsoft Win32 App Isolation,Tsunami Hits Linux Servers, ChatGPT Credentials Exposed on Dark Web appeared first on SecurityWeek.
The US government's cybersecurity agency adds VMware and Roundcube server flaws to its Known Exploited Vulnerabilities (KEV) catalog.
The post CISA Tells US Agencies to Patch Exploited Roundcube, VMware Flaws appeared first on SecurityWeek.
VMware published software updates to address multiple memory corruption vulnerabilities in vCenter Server that could lead to remote code execution.
The post VMware Patches Code Execution Vulnerabilities in vCenter Server appeared first on SecurityWeek.
MOVEit hack: Personal information of about 769,000 retired California employees and 2.5 million Genworth Financial policyholders were exposed.
The post 2.5M Genworth Policyholders and 769K Retired California Workers and Beneficiaries Affected by Hack appeared first on SecurityWeek.
Google CEO pledged $20 million in donations to support and expand the Consortium of Cybersecurity Clinics to introduce thousands of students to potential careers in cybersecurity
The post Google Backs Creation of Cybersecurity Clinics With $20 Million Donation appeared first on SecurityWeek.
The US army says soldiers says unsolicited, suspicious smartwatches are being sent to soldiers, exposing them to malware attacks.
The post US Military Personnel Receiving Unsolicited, Suspicious Smartwatches appeared first on SecurityWeek.
A Chinese hacking group flagged as APT15 is targeting foreign affairs ministries in the Americas with a new backdoor named Graphican.
The post China-Linked APT15 Targets Foreign Ministries With ‘Graphican’ Backdoor appeared first on SecurityWeek.
A hacking group linked to the North Korean government has been caught using new malware with microphone wiretapping capabilities.
The post North Korean Hackers Caught Using Malware With Microphone Wiretapping Capabilities appeared first on SecurityWeek.
A security researcher has published proof-of-concept (PoC) exploit code targeting a recent high-severity vulnerability (CVE-2023-20178) in Cisco AnyConnect Secure.
The post PoC Exploit Published for Cisco AnyConnect Secure Vulnerability appeared first on SecurityWeek.
Incorporating Red Zone threat intelligence into your security strategy will help you stay on top of the latest threats and better protect your organization.
The post The Benefits of Red Zone Threat Intelligence appeared first on SecurityWeek.
A new bill proposes to increase cybersecurity funding for rural water systems by $7.5 million dollars per year.
The post Bipartisan Bill Proposes Cybersecurity Funds for Rural Water Systems appeared first on SecurityWeek.
Apple ships major iOS security updates to cover code execution vulnerabilities already exploited in the wild.
The post Apple Patches iOS Flaws Used in Kaspersky ‘Operation Triangulation’ appeared first on SecurityWeek.
Digitalization brings new security challenges, new concerns, and new threats, and CISOs should not think that it’s just business as usual.
The post CISOs’ New Stressors Brought on by Digitalization: Report appeared first on SecurityWeek.
China's security and surveillance industry is focused on shoring up its vulnerabilities to the US and other outside actors, worried about risks posed by hackers, advances in AI and pressure from rival governments.
The post Cooperation or Competition? China’s Security Industry Sees the US, Not AI, as the Bigger Threat appeared first on SecurityWeek.
Two critical-severity authentication bypass vulnerabilities in WordPress plugins with tens of thousands of installations.
The post Critical WordPress Plugin Vulnerabilities Impact Thousands of Sites appeared first on SecurityWeek.
Russian anti-malware vendor shares technical details on spyware implant deployed as part of recent zero-click iMessage attacks.
The post Kaspersky Dissects Spyware Used in iOS Zero-Click Attacks appeared first on SecurityWeek.
Enphase Energy has ignored CISA requests to fix remotely exploitable vulnerabilities in Enphase products.
The post Enphase Ignores CISA Request to Fix Remotely Exploitable Flaws appeared first on SecurityWeek.
SecurityWeek talks to Chief Information Security Officers from Bill.com, FreedomPay, and Tassat about their role and experience as CISOs.
The post CISO Conversations: Three Leading CISOs From the Payment Industry appeared first on SecurityWeek.
New National Security Cyber Section will help the US disrupt and prosecute nation-state threat actors and state-sponsored cybercriminals.
The post DOJ Launches Cyber Unit to Prosecute Nation-State Threat Actors appeared first on SecurityWeek.
Why are there so many vulnerabilities in Chrome? Is it realistically safe to use? Can Google do anything to make the web browser safer?
The post Chrome and Its Vulnerabilities – Is the Web Browser Safe to Use? appeared first on SecurityWeek.
The Biden administration wants to figure out how to regulate AI, looking for ways to nurture its potential for economic growth and national security and protect against its potential dangers.
The post Biden Discusses Risks and Promises of Artificial Intelligence With Tech Leaders in San Francisco appeared first on SecurityWeek.
VMware updates a critical-level bulletin: “VMware has confirmed that exploitation of CVE-2023-20887 has occurred in the wild.”
The post VMware Confirms Live Exploits Hitting Just-Patched Security Flaw appeared first on SecurityWeek.
Businesses using ‘Log in with Microsoft’ could be exposed to privilege escalation and full account takeover exploits.
The post Researchers Flag Account Takeover Flaw in Microsoft Azure AD OAuth Apps appeared first on SecurityWeek.
A Russian hacking group has been caught hacking into Roundcube servers to spy on government institutions and military entities in Ukraine.
The post Russian APT Group Caught Hacking Roundcube Email Servers appeared first on SecurityWeek.
Gen Digital, which owns Avast, Avira, AVG, Norton, and LifeLock, said employee data was compromised in the MOVEit ransomware attack.
The post Norton Parent Says Employee Data Stolen in MOVEit Ransomware Attack appeared first on SecurityWeek.
Forescout Technologies has disclosed the details of vulnerabilities impacting operational technology (OT) products from Wago and Schneider Electric.
The post OT:Icefall: Vulnerabilities Identified in Wago Controllers appeared first on SecurityWeek.
Bitdefender finds new malware capable of monitoring incoming RDP connections and infect the connecting clients that have client drive mapping enabled.
The post New ‘RDStealer’ Malware Targets RDP Connections appeared first on SecurityWeek.
Nobody doubts the need to increase board level cyber expertise, but there is no single preferred route.
The post Fulfilling Expected SEC Requirements for Cybersecurity Expertise at Board Level appeared first on SecurityWeek.
The Office of the Australian Information Commissioner (OAIC) says some of its files were stolen in a ransomware attack on law firm HWL Ebsworth.
The post Australian Government Says Its Data Was Stolen in Law Firm Ransomware Attack appeared first on SecurityWeek.
Asus patches nine WiFi router security defects, including a highly critical 2018 vulnerability that exposes users to code execution attacks.
The post Asus Patches Highly Critical WiFi Router Flaws appeared first on SecurityWeek.
A new information stealer malware named Mystic Stealer is gaining traction among cybercriminals on prominent underground forums.
The post New Information Stealer ‘Mystic Stealer’ Rising to Fame appeared first on SecurityWeek.
Western Digital is blocking access to its cloud services for devices running firmware versions impacted by a critical security vulnerability.
The post Western Digital Blocks Unpatched Devices From Cloud Services appeared first on SecurityWeek.
New SaaS-based secrets manager from Akeyless requires no new infrastructure, and no specialist staff nor secrets management team.
The post Akeyless Launches SaaS-based External Secrets Manager appeared first on SecurityWeek.
The Alphv/BlackCat ransomware gang has taken responsibility for the February cyberattack that hit social media site Reddit.
The post Ransomware Gang Takes Credit for February Reddit Hack appeared first on SecurityWeek.
Security vendor consolidation is picking up steam with good reason. Everyone wants to improve security efficiency and effectiveness while paying for less.
The post Keep it, Tweak it, Trash it – What to do with Aging Tech in an Era of Consolidation appeared first on SecurityWeek.
All panel discussions and technical presentations from SecurityWeek's 2023 CISO Forum are available to watch free on demand.
The post Watch on Demand: 2023 CISO Forum Sessions appeared first on SecurityWeek.
A critical vulnerability (CVE-2023-35708) in MOVEit software could allow unauthenticated attackers to access database content.
The post MOVEit Customers Urged to Patch Third Critical Vulnerability appeared first on SecurityWeek.
Early June 2023 disruptions to Microsoft’s flagship office suite were Layer 7 DDoS attacks by a shadowy new hacktivist group dubbed Storm-1359 by Microsoft.
The post Microsoft Says Early June Disruptions to Outlook, Cloud Platform, Were Cyberattacks appeared first on SecurityWeek.
Cybersecurity news that you may have missed this week: Bug bounties for Linux kernel exploits, Cybersecurity Awareness Act, FBI data on BEC losses.
The post In Other News: Linux Kernel Exploits, Update on BEC Losses, Cybersecurity Awareness Act appeared first on SecurityWeek.
The US charges Russian national Ruslan Magomedovich Astamirov over his alleged role in LockBit ransomware attacks.
The post Russian National Arrested, Charged in US Over Role in LockBit Ransomware Attacks appeared first on SecurityWeek.
Russia-linked hacking group Gamaredon is infecting USB drives for lateral movement within compromised Ukrainian networks.
The post Russian Hackers Using USB-Spreading Malware in Attacks on Ukrainian Government, Military appeared first on SecurityWeek.
The Cl0p ransomware gang has listed more than two dozen victims of the MOVEit zero-day attack on its leak website.
The post Ransomware Group Starts Naming Victims of MOVEit Zero-Day Attacks appeared first on SecurityWeek.
CISA and the NSA have published new guidance to help organizations harden baseboard management controllers (BMCs).
The post CISA, NSA Share Guidance on Hardening Baseboard Management Controllers appeared first on SecurityWeek.
Investors pour $15 million into Silicon Valley startup building AI-powered technology to detect and monitor harmful content on the internet.
The post Content Moderation Tech Startup Trust Lab Snags $15M Investment appeared first on SecurityWeek.
Shift5 has now raised $108 million in funding to bring cybersecurity to OT within fleet vehicles: planes and boats and trains – and military vehicles and weapon systems.
The post OT Security Firm Shift5 Adds $33 Million in Funding appeared first on SecurityWeek.
Microsoft addressed two cross-site scripting (XSS) vulnerabilities in Azure Bastion and Azure Container Registry (ACR) leading to unauthorized access to user sessions.
The post XSS Vulnerabilities in Azure Led to Unauthorized Access to User Sessions appeared first on SecurityWeek.
Attacks exploiting the Barracuda zero-day CVE-2023-2868 have been linked to a Chinese cyberespionage group that has targeted government and other organizations.
The post Barracuda Zero-Day Attacks Attributed to Chinese Cyberespionage Group appeared first on SecurityWeek.
Cybersecurity startup SquareX launches a temporary bug bounty program for its cloud-based browser security solution.
The post SquareX Launches Bug Bounty Program for Browser Security Product appeared first on SecurityWeek.
Fake security researcher accounts seen distributing malware disguised as Chrome, Signal, WhatsApp, Discord and Exchange zero-day exploits.
The post Fake Security Researcher Accounts Pushing Malware Disguised as Zero-Day Exploits appeared first on SecurityWeek.
If you want to begin, or improve, sharing customized intelligence with key users, consider these four aspects as you develop your process.
The post Four Things to Consider as You Mature Your Threat Intel Program appeared first on SecurityWeek.
LockBit ransomware operators launched 1,700 attacks in the US and received roughly $91 million in ransom payments.
The post US Organizations Paid $91 Million to LockBit Ransomware Gang appeared first on SecurityWeek.
Authorities worldwide are racing to rein in artificial intelligence, including in the European Union, where groundbreaking legislation is set to pass a key hurdle.
The post How Europe is Leading the World in the Push to Regulate AI appeared first on SecurityWeek.
Microsoft is publicly exposing a Russian hacking group that worked on destructive wiper malware attacks that hit organizations in Ukraine.
The post Microsoft Outs New Russian APT Linked to Wiper Attacks in Ukraine appeared first on SecurityWeek.
CISA’s Binding Operational Directive 23-02 requires federal agencies to secure the network management interfaces of certain classes of devices.
The post CISA Instructs Federal Agencies to Secure Internet-Exposed Devices appeared first on SecurityWeek.
Hundreds of thousands of ecommerce sites are impacted by a critical vulnerability in the WooCommerce Stripe Payment Gateway plugin.
The post Hundreds of Thousands of eCommerce Sites Impacted by Critical Plugin Vulnerability appeared first on SecurityWeek.
Detection-focused threat intelligence firm Silent Push, which maps out the entire internet every day, has launched with $10 million in seed funding.
The post Threat Intelligence Firm Silent Push Launches With $10 Million in Seed Funding appeared first on SecurityWeek.
Google has released a Chrome 114 security update to address five vulnerabilities, including a critical-severity bug in Autofill payments.
The post Chrome 114 Update Patches Critical Vulnerability appeared first on SecurityWeek.
SAP has released eight new security notes on June 2023 Security Patch Day, including two that address high-severity vulnerabilities.
The post SAP Patches High-Severity Vulnerabilities With June 2023 Security Updates appeared first on SecurityWeek.
ICS Patch Tuesday: Siemens and Schneider Electric have published more than a dozen advisories addressing over 200 vulnerabilities.
The post ICS Patch Tuesday: Siemens Addresses Over 180 Third-Party Component Vulnerabilities appeared first on SecurityWeek.
Music streaming giant Spotify was fined 58 million kronor ($5.4 million) for not properly informing users on how data it collected on them was being used, Swedish authorities said.
The post Spotify Fined $5 Million for Breaching EU Data Rules appeared first on SecurityWeek.
Patch Tuesday: Microsoft ships updates to over at least 70 documented vulnerabilities affecting the Windows ecosystem.
The post Microsoft Patches Critical Windows Vulns, Warn of Code Execution Risks appeared first on SecurityWeek.
Mandiant has observed a Chinese cyberespionage group exploiting a VMware ESXi zero-day vulnerability for privilege escalation.
The post Chinese Cyberspies Caught Exploiting VMware ESXi Zero-Day appeared first on SecurityWeek.
Adobe ships urgent fixes for at least a dozen flaws that expose Adobe Commerce users to code execution attacks.
The post Patch Tuesday: Critical Flaws in Adobe Commerce Software appeared first on SecurityWeek.
The Russia-linked ICS malware named CosmicEnergy does not pose a direct threat to OT systems as it contains errors and lacks maturity.
The post CosmicEnergy ICS Malware Poses No Immediate Threat, but Should Not Be Ignored appeared first on SecurityWeek.
SecurityWeek’s 2023 CISO Forum Virtual Summit is taking place June 13-14 as a fully immersive online experience.
The post Virtual Event Today: CISO Forum 2023 – Register to Join appeared first on SecurityWeek.
A Romanian national who operated a bulletproof hosting service used by malware operators was sentenced to prison in the US.
The post Romanian Operator of Bulletproof Hosting Service Sentenced to Prison in US appeared first on SecurityWeek.
New research conducted by IOActive shows the potential of electromagnetic fault injection (EMFI) attacks against drones.
The post New Research Shows Potential of Electromagnetic Fault Injection Attacks Against Drones appeared first on SecurityWeek.
St. Margaret’s Health in Illinois is shutting down hospitals partly due to a 2021 ransomware attack that caused serious payment system disruptions.
The post Ransomware Attack Played Major Role in Shutdown of Illinois Hospital appeared first on SecurityWeek.
A database containing the personal information of roughly 9 million Zacks users has emerged online.
The post Data of 8.8 Million Zacks Users Emerges Online appeared first on SecurityWeek.
Fortinet has warned customers that the critical CVE-2023-27997 vulnerability that was patched recently could be a zero-day exploited in limited attacks.
The post Fortinet Warns Customers of Possible Zero-Day Exploited in Limited Attacks appeared first on SecurityWeek.
OMB has published new guidance on federal agencies obtaining security guarantees from software vendors.
The post US Government Provides Guidance on Software Security Guarantee Requirements appeared first on SecurityWeek.
Two Russian nationals are charged in the US with hacking a cryptocurrency exchange and conspiring to launder the proceeds.
The post US Charges Russians With Hacking Cryptocurrency Exchange appeared first on SecurityWeek.
Intellihartx says the personal information of roughly 490,000 individuals was compromised in the GoAnywhere zero-day attack earlier this year.
The post Intellihartx Informs 490k Patients of GoAnywhere-Related Data Breach appeared first on SecurityWeek.
By having a golden image you will put a process in place that allows you to quickly take action when a vulnerability is found within your organization.
The post Software Supply Chain: The Golden Container Ship appeared first on SecurityWeek.
Researchers discover new MOVEit vulnerabilities related to the zero-day, just as more organizations hit by the attack are coming forward.
The post New MOVEit Vulnerabilities Found as More Zero-Day Attack Victims Come Forward appeared first on SecurityWeek.
Switzerland said government operational data might have been stolen in a ransomware attack on a technology firm that provides software for several departments.
The post Swiss Fear Government Data Stolen in Cyberattack appeared first on SecurityWeek.
Fortinet has patched CVE-2023-27997, a critical FortiGate SSL VPN vulnerability that can be exploited for unauthenticated remote code execution.
The post Fortinet Patches Critical FortiGate SSL VPN Vulnerability appeared first on SecurityWeek.
Cybersecurity news that you may have missed this week: AI regulation, layoffs, US aerospace malware attacks, and post-quantum encryption.
The post In Other News: AI Regulation, Layoffs, US Aerospace Attacks, Post-Quantum Encryption appeared first on SecurityWeek.
Blackpoint Cyber raises $190 million in a growth funding round led by Bain Capital Tech Opportunities.
The post Blackpoint Raises $190 Million to Help MSPs Combat Cyber Threats appeared first on SecurityWeek.
The Google SAIF (Secure AI Framework) is designed to provide a security framework or ecosystem for the development, use and protection of AI systems.
The post Google Introduces SAIF, a Framework for Secure AI Development and Use appeared first on SecurityWeek.
ESET has linked several cybercrime and espionage campaigns to a threat actor tracked as Asylum Ambuscade.
The post ‘Asylum Ambuscade’ Group Hit Thousands in Cybercrime, Espionage Campaigns appeared first on SecurityWeek.
Evidence suggests that the Cl0p ransomware group has known about and conducted tests with the recently patched MOVEit zero-day since mid-2021.
The post Evidence Suggests Ransomware Group Knew About MOVEit Zero-Day Since 2021 appeared first on SecurityWeek.
A SaaS ransomware attack against a company’s Sharepoint Online was done without using a compromised endpoint.
The post SaaS Ransomware Attack Hit Sharepoint Online Without Using a Compromised Endpoint appeared first on SecurityWeek.
Google Cloud is offering up to $1 million in financial protection to cover expenses associated with undetected cryptomining attacks.
The post Google Cloud Now Offering $1 Million Cryptomining Protection appeared first on SecurityWeek.
As it pushes to renew a cornerstone law that authorizes major surveillance programs, the Biden administration faces an American public that’s broadly skeptical of common intelligence practices and of the need to sacrifice civil liberties for security.
The post Democrats and Republicans Are Skeptical of US Spying Practices, an AP-NORC Poll Finds appeared first on SecurityWeek.
Instead of deploying new point products, CISOs should consider sourcing technologies from vendors that develop products designed to work together as part of a platform.
The post Consolidate Vendors and Products for Better Security appeared first on SecurityWeek.
Japanese pharmaceutical company Eisai says it has taken systems offline after falling victim to a ransomware attack.
The post Pharmaceutical Giant Eisai Takes Systems Offline Following Ransomware Attack appeared first on SecurityWeek.
Vulnerabilities found by a researcher in a Honda ecommerce platform used for equipment sales exposed customer and dealer information.
The post Vulnerabilities in Honda eCommerce Platform Exposed Customer, Dealer Data appeared first on SecurityWeek.
Researchers believe North Korea-linked Lazarus Group has stolen at least $35 million in cryptocurrency from Atomic Wallet.
The post North Korean Hackers Blamed for $35 Million Atomic Wallet Crypto Theft appeared first on SecurityWeek.
Cisco releases fixes for a critical-severity vulnerability in Expressway series and TelePresence Video Communication Server (VCS).
The post Cisco Patches Critical Vulnerability in Enterprise Collaboration Solutions appeared first on SecurityWeek.
Barracuda Networks is telling customers to immediately replace hacked ESG email security appliances regardless of the patches they installed.
The post Barracuda Urges Customers to Replace Hacked Email Security Appliances appeared first on SecurityWeek.
The Cl0p cyber-extortion gang’s hack of the MOVEit file-transfer program popular with enterprises could have widespread global impact.
The post BBC, British Airways, Novia Scotia Among First Big-Name Victims in Global Supply-Chain Hack appeared first on SecurityWeek.
Sysdig is launching what it claims to be the first CNAPP with end-to-end detection and response, consolidating CNAPP and CDR.
The post Sysdig Introduces CNAPP With Realtime CDR appeared first on SecurityWeek.
Staying the course and sticking to strategic goals allows security professionals to steadily and continually improve the security posture of their organization.
The post Stay Focused on What’s Important appeared first on SecurityWeek.
VMware ships urgent patches to cover security defects that expose businesses to remote code execution attacks.
The post VMware Plugs Critical Flaws in Network Monitoring Product appeared first on SecurityWeek.
The Clop ransomware gang issued "an ultimatum" companies targeted in a recent large-scale hack of payroll data
The post Hackers Issue ‘Ultimatum’ Over Payroll Data Breach appeared first on SecurityWeek.
US and Israeli government agencies have published new guidance on preventing malicious exploitation of remote access software.
The post US, Israel Provide Guidance on Securing Remote Access Software appeared first on SecurityWeek.
OWASP’s ranking for the major API security risks in 2023 has been published. The list includes many parallels with the 2019 list, some reorganizations/redefinitions, and some new concepts.
The post OWASP’s 2023 API Security Top 10 Refines View of API Risks appeared first on SecurityWeek.
Google’s June 2023 security update for Android patches more than 50 vulnerabilities, including an Arm Mali GPU flaw exploited by spyware vendors.
The post Android’s June 2023 Security Update Patches Exploited Arm GPU Vulnerability appeared first on SecurityWeek.
Researchers show how ChatGPT/AI hallucinations can be exploited to distribute malicious code packages to unsuspecting software developers.
The post ChatGPT Hallucinations Can Be Exploited to Distribute Malicious Code Packages appeared first on SecurityWeek.
Blumira raises $15 million in Series B funding and launches a new XDR platform for small and medium-sized businesses (SMBs).
The post Blumira Raises $15 Million for SMB-Tailored XDR Platform appeared first on SecurityWeek.
Microsoft will pay a fine of $20 million to settle FTC charges that it illegally collected the data of children who signed up for Xbox.
The post Microsoft Will Pay $20M to Settle US Charges of Illegally Collecting Children’s Data appeared first on SecurityWeek.
KeePass 2.54 patches a vulnerability allowing attackers to retrieve the cleartext master password from a memory dump.
The post KeePass Update Patches Vulnerability Exposing Master Password appeared first on SecurityWeek.
AntChain has teamed up with Intel for a Massive Data Privacy-Preserving Computing Platform (MAPPIC) for AI machine learning.
The post AntChain, Intel Create New Privacy-Preserving Computing Platform for AI Training appeared first on SecurityWeek.
Keep Aware scores seed investment to build a human-centric browser security platform that provides protection against browser-based attacks.
The post Keep Aware Raises $2.4M to Eliminate Browser Blind Spots appeared first on SecurityWeek.
Google Workspace now offers support for passwordless authentication using passkeys, in beta.
The post Google Workspace Gets Passkey Authentication appeared first on SecurityWeek.
French cybersecurity startup Elba raises €2.5 million ($2.6 million) to help organizations identify their employees’ security issues.
The post Cybersecurity Startup Elba Raises €2.5 Million for Employee-Focused Product appeared first on SecurityWeek.
New options allow paid Zoom customers to specify certain data for meetings, webinars, and team chat to be stored within the EEA.
The post Zoom Expands Privacy Options for European Customers appeared first on SecurityWeek.
Major companies have confirmed being impacted by the recent MOVEit zero-day attack, including BBC, British Airways and Zellis.
The post Several Major Organizations Confirm Being Impacted by MOVEit Attack appeared first on SecurityWeek.
Apple on Monday detailed new privacy and security features rolling out to both desktop and mobile users.
The post Apple Unveils Upcoming Privacy and Security Features appeared first on SecurityWeek.
Verizon’s 16th annual Data Breach Investigations Report (DBIR) provides data on ransomware costs, the frequency of human error in breaches, and BEC trends.
The post Verizon 2023 DBIR: Human Error Involved in Many Breaches, Ransomware Cost Surges appeared first on SecurityWeek.
Google has released a Chrome 114 security update that patches CVE-2023-3079, the third zero-day vulnerability patched in the browser in 2023.
The post Google Patches Third Chrome Zero-Day of 2023 appeared first on SecurityWeek.
Security researchers have identified over 30 malicious extensions with millions of installs in the Chrome web store.
The post Dozens of Malicious Extensions Found in Chrome Web Store appeared first on SecurityWeek.
If we should face a Dead-End AI future, the cybersecurity industry will continue to rely heavily on traditional approaches, especially human-driven ones. It won’t quite be business as usual though.
The post What if the Current AI Hype Is a Dead End? appeared first on SecurityWeek.
Microsoft is making SMB signing a default requirement in Windows 11 Enterprise editions, starting with insider preview build 25381.
The post Microsoft Makes SMB Signing Default Requirement in Windows 11 to Boost Security appeared first on SecurityWeek.
Zyxel urges customers to update ATP, USG Flex, VPN, and ZyWALL/USG firewalls to prevent exploitation of recent vulnerabilities.
The post Zyxel Urges Customers to Patch Firewalls Against Exploited Vulnerabilities appeared first on SecurityWeek.
Gigabyte has announced BIOS updates that remove a recently identified backdoor feature in hundreds of its motherboards.
The post Gigabyte Rolls Out BIOS Updates to Remove Backdoor From Motherboards appeared first on SecurityWeek.
If after eighteen months, meaningful use of SBOMs is unachievable, we need to ask what needs to be done to fulfill Biden’s executive order.
The post SBOMs – Software Supply Chain Security’s Future or Fantasy? appeared first on SecurityWeek.
The recent MOVEit zero-day attack has been linked to a known ransomware group, which reportedly stole data from dozens of organizations.
The post Ransomware Group Used MOVEit Exploit to Steal Data From Dozens of Organizations appeared first on SecurityWeek.
Thirty-six cybersecurity-related merger and acquisition (M&A) deals were announced in May 2023.
The post Cybersecurity M&A Roundup: 36 Deals Announced in May 2023 appeared first on SecurityWeek.
Shift5 founder Josh Lospinoso discusses AI and how software vulnerabilities in weapons systems are a major threat to the U.S. military.
The post Insider Q&A: Artificial Intelligence and Cybersecurity In Military Tech appeared first on SecurityWeek.
Cybersecurity news that you may have missed this week: the spyware used by various governments, new vulnerabilities, industrial security products, and Linux router attacks.
The post In Other News: Government Use of Spyware, New Industrial Security Tools, Japan Router Hack appeared first on SecurityWeek.
OpenAI plans to shell out $1 million in grants for projects that empower defensive use-cases for generative AI technology.
The post OpenAI Unveils Million-Dollar Cybersecurity Grant Program appeared first on SecurityWeek.
Los Angeles startup Galvanick scores $10 million seed capital to build a modern industrial detection and response platform.
The post Galvanick Banks $10 Million for Industrial XDR Technology appeared first on SecurityWeek.
Point32Health says the personal and protected health information of 2.5 million Harvard Pilgrim Health Care subscribers was stolen in a recent ransomware attack.
The post Information of 2.5M People Stolen in Ransomware Attack at Massachusetts Health Insurer appeared first on SecurityWeek.
The US and Korea are warning of North Korean social engineering attacks targeting employees of think tanks, academic and research institutions, and news media organizations.
The post US, South Korea Detail North Korea’s Social Engineering Techniques appeared first on SecurityWeek.
Splunk has resolved multiple high-severity vulnerabilities in Splunk Enterprise, including bugs in third-party packages used by the product.
The post High-Severity Vulnerabilities Patched in Splunk Enterprise appeared first on SecurityWeek.
Two eastern Idaho hospitals and their clinics are working to resume full operations after a cyberattack on their computer systems.
The post Idaho Hospitals Working to Resume Full Operations After Cyberattack appeared first on SecurityWeek.
Enzo Biochem says the clinical test information of roughly 2.47 million individuals was exposed in a recent ransomware attack.
The post Enzo Biochem Ransomware Attack Exposes Information of 2.5M Individuals appeared first on SecurityWeek.
Apple has denied working with any government to add backdoors to its products after Russia accused the company of helping the NSA hack iPhones.
The post Apple Denies Helping US Government Hack Russian iPhones appeared first on SecurityWeek.
A zero-day vulnerability in Progress Software’s MOVEit Transfer product has been exploited to hack organizations and steal their data.
The post Zero-Day in MOVEit File Transfer Software Exploited to Steal Data From Organizations appeared first on SecurityWeek.
Google is offering a bug bounty reward of up to $180,000 for a full chain exploit leading to a sandbox escape in the Chrome browser.
The post Google Temporarily Offering $180,000 for Full Chain Chrome Exploit appeared first on SecurityWeek.
Kaspersky said its corporate network has been targeted with a zero-click iOS exploit, just as Russia's FSB said iPhones have been targeted by US intelligence.
The post Russia Blames US Intelligence for iOS Zero-Click Attacks appeared first on SecurityWeek.
Toyota says improper cloud configurations exposed vehicle and customer information in Japan and overseas for years.
The post Toyota Discloses New Data Breach Involving Vehicle, Customer Information appeared first on SecurityWeek.
Cisco is in the process of acquiring email security firm Armorblox for its predictive and generative artificial intelligence (AI) technology.
The post Cisco Acquiring Armorblox for Predictive and Generative AI Technology appeared first on SecurityWeek.
Critical authentication bypass and high-severity command injection vulnerabilities have been patched in Moxa’s MXsecurity product.
The post Moxa Patches MXsecurity Vulnerabilities That Could Be Exploited in OT Attacks appeared first on SecurityWeek.
The FTC charged Amazon-owned Ring with failing to implement basic protections to stop hackers or employees from accessing people's devices or accounts.
The post Amazon Settles Ring Customer Spying Complaint appeared first on SecurityWeek.
Salesforce ghost sites — domains that are no longer maintained but still accessible — can expose personal information and business data.
The post Organizations Warned of Salesforce ‘Ghost Sites’ Exposing Sensitive Information appeared first on SecurityWeek.
Adobe is inviting security researchers to join its private bug bounty program on the HackerOne platform.
The post Adobe Inviting Researchers to Private Bug Bounty Program appeared first on SecurityWeek.
Faronics patches critical-severity remote code execution (RCE) vulnerabilities in the Insight education software.
The post Critical Vulnerabilities Found in Faronics Education Software appeared first on SecurityWeek.
Chrome 114 stable brings 18 security fixes, including 13 for vulnerabilities reported by external researchers.
The post Chrome 114 Released With 18 Security Fixes appeared first on SecurityWeek.
A backdoor feature found in hundreds of Gigabyte motherboard models can pose a significant supply chain risk to organizations.
The post Organizations Warned of Backdoor Feature in Hundreds of Gigabyte Motherboards appeared first on SecurityWeek.
When teams have a way to break down enterprise silos and see and understand what is happening, they can improve protection across their increasingly dispersed and diverse environment.
The post Breaking Enterprise Silos and Improving Protection appeared first on SecurityWeek.
Security researchers have discovered spyware code in 101 Android applications that had over 421 million downloads in Google Play.
The post Spyware Found in Google Play Apps With Over 420 Million Downloads appeared first on SecurityWeek.
A decade-old critical vulnerability in Jetpack was force-patched on five million WordPress sites over the past few days.
The post Millions of WordPress Sites Patched Against Critical Jetpack Vulnerability appeared first on SecurityWeek.
The recently discovered Barracuda zero-day vulnerability CVE-2023-2868 has been exploited to deliver malware and steal data since at least October 2022.
The post Barracuda Zero-Day Exploited to Deliver Malware for Months Before Discovery appeared first on SecurityWeek.
PyPI will require all accounts that maintain a project to enable two-factor authentication (2FA) by the end of 2023.
The post PyPI Enforcing 2FA for All Project Maintainers to Boost Security appeared first on SecurityWeek.
Dental benefits manager MCNA is informing roughly 9 million individuals that their personal data was compromised in a data breach.
The post Personal Information of 9 Million Individuals Stolen in MCNA Ransomware Attack appeared first on SecurityWeek.
Multiple vulnerabilities in PrinterLogic’s enterprise management printer solution could expose organizations to various types of attacks.
The post Many Vulnerabilities Found in PrinterLogic Enterprise Software appeared first on SecurityWeek.
Industrial giant ABB has confirmed that it has been targeted in a ransomware attack, with the cybercriminals stealing some data.
The post Industrial Giant ABB Confirms Ransomware Attack, Data Theft appeared first on SecurityWeek.
The recently identified Buhti operation uses LockBit and Babuk ransomware variants to target Linux and Windows systems.
The post Organizations Worldwide Targeted in Rapidly Evolving Buhti Ransomware Operation appeared first on SecurityWeek.
Google makes ACME API available to all Google Cloud users to allow them to automatically acquire and renew TLS certificates for free.
The post Google Cloud Users Can Now Automate TLS Certificate Lifecycle appeared first on SecurityWeek.
A Mirai botnet has been exploiting a recently patched vulnerability tracked as CVE-2023-28771 to hack many Zyxel firewalls.
The post Zyxel Firewalls Hacked by Mirai Botnet appeared first on SecurityWeek.
Join thousands of attendees as we dive into threat hunting tools and frameworks, and explore value of threat intelligence data in the defender’s security stack. (Login Now)
The post Watch Now: Threat Detection and Incident Response Virtual Summit appeared first on SecurityWeek.
NCC Group announces new open source tools for finding hardcoded credentials and for distributing cloud workloads.
The post NCC Group Releases Open Source Tools for Developers, Pentesters appeared first on SecurityWeek.
Website impersonation detection and prevention company Memcyco raises $10 million in seed funding.
The post Memcyco Raises $10 Million in Seed Funding to Prevent Website Impersonation appeared first on SecurityWeek.
Mandiant has analyzed a new Russia-linked ICS malware named CosmicEnergy that is designed to cause electric power disruption.
The post New Russia-Linked CosmicEnergy ICS Malware Could Disrupt Electric Grids appeared first on SecurityWeek.
Regardless of the use case your security organization is focused on, you’ll likely waste time and resources and make poor decisions if you don’t start with understanding your threat landscape.
The post Security Pros: Before You Do Anything, Understand Your Threat Landscape appeared first on SecurityWeek.
The second-largest health insurer in Massachusetts was the victim of a ransomware attack in which sensitive personal information as well as health information of current and past members may have been compromised.
The post Major Massachusetts Health Insurer Hit by Ransomware Attack, Member Data May Be Compromised appeared first on SecurityWeek.
Google announces the general availability of ‘rules_oci’ Bazel plugin to improve the security of container images.
The post Google Releases Open Source Bazel Plugin for Container Image Security appeared first on SecurityWeek.
The Alphv/BlackCat ransomware group claims to have stolen more than 1TB of data from Constellation Software.
The post Ransomware Group Claims Attack on Constellation Software appeared first on SecurityWeek.
An XSS vulnerability in the Advanced Custom Fields WordPress plugin exposes more than 2 million sites to attacks.
The post Vulnerability in Field Builder Plugin Exposes Over 2M WordPress Sites to Attacks appeared first on SecurityWeek.
Twitter is informing users that tweets posted to their Circle may have been seen by individuals outside the Circle.
The post Private Tweets Exposed Due to Twitter Circle Security Bug appeared first on SecurityWeek.
NextGen Healthcare is informing roughly 1 million individuals that their personal information was compromised in a data breach.
The post 1 Million Impacted by Data Breach at NextGen Healthcare appeared first on SecurityWeek.
A $1.1 million payment was made to resolve a ransomware attack on San Bernardino county’s law enforcement computer network.
The post $1.1M Paid to Resolve Ransomware Attack on California County appeared first on SecurityWeek.
Western Digital has confirmed that a ransomware group has stolen customer and other information from its systems.
The post Western Digital Confirms Ransomware Group Stole Customer Information appeared first on SecurityWeek.
The French Senate's website was offline on Friday after pro-Russian hackers claimed to have taken it down, in just the latest such cyberattack since Russia invaded Ukraine last year.
The post Pro-Russian Hackers Claim Downing of French Senate Website appeared first on SecurityWeek.
The recently identified Fleckpe Android trojan has infected over 600,000 users in Southeast Asia via Google Play.
The post New Android Trojans Infected Many Devices in Asia via Google Play, Phishing appeared first on SecurityWeek.
Google has announced a new training program for cybersecurity analysts and those who graduate will get a professional certificate from Google.
The post Google Launches New Cybersecurity Analyst Training Program appeared first on SecurityWeek.
Fortinet has released patches for two high-severity vulnerabilities impacting FortiADC, FortiOS, and FortiProxy.
The post Fortinet Patches High-Severity Vulnerabilities in FortiADC, FortiOS appeared first on SecurityWeek.
Vice President Kamala Harris met with the heads of companies developing AI as the Biden administration rolls out initiatives to ensure the technology improves lives without putting people’s rights and safety at risk.
The post Biden, Harris Meet With CEOs About AI Risks appeared first on SecurityWeek.
Three vulnerabilities in the Azure API Management service could be exploited for internal asset access, DoS, firewall bypass, and the upload of malicious files.
The post Azure API Management Vulnerabilities Allowed Unauthorized Access appeared first on SecurityWeek.
A vulnerability in OpenAI’s account validation allowed anyone to obtain virtually unlimited free credit by registering new accounts with the same phone number.
The post Vulnerability Could Have Been Exploited for ‘Unlimited’ Free Credit on OpenAI Accounts appeared first on SecurityWeek.
Siemens recently patched a critical vulnerability affecting some of its energy ICS devices that could allow hackers to destabilize a power grid.
The post Critical Siemens RTU Vulnerability Could Allow Hackers to Destabilize Power Grid appeared first on SecurityWeek.
Google’s latest Android security updates patch over 40 vulnerabilities, including CVE-2023-0266, a kernel flaw exploited as a zero-day by a spyware vendor.
The post Android Security Update Patches Kernel Vulnerability Exploited by Spyware Vendor appeared first on SecurityWeek.
Former Uber security chief Joe Sullivan was sentenced to probation and community service for covering up the data breach suffered by the ride-sharing giant in 2016.
The post Former Uber CSO Joe Sullivan Avoids Prison Time Over Data Breach Cover-Up appeared first on SecurityWeek.
Fraud detection startup Moonsense has raised $4.2 million in a seed funding round co-led by Race Capital and XYZ Ventures.
The post Fraud Detection Startup Moonsense Raises $4.2 Million in Seed Funding appeared first on SecurityWeek.
Data security firm Satori has released a free and open source tool designed to help organizations find out who has access to what data and how.
The post Satori Releases Open Source Data Permissions Scanner for Enterprises appeared first on SecurityWeek.
Microsoft expanded public access to its generative artificial intelligence programs, despite fears that tech firms are rushing ahead too quickly with potentially dangerous technology.
The post Microsoft Expands AI Access to Public appeared first on SecurityWeek.
Given the crippling effects ransomware has had and indications that these types of attacks aren’t slowing down, it makes sense to look to threat intelligence to help.
The post Using Threat Intelligence to Get Smarter About Ransomware appeared first on SecurityWeek.
Meta says it disrupted the new NodeStealer malware, which likely has Vietnamese origins, within weeks after it emerged.
The post Meta Swiftly Neutralizes New ‘NodeStealer’ Malware appeared first on SecurityWeek.
Cisco warns of a critical-severity RCE vulnerability impacting EoL SPA112 2-Port Phone Adapters.
The post Cisco Warns of Critical Vulnerability in EoL Phone Adapters appeared first on SecurityWeek.
The US announces charges against Denis Gennadievich Kulkov, the creator and operator of card-checking platform Try2Check since 2005 until it was taken down this week.
The post US Announces Takedown of Card-Checking Service, Charges Against Russian Operator appeared first on SecurityWeek.
The Biden administration plans to announce an investment of $140 million to establish seven new AI research institutes, administration officials said.
The post Harris to Meet With CEOs About Artificial Intelligence Risks appeared first on SecurityWeek.
Apple has released firmware updates for Beats and AirPods to patch a vulnerability that can be exploited to gain access to headphones via a Bluetooth attack.
The post Apple Releases First-Ever Security Updates for Beats, AirPods Headphones appeared first on SecurityWeek.
Dallas was hit with a ransomware attack that brought down its Police Department and City Hall websites on May 3rd.
The post Ransomware Attack Affects Dallas Police, Court Websites appeared first on SecurityWeek.
Court says insurers must pay Merck for losses related to the Russia-linked NotPetya cyberattack.
The post Court Rules in Favor of Merck in $1.4 Billion Insurance Claim Over NotPetya Cyberattack appeared first on SecurityWeek.
Apple and Google propose new industry specification for Bluetooth location-tracking devices, to prevent unwanted tracking.
The post Apple, Google Propose Standard to Combat Misuse of Location-Tracking Devices appeared first on SecurityWeek.
Vulnerabilities in Netgear network management system allow attackers to retrieve cleartext passwords and escalate privileges.
The post Netgear Vulnerabilities Lead to Credentials Leak, Privilege Escalation appeared first on SecurityWeek.
Google has added passkeys support to Google accounts on all major platforms as part of the company’s passwordless sign-in efforts.
The post Passkeys Support Added to Google Accounts for Passwordless Sign-Ins appeared first on SecurityWeek.
Chrome 113 was released to the stable channel with 15 security fixes, including 10 that address vulnerabilities reported by external researchers.
The post Chrome 113 Released With 15 Security Patches appeared first on SecurityWeek.
Facebook parent Meta warned that hackers are using the promise of generative artificial intelligence like ChatGPT to trick people into installing malware on devices.
The post Hackers Promise AI, Install Malware Instead appeared first on SecurityWeek.
Open banking can be described as a perfect storm for cybersecurity. At one end, small startups with financial acumen but little or no security expertise or resources, are rushing new products to market.
The post Open Banking: A Perfect Storm for Security and Privacy? appeared first on SecurityWeek.
A subgroup of China-linked hacker group APT41 is using a new ‘stack rumbling’ DoS technique to disable security software.
The post Chinese APT Uses New ‘Stack Rumbling’ Technique to Disable Security Software appeared first on SecurityWeek.
Open source BGP implementation FRRouting is affected by three vulnerabilities that can be exploited to cause disruption via DoS attacks.
The post Exploitation of BGP Implementation Vulnerabilities Can Lead to Disruptions appeared first on SecurityWeek.
Authorities in the US and Ukraine have worked together to shut down nine websites offering cryptocurrency exchange services to cybercriminals.
The post US, Ukraine Shut Down Cryptocurrency Exchanges Used by Cybercriminals appeared first on SecurityWeek.
Law enforcement agencies around the world seized an online marketplace and arrested nearly 300 people allegedly involved in buying and selling drugs.
The post Global Operation Takes Down Dark Web Drug Marketplace appeared first on SecurityWeek.
German IT services giant Bitmarck has taken customer and internal systems offline following a cyberattack.
The post IT Services Firm Bitmarck Takes Systems Offline Following Cyberattack appeared first on SecurityWeek.
Wireless carrier T-Mobile says the personal information of a small number of individuals was exposed in a recent data breach.
The post T-Mobile Says Personal Information Stolen in New Data Breach appeared first on SecurityWeek.
CISA urges organizations to review FCC’s Covered List of risky communications equipment and incorporate it in their supply chain risk management efforts.
The post Critical Infrastructure Organizations Urged to Identify Risky Communications Equipment appeared first on SecurityWeek.
Apple has released its first Rapid Security Response patch, but iPhone users are complaining that they are having problems installing it.
The post iPhone Users Report Problems Installing Apple’s First Rapid Security Response Update appeared first on SecurityWeek.
Thirty-eight cybersecurity merger and acquisition (M&A) deals were announced in April 2023.
The post Cybersecurity M&A Roundup: 38 Deals Announced in April 2023 appeared first on SecurityWeek.
CISA warns of attacks exploiting an Oracle WebLogic vulnerability tracked as CVE-2023-21839, which was patched with the January 2023 CPU.
The post CISA Warns of Attacks Exploiting Oracle WebLogic Vulnerability Patched in January appeared first on SecurityWeek.
Fortinet warns of a massive spike in malicious attacks targeting a five-year-old authentication bypass vulnerability in TBK DVR devices.
The post Exploitation of 5-Year-Old TBK DVR Vulnerability Spikes appeared first on SecurityWeek.
Ransomware group leaked files showing the extent of their access to Western Digital systems and how they monitored the company’s initial response to the breach.
The post Leaked Files Show Extent of Ransomware Group’s Access to Western Digital Systems appeared first on SecurityWeek.
Registration is open for SecurityWeek's ICS Cybersecurity Conference, taking place October 23-26, 2023 in Atlanta.
The post Registration Now Open: 2023 ICS Cybersecurity Conference | Atlanta appeared first on SecurityWeek.
Russian cybercrime group TA505 has been observed using new hVNC malware called Lobshot in recent attacks.
The post New ‘Lobshot’ hVNC Malware Used by Russian Cybercriminals appeared first on SecurityWeek.
Out-of-control devices run the gamut from known to unknown and benign to malicious, and where you draw the line is unique to your organization.
The post Reigning in ‘Out-of-Control’ Devices appeared first on SecurityWeek.
Lawsuits filed against companies that have suffered a data breach are increasingly common, with action being taken even for incidents affecting less than 1,000 people.
The post Companies Increasingly Hit With Data Breach Lawsuits: Law Firm appeared first on SecurityWeek.
CISA has opened proposed guidance for secure software development to public review and comment.
The post CISA Asks for Public Opinion on Secure Software Attestation appeared first on SecurityWeek.
The Iranian government has been using the BouldSpy Android malware to spy on minorities and traffickers.
The post ‘BouldSpy’ Android Malware Used in Iranian Government Surveillance Operations appeared first on SecurityWeek.
OpenAI said ChatGPT is available again in Italy after the company met demands of regulators who temporarily blocked it over privacy concerns.
The post OpenAI: ChatGPT Back in Italy After Meeting Watchdog Demands appeared first on SecurityWeek.
Google says it prevented 1.4 million bad applications from being published on Google Play in 2022 and banned 173k developer accounts.
The post Google Blocked 1.4 Million Bad Apps From Google Play in 2022 appeared first on SecurityWeek.
Russian espionage group Nomadic Octopus infiltrated a Tajikistani telecoms provider to spy on 18 entities, including government officials and public service infrastructures.
The post Russian APT Hacked Tajikistani Carrier to Spy on Government, Public Services appeared first on SecurityWeek.
Cisco is working on a patch for an XSS vulnerability found in Prime Collaboration Deployment by a pentester from NATO’s Cyber Security Centre (NCSC).
The post Cisco Working on Patch for Vulnerability Reported by NATO Pentester appeared first on SecurityWeek.
FDA and CISA notify healthcare providers about a component used by several Illumina medical devices being affected by serious vulnerabilities that can allow remote hacking.
The post FDA, CISA: Illumina Medical Devices Vulnerable to Remote Hacking appeared first on SecurityWeek.
A newly identified variant of the RTM Locker ransomware is targeting Linux, NAS, and ESXi hosts.
The post RTM Locker Ransomware Variant Targeting ESXi Servers appeared first on SecurityWeek.
SecurityWeek is providing a summary of ICS/OT cybersecurity announcements made at RSA Conference 2023, including talks, products, and new initiatives.
The post RSA Conference 2023 – ICS/OT Cybersecurity Roundup appeared first on SecurityWeek.
A critical-severity vulnerability in Zyxel’s ATP, USG FLEX, VPN, and ZyWALL/USG firewalls can be exploited remotely for OS command execution.
The post Critical Vulnerability in Zyxel Firewalls Leads to Command Execution appeared first on SecurityWeek.
Cybersecurity firm Aadya has raised $5 million in Series A funding for its all-in-one platform tailored for small and mid-sized businesses.
The post Aadya Raises $5 Million for SMB-Focused Security Platform appeared first on SecurityWeek.
Chinese APT Evasive Panda has been observed targeting local members of an international NGO with the MgBot backdoor, delivered via legitimate software updates.
The post Chinese Cyberspies Delivered Malware via Legitimate Software Updates appeared first on SecurityWeek.
A new piece of malware named Atomic macOS Stealer (AMOS), offered for $1,000 per month, offers a wide range of data theft capabilities.
The post New ‘Atomic macOS Stealer’ Malware Offered for $1,000 Per Month appeared first on SecurityWeek.
SecurityWeek editor-at-large Ryan Naraine expects to see an explosion of well capitalized startups promising to protect AI machine learning models behind enterprise products.
The post Innovation Sandbox: Cybersecurity Investors Pivot to Safeguarding AI Training Models appeared first on SecurityWeek.
Court grants Google a temporary restraining order to disrupt CryptBot information stealer’s distribution.
The post Google Obtains Court Order to Disrupt CryptBot Distribution appeared first on SecurityWeek.
TikTok, Twitter, Facebook, Google, and Amazon are facing rising pressure from European authorities as London and Brussels advanced new rules Tuesday to curb the power of digital companies.
The post Big Tech Crackdown Looms as EU, UK Ready New Rules appeared first on SecurityWeek.
Microsoft says Cl0p ransomware operator has been exploiting a recently patched PaperCut vulnerability since April 13.
The post Microsoft: Cl0p Ransomware Exploited PaperCut Vulnerabilities Since April 13 appeared first on SecurityWeek.
Summary of announcements made at the 2023 RSA Conference, on day 3 of the cybersecurity event.
The post RSA Conference 2023 – Announcements Summary (Day 3) appeared first on SecurityWeek.
How will Artificial Intelligence develop in the near term, and how will this impact us as security planners and practitioners?
The post Cybersecurity Futurism for Beginners appeared first on SecurityWeek.
Russian cybercrime group FIN7 has been observed exploiting a Veeam Backup & Replication vulnerability patched in March 2023.
The post FIN7 Hackers Caught Exploiting Recent Veeam Vulnerability appeared first on SecurityWeek.
A high-severity vulnerability in the Service Location Protocol can be exploited to launch massive DoS amplification attacks.
The post SLP Vulnerability Allows DoS Attacks With Amplification Factor of 2,200 appeared first on SecurityWeek.
Hundreds of companies are showcasing their products and services this week at the 2023 edition of the RSA Conference in San Francisco.
The post RSA Conference 2023 – Announcements Summary (Day 2) appeared first on SecurityWeek.
Attackers can exploit Apache Superset installations with default configurations to gain administrator access and execute code on servers and databases.
The post Organizations Warned of Security Risk in Default Apache Superset Configurations appeared first on SecurityWeek.
VMware this week released patches for a critical vulnerability disclosed at the Pwn2Own Vancouver 2023 hacking contest.
The post VMware Patches Critical Vulnerability Disclosed at Pwn2Own Hacking Contest appeared first on SecurityWeek.
Iranian hackers broke into to a system used by a local government to support its election night operations but were kicked out before any attack could be launched, according to U.S. military and cybersecurity officials.
The post US Cyberwarriors Thwarted 2020 Iran Election Hacking Attempt appeared first on SecurityWeek.
XIoT security firm NetRise announced $8 million in additional funding, bringing the total raised by the company to $14 million.
The post NetRise Adds $8 Million in Funding to Grow XIoT Security Platform appeared first on SecurityWeek.
Token has raised a total of $53 million to work on a biometrics-powered wearable device featuring multi-factor authentication technologies.
The post Token Gets $30M Funding for Biometrics MFA Smart Ring appeared first on SecurityWeek.
Cybersecurity startup Sonet.io emerges from stealth mode with $6 million in seed funding and a secure access solution for remote workers.
The post Secure Access Startup Sonet.io Emerges From Stealth With $6 Million in Funding appeared first on SecurityWeek.
Aqua Security found over 250 million artifacts and more than 65,000 container images in misconfigured registries.
The post Millions of Exposed Artifacts Found in Misconfigured Cloud Software Registries appeared first on SecurityWeek.
Apiiro’s Risk Graph Explorer helps security teams to understand their application attack surface.
The post Apiiro Launches Application Attack Surface Exploration Tool appeared first on SecurityWeek.
Kaspersky believes that Russia-linked threat actors Tomiris and Turla are cooperating at least at a minimum level.
The post Kaspersky Analyzes Links Between Russian State-Sponsored APTs appeared first on SecurityWeek.
Hundreds of companies are showcasing their products and services this week at the 2023 edition of the RSA Conference in San Francisco.
The post RSA Conference 2023 – Announcements Summary (Day 1) appeared first on SecurityWeek.
OpenAI CTO Mira Murati discusses AI safeguards and the company’s vision for the futuristic concept of artificial general intelligence, known as AGI.
The post Insider Q&A: OpenAI CTO Mira Murati on Shepherding ChatGPT appeared first on SecurityWeek.
Over a nine-month audit, Google researchers identified ten security defects in Intel TDX, including nine vulnerabilities addressed with TDX code changes.
The post Google Audit Finds Vulnerabilities in Intel TDX appeared first on SecurityWeek.
Silicon Valley startup emerges from stealth with $4 million in seed-stage funding and ambitious plans to disrupt the IAM governance market.
The post Investors Place Early $4 Million Bet on Stack Identity appeared first on SecurityWeek.
Former Peloton CISO Adrian Stone has been tapped to steer the security ship at pharmaceutical and biotechnology giant Moderna.
The post Adrian Stone Joins Moderna as CISO appeared first on SecurityWeek.
Researchers warn that majority of Windows and macOS PaperCut installations still vulnerable to critical vulnerability already exploited in malware attacks.
The post Huntress: Most PaperCut Installations Not Patched Against Already-Exploited Security Flaw appeared first on SecurityWeek.
Several OT cybersecurity firms have teamed up to create an information sharing platform designed to serve as an early warning system for critical infrastructure.
The post New Data Sharing Platform Serves as Early Warning System for OT Security Threats appeared first on SecurityWeek.
North Korea-linked hacking group BlueNoroff/Lazarus was seen using the RustBucket macOS malware in recent attacks.
The post North Korean Hackers Target Mac Users With New ‘RustBucket’ Malware appeared first on SecurityWeek.
Threat actors have been observed abusing Kubernetes RBAC to create backdoors and hijack cluster resources for cryptocurrency mining.
The post Attackers Abuse Kubernetes RBAC to Deploy Persistent Backdoor appeared first on SecurityWeek.
Critical vulnerability found in Inea RTU can be exploited to remotely hack devices and cause disruption in industrial organizations.
The post Critical Flaw in Inea ICS Product Exposes Industrial Organizations to Remote Attacks appeared first on SecurityWeek.
SolarWinds has patched two high-severity vulnerabilities that could lead to command execution and privilege escalation.
The post SolarWinds Platform Update Patches High-Severity Vulnerabilities appeared first on SecurityWeek.
Learning how to spot the signs of narcissism and identify narcissists will help us ensure that we do not bring these people into our security and fraud teams, or our enterprises.
The post External Signs of Narcissism – Raising Awareness to Avoid Collateral Damage appeared first on SecurityWeek.
More than 3,000 participants from 38 countries took place in NATO’s 2023 Locked Shields cyber defense exercise.
The post 38 Countries Take Part in NATO’s 2023 Locked Shields Cyber Exercise appeared first on SecurityWeek.
The North Korean hacking group behind the supply chain attack that hit 3CX also broke into two critical infrastructure organizations in the energy sector.
The post Symantec: North Korean 3CX Hackers Also Hit Critical Infrastructure Orgs appeared first on SecurityWeek.
Texas startup scores financing to build an AI-powered anti-ransomware engine to help organizations ward off data-extortion attacks.
The post Halcyon Secures $50M Funding for Anti-Ransomware Protection Platform appeared first on SecurityWeek.
Attackers are installing the abandoned Eval PHP plugin on compromised WordPress sites to inject PHP code into web pages.
The post Abandoned WordPress Plugin Abused for Backdoor Deployment appeared first on SecurityWeek.
Five Eyes agencies have issued joint cybersecurity guidance and best practices for smart cities.
The post Five Eyes Agencies Issue Cybersecurity Guidance for Smart Cities appeared first on SecurityWeek.
A vulnerability in Google Cloud Platform allowed attackers to modify and hide OAuth applications to create a stealthy backdoor to any Google account.
The post Google Cloud Platform Vulnerability Led to Stealthy Account Backdoors appeared first on SecurityWeek.
GitHub this week introduced NPM package provenance and deployment protection rules and announced general availability of private vulnerability reporting.
The post GitHub Announces New Security Improvements appeared first on SecurityWeek.
A top administrator with Washington’s health insurance exchange apologized to House members on Wednesday for the data breach that resulted in the disclosure of personal information for thousands of users.
The post House Committee Hears Testimony on DC Health Data Breach appeared first on SecurityWeek.
Capita finally confirmed that hackers stole data after the Black Basta ransomware group offered to sell information allegedly stolen from the company.
The post Capita Confirms Data Breach After Ransomware Group Offers to Sell Stolen Information appeared first on SecurityWeek.
VMware warns of two critical vulnerabilities -- CVE-2023-20864 and CVE-2023-20865 -- in the VMware Aria Operations for Logs product.
The post VMware Patches Pre-Auth Code Execution Flaw in Logging Product appeared first on SecurityWeek.
Microsoft plans to use weather-themed naming of APT actors as part of a move to simplify the way threat actors are documented.
The post Microsoft Will Name Threat Actors After Weather Events appeared first on SecurityWeek.
Health insurer Point32Health takes systems offline after falling victim to ransomware attack.
The post Ransomware Attack Hits Health Insurer Point32Health appeared first on SecurityWeek.
The software supply chain security firm adds the Open Policy Agent to its risk analysis engine, increasing flexibility for the creation and enforcement of custom policies on the use of open source software.
The post Phylum Adds Open Policy Agent to Open Source Analysis Engine appeared first on SecurityWeek.
3CX hack is the first known cascading supply chain attack, with the breach starting after an employee downloaded compromised software from a different firm.
The post Cascading Supply Chain Attack: 3CX Hacked After Employee Downloaded Trojanized App appeared first on SecurityWeek.
Cisco this week released patches for critical-severity vulnerabilities impacting its Industrial Network Director and Modeling Labs applications.
The post Cisco Patches Critical Vulnerabilities in Industrial Network Director, Modeling Labs appeared first on SecurityWeek.
The Air Force is investigating how a lone airman could access and distribute possibly hundreds of highly classified documents, and in the meantime has taken away the intelligence mission from the unit where the leaks took place
The post Air Force Unit in Document Leaks Case Loses Intel Mission appeared first on SecurityWeek.
The UK government's information security arm warns of Russian state-aligned groups aiming to disrupt and destroy critical infrastructure in Western countries.
The post UK Warns of Russian Hackers Targeting Critical Infrastructure appeared first on SecurityWeek.
Print management solutions provider PaperCut warns that exploitation of a recently patched vulnerability has commenced.
The post PaperCut Warns of Exploited Vulnerability in Print Management Solutions appeared first on SecurityWeek.
Fortra has shared a summary of its investigation into the GoAnywhere zero-day incident that hit dozens of the company’s customers earlier this year.
The post Fortra Completes Investigation Into GoAnywhere Zero-Day Incident appeared first on SecurityWeek.
The recent data breach of personal information for thousands of users of Washington D.C.’s health insurance exchange, including members of Congress, was caused by basic human error
The post DC Health Link Data Breach Blamed on Human Error appeared first on SecurityWeek.
Safe Security, a startup building technology to help organizations manage cyber risk, has secured a $50 million Series B funding round.
The post Investors Bet Big on Safe Security for Cyber Risk Management appeared first on SecurityWeek.
Russian national Denis Dubnikov has been sentenced to time served after he pleaded guilty to charges related to laundering money for the Ryuk ransomware group.
The post Russian Man Who Laundered Money for Ryuk Ransomware Gang Sentenced appeared first on SecurityWeek.
The Series A funding round was led by Storm Ventures and brings the total raised by Dasera to $20 million.
The post Dasera Scores $12M Funding for Cloud Data Security appeared first on SecurityWeek.
Discarded enterprise routers are often not wiped and contain secrets that could be highly useful to malicious hackers.
The post Enterprises Exposed to Hacker Attacks Due to Failure to Wipe Discarded Routers appeared first on SecurityWeek.
Google warns of another zero-day vulnerability in Chrome, only days after addressing a similar issue.
The post Google Patches Second Chrome Zero-Day Vulnerability of 2023 appeared first on SecurityWeek.
Oracle’s April 2023 critical patch update (CPU) includes 433 new security patches, including more than 70 that fix critical vulnerabilities.
The post Oracle Releases 433 New Security Patches With April 2023 CPU appeared first on SecurityWeek.
Coro, an enterprise cybersecurity platform for mid-market organizations, has raised $75 million from Energy Impact Partners.
The post Coro Raises $75 Million for Mid-Market Cybersecurity Platform appeared first on SecurityWeek.
A subgroup of Iran-linked APT Phosphorus (Mint Sandstorm) has started to quickly adopt PoC exploit code targeting vulnerabilities in internet-facing applications.
The post Microsoft: Iranian Hackers Moved From Recon to Targeting US Critical Infrastructure appeared first on SecurityWeek.
US and UK government agencies have issued a joint warning for Russian group APT28 targeting Cisco routers by exploiting an old vulnerability.
The post US, UK: Russia Exploiting Old Vulnerability to Hack Cisco Routers appeared first on SecurityWeek.
Four GitHub repositories used by RedLine stealer control panels were suspended, disrupting the malware’s operations.
The post Takedown of GitHub Repositories Disrupts RedLine Malware Operations appeared first on SecurityWeek.
New Domino backdoor brings together former members of the Conti group and the FIN7 threat actors.
The post New ‘Domino’ Malware Linked to FIN7 Group, Ex-Conti Members appeared first on SecurityWeek.
Seattle startup SpecterOps secures $25 million in Series A funding to boost its BloodHound Enterprise platform.
The post SpecterOps Scores $25M Funding to Secure ID Attack Paths appeared first on SecurityWeek.
NSO Group used at least three iOS zero-click exploits in Pegasus attacks in 2022: FindMyPwn, PwnYourHome, and LatentImage.
The post NSO Group Used at Least 3 iOS Zero-Click Exploits in 2022: Citizen Lab appeared first on SecurityWeek.
Elon Musk plans to create an alternative to the popular AI chatbot ChatGPT that he is calling “TruthGPT,” which will be a "maximum truth-seeking AI that tries to understand the nature of the universe.”
The post Elon Musk Says He’ll Create ‘TruthGPT’ to Counter AI ‘Bias’ appeared first on SecurityWeek.
In a year dominated by kinetic/cyber war in Ukraine, North Korea doubles down on cryptocurrency thefts, China and Iran continue to take advantage, and a new form of personal intimidation of company personnel emerges.
The post Mandiant 2023 M-Trends Report Provides Factual Analysis of Emerging Threat Trends appeared first on SecurityWeek.
Personal identity and data protection provider Lockr has raised $2.5 million in pre-seed funding.
The post Lockr Raises $2.5 Million for Identity and Data Protection Platform appeared first on SecurityWeek.
The purpose of a backstop would be to make cyberinsurance more widely available and affordable to the whole market – but it isn’t yet clear whether this can be achieved.
The post Cyberinsurance Backstop: Can the Industry Survive Without One? appeared first on SecurityWeek.
CISA has added two vulnerabilities to its ‘must patch’ list, including a recently fixed Chrome flaw and a macOS flaw exploited by the DazzleSpy malware.
The post CISA Adds Chrome, macOS Bugs to Known Exploited Vulnerabilities Catalog appeared first on SecurityWeek.
Sixteen cybersecurity-related M&A deals were announced in the first half of April 2023.
The post Cybersecurity M&A Roundup for April 1-15, 2023 appeared first on SecurityWeek.
UK-based creative software developer Affinity recently informed the 175,000 users of its forum of a data breach that occurred on April 6.
The post Creative Software Maker Affinity Informs Customers of Forum Breach appeared first on SecurityWeek.
The low code/no code movement provides simplified app generation – but it needs to be understood to be safe.
The post The Security and Productivity Implications of Low Code/No Code Development appeared first on SecurityWeek.
Web security and threat intelligence firm ZeroFox is acquiring threat intelligence company LookingGlass for $26 million.
The post ZeroFox to Acquire Threat Intelligence Firm LookingGlass for $26 Million appeared first on SecurityWeek.
The LockBit ransomware gang is developing malware designed to encrypt files on macOS systems and researchers have analyzed if it poses a real threat.
The post LockBit Ransomware Group Developing Malware to Encrypt Files on macOS appeared first on SecurityWeek.
US payments giant NCR has confirmed being targeted in a ransomware attack for which the BlackCat/Alphv group has taken credit.
The post Payments Giant NCR Hit by Ransomware appeared first on SecurityWeek.
Boston-based Mobb has raised $5.4 million in seed funding for a product that automatically fixes vulnerabilities found in applications developed by customers.
The post Mobb Raises $5.4 Million in Seed Funding for Automatic Vulnerability Fixing Tool appeared first on SecurityWeek.
Online gaming forums have long been a particular worry of the military because of their lure for young service members.
The post Online Gaming Chats Have Long Been Spy Risk for US Military appeared first on SecurityWeek.
The high-severity vulnerability, tracked as CVE-2023-2033, is described as a type confusion in the Chrome V8 JavaScript engine.
The post Google Warns of New Chrome Zero-Day Attack appeared first on SecurityWeek.
A Massachusetts Air National Guard member was arrested Thursday in connection with the disclosure of highly classified military documents about the Ukraine war and other top national security issues.
The post FBI Arrests 21-Year-Old Guardsman in Leak of Classified Military Documents appeared first on SecurityWeek.
CISA has described and published a set of principles for the development of security-by-design and security-by-default cybersecurity products.
The post CISA Introduces Secure-by-design and Secure-by-default Development Principles appeared first on SecurityWeek.
A new Remcos RAT campaign is targeting US accounting and tax return preparation firms as Tax Day approaches.
The post Microsoft Warns Accounting, Tax Return Preparation Firms of Remcos RAT Attacks appeared first on SecurityWeek.
The Android vulnerability CVE-2023-20963, reportedly exploited as a zero-day by a Chinese app against millions of devices, was added to CISA’s KEV catalog.
The post Google, CISA Warn of Android Flaw After Reports of Chinese App Zero-Day Exploitation appeared first on SecurityWeek.
Juniper Networks this week announced patches for tens of vulnerabilities across its product portfolio, including critical bugs in Junos OS and STRM.
The post Juniper Networks Patches Critical Third-Party Component Vulnerabilities appeared first on SecurityWeek.
Authorization layer solution provider Cerbos has raised $7.5 million in an extended seed round led by Omers Ventures.
The post Cerbos Raises $7.5 Million for Authorization Platform appeared first on SecurityWeek.
Cybersecurity firm Darktrace has issued a statement after it was listed on the leak website of the LockBit ransomware group.
The post Darktrace Denies Getting Hacked After Ransomware Group Names Company on Leak Site appeared first on SecurityWeek.
New Google paper calls for increased transparency from vendors regarding their vulnerability management practices.
The post Google Proposes More Transparent Vulnerability Management Practices appeared first on SecurityWeek.
Threat intelligence and attack surface management company Cyfirma has raised $6 million in a pre-Series B funding round.
The post Cyfirma Raises $6 Million for Threat Management Platform appeared first on SecurityWeek.
Hikvision patches CVE-2023-28808, a critical authentication bypass vulnerability that exposes video data stored on its Hybrid SAN and cluster storage products.
The post Critical Vulnerability in Hikvision Storage Solutions Exposes Video Security Data appeared first on SecurityWeek.
An important area of differentiation to evaluate when you make your next security investment is the vendor’s effectiveness when it comes to customer success.
The post Looking for a New Security Technology? Choose a Partner, not a Vendor appeared first on SecurityWeek.
Microsoft has shared details on how threat hunters can check their systems for BlackLotus UEFI bootkit infections.
The post Microsoft Shares Resources for BlackLotus UEFI Bootkit Hunting appeared first on SecurityWeek.
Irrigation systems were disrupted recently in Israel in an attack that once again shows how easy it is to hack industrial control systems (ICS).
The post Irrigation Systems in Israel Disrupted by Hacker Attacks on ICS appeared first on SecurityWeek.
When every environment is treated the same, teams get consistent visibility, a unified view, and a common language to describe what’s happening for detection, investigation, and response across dispersed multi-cloud and hybrid environments.
The post Securing the Chaos – Harnessing Dispersed Multi-Cloud, Hybrid Environments appeared first on SecurityWeek.
A critical vulnerability in Fortinet’s FortiPresence data analytics solution leads to remote, unauthenticated access to Redis and MongoDB instances.
The post Fortinet Patches Critical Vulnerability in Data Analytics Solution appeared first on SecurityWeek.
Media player maker Kodi has started rebuilding its user forum after hackers stole databases containing user posts, messages, and login credentials.
The post 400,000 Users Hit by Data Breach at Media Player Maker Kodi appeared first on SecurityWeek.
A Windows zero-day tracked as CVE-2023-28252 and fixed by Microsoft with its April Patch Tuesday updates has been exploited in Nokoyawa ransomware attacks.
The post Windows Zero-Day Exploited in Nokoyawa Ransomware Attacks appeared first on SecurityWeek.
Two critical vulnerabilities in SAP Diagnostics Agent allow attackers to execute malicious commands on all monitored systems.
The post SAP Patches Critical Vulnerabilities in Diagnostics Agent, BusinessObjects appeared first on SecurityWeek.
3CX has confirmed previous reports that the recently disclosed supply chain attack was likely conducted by North Korean hackers.
The post Mandiant Also Links 3CX Supply Chain Attack to North Korean Hackers appeared first on SecurityWeek.
Join us for SecurityWeek's 2023 Zero Trust Strategies Summit as we decipher the confusing world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.
The post Virtual Event Today: Zero Trust Strategies Summit appeared first on SecurityWeek.
CISA has published the second version of its guide describing the necessary strategies and policies to achieve zero trust maturity.
The post CISA Publishes New Guidance for Achieving Zero Trust Maturity appeared first on SecurityWeek.
Microsoft and Citizen Lab release information on the activities, malware and victims of Israeli spyware vendor QuaDream.
The post Details Emerge on Israeli Spyware Vendor QuaDream and Its iOS Malware appeared first on SecurityWeek.
ChatGPT creator OpenAI announced a new bug bounty program that will pay up to $20,000 for advance notice on security vulnerabilities found by hackers.
The post ChatGPT Creator OpenAI Ready to Pay Hackers for Security Flaws appeared first on SecurityWeek.
Join this virtual event as we decipher the confusing world of zero trust and share war stories on securing organizations by eliminating implicit trust.
The post Virtual Event Tomorrow: Zero Trust Strategies Summit appeared first on SecurityWeek.
For the second month in a row, Microsoft patches an already-exploited vulnerability in its flagship Windows operating system.
The post Microsoft Patches Another Already-Exploited Windows Zero-Day appeared first on SecurityWeek.
Adobe documents 56 security defects in multiple products, some serious enough to expose Windows and macOS users to code execution attacks.
The post Adobe Plugs Gaping Security Holes in Reader, Acrobat appeared first on SecurityWeek.
Australian OSINT software company Fivecast has raised $20 million in a Series A funding round led by Ten Eleven.
The post OSINT Company Fivecast Raises $20 Million appeared first on SecurityWeek.
Microsoft Azure shared key authorization can be exploited to access business data and achieve remote code execution.
The post Microsoft Azure Users Warned of Potential Shared Key Authorization Abuse appeared first on SecurityWeek.
Siemens and Schneider Electric’s Patch Tuesday advisories for April 2023 address a total of 38 vulnerabilities found in their products.
The post ICS Patch Tuesday: Siemens, Schneider Electric Address Dozens of Vulnerabilities appeared first on SecurityWeek.
Three days after announcing patches for new zero-days affecting iOS and macOS, Apple released fixes for devices running older operating system versions.
The post Apple Rolls Out Zero-Day Patches to Older iOS, macOS Devices appeared first on SecurityWeek.
The national strategy outlined by the Federal Government on March 1, 2023, is a monumental attempt to weave a consistent approach to cybersecurity for the whole nation.
The post Potential Outcomes of the US National Cybersecurity Strategy appeared first on SecurityWeek.
KFC and Taco Bell parent company Yum Brands says personal information was compromised in a January 2023 ransomware attack.
The post Yum Brands Discloses Data Breach Following Ransomware Attack appeared first on SecurityWeek.
Microsoft Exchange Server 2013 has reached end of support on April 11, 2023, and will no longer receive security patches.
The post Microsoft Exchange Server 2013 Reaches End of Support appeared first on SecurityWeek.
Latitude Financial said it had recently received a ransom threat from the group behind the cyberattack, which it was ignoring in line with government advice.
The post Australian Finance Company Refuses Hackers’ Ransom Demand appeared first on SecurityWeek.
A Tesla owner is seeking class action status for a lawsuit accusing the automaker of allowing its workers to use intimate or embarrassing imagery captured by the electric vehicles.
The post Tesla Sued Over Workers’ Alleged Access to Car Video Imagery appeared first on SecurityWeek.
Tech giant MSI confirms a cyberattack that resulted in system disruptions and possible exposure to firmware image manipulations.
The post MSI Confirms Cyberattack, Issues Firmware Download Guidance appeared first on SecurityWeek.
Microsoft catches an Iranian government-backed APT launching destructive Azure wiper attacks disguised as ransomware.
The post Microsoft: Iranian Gov Hackers Caught in Azure Wiper Attacks appeared first on SecurityWeek.
CISO ordered federal agencies to patch Veritas Backup Exec vulnerabilities exploited in ransomware attacks.
The post Veritas Vulnerabilities Exploited in Ransomware Attacks Added to CISA ‘Must Patch’ List appeared first on SecurityWeek.
Security posture management firm XM Cyber took tens of thousands of attack path assessments involving more than 60 million exposures affecting 20 million entities during 2022.
The post Most Attack Paths Are Dead Ends, but 2% Lead to Critical Assets: Report appeared first on SecurityWeek.
The newest iOS 16.4.1 and iPadOS 16.4.1 patches a pair of code execution flaws that have already been exploited in the wild.
The post Apple Ships Urgent iOS Patch for Newly Exploited Zero-Days appeared first on SecurityWeek.
Andrey Shevlyakov was charged in the US for helping the Russian government and military purchase US-made electronics and hacking tools.
The post DoJ: Estonian Man Tried to Acquire US-Made Hacking Tools for Russia appeared first on SecurityWeek.
Recently identified dark web portal Styx Marketplace focuses on financial fraud, identity theft, and money laundering.
The post Financial Fraud-Focused Cybercrime Marketplace ‘Styx’ Emerges appeared first on SecurityWeek.
Forty-one cybersecurity-related M&A deals were announced in March 2023.
The post Cybersecurity M&A Roundup: 41 Deals Announced in March 2023 appeared first on SecurityWeek.
Law enforcement announced the takedown of Genesis Market, but the impact on the cybercrime marketplace’s infrastructure may be limited.
The post Success of Genesis Market Takedown Attempt Called Into Question appeared first on SecurityWeek.
Online tax return filing service eFile.com was injected with malicious JavaScript code serving malware to visitors.
The post Tax Return Filing Service eFile.com Caught Serving Malware appeared first on SecurityWeek.
Push Security has raised $15 million in a Series A funding round led by Google Ventures.
The post Push Security Raises $15 Million in Series A Funding appeared first on SecurityWeek.
Consulting giant KPMG spins out a startup building technology to secure AI (artificial intelligence) applications and deployments.
The post KPMG Tackles AI Security With Cranium Spinout appeared first on SecurityWeek.
Chrome 112 was released to the stable channel this week with 16 security fixes, including 14 for vulnerabilities reported by external researchers.
The post Chrome 112 Patches 16 Security Flaws appeared first on SecurityWeek.
Android’s April 2023 security updates were released this week with patches for two critical-severity vulnerabilities leading to remote code execution.
The post Android’s April 2023 Updates Patch Critical Remote Code Execution Vulnerabilities appeared first on SecurityWeek.
The FBI has seized Genesis Market, a major cybercrime website offering stolen device fingerprints.
The post Cybercrime Website Genesis Market Seized by FBI appeared first on SecurityWeek.
Nexx has ignored repeated attempts to report critical product vulnerabilities that can be exploited to remotely open garage doors, and take control of alarms and smart plugs.
The post Nexx Ignores Vulnerabilities Allowing Hackers to Remotely Open Garage Doors appeared first on SecurityWeek.
Strivacity, a Virginia startup working on technology to simplify and secure customer logins, has attracted $20 million in funding to fuel global expansion plans.
The post Strivacity Scores $20M for CIAM Expansion Plans appeared first on SecurityWeek.
CISA has added to its Known Exploited Vulnerabilities catalog a Zimbra vulnerability exploited in attacks targeting NATO countries
The post Zimbra Flaw Exploited by Russia Against NATO Countries Added to CISA ‘Must Patch’ List appeared first on SecurityWeek.
California startup Trustle banks a $6 million seed round to join the competitive cloud access management technology space.
The post Trustle Raises $6M Seed Funding for Access Management Tech appeared first on SecurityWeek.
The UK’s data protection regulator fined TikTok £12.7 million for “failing to use children’s personal data lawfully”
The post TikTok’s Trials and Tribulations Continue With UK Data Protection Fine appeared first on SecurityWeek.
Tel Aviv- and Boston-based CardinalOps has extended its detection posture management capability with MITRE ATT&CK Security Layers.
The post CardinalOps Extends MITRE ATT&CK-based Detection Posture Management appeared first on SecurityWeek.
The sophisticated, self-propagating Rorschach ransomware is one of the fastest at encrypting victim’s files.
The post Self-Propagating, Fast-Encrypting ‘Rorschach’ Ransomware Emerges appeared first on SecurityWeek.
NATO is looking for penetration testing vendors to assess the security of its internet-facing web assets.
The post NATO Seeks Contractors to Test Security of Web Assets appeared first on SecurityWeek.
Cybereason appoints new CEO as it receives $100 million in venture funding from SoftBank Corp.
The post Cybereason Raises $100 Million, Appoints New CEO appeared first on SecurityWeek.
3CX supply chain attack appears to have been conducted by North Korean hackers with the goal of targeting cryptocurrency firms.
The post 3CX Supply Chain Attack: North Korean Hackers Likely Targeted Cryptocurrency Firms appeared first on SecurityWeek.
Cisco is set to acquire Israel-based cloud security company Lightspin for a reported $200-250 million.
The post Cisco to Acquire Cloud Security Firm Lightspin for Reported $200 Million appeared first on SecurityWeek.
Two of humanity’s greatest drivers, greed and curiosity, will push AI development forward. Our only hope is that we can control it.
The post ChatGPT, the AI Revolution, and the Security, Privacy and Ethical Implications appeared first on SecurityWeek.
A severe vulnerability in the Elementor Pro WordPress plugin is being exploited to inject malware into vulnerable websites.
The post Elementor Pro Plugin Vulnerability Exploited to Hack WordPress Websites appeared first on SecurityWeek.
Microsoft is boosting the security of OneNote users by blocking embedded files with extensions that are considered dangerous.
The post Microsoft OneNote Starts Blocking Dangerous File Extensions appeared first on SecurityWeek.
New ‘Hack the Pentagon’ website helps DoD organizations launch bug bounty programs and recruit security researchers.
The post US Defense Department Launches ‘Hack the Pentagon’ Website appeared first on SecurityWeek.
Western Digital shuts down several of its services after discovering a network security breach.
The post Western Digital Shuts Down Services Due to Cybersecurity Breach appeared first on SecurityWeek.
Consumer loan provider TMX Finance is informing over 4.8 million individuals that their personal information was stolen in a data breach.
The post 4.8 Million Impacted by Data Breach at TMX Finance appeared first on SecurityWeek.
Europe, the United States and Australia seem to be the most impacted by the 3CX supply chain hack, according to data from two cybersecurity firms.
The post Europe, North America Most Impacted by 3CX Supply Chain Hack appeared first on SecurityWeek.
TikTok general counsel says company is trying to make it physically impossible for any government, including China, to access to U.S. user data.
The post TikTok Attorney: China Can’t Get U.S. Data Under Plan appeared first on SecurityWeek.
Italy is temporarily blocking the artificial intelligence software ChatGPT in the wake of a data breach as it investigates a possible violation of stringent European Union data protection rules.
The post Italy Temporarily Blocks ChatGPT Over Privacy Concerns appeared first on SecurityWeek.
The FDA is asking medical device manufacturers to provide cybersecurity-related information when submitting an application for a new product.
The post FDA Announces New Cybersecurity Requirements for Medical Devices appeared first on SecurityWeek.
Chinese hacking group linked previously to attacks on U.S. state government computers is still “highly active”
The post Report: Chinese State-Sponsored Hacking Group Highly Active appeared first on SecurityWeek.
Votiro raised $11.5 million in a Series A investment round led by Harvest Lane Asset Management.
The post Votiro Raises $11.5 Million to Prevent File-Borne Threats appeared first on SecurityWeek.
Communications and IT company Lumen Technologies fell victim to two cyberattacks that led to data theft.
The post Lumen Technologies Hit by Two Cyberattacks appeared first on SecurityWeek.
Documents show that Russian IT company NTC Vulkan was requested to develop offensive tools for government-backed hacking group Sandworm.
The post Leaked Documents Detail Russia’s Cyberwarfare Tools, Including for OT Attacks appeared first on SecurityWeek.
Several cybersecurity companies have published blog posts, advisories and tools to help organizations that may have been hit by the 3CX supply chain attack.
The post Mandiant Investigating 3CX Hack as Evidence Shows Attackers Had Access for Months appeared first on SecurityWeek.
A high-severity vulnerability in Azure Service Fabric Explorer could have allowed a remote, unauthenticated attacker to execute arbitrary code.
The post Severe Azure Vulnerability Led to Unauthenticated Remote Code Execution appeared first on SecurityWeek.
DataDome, a New York startup selling anti-bot and anti-fraud tech, has secured $42 million in new financing to fuel expansion plans.
The post Anti-Bot Software Firm DataDome Banks $42M Financing appeared first on SecurityWeek.
Water pumping systems made by ProPump and Controls are affected by several vulnerabilities that could allow hackers to cause significant problems.
The post Unpatched Security Flaws Expose Water Pump Controllers to Remote Hacker Attacks appeared first on SecurityWeek.
NCB Management Services is informing roughly 500,000 individuals of a data breach impacting their personal information.
The post 500k Impacted by Data Breach at Debt Buyer NCB appeared first on SecurityWeek.
The recently identified Melofee Linux implant allowed Chinese cyberespionage group Winnti to conduct stealthy, targeted attacks.
The post Chinese Cyberspies Use ‘Melofee’ Linux Malware for Stealthy Attacks appeared first on SecurityWeek.
When establishing visibility and security controls across endpoints, security professionals need to understand that each endpoint bears some or all responsibility for its own security.
The post Why Endpoint Resilience Matters appeared first on SecurityWeek.
An Azure Active Directory (AAD) misconfiguration leading to Bing.com compromise earned Wiz researchers a $40,000 bug bounty reward.
The post Microsoft Cloud Vulnerability Led to Bing Search Hijacking, Exposure of Office 365 Data appeared first on SecurityWeek.
3CX confirms investigating a security breach as the cybersecurity community is sharing more information on what appears to be a sophisticated supply chain attack.
The post 3CX Confirms Supply Chain Attack as Researchers Uncover Mac Component appeared first on SecurityWeek.
The proposed UK Online Safety Bill is the enactment of two long held government desires: the removal of harmful internet content, and visibility into end-to-end content
The post UK Introduces Mass Surveillance With Online Safety Bill appeared first on SecurityWeek.
A group computer scientists and tech experts are calling for a 6-month pause to consider the profound risks of AI to society and humanity.
The post Musk, Scientists Call for Halt to AI Race Sparked by ChatGPT appeared first on SecurityWeek.
CrowdStrike threat intelligence team warns about unexpected malicious activity from a legitimate, signed version of the 3CXDesktopApp.
The post Malware Hunters Spot Supply Chain Attack Hitting 3CX Desktop App appeared first on SecurityWeek.
New York startup LeapXpert secures funding for technology to help businesses manage the use of consumer messaging apps in the enterprise.
The post LeapXpert Banks $22M Funding to Secure Corporate Messaging With Consumer Apps appeared first on SecurityWeek.
Total Network Services rebrands to True I/O and raises $9 million to accelerate deployment of product.
The post Blockchain Security Firm True I/O Raises $9 Million appeared first on SecurityWeek.
Backed by YL Ventures, Spera banks $10 million to help businesses deal with identity and access sprawl in the enterprise.
The post Spera Banks $10 Million to Tackle Identity and Access Sprawl appeared first on SecurityWeek.
OpenAI resolved severe ChatGPT vulnerabilities that could have been exploited to take over accounts.
The post OpenAI Patches Account Takeover Vulnerabilities in ChatGPT appeared first on SecurityWeek.
OpenSSL 1.1.1 will reach EoL in six months and users are instructed to either upgrade to a newer version or pay for extended support to continue receiving security patches.
The post OpenSSL 1.1.1 Nears End of Life: Security Updates Only Until September 2023 appeared first on SecurityWeek.
A group of academic researchers devised an attack that can intercept Wi-Fi traffic at the MAC layer, bypassing client isolation.
The post New Wi-Fi Attack Allows Traffic Interception, Security Bypass appeared first on SecurityWeek.
Australian casino giant Crown Resorts says the Cl0p ransomware group contacted them to claim data theft in the GoAnywhere attack.
The post Casino Giant Crown Resorts Investigating Ransomware Group’s Data Theft Claims appeared first on SecurityWeek.
Google has linked several zero-day vulnerabilities used last year to target Android and iOS devices to commercial spyware vendors.
The post Google Links More iOS, Android Zero-Day Exploits to Spyware Vendors appeared first on SecurityWeek.
A new research report discusses the five most exploited vulnerabilities of 2022, and the five key risks that security teams should consider.
The post Most Weaponized Vulnerabilities of 2022 and 5 Key Risks: Report appeared first on SecurityWeek.
Chinese cyberespionage group Mustang Panda was seen targeting maritime, shipping, border control, and immigration organizations in recent attacks.
The post Over 200 Organizations Targeted in Chinese Cyberespionage Campaign appeared first on SecurityWeek.
Quantum cybersecurity firm QuSecure has collaborated with Accenture to develop a multi-orbit quantum-resilient satellite communications capability.
The post QuSecure and Accenture Test Multi-Orbit Communications Link Using Post-Quantum Cryptography appeared first on SecurityWeek.
While there are likely many different approaches, here are a few points that are important for enterprises to consider when evaluating bot solutions.
The post What Makes an Effective Anti-Bot Solution? appeared first on SecurityWeek.
Mandiant flags APT43 as a “moderately-sophisticated cyber operator that supports the interests of the North Korean regime."
The post Mandiant Catches Another North Korean Gov Hacker Group appeared first on SecurityWeek.
Microsoft has rolled out a preview version of Security Copilot, a ChatGPT-powered tool to help organizations automate cybersecurity tasks.
The post Microsoft Puts ChatGPT to Work on Automating Cybersecurity appeared first on SecurityWeek.
Enjoy this session as we walk through three recent use cases where a new threat caught organizations off-guard.
The post Video: How to Build Resilience Against Emerging Cyber Threats appeared first on SecurityWeek.
Solomon Ekunke Okpe was sentenced to four years in prison in the US for his role in a BEC fraud ring.
The post Nigerian BEC Scammer Sentenced to Prison in US appeared first on SecurityWeek.
A South Asian espionage group named Bitter has been targeting the Chinese nuclear energy sector.
The post China’s Nuclear Energy Sector Targeted in Cyberespionage Campaign appeared first on SecurityWeek.
SecurityScorecard is offering free digital forensics and incident response (DFIR) services to customers that have scored an ‘A’ rating if they have been breached.
The post SecurityScorecard Guarantees Accuracy of Its Security Ratings appeared first on SecurityWeek.
OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an actively exploited vulnerability.
The post ChatGPT Data Breach Confirmed as Security Firm Warns of Vulnerable Component Exploitation appeared first on SecurityWeek.
Australian financial services provider Latitude says roughly 14 million user records were stolen in a recent cyberattack.
The post 14 Million Records Stolen in Data Breach at Latitude Financial Services appeared first on SecurityWeek.
Microsoft says it has evidence that Russian APT actors were exploiting a nasty Outlook zero-day as far back as April 2022, upping the stakes on organizations to start hunting for signs of compromise.
The post Microsoft: No-Interaction Outlook Zero Day Exploited Since Last April appeared first on SecurityWeek.
Executive order will require the head of any U.S. agency using commercial spyware programs to certify that the program doesn’t pose a significant counterintelligence or other security risk.
The post US to Adopt New Restrictions on Using Commercial Spyware appeared first on SecurityWeek.
Security researchers raked in more than $1 million in prizes at this year's CanSecWest Pwn2Own software exploitation contest.
The post Hackers Earn Over $1 Million at Pwn2Own Exploit Contest appeared first on SecurityWeek.
Several major organizations are confirming impact from the latest zero-day exploits hitting Fortra's GoAnywhere software.
The post GoAnywhere Zero-Day Attack Hits Major Orgs appeared first on SecurityWeek.
Law enforcement in Australia announce the arrest of four individuals accused of running business email compromise (BEC) schemes.
The post Australia Dismantles BEC Group That Laundered $1.7 Million appeared first on SecurityWeek.
Criminals are set to take advantage of artificial intelligence like ChatGPT to commit fraud and other cybercrimes,
Europe's policing agency warned.
The post ‘Grim’ Criminal Abuse of ChatGPT is Coming, Europol Warns appeared first on SecurityWeek.
Webinar on third-party identity access risks will discuss topics such as unauthorized access, data breaches, and the manipulation or theft of sensitive information
The post Webinar Tomorrow: Understanding Hidden Third-Party Identity Access Risks appeared first on SecurityWeek.
GitHub replaced the RSA SSH private key used to secure Git operations for GitHub.com after it was exposed in a public GitHub repository.
The post GitHub Rotates Publicly Exposed RSA SSH Private Key appeared first on SecurityWeek.
Twitter sent a copyright notice to code hosting service GitHub to request the removal of a repository that contained Twitter source code.
The post GitHub Suspends Repository Containing Leaked Twitter Source Code appeared first on SecurityWeek.
Intel Corp. co-founder Gordon Moore, who the breakneck pace of progress in the digital age with a simple 1965 prediction of how quickly engineers would boost the capacity of computer chips, has died. He was 94.
The post Intel Co-founder, Philanthropist Gordon Moore Dies at 94 appeared first on SecurityWeek.
Dope.security raised $16 million in Series A funding for its fly-direct Secure Web Gateway (SWG).
The post Google Leads $16 Million Investment in Dope.security appeared first on SecurityWeek.
The US Justice Department charged Conor Brian Fitzpatrick, founder of BreachForums, a major underground website for computer hackers.
The post US Charges 20-Year-Old Head of Hacker Site BreachForums appeared first on SecurityWeek.
Researchers at offensive hacking shop Synacktiv demonstrated successful exploit chains and were able to “fully compromise” Tesla’s newest electric car and take top billing at the annual Pwn2Own contest.
The post Tesla Hacked Twice at Pwn2Own Exploit Contest appeared first on SecurityWeek.
The U.S. government’s cybersecurity agency ships a new tool to help network defenders hunt for signs of compromise in Microsoft’s Azure and M365 cloud deployments.
The post CISA Ships ‘Untitled Goose Tool’ to Hunt for Microsoft Azure Cloud Infections appeared first on SecurityWeek.
A critical-severity flaw in the WooCommerce Payments WordPress plugin could allow attackers to take over site administrator accounts.
The post Critical WooCommerce Payments Vulnerability Leads to Site Takeover appeared first on SecurityWeek.
Proof-of-concept code to exploit a just-patched security hole in the Veeam Backup & Replication product has been published online.
The post PoC Exploit Published for Just-Patched Veeam Data Backup Solution Flaw appeared first on SecurityWeek.
CISA has sent notifications to more than 60 organizations as part of a new initiative to alert entities of early-stage ransomware attacks.
The post CISA Gets Proactive With New Pre-Ransomware Alerts appeared first on SecurityWeek.
Join us for the virtual experience as we bring together security experts to discuss the complex nature of the supply chain problem, best practices for mitigating security issues.
The post Watch on Demand: Supply Chain & Third-Party Risk Summit Sessions appeared first on SecurityWeek.
A nearly six-hour grilling of TikTok’s CEO by lawmakers brought the platform’s 150 million U.S. users no closer to an answer as to whether the app will be wiped from their devices.
The post TikTok CEO Grilled by Skeptical Lawmakers on Safety, Content appeared first on SecurityWeek.
New CISA and NSA guidance includes recommended best practices for identity and access management (IAM) administrators.
The post CISA, NSA Issue Guidance for IAM Administrators appeared first on SecurityWeek.
On March 15, 2023, the SEC announced a proposal for new cybersecurity requirements for covered entities.
The post Analysis: SEC Cybersecurity Proposals and Biden’s National Cybersecurity Strategy appeared first on SecurityWeek.
Intel’s newest vPro platform brings threat prevention features with dozens of security capabilities built into the silicon.
The post Intel Boasts Attack Surface Reduction With New 13th Gen Core vPro Platform appeared first on SecurityWeek.
Cisco’s semiannual security updates for IOS and IOS XE software resolve high-severity DoS, command injection, and privilege escalation vulnerabilities.
The post Cisco Patches High-Severity Vulnerabilities in IOS Software appeared first on SecurityWeek.
Promoted as a MaaS, the Nexus Android trojan targets 450 financial applications for account takeover.
The post ‘Nexus’ Android Trojan Targets 450 Financial Applications appeared first on SecurityWeek.
Making threat intelligence actionable requires more than automation; it also requires contextualization and prioritization.
The post Tackling the Challenge of Actionable Intelligence Through Context appeared first on SecurityWeek.
Dole has admitted in an SEC filing that its investigation into the recent ransomware attack found that the hackers had accessed employee information.
The post Dole Says Employee Information Compromised in Ransomware Attack appeared first on SecurityWeek.
Backslash Security banks seed-stage capital to build new technology to identify and mitigate “toxic code flows” in cloud-native applications.
The post Backslash Snags $8M Seed Financing for AppSec Tech appeared first on SecurityWeek.
Black Lantern Security introduces Badsecrets, an open source tool for identifying known or weak cryptographic secrets across multiple platforms.
The post ‘Badsecrets’ Open Source Tool Detects Secrets in Many Web Frameworks appeared first on SecurityWeek.
Cisco Talos researchers found two high-severity vulnerabilities in WellinTech’s KingHistorian industrial data historian software.
The post High-Severity Vulnerabilities Found in WellinTech Industrial Data Historian appeared first on SecurityWeek.
The latest Chrome update brings patches for eight vulnerabilities, including seven reported by external researchers.
The post Chrome 111 Update Patches High-Severity Vulnerabilities appeared first on SecurityWeek.
The popular cybercrime forum BreachForums is being shut down following the arrest of Conor Brian Fitzpatrick, who is accused of running the website.
The post BreachForums Shut Down Over Law Enforcement Takeover Concerns appeared first on SecurityWeek.
CISA announces adding more experts to its Cybersecurity Advisory Committee and updating the Cybersecurity Performance Goals.
The post CISA Expands Cybersecurity Committee, Updates Baseline Security Goals appeared first on SecurityWeek.
Many of the most successful cybercriminals are shrewd; they want good ROI, but they don’t want to have to reinvent the wheel to get it.
The post Malware Trends: What’s Old Is Still New appeared first on SecurityWeek.
Security professionals understand the need for resilience in their company’s security posture, but often fail to build their own psychological resilience to stress.
The post Burnout in Cybersecurity – Can It Be Prevented? appeared first on SecurityWeek.
Spain needs more transparency over the Pegasus spyware hacking scandal, a European Parliament committee said.
The post Spain Needs More Transparency Over Pegasus: EU Lawmakers appeared first on SecurityWeek.
Ransomware and data related attacks are the top cybersecurity threats to the transport sector in the EU, ENISA says.
The post Ransomware Will Likely Target OT Systems in EU Transport Sector: ENISA appeared first on SecurityWeek.
Cryptocurrency ATM maker General Bytes discloses a security incident resulting in the theft of millions of dollars’ worth of crypto-coins.
The post Millions Stolen in Hack at Cryptocurrency ATM Manufacturer General Bytes appeared first on SecurityWeek.
Waterfall Security Solutions and TXOne Networks have each announced launching new OT security appliances.
The post Waterfall Security, TXOne Networks Launch New OT Security Appliances appeared first on SecurityWeek.
Hitachi Energy has blamed a data breach affecting employees on the recent exploitation of a zero-day vulnerability in Fortra’s GoAnywhere solution.
The post Hitachi Energy Blames Data Breach on Zero-Day as Ransomware Gang Threatens Firm appeared first on SecurityWeek.
NBA is notifying individuals that their information was stolen in a data breach at a third-party mailing services provider.
The post NBA Notifying Individuals of Data Breach at Mailing Services Provider appeared first on SecurityWeek.
Cybercriminals are abusing the Adobe Acrobat Sign service in a campaign distributing the RedLine information stealer malware.
The post Adobe Acrobat Sign Abused to Distribute Malware appeared first on SecurityWeek.
Conor Brian Fitzpatrick of New York was arrested and charged last week for allegedly running the popular cybercrime forum BreachForums.
The post New York Man Arrested for Running BreachForums Cybercrime Website appeared first on SecurityWeek.
Huawei has replaced thousands of product components banned by the US with homegrown versions, its founder has said.
The post Huawei Has Replaced Thousands of US-Banned Parts With Chinese Versions: Founder appeared first on SecurityWeek.
Latitude Financial Services says the personal information of 300,000 customers was stolen in a cyberattack.
The post Latitude Financial Services Data Breach Impacts 300,000 Customers appeared first on SecurityWeek.
Three US government agencies have issued a joint warning to organizations about LockBit 3.0 ransomware attacks.
The post US Government Warns Organizations of LockBit 3.0 Ransomware Attacks appeared first on SecurityWeek.
The recently identified Trigona ransomware has been highly active, targeting tens of organizations globally.
The post New ‘Trigona’ Ransomware Targets US, Europe, Australia appeared first on SecurityWeek.
A newly identified threat actor named YoroTrooper is targeting organizations in Europe and the CIS region for espionage and data theft.
The post New Espionage Group ‘YoroTrooper’ Targeting Entities in European, CIS Countries appeared first on SecurityWeek.
Mandiant links exploitation of the Fortinet zero-day CVE-2022-41328, exploited in government attacks, to a Chinese cyberespionage group.
The post Exploitation of Recent Fortinet Zero-Day Linked to Chinese Cyberspies appeared first on SecurityWeek.
Critical security flaws expose Samsung’s Exynos modems to “Internet-to-baseband remote code execution” attacks with no user interaction. Project Zero says an attacker only needs the victim’s phone number.
The post Project Zero: Samsung Mobile Chipsets Vulnerable to Baseband Code Execution Exploits appeared first on SecurityWeek.
Meta has developed a ten-phase cyber kill chain model that it believes will be more inclusive and more effective than the existing range of models.
The post Meta Develops New Kill Chain Thesis appeared first on SecurityWeek.
Firefox 111 patches 13 CVEs, including several vulnerabilities classified as high severity.
The post Mozilla Patches High-Severity Vulnerabilities With Release of Firefox 111 appeared first on SecurityWeek.
Polish counter-intelligence has dismantled a Russian spy ring that gathered information on military equipment deliveries to Ukraine.
The post Poland Breaks up Russian Spy Ring appeared first on SecurityWeek.
CISA this week announced it is seeking public input on draft guidance for securing cloud business applications.
The post CISA Seeks Public Opinion on Cloud Application Security Guidance appeared first on SecurityWeek.
Join us for this webinar as we walk through three recent use cases where a new threat caught organizations off-guard.
The post Webinar Today: How to Build Resilience Against Emerging Cyber Threats appeared first on SecurityWeek.
Microsoft says Russia targeted at least 17 European nations in 2023 — mostly governments — and 74 countries since the start of the Ukraine war.
The post Microsoft: 17 European Nations Targeted by Russia in 2023 as Espionage Ramping Up appeared first on SecurityWeek.
SecurityWeek’s Cyber Madness Bracket Challenge is a contest designed to bring the community together in a fun, competitive way through one of America’s top sporting events.
The post Make Your Picks: Cyber Madness Bracket Challenge Starts Today appeared first on SecurityWeek.
Health services company Independent Living Systems has disclosed a data breach that impacts more than 4 million individuals.
The post Data Breach at Independent Living Systems Impacts 4 Million Individuals appeared first on SecurityWeek.
Russia-backed threat group Winter Vivern has targeted government entities in Poland, Ukraine, Italy, and India in recent campaigns
The post Russia-Linked APT ‘Winter Vivern’ Targeting Governments in Europe, Asia appeared first on SecurityWeek.
Cyberspies and cybercriminals exploited a Telerik vulnerability tracked as CVE-2019-18935 on a government agency’s IIS server.
The post Cybercriminals, APT Exploited Telerik Vulnerability in Attacks on US Government Agency appeared first on SecurityWeek.
Social media platform Facebook unlawfully processed Dutch users' personal details without consent for advertising purposes for almost a decade.
The post Facebook ‘Unlawfully’ Used Dutch Personal Data: Court appeared first on SecurityWeek.
Rapid7 spends $38 million to acquire Israeli anti-ransomware startup Minerva Labs to beef up its managed detection and response portfolio.
The post Rapid7 Buys Anti-Ransomware Firm Minerva Labs for $38 Million appeared first on SecurityWeek.
Microsoft blames a “Russian-based threat actor” for in-the-wild attacks hitting its flagship Microsoft Outlook and has released a detection script to help defenders.
The post Microsoft Pins Outlook Zero-Day Attacks on Russian Actor, Offers Detection Script appeared first on SecurityWeek.
NSA publishes recommendations on maturing identity, credential, and access management capabilities to improve cyberthreat protections.
The post NSA Shares Guidance on Maturing ICAM Capabilities for Zero Trust appeared first on SecurityWeek.
Sagar Singh and Nicholas Ceraolo have been charged for their alleged roles in a doxing operation that involved hacking a law enforcement platform and email account.
The post US Charges Two Men Over Use of Hacked Law Enforcement Database for Doxing appeared first on SecurityWeek.
The Chinese hacker group Tick has targeted an East Asian data loss prevention firm whose customers include military and other government organizations.
The post Chinese Cyberspies Hacked DLP Company Serving Military, Government Orgs appeared first on SecurityWeek.
Compliance and ZTNA are driving encryption into every aspect of an organization’s network and enterprise and, in turn, forcing us to change how we think about protecting our environments.
The post Are Encryption and Zero Trust Breaking Key Protections? appeared first on SecurityWeek.
Russia-linked APT29 was seen abusing the legitimate information exchange systems used by European countries in attacks aimed at governments.
The post Russian Cyberspies Abuse EU Information Exchange Systems in Government Attacks appeared first on SecurityWeek.
Dero cryptojacking operation infecting Kubernetes infrastructure is being targeted by Monero criptojackers for control over the same clusters.
The post Dero, Monero Cryptojackers Fighting for Same Kubernetes Clusters appeared first on SecurityWeek.
While the BISO might appear to be a new role, it is not – and understanding its past provides insights into its present.
The post The Rise of the BISO in Contemporary Cybersecurity appeared first on SecurityWeek.
SAP has released 19 new notes on March 2023 Security Patch Day, including five notes rated hot news.
The post SAP Releases Five ‘Hot News’ Notes on March 2023 Patch Day appeared first on SecurityWeek.
The Hawaii DOH says roughly 3,400 death records were accessed via the compromised account of a former employee.
The post Hawaii Health Department Says Death Records Compromised in Recent Data Breach appeared first on SecurityWeek.
Cybersecurity firm Rubrik has confirmed being hit by the GoAnywhere zero-day exploit after the Cl0p ransomware group named the company on its leak website.
The post Data Security Firm Rubrik Targeted With GoAnywhere Zero-Day Exploit appeared first on SecurityWeek.
A cybercrime group has been exploiting a Microsoft SmartScreen zero-day vulnerability tracked as CVE-2023-24880 to deliver the Magniber ransomware.
The post Microsoft SmartScreen Zero-Day Exploited to Deliver Magniber Ransomware appeared first on SecurityWeek.
Patch Tuesday: Microsoft warns vulnerability (CVE-2023-23397) could lead to exploitation before an email is viewed in the Preview Pane.
The post Microsoft Warns of Outlook Zero-Day Exploitation, Patches 80 Security Vulns appeared first on SecurityWeek.
Adobe issues urgent warning for “very limited attacks” exploiting a zero-day vulnerability in its ColdFusion web app development platform.
The post Adobe Warns of ‘Very Limited Attacks’ Exploiting ColdFusion Zero-Day appeared first on SecurityWeek.
The LockBit ransomware group claims to have stolen valuable SpaceX data after breaching the systems of Maximum Industries.
The post Ransomware Group Claims Theft of Valuable SpaceX Data From Contractor appeared first on SecurityWeek.
Cyberattacks have exposed a myriad of vulnerabilities in our healthcare infrastructure, and will continue to do so as new and innovative medical technologies are developed.
The post How the Best CISOs Drive Operational Resilience appeared first on SecurityWeek.
A new CISA pilot program to warn critical infrastructure organizations if their systems are unpatched against vulnerabilities exploited in ransomware attacks.
The post CISA Program Warns Critical Infrastructure Organizations Vulnerable to Ransomware Attacks appeared first on SecurityWeek.
Two new surveys stress the need for automation and AI – but one survey raises the additional specter of the growing use of bring your own AI (BYO-AI).
The post ChatGPT and the Growing Threat of Bring Your Own AI to the SOC appeared first on SecurityWeek.
Israeli cloud security startup Mitiga adds Samsung Next as an investor in a completed $45 million Series A financing round.
The post Cloud Forensics Startup Mitiga Completes $45M Series A appeared first on SecurityWeek.
Siemens and Schneider Electric have addressed more than 100 vulnerabilities with their March 2023 Patch Tuesday security advisories.
The post ICS Patch Tuesday: Siemens, Schneider Electric Address Over 100 Vulnerabilities appeared first on SecurityWeek.
Ring says it has no indications it has fallen victim to a ransomware attack after cybergang threatens to publish supposedly stolen data.
The post Ring Denies Falling Victim to Ransomware Attack appeared first on SecurityWeek.
Fortinet says recently patched FortiOS vulnerability was exploited in sophisticated attacks targeting government entities.
The post Fortinet Finds Zero-Day Exploit in Government Attacks After Devices Detect Integrity Breach appeared first on SecurityWeek.
The FBI received more than 800,000 cybercrime-related complaints in 2022, with losses totaling over $10 billion.
The post Cybercrime Losses Exceeded $10 Billion in 2022: FBI appeared first on SecurityWeek.
CISA has added vulnerabilities in Plex Media Server and VMware NSX-V to its Known Exploited Vulnerabilities catalog.
The post CISA Warns of Plex Vulnerability Linked to LastPass Hack appeared first on SecurityWeek.
London, UK based De-Fi platform company Euler has lost a reported $196 million to a flash loan attack.
The post Euler Loses Nearly $200 Million to Flash Loan Attack appeared first on SecurityWeek.
The recently identified Golang-based GoBruteforcer botnet is targeting web servers running FTP, MySQL, phpMyAdmin, and Postgres services.
The post New ‘GoBruteforcer’ Botnet Targets Web Servers appeared first on SecurityWeek.
NMFTA appoints Antwan Banks as director of enterprise security as the organization shifts focus to end-to-end security for the trucking industry.
The post NMFTA Appoints Cybersecurity Director to Help Protect Trucking Industry appeared first on SecurityWeek.
Zoll Medical is notifying one million individuals that their personal information was compromised in a data breach earlier this year.
The post Zoll Medical Data Breach Impacts 1 Million Individuals appeared first on SecurityWeek.
Reports published by various industrial cybersecurity companies provide different numbers on ICS vulnerabilities — here’s why.
The post Counting ICS Vulnerabilities: Examining Variations in Numbers Reported by Security Firms appeared first on SecurityWeek.
The FDIC seized the assets of Silicon Valley Bank on Friday, which could impact cybersecurity firms that use the bank's services.
The post Silicon Valley Bank Seized by FDIC as Depositors Pull Cash appeared first on SecurityWeek.
Blackbaud has been slapped with a $3 million civil penalty by the SEC for "making misleading disclosures" about a 2020 ransomware attack that impacted more than 13,000 customers.
The post Blackbaud Fined $3M For ‘Misleading Disclosures’ About 2020 Ransomware Attack appeared first on SecurityWeek.
Researchers discover a dozen serious vulnerabilities in Akuvox smart intercom, but the vendor has not released any patches.
The post Unpatched Akuvox Smart Intercom Vulnerabilities Can Be Exploited for Spying appeared first on SecurityWeek.
SecurityWeek’s Cyber Madness Bracket Challenge is a contest designed to bring the community together in a fun, competitive way through one of America’s top sporting events.
The post Cyber Madness Bracket Challenge – Register to Play appeared first on SecurityWeek.
Authorities seized a domain distributing the NetWire RAT and arrested a Croatian individual who administered the website.
The post Alleged NetWire RAT Operator Arrested in Croatia as FBI Seizes Website appeared first on SecurityWeek.
AT&T is notifying millions of wireless customers that their CPNI was compromised in a data breach at a third-party vendor.
The post Millions of AT&T Customers Notified of Data Breach at Third-Party Vendor appeared first on SecurityWeek.
A serious vulnerability in Veeam Backup & Replication may allow attackers to obtain encrypted credentials from the configuration database.
The post Serious Vulnerability Patched in Veeam Data Backup Solution appeared first on SecurityWeek.
Cerebral is informing 3.1 million individuals that their PHI was inadvertently exposed via third-party tracking technologies.
The post Cerebral Informing 3.1 Million Individuals of Inadvertent Data Exposure appeared first on SecurityWeek.
President Biden’s new $6.9 trillion budget proposal for 2024 shows that the administration wants to increase cybersecurity spending.
The post White House Budget Plan Seeks to Boost Cybersecurity Spending appeared first on SecurityWeek.
Acronis said a single customer’s account was compromised after a hacker leaked gigabytes of information on a cybercrime forum.
The post Acronis Clarifies Hack Impact Following Data Leak appeared first on SecurityWeek.
Malware deployed by Chinese hackers on a SonicWall SMA appliance includes credential theft, shell access, and persistence functionality.
The post Custom Chinese Malware Found on SonicWall Appliance appeared first on SecurityWeek.
Cisco has released patches for a high-severity DoS vulnerability in IOS XR software for several enterprise-grade routers.
The post Vulnerability Exposes Cisco Enterprise Routers to Disruptive Attacks appeared first on SecurityWeek.
QuSecure announced an end-to-end quantum resilient encrypted communications link that protects data delivered by satellite.
The post QuSecure Unveils Quantum-Resilient Communications Satellite Link appeared first on SecurityWeek.
An analysis found that over 40 exploited vulnerabilities, mostly leveraged by botnets, are missing from CISA’s ‘must patch’ catalog.
The post Dozens of Exploited Vulnerabilities Missing From CISA ‘Must Patch’ List appeared first on SecurityWeek.
Two vulnerabilities recently addressed in Jenkins server can be chained to achieve arbitrary code execution.
The post Jenkins Server Vulnerabilities Chained for Remote Code Execution appeared first on SecurityWeek.
Fortinet has patched a critical buffer underflow vulnerability in FortiOS and FortiProxy that could lead to remote code execution without authentication.
The post Fortinet Patches Critical Unauthenticated RCE Vulnerability in FortiOS appeared first on SecurityWeek.
Deepfakes are becoming increasingly popular with cybercriminals, and as these technologies become even easier to use, organizations must become even more vigilant.
The post Defeating the Deepfake Danger appeared first on SecurityWeek.
Google has announced the discontinuation of the Chrome Cleanup Tool, an application for identifying and removing unwanted software.
The post Google Discontinuing Chrome Tool for Removing Unwanted Software appeared first on SecurityWeek.
Threat actors really only stop when their infrastructure is disrupted and their flow of funds disappears.
The post Mistakes by Threat Actors Lead to Disruption, Not Just Better Blocking appeared first on SecurityWeek.
The Sys01 Stealer has been observed targeting the Facebook accounts of critical government infrastructure employees.
The post ‘Sys01 Stealer’ Malware Targeting Government Employees appeared first on SecurityWeek.
TSA instructs airport and aircraft operators to improve their cybersecurity resilience and prevent infrastructure disruption and degradation.
The post TSA Requires Aviation Sector to Enhance Cybersecurity Resilience appeared first on SecurityWeek.
Russia is continuing its campaign of disinformation around the Ukraine war through advanced social engineering delivered by a threat group tracked as TA499.
The post Pre-Deepfake Campaign Targets Putin Critics appeared first on SecurityWeek.
Register for SecurityWeek’s Ransomware Resilience & Recovery Summit, a virtual event designed to help businesses to plan, prepare, and recover from a ransomware incident.
The post Virtual Event Tomorrow: Ransomware Resilience & Recovery Summit appeared first on SecurityWeek.
A vulnerability in Toyota Customer 360 CRM platform provided a security researcher with full access to the car maker’s Mexican customers
The post Vulnerability in Toyota Management Platform Provided Access to Customer Data appeared first on SecurityWeek.
Acer said one of its document servers was hacked after a hacker claimed to have stolen 160 Gb of data from the company.
The post Acer Confirms Breach After Hacker Offers to Sell Stolen Data appeared first on SecurityWeek.
German cybersecurity start-up Edgeless Systems raises $5 million to build an open-source stack for confidential computing.
The post Edgeless Systems Raises $5M for Trustworthy Data Processing appeared first on SecurityWeek.
SecurityWeek spoke to Chris Storer, head of the cyber center of excellence at reinsurance giant Munich Re, for the cyber insurers’ view of cyberinsurance.
The post Talking Cyberinsurance With Munich Re appeared first on SecurityWeek.
Kaspersky has seen a surge in attacks on ICS computers in Russia and blames it on the exploitation of a Bitrix CMS vulnerability tracked as CVE-2022-27228.
The post Exploitation of Bitrix CMS Vulnerability Drives ICS Attack Surge in Russia appeared first on SecurityWeek.
Wallarm Detect warns of ongoing exploitation of a critical vulnerability in VMware Cloud Foundation and NSX Data Center for vSphere (NSX-V).
The post Exploitation of Critical Vulnerability in End-of-Life VMware Product Ongoing appeared first on SecurityWeek.
Google has released patches for more than 50 vulnerabilities as part of the March 2023 security updates for the Android platform.
The post Android’s March 2023 Updates Patch Over 50 Vulnerabilities appeared first on SecurityWeek.
A ransomware attack on one of Barcelona’ s main hospitals has crippled the center’s computer system and forced the cancellation of non-urgent operations and patient checkups.
The post Cyberattack Hits Major Hospital in Spanish City of Barcelona appeared first on SecurityWeek.
Several locations in Germany and Ukraine were raided recently as part of an international law enforcement operation targeting the DoppelPaymer ransomware.
The post Police Looking for Russian Suspects Following DoppelPaymer Ransomware Crackdown appeared first on SecurityWeek.
Metabase Q documents FiXS, a new malware family targeting ATMs in Latin America.
The post New ATM Malware ‘FiXS’ Emerges appeared first on SecurityWeek.
Microsoft and Mitre release Arsenal plugin to help cybersecurity professionals emulate attacks on machine learning (ML) systems.
The post New Tool Made by Microsoft and Mitre Emulates Attacks on Machine Learning Systems appeared first on SecurityWeek.
Authorities disrupted an international cybercrime gang which has been blackmailing large companies and institutions for years.
The post European Police, FBI Bust International Cybercrime Gang appeared first on SecurityWeek.
Play ransomware operators have leaked data allegedly stolen from the City of Oakland last month.
The post Ransomware Operators Leak Data Allegedly Stolen From City of Oakland appeared first on SecurityWeek.
The online counseling service BetterHelp has agreed to return $7.8 million to customers to settle with the Federal Trade Commission for sharing health data it had promised to keep private
The post BetterHelp Shared Users’ Sensitive Health Data, FTC Says appeared first on SecurityWeek.
Carding marketplace BidenCash last week released information on more than 2.1 million credit and debit cards.
The post Cybercrime Marketplace Leaks Over 2.1 Million Payment Cards appeared first on SecurityWeek.
There are nearly 900 vulnerabilities in CISA's Known Exploited Vulnerabilities (KEV) catalog, including nearly 100 discovered in 2022.
The post 557 CVEs Added to CISA’s Known Exploited Vulnerabilities Catalog in 2022 appeared first on SecurityWeek.
Thirty-five cybersecurity-related M&A deals were announced in February 2023
The post Cybersecurity M&A Roundup: 35 Deals Announced in February 2023 appeared first on SecurityWeek.
Wago has patched critical vulnerabilities that can allow hackers to take complete control of its programmable logic controllers (PLCs).
The post Critical Vulnerabilities Allow Hackers to Take Full Control of Wago PLCs appeared first on SecurityWeek.
The Biden administration said it would require states to report on cybersecurity threats in their audits of public water systems, a day after it released a broader plan to protect critical infrastructure against cyberattacks.
The post EPA Mandates States Report on Cyber Threats to Water Systems appeared first on SecurityWeek.
Cybersecurity startup Wiz warns of a widespread redirection campaign in which thousands of websites have been compromised using legitimate FTP credentials.
The post Thousands of Websites Hijacked Using Compromised FTP Credentials appeared first on SecurityWeek.
FBI and CISA have issued an alert to warn organizations of the risks associated with Royal ransomware attacks.
The post Organizations Warned of Royal Ransomware Attacks appeared first on SecurityWeek.
Feedback Friday: Industry professionals commented on various aspects of the new national cybersecurity strategy, its impact, and implications.
The post Industry Experts Analyze US National Cybersecurity Strategy appeared first on SecurityWeek.
Some say the White House cybersecurity strategy is largely aspirational. Its boldest initiatives — including stricter rules on breach reporting and software liability — are apt to meet resistance from business and Republicans in Congress.
The post White House Cybersecurity Strategy Stresses Software Safety appeared first on SecurityWeek.
Chick-fil-A is informing users that their accounts have been compromised in a two-month-long credential stuffing campaign.
The post Over 71k Impacted by Credential Stuffing Attacks on Chick-fil-A Accounts appeared first on SecurityWeek.
ESET says the BlackLotus UEFI bootkit can bypass secure boot on fully updated Windows 11 systems.
The post BlackLotus Bootkit Can Target Fully Patched Windows 11 Systems appeared first on SecurityWeek.
Anna Tutt, CMO of Oort, shares her experiences and perspectives on how we can accelerate growth of women in cybersecurity.
The post Advancing Women in Cybersecurity – One CMO’s Journey appeared first on SecurityWeek.
CISA has released a free and open source tool that makes it easier to map an attacker’s TTPs to the Mitre ATT&CK framework.
The post New CISA Tool ‘Decider’ Maps Attacker Behavior to ATT&CK Framework appeared first on SecurityWeek.
GitHub this week made secret scanning generally available and free for all public repositories.
The post GitHub Secret Scanning Now Generally Available appeared first on SecurityWeek.
Proton, perhaps best known for its encrypted email service, sees its mission of ensuring privacy and online access as a vital tool in shoring up democracy in the digital age.
The post Internet Access, Privacy ‘Essential for Freedom’: Proton Chief appeared first on SecurityWeek.
So how serious is the threat of using TikTok? Should TikTok users who don’t work for the government be worried about the app, too?
The post Why TikTok Is Being Banned on Gov’t Phones in US and Beyond appeared first on SecurityWeek.
Join SecuityWeek and LogRhythm as we dive into security risks associated with SaaS, as well as best practices for mitigating these risks and protecting data.
The post Webinar Tomorrow: Entering the Cloud Native Security Era appeared first on SecurityWeek.
Endor Labs has introduced an OWASP-style listing of the most important or impactful risks inherent in the use of open source software (OSS).
The post Top 10 Security, Operational Risks From Open Source Code appeared first on SecurityWeek.
Cisco announced plans to acquire Valtix, an early-stage Silicon Valley startup in the cloud network security business.
The post Cisco to Acquire Valtix for Cloud Network Security Tech appeared first on SecurityWeek.
History has shown that when it comes to ransomware, organizations cannot let their guards down.
The post Ransomware Attacks: Don’t Let Your Guard Down appeared first on SecurityWeek.
Two APTs, named Winnti and Clasiopa, have been observed targeting Asian organizations in the materials sector.
The post Two Hacking Groups Seen Targeting Materials Sector in Asia appeared first on SecurityWeek.
In January and February 2023, six law firms were targeted with the GootLoader and SocGholish malware in two separate campaigns.
The post Several Law Firms Targeted in Malware Attacks appeared first on SecurityWeek.
The Biden administration urged Congress to renew the Foreign Intelligence Surveillance Act (FISA) that the government sees as vital in countering overseas terrorism, and cyberattacks.
The post US Officials Make Case for Renewing FISA Surveillance Powers appeared first on SecurityWeek.
Google this week made client-side encryption for Gmail and Calendar available for Workspace customers.
The post Google Workspace Client-Side Encryption Now Generally Available in Gmail, Calendar appeared first on SecurityWeek.
In this issue of CISO Conversations we talk to two CISOs about solving the CISO/CIO conflict by combining the roles under one person.
The post CISO Conversations: Code42, BreachQuest Leaders Discuss Combining CISO and CIO Roles appeared first on SecurityWeek.
The South American cyberespionage group Blind Eagle has been observed impersonating a Colombian government tax agency in recent attacks.
The post South American Cyberspies Impersonate Colombian Government in Recent Campaign appeared first on SecurityWeek.
Satellite TV giant Dish Network has confirmed rumors that a recent outage was the result of a cyberattack and admitted that data was stolen.
The post Dish Network Says Outage Caused by Ransomware Attack appeared first on SecurityWeek.
Several ThingWorx and Kepware products are affected by two vulnerabilities that can be exploited for DoS attacks and unauthenticated remote code execution.
The post Critical Vulnerabilities Patched in ThingWorx, Kepware IIoT Products appeared first on SecurityWeek.
Security defects in the Trusted Platform Module (TPM) 2.0 reference library specification expose devices to code execution attacks.
The post Security Defects in TPM 2.0 Spec Raise Alarm appeared first on SecurityWeek.
The US Marshals Service has confirmed that ransomware was deployed on one of its systems that contains sensitive law enforcement information.
The post Ransomware Attack Hits US Marshals Service appeared first on SecurityWeek.
Trackd, an early stage startup founded by former NSA engineer Mike Starr, has secured $3.35 million in seed funding to automate vulnerability remediation.
The post Trackd Snags $3.35M Seed Funding to Automate Vuln Remediation appeared first on SecurityWeek.
The time from vulnerability disclosure to exploitation is decreasing, according to a new intelligence report from Rapid7.
The post Vulnerabilities Being Exploited Faster Than Ever: Analysis appeared first on SecurityWeek.
A recently identified post-exploitation framework ‘Exfiltrator-22’ uses the same C&C infrastructure as the LockBit ransomware.
The post New ‘Exfiltrator-22’ Post-Exploitation Framework Linked to Former LockBit Affiliates appeared first on SecurityWeek.
CrowdStrike identified 33 new threat actors and campaigns in 2022, including many cybercrime groups and operations.
The post 33 New Adversaries Identified by CrowdStrike in 2022 appeared first on SecurityWeek.
Russian authorities said that several television and radio stations that have recently broadcast air raid alerts had been breached by hackers.
The post ‘Hackers’ Behind Air Raid Alerts Across Russia: Official appeared first on SecurityWeek.
AI-driven identity verification platform Vouched has raised $6.3 million in a funding round led by BHG VC and SpringRock Ventures.
The post Vouched Raises $6.3 Million for Identity Verification Platform appeared first on SecurityWeek.
A critical vulnerability in the Houzez premium WordPress theme and plugin has been exploited in the wild.
The post Vulnerability in Popular Real Estate Theme Exploited to Hack WordPress Websites appeared first on SecurityWeek.
The National Rural Electric Cooperative Association (NRECA) announces commercial launch of its OT cybersecurity solution.
The post US Electric Cooperative Association Launches Commercial OT Security Solution appeared first on SecurityWeek.
The White House is giving all federal agencies 30 days to wipe TikTok off all government devices.
The post White House: No More TikTok on Gov’t Devices Within 30 Days appeared first on SecurityWeek.
LastPass DevOp engineer's home computer hacked and implanted with keylogging malware as part of a sustained cyberattack that exfiltrated corporate data from the cloud storage resources.
The post LastPass Says DevOps Engineer Home Computer Hacked appeared first on SecurityWeek.
A cyberattack on the Boston-based Pipefitters Local 537 union’s health fund resulted in the loss of $6.4 million.
The post Cyberattack on Boston Union Results in $6.4M Loss appeared first on SecurityWeek.
The U.S. government is set to green-light a more aggressive ‘hack-back’ approach to dealing with foreign adversaries and mandatory regulation of critical infrastructure vendors.
The post US National Cyber Strategy Pushes Regulation, Aggressive Hack-Back Operations appeared first on SecurityWeek.
US Department of Treasury has announced a fresh set of sanctions against entities helping Russia in the war against Ukraine.
The post US Sanctions Several Entities Aiding Russia’s Cyber Operations appeared first on SecurityWeek.
Threat actor uses the PureCrypter downloader to deliver malware to government entities in Asia-Pacific and North America.
The post ‘PureCrypter’ Downloader Used to Deliver Malware to Governments appeared first on SecurityWeek.
Cloud security company Wiz has raised $300 million in a Series D funding round that brings the total raised by the company to $900 million.
The post Cloud Security Firm Wiz Raises $300 Million at $10 Billion Valuation appeared first on SecurityWeek.
New QNAP Systems bug bounty program covers vulnerabilities in applications, cloud services, and operating systems.
The post QNAP Offering $20,000 Rewards via New Bug Bounty Program appeared first on SecurityWeek.
News Corp says a threat group, previously linked to the Chinese government, had access to its systems for two years before the breach was discovered.
The post Media Giant News Corp Discloses New Details of Data Breach appeared first on SecurityWeek.
Palo Alto Networks introduces a new OT security solution for industrial organizations that provides visibility, zero trust and simplified operations.
The post Palo Alto Networks Unveils Zero Trust OT Security Solution appeared first on SecurityWeek.
750 cyber specialists have participated in Defence Cyber Marvel 2 (DCM2), the biggest military cyberwarfare exercise in Western Europe.
The post 11 Countries Take Part in Military Cyberwarfare Exercise appeared first on SecurityWeek.
Fortinet provides clarifications following ‘sensationalized reports’ related to exploitation attempts targeting the FortiNAC vulnerability CVE-2022-39952
The post Fortinet Shares Clarifications on Exploitation of FortiNAC Vulnerability appeared first on SecurityWeek.
Dole was forced to shut down systems in North America due to a ransomware attack, which has reportedly led to salad shortages in some grocery stores.
The post Ransomware Attack Forces Produce Giant Dole to Shut Down Plants appeared first on SecurityWeek.
Cybercriminals are delivering stealthy cryptojacking malware to Macs using pirated apps and they could use the same method for other malware.
The post Stealthy Mac Malware Delivered via Pirated Apps appeared first on SecurityWeek.
Over 1,000 cybersecurity funding announcements were made in 2022, and startups raised $79 billion across more than 4,200 deals since 2018.
The post Cybersecurity VC Funding Topped $18 Billion in 2022: Report appeared first on SecurityWeek.
The European Union’s executive branch has banned TikTok from phones used by employees as a cybersecurity measure, reflecting widening worries over the Chinese-owned video app.
The post TikTok Banned From EU Commission Phones Over Cybersecurity appeared first on SecurityWeek.
A Russian malware developer behind the NLBrute brute-forcing tool has been extradited to the United States from Georgia.
The post Russian Accused of Developing NLBrute Malware Extradited to US appeared first on SecurityWeek.
Join this webinar to gain clear advice on the people, process and technology considerations that must be made at every stage of an OT security program’s lifecycle.
The post Webinar Today: Building Sustainable OT Cybersecurity Programs appeared first on SecurityWeek.
Cisco has patched DoS and CSRF vulnerabilities in the Application Policy Infrastructure Controller (APIC) and Nexus 9000 series switches.
The post Cisco Patches High-Severity Vulnerabilities in ACI Components appeared first on SecurityWeek.
Hackers started exploiting the Fortinet FortiNAC vulnerability CVE-2022-39952 the same day a PoC exploit was released.
The post Fortinet FortiNAC Vulnerability Exploited in Wild Days After Release of Patch appeared first on SecurityWeek.
Intel paid out more than $935,000 through its bug bounty program in 2022, but found over half of the vulnerabilities internally.
The post Intel Paid Out Over $4.1 Million via Bug Bounty Program Since 2017 appeared first on SecurityWeek.
Google rewarded over 700 researchers in 2022 for contributions to its bug bounty program, with the highest single payout at $605,000.
The post Google Paid Out $12 Million via Bug Bounty Programs in 2022 appeared first on SecurityWeek.
CISA has added two Mitel MiVoice Connect vulnerabilities to its known exploited vulnerabilities catalog and instructed federal agencies to patch them within three weeks.
The post CISA Warns of Two Mitel Vulnerabilities Exploited in Wild appeared first on SecurityWeek.
VMware issues a critical fix for a vulnerability that allows hacker to gain full access to the underlying server operating system.
The post VMware Plugs Critical Carbon Black App Control Flaw appeared first on SecurityWeek.
The conventional tools we rely on to defend corporate networks are creating gaps in network visibility and in our capabilities to secure them.
The post Enterprise Blind Spots and Obsolete Tools – Security Teams Must Evolve appeared first on SecurityWeek.
In this virtual summit, SecurityWeek brings together expert defenders to share best practices around reducing attack surfaces in modern computing.
The post Register Now: Attack Surface Management Summit – Feb. 22 appeared first on SecurityWeek.
Apple has updated its security advisories to add new iOS and macOS vulnerabilities, including ones belonging to a new class of bugs.
The post Apple Updates Advisories as Security Firm Discloses New Class of Vulnerabilities appeared first on SecurityWeek.
The CRYSTALS-Kyber public-key encryption and key encapsulation mechanism recommended by NIST for post-quantum cryptography has been broken using AI combined with side channel attacks.
The post AI Helps Crack NIST-Recommended Post-Quantum Encryption Algorithm appeared first on SecurityWeek.
HardBit ransomware operators want to work with victims to negotiate a ransom behind the back of cyberinsurance companies.
The post HardBit Ransomware Offers to Set Ransom Based on Victim’s Cyberinsurance appeared first on SecurityWeek.
India-based Scrut Automation has raised money to improve its risk observability and compliance automation platform and expand its presence in the US.
The post Scrut Automation Raises $7.5 Million for GRC Platform appeared first on SecurityWeek.
Twitter started a security ruckus over the weekend with the sudden decision to turn off text message/SMS method of two-factor authentication (2FA) for non-subscribers.
The post Twitter Shuts Off Text-Based 2FA for Non-Subscribers appeared first on SecurityWeek.
Coinbase was recently targeted in a sophisticated phishing attack and the cryptocurrency exchange linked the hack to the 0ktapus group.
The post Coinbase Attack Linked to Group Behind Last Year’s Twilio, Cloudflare Hacks appeared first on SecurityWeek.
Samsung’s Message Guard provides a sandbox designed to protect phones and tablets against zero-click exploits.
The post New Samsung Message Guard Protects Mobile Devices Against Zero-Click Exploits appeared first on SecurityWeek.
Fortinet releases 40 security advisories to inform customers about patches, including for critical code execution vulnerabilities in FortiNAC and FortiWeb.
The post Fortinet Patches Critical Code Execution Vulnerabilities in FortiNAC, FortiWeb appeared first on SecurityWeek.
Seventeen cybersecurity-related M&A deals were announced in the first half of February 2023.
The post Cybersecurity M&A Roundup for February 1-15, 2023 appeared first on SecurityWeek.
GoDaddy recently discovered a hacker attack where a sophisticated threat group infected websites and servers with malware.
The post GoDaddy Says Recent Hack Part of Multi-Year Campaign appeared first on SecurityWeek.
Spanish Court agreed to extradite Joseph James O’Connor to he U.S., who allegedly took part in the July 2020 hacking of Twitter accounts of public figures such as Joseph Biden, Barack Obama and Bill Gates.
The post Spain Orders Extradition of British Alleged Hacker to U.S. appeared first on SecurityWeek.
Malwarebytes warns of a remote code execution vulnerability impacting Arris G2482A, TG2492, and SBG10 routers, which have reached end-of-life (EOL).
The post Newly Disclosed Vulnerability Exposes EOL Arris Routers to Attacks appeared first on SecurityWeek.
The Frebniis malware abuses a Microsoft IIS feature to deploy a backdoor and monitor all HTTP traffic to the system.
The post ‘Frebniis’ Malware Hijacks Microsoft IIS Function to Deploy Backdoor appeared first on SecurityWeek.
Top state election and cybersecurity officials warned about threats posed by Russia and other foreign adversaries ahead of the 2024 elections
The post Security Experts Warn of Foreign Cyber Threat to 2024 Voting appeared first on SecurityWeek.
SolarWinds advisories describe multiple high-severity vulnerabilities that a Platform update will patch by the end of February.
The post SolarWinds Announces Upcoming Patches for High-Severity Vulnerabilities appeared first on SecurityWeek.
ENISA and CERT-EU warn of Chinese threat actors targeting businesses and government organizations in the European Union.
The post EU Organizations Warned of Chinese APT Attacks appeared first on SecurityWeek.
White hat hackers received $180,000 at Pwn2Own Miami 2023 for exploits targeting widely used ICS products.
The post Hackers Earn $180,000 for ICS Exploits at Pwn2Own Miami 2023 appeared first on SecurityWeek.
CommandK announced that it has raised $3 million in a seed funding round for a solution designed to help organizations secure sensitive data.
The post Data Security Startup CommandK Raises $3 Million in Seed Funding appeared first on SecurityWeek.
A group of hackers has leaked Atlassian employee records and floorplans, information that was obtained from third-party workplace platform Envoy.
The post Atlassian Investigating Security Breach After Hackers Leak Data appeared first on SecurityWeek.
A look at some of the lessons from the Ukraine war and how they could apply to a Taiwan conflict.
The post How Ukraine War Has Shaped US Planning for a China Conflict appeared first on SecurityWeek.
While the total number of new XIoT vulnerabilities is reducing, the difficulty in securing these devices remains high – especially in OT situations.
The post Published XIoT Vulnerabilities Trend Down, but Vigilance Must Remain High: Report appeared first on SecurityWeek.
The former NSA deputy director Chris Inglis was picked 17 months ago to be President Joe Biden’s top advisor on cybersecurity issues.
The post Chris Inglis Steps Down as US National Cyber Director appeared first on SecurityWeek.
Mozilla releases Firefox 110 and Firefox ESR 102.8 with patches for 10 high-severity vulnerabilities.
The post Firefox Updates Patch 10 High-Severity Vulnerabilities appeared first on SecurityWeek.
A recent variant of the Mirai malware has been observed targeting 13 IoT vulnerabilities to ensnare devices into a botnet.
The post Mirai Variant V3G4 Targets 13 Vulnerabilities to Infect IoT Devices appeared first on SecurityWeek.
Cisco updates endpoint, cloud, and web security products to address a critical vulnerability in third-party scanning library ClamAV.
The post Critical Vulnerability Patched in Cisco Security Products appeared first on SecurityWeek.
Hundreds of new servers were compromised in the past days as part of ESXiArgs ransomware attacks, but it’s still unclear which vulnerability is being exploited.
The post Surge in ESXiArgs Ransomware Attacks as Questions Linger Over Exploited Vulnerability appeared first on SecurityWeek.
Private equity firm Francisco Partners is acquiring cloud monitoring, log management and SIEM solutions provider Sumo Logic.
The post PE Firm Francisco Partners to Take Sumo Logic Private in $1.7B Deal appeared first on SecurityWeek.
The city of Oakland, California issued a local state of emergency as a result of the impacts following a ransomware attack.
The post Ransomware Attack Pushes City of Oakland Into State of Emergency appeared first on SecurityWeek.
Splunk updates for Enterprise products resolve multiple high-severity vulnerabilities, including several in third-party packages.
The post Splunk Enterprise Updates Patch High-Severity Vulnerabilities appeared first on SecurityWeek.
Intel has released patches for multiple critical- and high-severity vulnerabilities across its product portfolio.
The post Dozens of Vulnerabilities Patched in Intel Products appeared first on SecurityWeek.
Descope raises an abnormally large $53 million seed-stage funding round for technology in the customer identity and authentication space.
The post Descope Targets Customer Identity Market with Massive $53M Seed Round appeared first on SecurityWeek.
A vulnerability affecting IBM’s Aspera Faspex file transfer solution, tracked as CVE-2022-47986, has been exploited in attacks.
The post Recently Patched IBM Aspera Faspex Vulnerability Exploited in the Wild appeared first on SecurityWeek.
Siemens and Schneider Electric address nearly 100 vulnerabilities across several of their products with their February 2023 Patch Tuesday advisories.
The post ICS Patch Tuesday: 100 Vulnerabilities Addressed by Siemens, Schneider Electric appeared first on SecurityWeek.
Israeli startup Oligo Security raises $28 million to build technology to detect and mitigate open source code vulnerabilities.
The post Oligo Security Exits Stealth with $28M for AppSec, Open Source Security appeared first on SecurityWeek.
Citrix released patches for multiple vulnerabilities in Virtual Apps and Desktops, and Workspace apps for Windows and Linux.
The post Citrix Patches High-Severity Vulnerabilities in Windows, Linux Apps appeared first on SecurityWeek.
SAP has released 21 notes on February 2023 Security Patch Day, including three notes addressing high-severity vulnerabilities in SAP Start Service and BusinessObjects.
The post SAP’s February 2023 Security Updates Patch High-Severity Vulnerabilities appeared first on SecurityWeek.
Cybersecurity firm Forescout shows how various ICS vulnerabilities can be chained for an exploit that allows hackers to cause damage to a bridge.
The post ICS Vulnerabilities Chained for Deep Lateral Movement and Physical Damage appeared first on SecurityWeek.
Vladislav Klyushin was found guilty on all charges against him, including wire fraud and securities fraud, after a two-week trial in federal court in Boston.
The post Russian Businessman Guilty in Hacking, Insider Trade Scheme appeared first on SecurityWeek.
Zcaler plans to acquire Israeli startup Canonic Security to expand into the red-hot software supply chain security business.
The post Zscaler to Acquire Israeli Startup Canonic Security appeared first on SecurityWeek.
Microsoft’s Patch Tuesday machine is humming loudly with software updates to fix at least 76 vulnerabilities in Windows and OS components.
The post Patch Tuesday: Microsoft Warns of Exploited Windows Zero-Days appeared first on SecurityWeek.
Patch Tuesday: Adobe ships security fixes for at least a half dozen vulnerabilities that expose Windows and macOS users to malicious hacker attacks.
The post Adobe Plugs Critical Security Holes in Illustrator, After Effects Software appeared first on SecurityWeek.
Spanish and US authorities have dismantled a cybercrime ring that defrauded victims of more than $5.3 million.
The post Spanish, US Authorities Dismantle Cybercrime Ring That Defrauded Victims of $5.3 Million appeared first on SecurityWeek.
Dragos ICS/OT Cybersecurity Year in Review 2022 report covers state-sponsored attacks, ransomware, and vulnerabilities.
The post 2022 ICS Attacks: Fewer-Than-Expected on US Energy Sector, But Ransomware Surged appeared first on SecurityWeek.
SecurityWeek examines the role of the virtual CISO in a conversation with Chris Bedel and Greg Schaffer.
The post CISO Conversations: The Role of the vCISO appeared first on SecurityWeek.
Pepsi Bottling Ventures, the largest privately-held bottler of Pepsi-Cola products in the United States, says data was stolen from its systems following a malware attack.
The post Pepsi Bottling Ventures Discloses Data Breach appeared first on SecurityWeek.
Cloudflare over the weekend mitigated a record-setting DDoS attack that peaked at 71 million requests per second.
The post Record-Breaking 71 Million RPS DDoS Attack Seen by Cloudflare appeared first on SecurityWeek.
Organizations hit by exploitation of the GoAnywhere MFT zero-day vulnerability CVE-2023-0669 have started coming forward.
The post GoAnywhere Zero-Day Attack Victims Start Disclosing Significant Impact appeared first on SecurityWeek.
Hackers took down the websites of Bahrain’s international airport and state news agency to mark the 12-year anniversary of an Arab Spring uprising in the small Gulf country.
The post Hackers Target Bahrain Airport, News Sites to Mark Uprising appeared first on SecurityWeek.
Apple has released updates for macOS, iOS and Safari and they all include a WebKit patch for a zero-day vulnerability tracked as CVE-2023-23529.
The post Apple Patches Actively Exploited WebKit Zero-Day Vulnerability appeared first on SecurityWeek.
The war in Ukraine is the first major conflagration between two technologically advanced powers in the age of cyber. It prompts us to question the nature of modern warfare and the role of cyber in its operation.
The post The Lessons From Cyberwar, Cyber-in-War and Ukraine appeared first on SecurityWeek.
The personal and health information of more than 3.3 million individuals was stolen in a ransomware attack at Regal Medical Group.
The post 3.3 Million Impacted by Ransomware Attack at California Healthcare Provider appeared first on SecurityWeek.
The City of Oakland has disclosed a ransomware attack that impacted several non-emergency systems.
The post City of Oakland Hit by Ransomware Attack appeared first on SecurityWeek.
Cybersecurity company Group-IB claims it was repeatedly targeted by a Chinese APT called Tonto Team, CactusPete, and Karma Panda.
The post Cybersecurity Firm Group-IB Repeatedly Targeted by Chinese APT appeared first on SecurityWeek.
The Play ransomware group has claimed responsibility for a cyberattack on application delivery controller maker A10 Networks
The post Play Ransomware Group Claims Attack on A10 Networks appeared first on SecurityWeek.
Forty cybersecurity-related M&A deals were announced in January 2023.
The post Cybersecurity M&A Roundup: 40 Deals Announced in January 2023 appeared first on SecurityWeek.
SecurityWeek spoke with more than 300 cybersecurity experts to see what is bubbling beneath the surface, and examine how those evolving threats will present new and expanded risk for cybersecurity teams in 2023 and beyond.
The post SecurityWeek Cyber Insights 2023 Series appeared first on SecurityWeek.
The United States on Friday blacklisted six Chinese entities it said were linked to Beijing’s aerospace programs as part of its retaliation over an alleged Chinese spy balloon that traversed U.S. airspace.
The economic restrictions followed the Biden administration’s pledge to consider broader efforts to address Chinese surveillance activities and will make it more difficult for the five companies and one research institute to obtain American technology exports.
The move is likely to further escalate the diplomatic row between the U.S. and China sparked by the balloon, which was shot down last weekend off the Carolina coast. The U.S. said the balloon was equipped to detect and collect intelligence signals, but Beijing insists it was a weather craft that had blown off course.
The incident prompted Secretary of State Antony Blinken to abruptly cancel a high-stakes trip to Beijing aimed at easing tensions.
The U.S. Bureau of Industry and Security said the six entities were being targeted for “their support to China’s military modernization efforts, specifically the People’s Liberation Army’s (PLA) aerospace programs including airships and balloons.”
“The PLA is utilizing High Altitude Balloons (HAB) for intelligence and reconnaissance activities,” it said.
Deputy Secretary of Commerce Don Graves said on Twitter his department “will not hesitate to continue to use” such restrictions and other regulatory and enforcement tools “to protect U.S. national security and sovereignty.”
The six entities are Beijing Nanjiang Aerospace Technology Co., China Electronics Technology Group Corporation 48th Research Institute, Dongguan Lingkong Remote Sensing Technology Co., Eagles Men Aviation Science and Technology Group Co., Guangzhou Tian-Hai-Xiang Aviation Technology Co., and Shanxi Eagles Men Aviation Science and Technology Group Co.
The research institute did not immediately respond to a request for comment. The other five entities could not be reached.
On Friday, a U.S. military fighter jet shot down an unknown object flying off the remote northern coast of Alaska on orders from President Joe Biden. The object was downed because it reportedly posed a threat to the safety of civilian flights, instead of any knowledge that it was engaged in surveillance.
But the twin incidents in such close succession reflect heightened concerns over China’s surveillance program and public pressure on Biden to take a tough stand against it.
The post US Blacklists 6 Chinese Entities Over Balloon Program appeared first on SecurityWeek.
Organizations worldwide have been warned of an increase in the number of attacks abusing Microsoft OneNote documents for malware delivery.
Part of the Office suite, OneNote is typically used within organizations for note taking and task management, among other operations.
What makes OneNote documents an attractive target for threat actors includes the fact that they do not benefit from the Mark-of-the-Web (MOTW) protection, along with the fact that files can be attached to OneNote notebooks and then executed with minimal warnings.
In August last year, security researchers warned that MOTW was not applied to OneNote attachments, meaning that unsigned executables or macro-enabled documents could be used to bypass existing protections.
According to WithSecure, however, Microsoft last month silently patched the ability to bypass MOTW for OneNote attachments, which decreases the potential for abuse, but does not completely eliminate it, allowing threat actors to embed files in OneNote documents and lure users into executing them.
Attacks abusing OneNote documents for malware delivery are not different from those using other types of malicious Office files: under different pretenses, the user is tricked into opening the document and enabling editing, which results in the execution of attached code.
In December 2022 and January 2023, Proofpoint observed more than 50 malicious campaigns abusing OneNote documents for the delivery of malware such as AsyncRAT, AgentTesla, DoubleBack, NetWire RAT, Redline, Quasar RAT, and XWorm.
Both Proofpoint and Sophos observed initial access broker TA577 joining the fray at the end of January, relying on the same technique for the delivery of Qbot (also known as Quakbot).
The observed campaigns are different in volume, some targeting a small number of industries, while others involve thousands of messages sent to numerous recipients. According to Proofpoint, the attacks targeted organizations worldwide, with a focus on North America and Europe.
“Based on data in open-source malware repositories, initially observed attachments were not detected as malicious by multiple antivirus engines, thus it is likely initial campaigns had a high efficacy rate if the email was not blocked,” Proofpoint notes.
According to Opalsec, the list of malware delivered via malicious OneNote documents also includes the Formbook infostealer, the IcedID trojan, and the Remcos RAT.
Security researcher Marco Ramilli says that the abuse of OneNote for malware delivery has been ongoing for more than four months. The observed payloads, he says, include some of the aforementioned remote access trojan (RAT) families.
These attacks are efficient because the target interacts with the malicious document. Thus, educating users and employees on not opening files received from untrusted sources can mitigate risks.
Related:Malicious Macro-Enabled Docs Delivered via Container Files to Bypass Microsoft Protections
Related: Microsoft Resumes Rollout of Macro Blocking Feature
Related: Microsoft Restricts Excel 4.0 Macros by Default
The post Microsoft OneNote Abuse for Malware Delivery Surges appeared first on SecurityWeek.
The number of vulnerabilities discovered in industrial control systems (ICS) continues to increase, and many of them have a ‘critical’ or ‘high’ severity rating, according to a new report from industrial cybersecurity firm SynSaber.
The report compares the number of ICS and ICS medical advisories published by CISA between 2020 and 2022. While the number of advisories was roughly the same in 2021 and 2022, at 350, the number of vulnerabilities discovered last year reached 1,342, compared to 1,191 in the previous year.
The number of vulnerabilities rated ‘critical’ has increased even more significantly, from 186 in 2021 to nearly 300 in 2022. In total, nearly 1,000 vulnerabilities are ‘critical’ or ‘high severity’ based on their CVSS score.
While CVSS scores can be misleading in the case of ICS flaws and they should not be used on their own for patching prioritization, these scores can still be useful for ranking issues that meet an organization’s applicability criteria.
Synsaber’s report shows that Siemens stands out when it comes to ICS vulnerability volume. Not only do many of the security holes discovered in 2022 impact Siemens products, the German industrial giant is also responsible for self-reporting the highest number of vulnerabilities, far more than other vendors.
Siemens’ product security team reported 544 vulnerabilities in 2022, up from 230 in the previous year. The second vendor is Hitachi, with 64 bugs.
“The team at Siemens product security continues to increase its reporting cadence with significant year-over-year growth of nearly 3x. While this does inflate the number of known CVEs that affect Siemens product lines compared to others, this should not be viewed as Siemens products being less secure. On the contrary, a mature and repeatable OEM self-reporting process is something all other OEMs should strive to achieve,” SynSaber noted.
Siemens typically addresses dozens of vulnerabilities every month, but many affect third-party components used by the company’s products.
While the number of vulnerabilities discovered last year is high, nearly one-third require user interaction for successful exploitation and roughly one-quarter require local or physical access to the targeted system. It’s worth noting, however, that the percentage of flaws requiring user interaction and local access has decreased compared to 2021.
Looking at the data for the past three years, one worrying aspect is that the number of ‘forever-day vulnerabilities’ — these are flaws that will likely never get patches — increased to 28% in 2022, up from 14% in 2021.
ICS vulnerabilities can impact software, firmware or protocols. The percentage of issues found in each of these categories has been fairly constant in 2020-2022, with software accounting for 56%, firmware for 36% and protocols for 8%, on average over the three years.
Related: 2023 ICS Patch Tuesday Debuts With 12 Security Advisories From Siemens, Schneider
Related: SynSaber Launches Palm-Sized Threat Sensor for OT Environments
The post Siemens Drives Rise in ICS Vulnerabilities Discovered in 2022: Report appeared first on SecurityWeek.
The National Institute of Standards and Technology (NIST) has selected a group of cryptographic algorithms called Ascon as the lightweight cryptography standard to protect data flowing through IoT devices.
Following a multi-year effort that included security code reviews, NIST announced the Ascon family of algorithms will soon be the standard to protect data created and transmitted by the Internet of Things (IoT), including its myriad tiny sensors and actuators.
The Ascon algorithms, developed in 2014 by a team of cryptographers from Graz University of Technology, Infineon Technologies, Lamarr Security Research and Radboud University, are designed for miniature technologies such as implanted medical devices, stress detectors inside roads and bridges, and keyless entry fobs for vehicles.
According to NIST, these tiny devices need “lightweight cryptography” — protection that uses the limited amount of electronic resources they possess
The Ascon family was selected in 2019 as the primary choice for lightweight authenticated encryption in the final portfolio of the CAESAR competition, a sign that Ascon had withstood years of examination by cryptographers, NIST said in a note announcing the choice.
“The world is moving toward using small devices for lots of tasks ranging from sensing to identification to machine control, and because these small devices have limited resources, they need security that has a compact implementation,” said NIST computer scientist Kerry McKay. “These algorithms should cover most devices that have these sorts of resource constraints.”
The standards body expects Ascon to power two of the most important tasks in lightweight cryptography: authenticated encryption with associated data (AEAD) and hashing.
The Institute made it clear that the new algorithms are not intended to be used for post-quantum encryption.
“One of the Ascon variants offers a measure of resistance to the sort of attack a powerful quantum computer might mount. However, that’s not the main goal here,” McKay said. “Post-quantum encryption is primarily important for long-term secrets that need to be protected for years. Generally, lightweight cryptography is important for more ephemeral secrets.”
Related: Is OTP a Viable Alternative to NIST’s Post-Quantum Algorithms?
Related: CISA: Critical Infrastructure Must Prep for Post-Quantum Cryptography
Related: NIST Post-Quantum Algorithm Finalist Cracked Using a Classical PC
Related: NIST Announces Post Quantum Encryption Competition Winners
The post NIST Picks Ascon Algorithms to Protect Data on IoT, Small Electronic Devices appeared first on SecurityWeek.
Riot Security, a startup focused on security awareness training, has secured $12 million in a Series A funding round led by San Francisco-based VC fund Base10.
Riot’s SaaS-based platform provides personalized awareness programs that can be consistently sent to employees in order to foster cybersecurity culture within companies.
The programs are run through an interactive chatbot that integrates with Slack and Microsoft Teams, and the platform offers quick, immersive courses that generate user-specific content, along with regularly simulated phishing attacks to evaluate risks across employees.
Founded by Benjamin Netter, Riot emerged from the YCombinator startup accelerator and raised $3 million in their 2020 seed round. This Series A round brings the total amount raised by the company to $15 million.
Additional investors in the Series A round include existing investors Y Combinator, Funders Club and Founders Future, as well as angel investors such as Snyk founder Guy Podjarny, Duolingo co-founder Severin Hacker, Supercell co-founder lkka Paananen, Deel co-founder Alex Bouaziz, and Slack CPO Tamar Yehoshua.
Related: Investors Bet Big on Subscription-Based Security Skills Training
Related: Measuring Cybersecurity Training Effectiveness
The post Security Awareness Training Startup Riot Raises $12 Million appeared first on SecurityWeek.
A newly identified threat actor has been targeting military organizations in Pakistan with sophisticated malware, BlackBerry reports.
Tracked as NewsPenguin, the adversary has been observed sending phishing emails that use the upcoming Pakistan International Maritime Expo & Conference (PIMEC-2023) as bait and which carry weaponized documents to deliver an advanced espionage tool.
Running February 10-12, PIMEC is an initiative of the Pakistani Navy that helps private and public organizations showcase products and develop relationships.
NewsPenguin’s malicious documents, which pose as an exhibitor manual that appears to target PIMEC visitors, carry embedded Visual Basic for Applications (VBA) macros to execute malware.
Once opened, the lure document uses a remote template injection technique to fetch the next stage from a remote server that only serves the payload to Pakistani IP addresses.
The victim is prompted to enable editing in the document and, once that happens, embedded VBA macro code is executed to save an RTF file on the machine. The script also checks the OS version, invokes the command prompt, and adds a registry key for persistence.
Multiple other files leading to the final payload are also downloaded on the victim’s machine. NewsPenguin’s agent, which is injected into explorer.exe, is a previously undocumented espionage tool that can bypass sandboxes and virtual machines (VMs).
NewsPenguin performs multiple checks to determine whether it runs in a sandbox environment, then connects to a hardcoded remote server to receive the IP of the command-and-control (C&C) server and start receiving commands, which are base64 encoded.
The researchers discovered that the malware waits five minutes between commands, likely another attempt to bypass sandboxes, which typically have a time limit of fewer than five minutes per sample.
Based on received commands, the malware collects and sends information about the machine, runs an additional thread, copies or moves files, deletes files, creates directories, sends the content of files to the server, executes files, and uploads or downloads files from the server.
Domains associated with these attacks were registered in the second half of 2022, showing that NewsPenguin has been planning the operation for a while.
The threat actor’s targets include military technology companies, nation-states, and military organizations in Pakistan, including PIMEC organizers, exhibitors, and visitors.
“Given the highly focused nature of the targets (the Pakistan maritime industry), previously unseen tooling, and new network infrastructure, it is unlikely that the threat actor behind it is connected to casual cybercrime. Instead, we consider it highly likely that the attacker is a nation-state or an outsourced team working for a nation-state threat actor,” BlackBerry concludes.
Related:Nation-State Hacker Attacks on Critical Infrastructure Soar: Microsoft
Related:After Nation-State Hackers, Cybercriminals Also Add Sliver Pentest Tool to Arsenal
Related:Sophisticated Cyberattack Targets Pakistani Military
The post Military Organizations in Pakistan Targeted With Sophisticated Espionage Tool appeared first on SecurityWeek.
The United States and South Korea have issued a joint advisory on ransomware attacks on critical infrastructure that are funding North Korea’s malicious cyber activities.
North Korean government-backed threat actors have been using ransomware in attacks against critical infrastructure for years, with at least two ransomware families attributed to them, namely Maui and H0lyGh0st.
In July last year, the US government issued a warning on North Korea’s use of Maui ransomware in attacks targeting healthcare and public health sectors.
This week, the US and South Korea issued an updated advisory, warning that North Korea is relying on ransomware attacks against healthcare and other critical infrastructure organizations to fund various objectives, including malicious cyber operations.
Typically, after compromising an organization’s network, the threat actors deploy ransomware and use it to encrypt the victim’s files. The attackers then demand a ransom to be paid in cryptocurrency in exchange for a decryption key.
“The authoring agencies assess that an unspecified amount of revenue from these cryptocurrency operations supports DPRK national-level priorities and objectives, including cyber operations targeting the United States and South Korea governments,” the alert reads.
As part of the observed ransomware operations, the North Korean threat actors build infrastructure (domains, online personas and accounts) and rely on cryptocurrency services to receive ransom proceeds that are then used to procure infrastructure for other malicious activities.
The attackers attempt to hide their identity by operating with or under third-party foreign affiliate identities, use intermediaries to receive ransom payments, and use virtual private networks (VPNs) and virtual private servers (VPSs) to hide their real IP addresses.
The threat actors have been observed exploiting known vulnerabilities for initial access, including Apache Log4j and SonicWall security bugs, but also deploying malware via trojanized files in attacks targeting small and medium-size hospitals in South Korea.
Following initial access, the attackers perform reconnaissance and lateral movement, and then deploy either custom ransomware, such as Maui and H0lyGh0st, or publicly available tools, including BitLocker, Deadbolt, Hidden Tear, Jigsaw, LockBit, Ryuk, and others.
Typically, North Korean threat actors demand from their victims a ransom in Bitcoin and communicate with them via Proton Mail email accounts.
Organizations are advised to encrypt connections with all devices on the network, implement the principle of least privilege, turn off unused network protocols and services, secure the collection, transfer and storing of personally identifiable and protected healthcare information (PII and PHI), implement multi-layer network segmentation, and monitor networks for suspicious behavior.
Furthermore, organizations should keep isolated data backups, should implement a cyber incident response plan, should keep all applications and operating systems updated, enforce strong passwords and multi-factor authentication, educate employees and users on phishing, and make sure that all remote desktop protocol (RDP) and similar connections are monitored and secured.
Related: US Disrupts North Korean Hackers That Targeted Hospitals
Related: US Healthcare Organizations Warned of ‘Daixin Team’ Ransomware Attacks
Related:US Says Chinese Military Behind Vast Aerial Spy Program
The post US, South Korea: Ransomware Attacks Fund North Korea’s Cyber Operations appeared first on SecurityWeek.
The recent exploitation of a zero-day vulnerability in the GoAnywhere managed file transfer (MFT) software has been linked by a cybersecurity firm to a known cybercrime group that has likely attempted to exploit the flaw in a ransomware attack.
On February 1, Fortra alerted GoAnywhere MFT users about a zero-day remote code injection exploit. The vendor immediately provided indicators of compromise (IoCs) and mitigations, but released a patch only a week later.
Users, particularly those who are running an admin portal that is exposed to the internet, have been instructed to urgently install the patch.
There appear to be more than 1,000 internet-exposed instances of GoAnywhere. However, according to the vendor, exploitation requires access to the application’s admin console, and at least some of the exposed instances are associated with the product’s web client interface, which is not impacted.
No information was made available about the attacks exploiting the vulnerability, but managed endpoint detection and response firm Huntress reported this week that these attacks may have been conducted by a known cybercrime group. The company reached the conclusion after analyzing an attack detected in a customer environment on February 2.
Huntress has linked the attack to a malware family named Truebot, which was previously associated with a Russian-speaking threat actor named Silence. This group has also been linked to TA505, a threat group known for distributing the notorious Cl0p ransomware.
“Based on observed actions and previous reporting, we can conclude with moderate confidence that the activity Huntress observed was intended to deploy ransomware, with potentially additional opportunistic exploitation of GoAnywhere MFT taking place for the same purpose,” Huntress said in a blog post.
Cybersecurity firm Rapid7 has analyzed the vulnerability and assigned it the CVE identifier CVE-2023-0669. While the product does not belong to Rapid7, the company is a CVE Numbering Authority and it can assign CVEs to flaws found in the products of other vendors.
Related: Patch Tuesday: Microsoft Plugs Windows Hole Exploited in Ransomware Attacks
Related: Decade-Old Adobe ColdFusion Vulnerabilities Exploited by Ransomware Gang
Related: PetitPotam Vulnerability Exploited in Ransomware Attacks
The post GoAnywhere MFT Zero-Day Exploitation Linked to Ransomware Attacks appeared first on SecurityWeek.
Reddit on Thursday informed users that its systems were hacked as a result of what the company described as a sophisticated and highly targeted phishing attack aimed at employees.
According to Reddit, the intrusion was detected on February 5. The hackers gained access to some internal documents, source code, internal dashboards and business systems.
Up until this point in the investigation, Reddit has determined that the exposed information includes limited contact information for hundreds of contacts and current and former employees, as well as some advertiser information.
“Based on several days of initial investigation by security, engineering, and data science (and friends!), we have no evidence to suggest that any of your non-public data has been accessed, or that Reddit’s information has been published or distributed online,” Reddit said.
There is no indication that user passwords or accounts have been compromised. The company also said there is no evidence of a breach of production systems, where the platform runs and where a majority of its data is stored.
The data breach was discovered after an employee informed Reddit’s security team that they had fallen for a phishing attack. The attackers targeted Reddit employees with “plausible-sounding prompts” that led them to a phishing website mimicking its intranet gateway.
A Reddit representative noted in an AMA (Ask Me Anything) thread that the employee whose credentials were phished did have two-factor authentication (2FA) enabled on their account, as the company requires it for all employees.
However, it seems that the phishing page targeted not only employee credentials, but also their second-factor tokens.
Several major tech companies were targeted in sophisticated phishing attacks in the past months. One of them is Zendesk, which revealed recently that some employees handed over their credentials to threat actors in the fall of 2022.
At around the same time, companies such as Twilio, Cloudflare and at least 130 others were targeted in a phishing campaign dubbed Oktapus, which appeared to be the work of financially-motivated threat actors.
Related: Reddit Names Allison Miller as CISO, VP of Trust
Related: Accounts of Reddit Moderators Hijacked in Pro-Trump Hack
Related: Reddit Locks Down Accounts Due to ‘Security Concern’
The post Documents, Code, Business Systems Accessed in Reddit Hack appeared first on SecurityWeek.
Australia’s Defense Department will remove surveillance cameras made by Chinese Communist Party-linked companies from its buildings, the government said Thursday after the U.S. and Britain made similar moves.
The Australian newspaper reported Thursday that at least 913 cameras, intercoms, electronic entry systems and video recorders developed and manufactured by Chinese companies Hikvision and Dahua are in Australian government and agency offices, including the Defense Department and the Department of Foreign Affairs and Trade.
Hikvision and Dahua are partly owned by China’s Communist Party-ruled government.
Australian Defense Minister Richard Marles said his department is assessing all its surveillance technology.
“Where those particular cameras are found, they’re going to be removed,” Marles told Australian Broadcasting Corp. “There is an issue here and we’re going to deal with it.”
Asked about Australia’s decision, Chinese Foreign Ministry spokesperson Mao Ning criticized what she called “wrongful practices that overstretch the concept of national security and abuse state power to suppress and discriminate against Chinese enterprises.”
Without mentioning Australia by name, Mao said the Chinese government has “always encouraged Chinese enterprises to carry out foreign investment and cooperation in accordance with market principles and international rules, and on the basis of compliance with local laws.”
“We hope Australia will provide a fair and non-discriminatory environment for the normal operation of Chinese enterprises and do more things that are conducive to mutual trust and cooperation between the two sides,” she told reporters at a daily briefing.
The U.S. government said in November it was banning telecommunications and video surveillance equipment from several prominent Chinese brands including Hikvision and Dahua in an effort to protect the nation’s communications network.
Security cameras made by Hikvision were also banned from British government buildings in November.
An audit in Australia found that Hikvision and Dahua cameras and security equipment were found in almost every department except the Agriculture Department and the Department of Prime Minister and Cabinet.
The Australian War Memorial and National Disability Insurance Agency have said they will remove the Chinese cameras found at their sites, the ABC reported.
Opposition cybersecurity spokesman James Paterson said he had prompted the audit by asking questions over six months of each federal agency, after the Home Affairs Department was unable to say how many of the cameras, access control systems and intercoms were installed in government buildings.
“We urgently need a plan from the … government to rip every one of these devices out of Australian government departments and agencies,” Paterson said.
Both companies are subject to China’s National Intelligence Law which requires them to cooperate with Chinese intelligence agencies, he said.
“We would have no way of knowing if the sensitive information, images and audio collected by these devices are secretly being sent back to China against the interests of Australian citizens,” Paterson said.
Related: US Says Chinese Military Behind Vast Aerial Spy Program
The post Australian Defense Department to Remove Chinese-Made Cameras appeared first on SecurityWeek.
VulnCheck, a Massachusetts startup with ambitious plans in the vulnerability intelligence space, has attracted $3.2 million in seed-stage funding from several prominent investors.
The early-stage financing round was led by Sorensen Ventures and included equity stakes for In-Q-Tel, Lux Capital, and Aviso Ventures.
Based in Lexington, Mass., VulnCheck is building technology that promises exploit intelligence for vulnerability prioritization and an early-warning system for in-the-wild software exploitation activity.
Founded in 2021, VulnCheck is the brainchild of Anthony Bettini, former head of Tenable research and former founder and CEO of FlawCheck and Appthority.
The company has ambitious plans in a category that spans threat-intelligence, attack surface management, red-teaming and penetration testing.
VulnCheck is promising threat intelligence services to help organizations wade through the growing volume of publicly announced vulnerabilities and preemptively take action to stave off malicious hacker attacks.
Attack Surface Management Summit | Virtual Event – February 22, 2023The VulnCheck offerings include:
The company and its investors are betting there’s revenue to be found in managing vulnerability and exploit data overload. The idea, according to VulnCheck, is to enrich vulnerability data with information about exploit activity to give security teams visibility and tools to prioritize remediation based on a real-time assessment of live exploitation.
Related: Investors Bet on Cyberpion in Attack Surface Management Space
Related: Cyber Insights 2023 | Attack Surface Management
Related: IBM to Acquire Randori for Attack Surface Management Tech
The post VulnCheck Raises $3.2M Seed Round for Threat Intel appeared first on SecurityWeek.
The US Treasury on Thursday slapped sanctions against seven Russians accused of running the notorious Trickbot cybercrime operation, freezing assets in multiple countries and imposing travel bans.
The seven individuals are being blamed for a series of major ransomware attacks targeting organizations in the US and the United Kingdom and the Treasury Department said it has information linking the hacking group to Russian intelligence services.
“Current members of the Trickbot Group are associated with Russian Intelligence Services. The Trickbot Group’s preparations in 2020 aligned them to Russian state objectives and targeting previously conducted by Russian Intelligence Services. This included targeting the U.S. government and U.S. companies,” the department said in a statement announcing the cross-border sanctions.
The sanctioned Russians include:
The notorious Trickbot cybercrime operation was born out of a malware first identified in 2016 that conducted online bank robberies out of Moscow, Russia. The US estimates that the Trickbot malware infected millions of victim computers worldwide, including those of U.S. businesses, and individual victims.
The malware has since evolved into a highly modular malware suite run by a Trickbot Group that regularly launches data-encryption and extortion (ransomware) attacks.
Trickbot has been known to target hospitals and healthcare centers across the United States with ransomware attacks that disrupt computer networks and telephones, sometimes causing a diversion of ambulances and medical resources.
“Members of the Trickbot Group publicly gloated over the ease of targeting the medical facilities and the speed with which the ransoms were paid to the group,” the Treasury said.
As a result of the sanctions, assets in the US and the UK will be frozen and travel bans will be imposed. In addition, the government warns that making funds available to the individuals (via ransom payments, including in crypto assets) is prohibited under these sanctions.
Related: IBM Dives Into TrickBot Gang’s Malware Crypting Operation
Related: Conti Ransomware ‘Acquires’ TrickBot as It Thrives Amid Crackdowns
Related: Russian Man Extradited to U.S. for Role in TrickBot Malware Development
Related: TrickBot Botnet Survives Takedown Attempt
The post US, UK Slap Sanctions on Trickbot Cybercrime Gang appeared first on SecurityWeek.
China’s balloon that crossed the United States was equipped to collect intelligence signals and was part of a huge, military-linked aerial spy program that targeted more than 40 countries, the Biden administration said Thursday, outlining the scope and capabilities of the huge balloon that captivated the country’s attention before being shot down.
The fleet of balloons operates under the direction of the People’s Liberation Army and is used specifically for spying, outfitted with high-tech equipment designed to collect sensitive information from targets across the globe, the U.S. said. Similar balloons have floated over five continents, it U.S. said.
The statement from a senior State Department official offered the most detail to date linking China’s military to the balloon that traversed the U.S. before being shot down last Saturday over the Atlantic Ocean. The public details are meant to refute China’s persistent denials that the balloon was used for spying, including a claim Thursday that U.S. accusations about the balloon amount to “information warfare” against Beijing.
In Beijing, before the U.S. offered new information, Chinese Foreign Ministry spokesperson Mao Ning repeated her nation’s insistence that the large unmanned balloon was a civilian meteorological airship that had blown off course and that the U.S. had “overreacted” by shooting it down.
“It is irresponsible,” Mao said. The latest accusations, he said, “may be part of the U.S. side’s information warfare against China.”
China’s defense minister refused to take a phone call from Defense Secretary Lloyd Austin to discuss the balloon issue on Saturday, the Pentagon said. China has not answered questions as to what government department or company the balloon belonged to, or how it planned to follow up on a pledge to take further action over the matter.
The U.S. offered a flatly contradictory characterization of the balloon and its purpose. It said imagery of the balloon collected by American U-2 spy planes as it crossed the country showed that it was “capable of conducting signals intelligence collection” with multiple antennas and other equipment designed to upload sensitive information and solar panels to power them.
The official said an analysis of the balloon debris was “inconsistent” with China’s explanation that it was a weather balloon that went off course. The U.S. is reaching out to countries that have also been targeted, the official said, to discuss the scope of the Chinese surveillance program, and is looking into potential action that “supported the balloon’s incursion into U.S. airspace.”
The official provided details to reporters by email on condition of anonymity due to the sensitive nature of the matter, which had already forced the cancellation of a planned visit to China earlier this week by Secretary of State Antony Blinken.
The official said the U.S. has confidence that the manufacturer of the balloon shot down on Saturday has “a direct relationship with China’s military and is an approved vendor of the” army. The official cited information from an official PLA procurement portal as evidence for the connection between the company and the military.
This is not the first time the U.S. government has publicly called out alleged activities of the People’s Liberation Army. In a first-of-its-kind prosecution in 2014, the Obama administration Justice Department indicted five accused PLA hackers of breaking into the computer networks of major American corporations in an effort to steal trade secrets.
Alleged hackers with the PLA were also charged in 2020 with stealing the personal data of tens of millions of Americans in a breach of the credit-reporting agency Equifax.
The post US Says Chinese Military Behind Vast Aerial Spy Program appeared first on SecurityWeek.
Google this week announced the availability of the first Android 14 developer preview and also shared details on some of the security and privacy improvements the platform update will bring.
Expected to arrive on devices sometime in fall, Android 14 brings new features and APIs, as well as behavioral changes that might impact applications. The purpose of the developer preview is to help application developers learn about these changes and test their applications for compatibility issues.
One of the security enhancements the platform update is set to bring is related to runtime receivers and builds on changes introduced in Android 13, when Google instructed developers to specify whether their application’s registered broadcast receiver should be visible to other apps on the device.
Before Android 13, any application could send unprotected broadcasts to dynamically-registered receivers that were not protected by a signature permission.
To help protect apps from security vulnerabilities, “apps and services that target Android 14 and use context-registered receivers are required to specify a flag to indicate whether or not the receiver should be exported to all other apps on the device,” Google says.
Android 14 also attempts to protect applications from malicious software that might intercept intents, by restricting apps from sending intents internally that do not specify a package.
Additionally, apps can now send implicit intents to exported components only and “must either use an explicit intent to deliver to unexported components, or mark the component as exported”, the internet giant explains.
To prevent malicious use of dynamic code loading (DCL), applications built for Android 14 will have to mark dynamically loaded files as read-only. According to Google, developers should avoid dynamically loading code, as this exposes applications to code injection or code tampering.
Because some malware versions use an API level of 22 (to avoid the runtime permission model introduced in Android 6.0), Android 14 will also prevent the installation of applications that target an API level lower than 23. However, applications with a targetSdkVersion lower than 23 will remain installed.
Android 14 also arrives with Credential Manager, a new Jetpack API that includes support for multiple sign-in methods, including federated sign-in solutions and passkeys, along with the classic username and password pair.
Currently available in alpha, Credential Manager allows users to create passkeys and save them in Google Password Manager, for passwordless authentication across devices, in both Android and Chrome.
Related:Google Migrating Android to Memory-Safe Programming Languages
Related: Google Brings Passkey Support to Android and Chrome
Related:Google Ready to Roll Out Android Privacy Sandbox in Beta
The post Google Describes Privacy, Security Improvements in Android 14 appeared first on SecurityWeek.
Multiple cross-site scripting (XSS) vulnerabilities in popular document management system (DMS) products could allow attackers to access sensitive documents, Rapid7 reports.
DMS solutions help users manage the production, storage, and distribution of documents. They may also provide collaboration capabilities and support for managing other types of files.
A total of eight XSS vulnerabilities were identified in products from OnlyOffice, OpenKM, LogicalDOC, and Mayan, all of which can be described as issues related to improper neutralization of input during web page generation.
None of these issues, however, has been resolved. Despite Rapid7’s efforts to contact the impacted vendors, none of them responded.
All the vulnerable DMS solutions – available as on-prem or cloud-hosted collaboration platforms – are designed for small to medium-sized businesses (SMBs) and the exploitation of the identified bugs in attacks could have dire consequences.
Tracked as CVE-2022-47412, the most severe of the vulnerabilities impacts OnlyOffice Workspace and requires an attacker to trick a user into storing a malicious document in the DMS and then convince them to open the document via an embedded search function.
Two XSS bugs (CVE-2022-47413 and CVE-2022-47414) were identified in OpenKM. The first of the issues can be triggered like CVE-2022-47412, but the second requires access to the OpenKM console.
Four XSS vulnerabilities were found in the LogicalDOC DMS: CVE-2022-47415 in the in-app messaging system, CVE-2022-47416 in the chat system, CVE-2022-47417 in the document file name, and CVE-2022-47418 in stored version comments.
The Mayan EDMS flaw, CVE-2022-47419, impacts the platform’s in-product tagging system.
An attacker exploiting any of these vulnerabilities could steal the session cookie of a locally logged-in administrator and then impersonate the user to create a rogue account on the platform, which would provide them with access to all documents stored in the DMS.
Rapid7 recommends that users pay extra care when importing documents from unknown or untrusted sources into the DMS and that administrators limit the creation of anonymous, untrusted users for the affected DMS products.
Affected DMS versions include OnlyOffice Workspace 12.1.0.1760, OpenKM 6.3.12, LogicalDOC CE/Enterprise 8.7.3/8.8.2, LogicalDOC Enterprise 8.8.2, and Mayan EDMS 4.3.3.
“Given the high severity of a stored XSS vulnerability in a document management system, especially one that is often part of automated workflows, administrators are urged to apply any vendor-supplied updates on an emergency basis,” Rapid7 notes.
Related:Atlassian Warns of Critical Jira Service Management Vulnerability
Related: Exploitation of Oracle E-Business Suite Vulnerability Starts After PoC Publication
Related: F5 BIG-IP Vulnerability Can Lead to DoS, Code Execution
The post Vulnerabilities in Popular DMS Products Can Expose Sensitive Documents appeared first on SecurityWeek.
Google this week announced the release of patches for 40 vulnerabilities as part of the February 2023 security updates for the Android operating system.
The first part of the update arrives on devices as a 2023-02-01 security patch level and resolves a total of 17 high-severity vulnerabilities impacting components such as Framework, Media Framework, and System.
“The most severe of these issues is a high security vulnerability in the Framework component that could lead to local escalation of privilege with no additional execution privileges needed,” Google notes in its advisory.
While most of the vulnerabilities addressed with this patch level could lead to escalation of privilege, several information disclosure and denial-of-service (DoS) bugs were also resolved.
The second part of the update arrives on devices as the 2023-02-05 security patch level and resolves 23 security defects in Kernel, MediaTek, Unisoc, Qualcomm, and Qualcomm closed-source components.
This month, Google also announced fixes for three vulnerabilities specific to Pixel devices. All Pixels running a patch level of 2023-02-05 will be patched against these three bugs and all the issues resolved with Android’s February 2023 security update.
The internet giant also announced the release of one patch as part of this month’s Android Automotive OS (AAOS) update, in addition to the fixes described in the February 2023 Android security bulletin.
As usual, Google notified manufacturers of the addressed issues at least a month before publishing the security bulletins. The company also released source code patches to the Android Open Source Project (AOSP) repository.
While Pixel users can already manually grab the latest security fixes, users of other devices will have to wait for their phone makers to release the necessary updates for them.
Related: Android’s First Security Updates for 2023 Patch 60 Vulnerabilities
Related: Over 75 Vulnerabilities Patched in Android With December 2022 Security Updates
Related: Google Patches High-Severity Privilege Escalation Vulnerabilities in Android
The post Android’s February 2023 Updates Patch 40 Vulnerabilities appeared first on SecurityWeek.
A recently identified financially motivated threat actor is targeting companies in the United States and Germany with custom malware, including a screenlogger it uses for reconnaissance, Proofpoint reports.
Tracked as TA866, the adversary appears to have started the infection campaign in October 2022, with the activity continuing into January 2023.
As part of the campaign, which Proofpoint refers to as Screentime, victims are targeted with malicious emails containing an attachment or a URL that leads to the deployment of malware. In some cases, based on the attacker’s assessment of the victim, post-exploitation activity may commence.
In October and November 2022, a small number of companies in the US were targeted with emails carrying Publisher file attachments containing malicious macros.
In November and December, the attackers switched to using URLs leading the intended victims to Publisher files containing macros or to JavaScript files. Some of the emails were seen carrying PDF attachments containing URLs to JavaScript files.
After switching to URLs, the attackers also scaled the campaign, sending thousands or tens of thousands of malicious messages several times per week, targeting thousands of organizations. In January 2023, the email volume increased even more, but the frequency of attacks was reduced, Proofpoint says.
Emails observed in January appeared to use thread hijacking with a ‘check my presentation’ lure to trick recipients into clicking the malicious URLs.
The malicious links lead to the 404 TDS (traffic distribution system) that filters the traffic and redirects the victim to a JavaScript file. If the victim runs the file, a MSI package is fetched and executed, which in turn runs an embedded VBS script and achieves persistence.
The script is the WasabiSeed malware, which downloads and executes another MSI file representing a piece of malware named Screenshotter, and then continues polling the URL for additional payloads.
With variants implemented in different programming languages (including Python, AutoIT, and JavaScript/IrfanView), Screenshotter was designed to take screenshots of the victim’s screen and send them to a command-and-control (C&C) server.
According to Proofpoint, the attackers likely manually inspect the screenshots and use WasabiSeed to deploy additional payloads if the victim is deemed interesting, such as the AHK Bot, which too enters a loop to fetch additional components.
AHK Bot has been observed deploying a script to check the victim machine’s Active Directory (AD) domain and downloading and loading in memory the Rhadamanthys information stealer. The AD profiling, Proofpoint notes, could lead to the compromise of other domain-joined hosts.
Proofpoint has been tracking the use of 404 TDS since September and believes that it is either sold or shared between cybercriminals, as it has been used in various phishing and malware campaigns.
As part of TA866’s Screentime campaign, hundreds of random URLs were used, leading to 20 domains that were registered on the day of the attack.
“These domains were previously registered, expired, and then re-sold to the TDS operator,” Proofpoint notes.
Some parts of the observed attacks involve manual interaction from the threat actor and, based on payload download time, Proofpoint’s security researchers believe that TA866 could be residing in the UTC+2 or UCT+3 time zones. These time zones correspond, among others, to Russia.
Furthermore, the researchers discovered that AHK Bot contains Russian language variable names and comments, and that the malware has been used in attacks since at least 2019, with some of the previous activity seemingly having an espionage objective.
“TA866 is a newly identified threat actor that distributes malware via email utilizing both commodity and custom tools. Most of the activity recently observed by Proofpoint suggests recent campaigns are financially motivated, however assessment of historic related activities suggests a possible, additional espionage objective,” Proofpoint concludes.
Related:North Korean Hackers Created 70 Fake Bank, Venture Capital Firm Domains
Related:Vietnam-Based Ducktail Cybercrime Operation Evolving, Expanding
Related:US Government Agencies Warn of Malicious Use of Remote Management Software
The post Cybercrime Gang Uses Screenlogger to Identify High-Value Targets in US, Germany appeared first on SecurityWeek.
Researchers have discovered a vulnerability that can be exploited by remote hackers to tamper with the timestamp of videos recorded by Dahua security cameras.
The flaw, tracked as CVE-2022-30564, was discovered last year by India-based CCTV and IoT cybersecurity company Redinent Innovations. Advisories describing the vulnerability were published on Wednesday by both Dahua and Redinent.
Redinent has assigned the vulnerability a ‘high’ severity rating, but Dahua has calculated a 5.3 CVSS score for it, which makes it ‘medium severity’.
According to the Chinese video surveillance equipment maker, the flaw impacts several types of widely used cameras and video recorders, including IPC, SD, NVR, and XVR products.
An attacker can exploit the vulnerability to modify a device’s system time by sending it a specially crafted packet.
Redinent says there are thousands of internet-exposed cameras that can be targeted directly by hackers. Exploitation from the local network is also possible. However, the company noted that an attacker needs to have knowledge of an APIs parameters in order to exploit the vulnerability.
“An attacker can make modification to the timestamp of the video feed, leading to inconsistent date and time showing up on the recorded video, without the need of knowing the username and password of the camera. It has a direct impact on digital forensics,” Redinent explained in its advisory.
Dahua device vulnerabilities may be targeted by DDoS botnets, but in the case of CVE-2022-30564, it would most likely be exploited in highly targeted attacks whose goal is to tamper with evidence, rather than cybercrime operations.
The issue was reported to the vendor in the fall of 2022. Dahua has released patches for each of the impacted devices.
In December, Redinent disclosed a vulnerability affecting Hikvision wireless bridges. Exploitation of the flaw could lead to remote CCTV hacking.
Related: Backdoor Found in Dahua Video Recorders, Cameras
Related: CISA Warns of Hikvision Camera Flaw as U.S. Aims to Rid Chinese Gear From Networks
Related: FCC: Telecom Firms Requested $5.6 Billion to Replace Chinese Gear
The post Vulnerability Allows Hackers to Remotely Tamper With Dahua Security Cameras appeared first on SecurityWeek.
There have been some new developments in the case of the ESXiArgs ransomware attacks, including related to the encryption method used by the malware, victims, and the vulnerability exploited by the hackers.
After the US Cybersecurity and Infrastructure Security Agency (CISA) announced the availability of an open source tool designed to help some victims of the ESXiArgs ransomware recover their files without paying a ransom, the FBI and CISA released a document providing recovery guidance.
The FBI and CISA are aware of more than 3,800 servers that were compromised around the world in ESXiArgs ransomware attacks.
Currently, the Shodan and Censys search engines show 1,600-1,800 hacked servers, but there is indication that many impacted organizations have started responding to the attack and cleaning up their systems.
Reuters has conducted an analysis and determined that the victims include Florida’s Supreme Court and universities in the United States and Europe.
An analysis of the file-encrypting malware deployed in the ESXiArgs attacks showed that it has targeted files associated with virtual machines (VMs). However, experts noticed that the ransomware mainly targeted VM configuration files, but did not encrypt the flat files that store data, allowing some users to recover their data.
The tool released by the US government reconstructs the encrypted configuration files based on the unencrypted flat files.
However, Bleeping Computer reported on Wednesday that some victims have been targeted with a new version of the ESXiArgs malware, one with a different encryption process that involves encrypting more data, which prevents the recovery of files.
Until now, the ransomware did not encrypt the majority of data in large files, but the new version of the malware encrypts a far more significant amount of data in large files. Up until now, researchers have not found any flaws in the actual encryption, making it impossible to restore encrypted files.
It has been assumed that the ESXiArgs attacks leverage CVE-2021-21974 for initial access. This is a high-severity remote code execution vulnerability in VMware ESXi that VMware patched in February 2021. The issue is related to OpenSLP.
VMware has not confirmed exploitation of CVE-2021-21974, but it did say that there is no evidence of a zero-day vulnerability being leveraged in the attacks.
However, threat intelligence company GreyNoise is not convinced that there is enough evidence that CVE-2021-21974 is being exploited. GreyNoise pointed out that several OpenSLP-related vulnerabilities have been found in ESXi in recent years, and any of them could have been exploited in the ESXiArgs attacks, including CVE-2020-3992 and CVE-2019-5544.
Data collected by cloud security company Wiz showed that, as of February 7, 12% of ESXi servers were unpatched against CVE-2021-21974 and vulnerable to attacks.
The attacks have yet to be attributed to a known threat actor, but the evidence collected so far suggests that the file-encrypting malware is based on Babuk source code that was leaked in 2021.
“Due to the relatively low ransom demand (2 BTC) and widespread, opportunistic targeting, we assess with moderate confidence this campaign is not tied to ransomware groups known for ‘Big Game Hunting’,” said SOC-as-a-service provider Arctic Wolf. “More established ransomware groups typically conduct OSINT on potential victims before conducting an intrusion and set the ransom payment based on perceived value.”
Related: VMware Patches VM Escape Flaw Exploited at Geekpwn Event
Related:VMware Confirms Exploit Code Released for Critical vRealize Logging Vulnerabilities
The post ESXiArgs Ransomware Hits Over 3,800 Servers as Hackers Continue Improving Malware appeared first on SecurityWeek.
Spain’s government on Wednesday pledged stronger action against cybercrime, saying it has come to account for about a fifth of all offenses registered in the country.
Interior Minister Fernando Grande-Marlaska said police would be given additional staff, funding and resources to address online crime. He said reported cases of cybercrime were up 72% last year compared to 2019, and 352% compared to 2015.
“The … decline in conventional crime and the increase in cybercrime has brought us to a turning point: today, one in every five crimes in Spain is committed online,” he told a press conference in Madrid.
Almost 90% of cybercrimes reported last year involved online fraud schemes, Grande-Marlaska said. “This … has a remarkable and negative impact on national interests, institutions, companies and citizens,” he added.
On Tuesday, Spain’s defense minister approved the creation of a new military cyberoperations training school to further reinforce national security online.
Spain is among the countries that suffer the largest numbers of remote online attacks in the world, according to data from antivirus protection specialist ESET. Small businesses are particularly affected.
José Cano, Research Director at market intelligence firm IDC Spain, said a lack of talent and skills had left Spanish businesses exposed to the increasing sophistication of online criminals, who are innovating to bypass multi-factor authentication and other safeguards.
“Cyber-resilience is not only about enterprise value and reducing business risk, but also about national economic security,” Cano said. “European companies, especially Spanish companies, will increasingly incorporate cyber-resilience planning into their business and security strategies.”
The post Minister: Cybercrimes Now 20% of Spain’s Registered Offenses appeared first on SecurityWeek.
Skybox Security, a late-stage California startup in the security analytics space, has closed a $50 million financing round and hired a new chief executive.
The San Jose company announced Wednesday that former Digital Guardian CEO Mordecai (Mo) Rosen will take the reins at Skybox and manage the company through a new financing round that brings the total raised to $335 million.
The private equity-backed Skybox said investors in the latest round include CVC Growth Funds, Pantheon, and J.P. Morgan.
Skybox has built and marketed a security analytics platform that helps defenders with security policy and vulnerability management tooling. The company’s product suite includes tools for firewall management, automated change management, network assurance, vulnerability control and threat intelligence.
With a new chief executive on board, the company said the plan is to find revenues in the Skybox Cloud Edition, a software-as-a-service product for managing security policy in hybrid multi-vendor environments.
Before joining Skybox, Rosen worked as president and chief executive at data loss prevention software firm Digital Guardian.
Related: Skybox Raises $150 Million to Advance its Security Management Product
Related: Providence Equity Pumps $96 Million Into Skybox Security
Related: Skybox Security Raises $6 Million
The post Skybox Security Raises $50M, Hires New CEO appeared first on SecurityWeek.
An alleged Chinese surveillance balloon over the United States last week sparked a diplomatic furore and renewed fears over how Beijing gathers intelligence on its largest strategic rival.
FBI Director Christopher Wray said in 2020 that Chinese spying poses “the greatest long-term threat to our nation’s information and intellectual property, and to our economic vitality”.
China’s foreign ministry said in a statement to AFP that it “resolutely opposed” spying operations and that American accusations are “based on false information and sinister political aims”.
The United States also has its own ways of spying on China, deploying surveillance and interception techniques as well as networks of informants.
Former US president Barack Obama said in 2015 that his Chinese counterpart Xi Jinping had promised not to conduct commercial cyber spying. Subsequent statements by Washington have indicated the practice has continued.
Here are some of the ways Beijing has worked to spy on the United States in recent years:
Cyber warfare
The United States warned in a major annual intelligence assessment in 2022 that the Asian giant represents “the broadest, most active, and persistent cyber espionage threat” to the government and private sector.
According to researchers and Western intelligence officials, China has become adept at hacking rival nations’ computer systems to make off with industrial and trade secrets. In 2021, the United States, NATO and other allies said China had employed “contract hackers” to exploit a breach in Microsoft email systems, giving state security agents access to emails, corporate data and other sensitive information.
Chinese cyber spies have also hacked the US energy department, utility companies, telecommunications firms and universities, according to US government statements and media reports.
Tech fears
Fears of the threat from Beijing have seeped into the technology sector, with concerns that state-linked firms would be obliged to share intel with the Chinese government.
In 2019, the US Department of Justice charged tech giant Huawei with conspiring to steal US trade secrets, evade sanctions on Iran, and other offenses.
Washington has banned the firm from supplying US government systems and strongly discouraged the use of its equipment in the private sector over fears that it could be compromised.
Huawei denies the charges.
Similar anxiety over TikTok animates Western political debate, with some lawmakers calling for an outright ban on the hugely popular app developed by China’s ByteDance over data security fears.
Industrial and military espionage
Beijing has leaned on Chinese citizens abroad to help gather intelligence and steal sensitive technology, according to experts, US lawmakers and media reports.
One of the most high-profile cases was that of Ji Chaoqun, who in January was sentenced to eight years in a US prison for passing information on possible recruitment targets to Chinese intelligence.
An engineer who arrived in the United States on a student visa in 2013 and later joined the army reserves, Ji was accused of supplying information about eight people to the Jiangsu province ministry of state security, an intelligence unit accused of engaging in the theft of US trade secrets.
Last year, a US court sentenced a Chinese intelligence officer to 20 years in prison for stealing technology from US and French aerospace firms.
The man, named Xu Yanjun, was found guilty of playing a leading role in a five-year Chinese state-backed scheme to steal commercial secrets from GE Aviation, one of the world’s leading aircraft engine manufacturers, and
France’s Safran Group.
In 2020, a US court jailed Raytheon engineer Wei Sun — a Chinese national and naturalized US citizen — for bringing sensitive information about an American missile system into China on a company laptop.
Spying on politicians
With the goal of advancing Beijing’s interests, Chinese operatives have allegedly courted American political, social and business elites.
US news website Axios ran an investigation in 2020 claiming that a Chinese student enrolled at a university in California had developed ties with a range of US politicians under the auspices of Beijing’s main civilian spy agency.
The student, named Fang Fang, used campaign financing, developed friendships and even initiated sexual relationships to target rising politicians between 2011 and 2015, according to the report.
Police stations
Another technique used by Chinese operatives is to tout insider knowledge about the Communist Party’s opaque inner workings and dangle access to top leaders to lure high-profile Western targets, researchers say.
The aim has been to “mislead world leaders about (Beijing’s) ambitions” and make them believe “China would rise peacefully — maybe even democratically,”
Chinese-Australian author Alex Joske wrote in his book, “Spies and Lies: How China’s Greatest Covert Operations Fooled the World”.
Beijing has also exerted pressure on overseas Chinese communities and media organizations to back its policies on Taiwan, and to muzzle criticism of the Hong Kong and Xinjiang crackdowns.
In September 2022, Spain-based NGO Safeguard Defenders said China had set up 54 overseas police stations around the world, allegedly to target Communist Party critics.
Beijing has denied the claims.
The Netherlands ordered China to close two “police stations” there in November.
A month later, the Czech Republic said China had closed two such centers in Prague.
The post Spies, Hackers, Informants: How China Snoops on the US appeared first on SecurityWeek.
Australian authorities this week announced the sentencing of a Sydney man for attempting to blackmail Optus customers using leaked data stolen during a September 2022 data breach at the wireless carrier.
The Optus hack resulted in the theft of personal information belonging to 9.8 million customers, including names, birth dates, physical and email addresses, and phone numbers. For 2.1 million customers, numbers associated with identification documents were also compromised.
The incident was disclosed on September 22, with the attackers leaking the personal information of roughly 10,000 individuals a few days later.
The attackers demanded a $1 million ransom in cryptocurrency, threatening to release more of the stolen information each day until a payment was made.
On October 6, the Australian Federal Police announced the arrest of a Sydney man who attempted to use the leaked data to extort money from individuals impacted by the data breach.
The man, now 20, sent text messages to more than 90 Optus customers, demanding that they transfer $2,000 AUD (roughly $1,300 USD) to a bank account in the name of the scammer.
The youngster pleaded guilty on November 8 to two “counts of using a telecommunications network with intent to commit a serious offense […], where the serious offense is blackmail”, the Australian authorities say.
The individual was sentenced to 18-month community correction order and 100 hours of community service.
Related:Email Hack Hits 15,000 Business Customers of Australian Telecoms Firm TPG
Related: Hackers Leak Australian Health Records on Dark Web
Related: Medibank Confirms Data Breach Impacts 9.7 Million Customers
The post Australian Man Sentenced for Scam Related to Optus Hack appeared first on SecurityWeek.
Google this week announced that the first stable release of Chrome 110 brings 15 security fixes, including 10 that address vulnerabilities reported by external researchers.
Of the externally reported bugs, three are rated ‘high severity’. These include a type confusion flaw in the V8 engine, an inappropriate implementation issue in full screen mode, and an out-of-bounds read vulnerability in WebRTC.
Tracked as CVE-2023-0696, the first of the security defects is described as a heap corruption that can be exploited remotely via a crafted HTML page. Google paid a $7,000 bug bounty to the reporting researcher.
The second high-severity flaw, CVE-2023-0697, impacts Chrome for Android and could allow a remote attacker to use a crafted HTML page to spoof the contents of the security UI. Google rewarded the reporting researcher $4,000 for this bug.
CVE-2023-0698, the third issue, could be exploited remotely via an HTML page to perform an out-of-bounds memory read. The reporting researcher received a $2,000 bug bounty for the find, Google notes in its advisory.
Chrome 110 also resolves five medium-severity vulnerabilities reported by external researchers, including a use-after-free flaw in GPU, an inappropriate implementation bug in Download, a heap buffer overflow defect in WebUI, and two type confusion issues in Data Transfer and DevTools.
Google says it handed out over $26,000 in bug bounty rewards to the reporting researchers.
The internet giant makes no mention of any of these vulnerabilities being exploited in attacks.
The latest Chrome release is rolling out to users as versions 110.0.5481.77/.78 for Windows, and version 110.0.5481.77 for Mac and Linux.
The iOS and Android versions of the browser have been updated to 110.0.5481.83 and 110.0.5481.63/.64, respectively.
Related: Security Update for Chrome 109 Patches 6 Vulnerabilities
Related: Chrome 109 Patches 17 Vulnerabilities
Related: High-Severity Memory Safety Bugs Patched With Latest Chrome 108 Update
The post Chrome 110 Patches 15 Vulnerabilities appeared first on SecurityWeek.
I’ve always found it entertaining that so many sales pitches are essentially a listing of features for the product or service being sold. The reason I find this entertaining is that for anyone who has worked on the customer side or has ever listened to customers, it is obvious that customers buy solutions, not products. Thus, the notion of showing off how proud you are of your product by rattling off a laundry list of features has always seemed a bit odd to me.
In other words, customers have a number of different problems, issues, and challenges that they are looking to solve. They are not necessarily interested in all of the different things your product or service can do. Rather, they are interested in learning how your solution can help them address their strategic priorities and move forward on the goals they have set for their security and fraud problems. It is incumbent upon vendors to understand that and to make it easy for potential customers to understand that mapping.
Along those lines, improving application security is a common goal customers have. As you might imagine, any solution geared towards improving the security of an application is going to be complex, consisting of many different moving parts. Thus, forcing customers to hunt for the components they need within your product data sheets and overviews is not going to be an effective way to convince those customers that you have a solution they might be in the market for.
So what can vendors do to convince customers that they have a solution worth that customer’s time to evaluate? For starters, they can bundle various features into use cases that can be easily demonstrated to, evaluated, and consumed by customers. Along those lines, what would a bundle around the popular application security protection use case look like?
While not an exhaustive list, here are some thoughts:
Securing applications is a top priority for nearly all businesses. While there are many routes to application security, bundles that allow security teams to quickly and easily secure applications and affect security posture in a self-service manner are becoming increasingly popular. These bundles inform application providers and allow them to make better, more informed decisions to improve security posture without introducing unnecessary friction to the end-user.
The post Application Security Protection for the Masses appeared first on SecurityWeek.
For the past seven months, the Tor anonymity network has been hit with numerous distributed denial-of-service (DDoS) attacks, its maintainers announced this week.
Some of the attacks have been severe enough to prevent users from loading pages or accessing onion services, the Tor Project says.
Publicly released in 2003, Tor directs traffic through a global network of more than 7,000 relays, to help users maintain anonymity and protect their privacy while navigating the web. Despite its legitimate purpose, Tor has also been used for illegal activities.
Attacks against Tor are not new, with many of them seeking to deanonymize users. In DDoS attacks, the target is flooded with rogue network traffic originating from multiple different sources in an effort to disrupt the target service by depleting resources.
According to the Tor Project, despite its efforts to mitigate the impact of the experienced DDoS attacks, continuous shifts in methods are making the task difficult.
“The methods and targets of these attacks have changed over time and we are adapting as these attacks continue. It’s not possible to determine with certainty who is conducting these attacks or their intentions,” Tor says.
To improve defenses, the Tor Project is adding two new members to its network team, to focus on the development of the onion services.
At the same time, the organization is making an appeal to the community to help it fund onion service development through donations. Offering services for free, the Tor Project is funded from donations, with support coming from the Electronic Frontier Foundation (EFF), various US governmental agencies, individuals, and other third-parties.
Related: US Charges Six in Operation Targeting 48 DDoS-for-Hire Websites
Related:US Agencies Issue Guidance on Responding to DDoS Attacks
Related:Pro-Russian Group DDoS-ing Governments, Critical Infrastructure in Ukraine, NATO Countries
The post Tor Network Under DDoS Pressure for 7 Months appeared first on SecurityWeek.
The Siemens Automation License Manager is affected by two serious vulnerabilities that could be chained to hack industrial control systems (ICS), according to industrial cybersecurity firm Otorio.
On January 10, Siemens released its first round of Patch Tuesday updates for 2023, addressing a total of 20 vulnerabilities affecting the company’s products.
One of the six advisories published at the time describes two high-severity security holes discovered by a researcher from Otorio in the Siemens Automation License Manager (ALM), which is designed for centrally managing license keys for Siemens software.
One of the flaws, tracked as CVE-2022-43513, can allow a remote, unauthenticated attacker to rename and move license files as a System user.
The second issue, CVE-2022-43514, allows a remote, unauthenticated attacker to execute operations on files outside the specified root folder. Chaining the two vulnerabilities can lead to remote code execution, Siemens said.
In a blog post published on Tuesday, Otorio explained that most of Siemens’ software products use the ALM by default for license management. This means the vulnerabilities impact organizations that use one of many Siemens products, including the Simatic PCS 7 historian, the Sicam Device Manager, WinCC, TIA Portal, and the DIGSI engineering tool.
According to Otorio, an attacker who has gained access to the targeted organization’s operational technology (OT) network, even with limited permissions, could exploit the vulnerabilities to fully compromise the OT network.
“For example, the PCS 7 Historian, which is used as a repository for industrial process data, can be used as a ‘bridge’ for an attacker to propagate from the corporate network into the OT network. Once an attacker breaches the Historian server, one can potentially gain access to engineering, control, and monitoring systems,” explained Eran Jacob, research team leader at Otorio.
“An attack could take place not only from the enterprise network. For example, any compromised station with minimal privileges in the network, such as a thin client computer that has access to one of the Siemens servers, could lead to a full compromise of the network,” Jacob added.
Siemens has released an update that should fix the flaws in ALM 6, but the company currently does not plan on releasing a patch for version 5. Workarounds and mitigations are also available.
Related: Cybersecurity Experts Cast Doubt on Hackers’ ICS Ransomware Claims
Related: InHand Industrial Router Vulnerabilities Expose Internal OT Networks to Attacks
Related: Unpatchable Hardware Vulnerability Allows Hacking of Siemens PLCs
The post Siemens License Manager Vulnerabilities Allow ICS Hacking appeared first on SecurityWeek.
North Korean hackers working for the government stole record-breaking virtual assets last year estimated to be worth between $630 million and more than $1 billion, U.N. experts said in a new report.
The panel of experts said in the wide-ranging report seen Tuesday by The Associated Press that the hackers used increasingly sophisticated techniques to gain access to digital networks involved in cyberfinance, and to steal information that could be useful in North Korea’s nuclear and ballistic missile programs from governments, individuals and companies.
With growing tensions on the Korean Peninsula, the report said North Korea continued to violate U.N. sanctions, producing weapons-grade nuclear material, and improving its ballistic missile program, which “continued to accelerate dramatically.”
In 2022, the Democratic People’s Republic of Korea – the North’s official name – launched at least 73 ballistic missiles and missiles combining ballistic and guidance technologies including eight intercontinental ballistic missiles, the panel said. And 42 launches, including the test of a reportedly new type of ICBM and a new solid-fueled ICBM engine, were conducted in the last four months of the year.
North Korea’s leader Kim Jong Un ordered an “exponential increase of the country’s nuclear arsenal” in January, and the panel said “a new law discussed an increased focus on tactical nuclear capability, a new first-use doctrine, and the `irreversible nature’ of the DPRK’s nuclear status.”
“The ability to carry out an unexpected nuclear strike on any regional or international target, described in DPRK’s new law on nuclear doctrine and progressively in public statements since 2021, is consistent with the observed production, testing, and deployment of its tactical and strategic delivery systems,” the experts said in the report to the U.N. Security Council.
{ Read: North Korean APT Expands Its Attack Repertoire }
The panel said that South Korean authorities quoted in media reports “estimated that state sponsored DPRK cyber threat actors had stolen virtual assets worth around $1.2 billion globally since 2017, including about $630 million in 2022 alone.”
The experts monitoring sanctions against North Korea said an unnamed cybersecurity firm “assessed that in 2022, DPRK cybercrime yielded cyber currencies worth over $1 billion at the time of the threat, which is more than double the total proceeds in 2021.”
The variation in the U.S. dollar value of cryptocurrency in recent months is likely to have affected these estimates, the panel said, “but both show that 2022 was a record-breaking year for DPRK virtual asset theft.”
The panel said three groups that are part of the Reconnaissance General Bureau, North Korea’s primary foreign intelligence organization, “continued illicitly to target victims to generate revenue and solicit information of value to the DPRK including its weapons programs” – Kimsuky, Lazarus Group and Andariel.
Between February and July 2022, the panel said, the Lazarus Group “reportedly targeted energy providers in multiple member states using a vulnerability” to install malware and gain long-term access. It said this “aligns with historical Lazarus intrusions targeting critical infrastructure and energy companies … to siphon off proprietary intellectual property.”
Lazarus Group’s primary focus is on specific types of industry, aerospace and defense and conventional finance and cryptocurrencies, with the objective of accessing the internal knowledge bases of the compromised companies, the experts said. They quoted the cybersecurity section of an internet technology company as saying Lazarus has been targeting engineers and technical support employees “using malicious versions of open source applications.”
In December 2022, the panel said, South Korea’s national police agency announced that Kimsuky had targeted 892 foreign policy related experts “in an effort to steal personal data and email lists.”
The police reported that the hackers didn’t manage to steal sensitive information, but they “laundered IP addresses of the victims and employed 326 detour servers and 26 member states to make tracing difficult,” the experts said. The police noted it was the first time they detected Kimsuky using ransomware, saying 19 servers and 13 businesses were affected, of which two paid 2.5 million South Korean won ($1,980) in Bitcoin to the hackers.
On military-related issues, the experts said they investigated the “apparent export” of military communications equipment from a North Korean company under U.N. sanctions to Ethiopia’s defense ministry in June 2022.
The panel said it has not yet received a reply from Ethiopia’s government about a photo published by the Ethiopian media in November allegedly showing a piece of equipment from the Global Communications Co., known as Glocom, being used by a top military official. Eritrea also hasn’t responded to questions about its alleged procurement of Glocom equipment, the experts said.
North Korea may also have illegally traded arms and related material with a number of countries, including sending artillery shells, infantry rockets and missiles to Russia – claims Pyongyang and Moscow have consistently denied, the panel said. And the experts said they are investigating the reported sale of weapons from a North Korean company on the U.N. sanctions list to the Myanmar military through a Myanmar company.
The post UN Experts: North Korean Hackers Stole Record Virtual Assets appeared first on SecurityWeek.
Denis Mihaqlovic Dubnikov, of Russia, has admitted in a United States court to laundering cryptocurrency for the Ryuk ransomware gang.
Ryuk is a file-encrypting ransomware that emerged in 2018 and which was operated by the same cybercriminals as the Trickbot botnet.
In early 2021, security researchers estimated the Ryuk operation to be worth over $150 million. Ryuk was then replaced in attacks by the Conti ransomware.
According to court documents, between August 2018 and August 2021, Dubnikov, now 30, laundered the proceeds of Ryuk ransomware attacks on entities in the US and elsewhere.
In a typical ransomware attack, cybercriminals breach the systems of individuals or organizations, deploy the file-encrypting malware, and use it to render data on the infected systems unusable. The victim is usually instructed to pay a ransom in exchange for a decryption key.
Dubnikov, who was arrested in the Netherlands in November 2021 and extradited to the US in August 2022, engaged in various financial transactions to conceal the source and ownership of ransom proceeds from Ryuk attacks.
Following one ransomware attack, a US-based company paid a 250 Bitcoin ransom to Ryuk threat actors, who then transferred 35 Bitcoin to Dubnikov, in exchange for approximately $400,000.
Dubnikov then converted the Bitcoin to Tether and sent it to another co-conspirator, who exchanged it for Chinese Renminbi. Dubnikov’s co-conspirators laundered additional funds from the ransom payment.
According to court documents, Dubnikov received financial compensation for his role in the scheme.
Dubnikov has pleaded guilty to one count of conspiracy to commit money laundering and he faces up to 20 years in prison and a $500,000 fine. He is scheduled for sentencing on April 11, 2023.
Related: Former Ubiquiti Employee Who Posed as Hacker Pleads Guilty
Related:Canadian NetWalker Ransomware Affiliate Pleads Guilty in US
Related: Nigerian Admits in US Court to Hacking Payroll Company
The post Russian Admits in US Court to Laundering Money for Ryuk Ransomware Gang appeared first on SecurityWeek.
GootLoader was born from GootKit, a banking trojan that first appeared around 2014. In recent years GootKit has evolved into a sophisticated and evasive loader — and it was given a new name to reflect its new purpose in 2021. The same group is responsible for both versions of the malware, and is monitored by Mandiant as UNC2565.
The evolution of GootLoader reflects the evolution of cybercriminal gangs. Many of the more sophisticated gangs are switching to a malware-as-a-service business model. They develop the malware, but less-advanced gangs or individuals pay for use of that malware. In this case, it is access (or victim) as a service. GootLoader provides access to victims primarily for ransomware. The access is likely taken up by ransomware-as-a-service (RaaS) groups who sell-on the access to ransomware groups or individual criminals. For further details on this business model, see Cyber Insights 2023: Criminal Gangs.
GootLoader continues to evolve. Researchers at Cybereason have published a deep dive into the latest version.
The infection journey starts within compromised WordPress sites. These sites are given greater validity through SEO poisoning techniques, with key words likely hidden within html code on valid pages. Google Ads may also be used. With a high search engine ranking, potential victims are more likely to visit the compromised site.
The primary targets are healthcare and finance within English speaking countries, such as the US, the UK and Australia.
If a victim is drawn into a watering hole WordPress site, he is provided with a ZIP file containing a malicious JavaScript. This is described as stage-1 of the GootLoader infection. The JavaScript establishes persistence by creating and running a ‘Customer Engineering’ scheduled task. It also generates a second JavaScript file (stage-2 of the infection) which is 40 MB in size (random junk code is added, probably to confuse and evade detection).
The Customer Engineering task has been configured to execute this large new JavaScript file. It ultimately provides PowerShell code, which executes a command and control function every 20 seconds using random GootLoader C2 URLs as parameters. It uses system discovery calls to obtain the environment variables, processes, desktop items and disks on the victim machine. This data is compressed, and encoded, and sent to the C2 disguised as a cookie.
GootLoader infection process (Image Credit: Cybereason IR team)
As an aside, the researchers used ChatGPT to make some of the PowerShell code more easily understood. It was used, for example, to change the original variable names into more descriptively pertinent names. This it did effectively, but researcher Loic Castel told SecurityWeek that ChatGPT’s value to seasoned researchers is limited. “It cannot help with the more complex work – couldn’t help with the de-obfuscation – but it may be used by junior researchers in more basic stages.”
Lateral movement starts with disabling Microsoft Defender, and proceeds with Cobalt Strike loaded through DLL hijacking. SystemBC is deployed.
Cybereason was unable to see the final effect of GootLoader. The instance comes from its own telemetry where it detected and stopped GootLoader’s progress. The final malware deployment didn’t happen. But they did detect the deployment of SystemBC.
“SystemBC is what we call the precursor of ransomware,” explained Castel. “We often see it hours, maybe days, before the ransomware is actually deployed. This is something that is often deployed just before a ransomware attack.”
Any subsequent ransomware attack would almost certainly not have been delivered by UNC2565. Their function within the modern criminal ecosphere is to provide access to victims, and to sell that access to other criminals. The final payload is not pre-defined, but it seems likely to be particularly relevant for ransomware.
GootLoader is not a specifically targeted attack. However, some generalized targeting is achieved through the development of the original watering hole process. This suggests that this instance of the malware is aimed at the healthcare and finance sectors within English-speaking countries.
Cybereason assesses the GootLoader threat level as ‘severe’. The malware uses a combination of evasion and living off the land techniques, and its presence is unlikely to be spotted by anything other than AI-assisted anomaly detection.
Related: Ransomware, Malware-as-a-Service Dominate Threat Landscape
Related: Recent GootLoader Campaign Targets Law, Accounting Firms
Related: Mouseover Macro Campaign Delivers Gootkit Trojan Via PowerPoint
Related: GootKit Trojan Targets Banks With Redirection Attacks
The post A Deep Dive Into the Growing GootLoader Threat appeared first on SecurityWeek.
The US Cybersecurity and Infrastructure Security Agency (CISA) has released an open source tool that could help some victims of the recent ESXiArgs ransomware attacks recover their files.
The ESXiArgs ransomware attacks, first observed on February 3, involve exploitation of CVE-2021-21974, a high-severity ESXi remote code execution vulnerability that VMware patched in February 2021.
Hackers are leveraging the vulnerability to deploy file-encrypting malware that targets virtual machines (VMs). The cybercriminals are also claiming to have stolen data — which they threaten to leak — but currently there is no evidence to back up their claims.
Technical details and a proof-of-concept (PoC) exploit for CVE-2021-21974 have been around for nearly two years, but there is no indication that in-the-wild exploitation has been observed until now. VMware is warning users to take action, noting that there is no evidence that a zero-day vulnerability has been involved in the ESXiArgs attacks.
The Censys and Shodan search engines show there are currently roughly 2,000 compromised ESXi servers. It’s worth noting that the number of hacked systems identified by Censys has decreased in the past days, which indicates that affected organizations have started cleaning up their networks.
An analysis of the ESXiArgs attack shows that once a server is compromised, the attacker places a series of files in the /tmp folder, including an encryptor, a shell script managing the attack flow, a public RSA encryption key, and a ransom note.
The shell script is responsible for changing VMX configuration file names, killing running VMX processes, identifying and encrypting VM-related files, placing the ransom note on the targeted system, and deleting the originals of the encrypted files, according to an analysis conducted by BlackBerry researchers.
While the ransomware does encrypt some files associated with virtual machines, it appears that — at least in some cases — it only encrypts configuration files, not the disk files that store data. This can allow victims to recover their data without paying a ransom to the cybercriminals.
Security researchers Enes Sonmez and Ahmet Aykac have described the steps that users need to take to recover their data. CISA has taken the researchers’ tutorial and other publicly available resources and created an ESXiArgs ransomware recovery tool that reconstructs VM metadata from virtual disks that were not encrypted by the malware.
“Any organization seeking to use CISA’s ESXiArgs recovery script should carefully review the script to determine if it is appropriate for their environment before deploying it. This script does not seek to delete the encrypted config files, but instead seeks to create new config files that enable access to the VMs,” CISA explained.
Based on an initial analysis, experts say the files that have actually been encrypted by the ransomware cannot be recovered.
ESXiArgs has not been linked to any known ransomware group, but some believe the malware may have been derived from the Babuk source code that was leaked in 2021.
Related: VMware Patches VM Escape Flaw Exploited at Geekpwn Event
Related:VMware Confirms Exploit Code Released for Critical vRealize Logging Vulnerabilities
The post CISA Releases Open Source Recovery Tool for ESXiArgs Ransomware appeared first on SecurityWeek.
San Diego healthcare services provider Sharp HealthCare is informing patients that some of their information was compromised in a recent data breach.
A not-for-profit healthcare provider, Sharp operates multiple hospitals and facilities in San Diego County, has 19,000 employees and works with roughly 2,700 affiliated physicians.
The incident took place on January 12, when an unauthorized party gained access to a server running the Sharp.com website, the company says in a data breach notice.
According to the healthcare services provider, the unauthorized access lasted for a few hours only, but, during this time, the attackers accessed a file containing patient data.
The compromised information, the company says, includes names, payment amounts, which Sharp facilities received the payments, and Sharp identification numbers and/or invoice numbers.
Payment card data, Social Security numbers, contact information, health insurance details, birth dates, clinical information, or details about received services were not accessed.
“Additionally, this incident did not involve unauthorized access to Sharp’s medical record systems or the FollowMyHealth patient portal,” the healthcare provider says.
According to the organization, the incident only impacted Sharp patients who used the online bill payment service to pay a bill or invoice between August 12, 2021, and January 12, 2023. According to The San Diego Union Tribune, roughly 63,000 individuals were impacted.
“We have no indication that anyone’s information has been misused. However, as a precaution, we are mailing notification letters to individuals whose information was involved in this incident,” Sharp says.
Stolen personal and medical information is often shared or traded on underground hacker forums and later used by cybercriminals in phishing and other types of cyberattacks.
Related: Vulnerabilities in OpenEMR Healthcare Software Expose Patient Data
Related:Ransomware Hit 200 US Gov, Education and Healthcare Organizations in 2022
Related:Data Breach at Louisiana Healthcare Provider Impacts 270,000 Patients
The post Patient Information Compromised in Data Breach at San Diego Healthcare Provider appeared first on SecurityWeek.
The German government announced the appointment Tuesday of the European Central Bank’s head of IT systems to lead the national cybersecurity agency, months after her predecessor was removed following reports of possible problematic ties to Russia.
Interior Minister Nancy Faeser said Claudia Plattner “brings the experience and expertise with her that we need for cybersecurity in these particularly challenging times.” She will take charge of the BSI agency on July 1, becoming the first woman in the role.
Faeser dismissed the BSI’s previous head, Arne Schoenbohm, in October. He had been in charge of the agency since 2016.
Schoenbohm co-founded a cybersecurity group a decade ago that brought together experts from public institutions and the private sector. German media reported that one of its members was a company founded by a former Russian intelligence agent. The group said last week that it had thrown out the company.
The Interior Ministry said in the fall that the allegations “damaged the necessary confidence of the public in the neutrality and impartiality” of Schoenbohm’s management.
Schoenbohm defended himself against the allegations. He has since taken up a new job as the head of another body overseen by the Interior Ministry, the Federal Academy of Public Administration.
Plattner worked for German railway operator Deutsche Bahn’s IT provider, DB Systel, before joining the ECB in July 2021. The Frankfurt-based central bank said it would announce a successor “in due course.”
The post Germany Appoints Central Bank IT Chief to Head Cybersecurity appeared first on SecurityWeek.
The OpenSSL Project on Tuesday shipped a major security update to cover at least eight documented security flaws that expose OpenSSL users to malicious hacker attacks.
The most serious of the bugs, a type confusion issue tracked as CVE-2023-0286, may allow an attacker to pass arbitrary pointers to a memcmp call, enabling them to read memory contents or launch denial-of-service exploits.
The OpenSSL maintainers slapped a high-severity rating on the flaw but notes that the vulnerability is most likely to only affect applications which have implemented their own functionality for retrieving CRLs over a network.
Organizations running OpenSSL versions 3.0, 1.1.1 and 1.0.2 are urged to apply available upgrades immediately.
The open-source project also documented seven moderate-severity issues that require urgent attention.
According to an OpenSSL advisory, these include:
The group also patched multiple memory corruption issues that exposes OpenSSL users to denial-of-service conditions.
Related: OpenSSL Flaw Severity Downgraded From Critical to High
Related: OpenSSL Vulnerability Can Be Exploited to Change Application Data
Related: High-Severity DoS Vulnerability Patched in OpenSSL
Related: OpenSSL Patches Remote Code Execution Vulnerability
The post OpenSSL Ships Patch for High-Severity Flaws appeared first on SecurityWeek.
Software supply chain security startup Lineaje today announced that it has raised $7 million in a seed funding round led by Tenable Ventures.
Dreamit Ventures and Veear Capital also participated in the investment round, along with various angel investors.
Founded in 2021, the Saratoga, California-based company helps organizations secure their software supply chain, regardless of whether they are the developers, suppliers, or users of software.
Lineaje’s SB0M360 software supply chain management solution can identify all the components of software, along with their dependencies, to assess the supply chain authenticity and identify potential compromise.
Lineaje’s platform manages over 150,000 software bills of materials (SBOMs) across custom applications, open source software, commercial off-the-shelf (COTS) solutions, mobile applications, and containers.
The company is also assisting Tenable Ventures in building shareable data models to improve runtime security and mitigate weaknesses in deployed software.
The funding will allow Lineaje to accelerate go-to-market operations, expand its employee base, and invest in research and development.
Related: Boxx Insurance Raises $14.4 Million in Series B Funding
Related: Guardz Emerges From Stealth Mode With $10 Million in Funding
Related: Strata Raises $26 Million for Multi-Cloud Identity Management Platform
The post Software Supply Chain Security Firm Lineaje Raises $7 Million appeared first on SecurityWeek.
Industrial control systems (ICS) cybersecurity company Opscura announced its launch on Tuesday with $9.4 million in Series A funding.
Opscura is a new brand and the company has a new global management team, but it’s not new in the ICS cybersecurity sector. The company was founded in Spain as Enigmedia and it has been around for more than a decade.
Enigmedia co-founders Gerard Vidal and Carlos Tomás will serve as CTO and VP of engineering at Opscura, respectively. David Hatchell has been named Opscura’s CEO.
The new funding round, led by Anzu Partners with participation from Dreamit and Mundi Ventures, will be used for the company’s growth and expansion in the United States.
Opscura provides solutions designed to protect industrial networks by isolating, cloaking and authenticating sensitive assets and data in operational technology (OT) networks. Its cloaking technology obscures deep OT Level 2 network and Layer 2 data without disrupting operations.
The company says its solutions enable organizations to gain deep OT visibility, provide access control capabilities between IT and OT networks, provide protection for critical legacy endpoints, and help reduce the OT attack surface.
Opscura says its solutions are designed to complement the offerings of companies such as Nozomi Networks, Claroty and Fortinet.
The ICS security firm claims to have customers in the transportation, renewable energy, government, manufacturing and chemical sectors.
Related: OT Security Firm Network Perception Raises $13 Million
Related: OT Remote Access Firm Xona Raises $7.2 Million in Series A Funding
Related: SynSaber Raises $13 Million for OT Asset and Network Monitoring Solution
Related: Industrial Cybersecurity Firm Claroty Raises $140 Million in Series D Funding
The post ICS Cybersecurity Firm Opscura Launches With $9.4 Million in Series A Funding appeared first on SecurityWeek.
A severe vulnerability in the web portal of Toyota’s global supplier management network allowed a security researcher to gain access to sensitive information.
The issue was identified by US-based researcher Eaton Zveare in Toyota’s Global Supplier Preparation Information Management System (GSPIMS), a web portal that provides Toyota employees and suppliers with access to ongoing projects, surveys, information on purchases, and more.
The issue, Zveare says, was related to the implementation of JWT (JSON Web Token) authentication and could allow access to any account to anyone using a valid email address.
Essentially, JWT is a session token that is typically generated when logging in to a website, and which is then used to authenticate the user to secure sections of the website or APIs.
What the researcher discovered was that Toyota’s GSPIMS contained a function that would allow users to generate a JWT based on the provided email address, without requiring a password.
With corporate Toyota email addresses easy to guess – as they are using the format firstname.lastname@toyota.com – the researcher was able to guess an email address by searching the internet for Toyota employees that might be involved in the supply chain.
Next, Zveare used that email address to generate a valid JWT and used it to access the GSPIMS. After some reconnaissance on the portal, he discovered an account with system administrator privileges and used the same method to access it.
The system admin account, the researcher says, provided access to everything on the portal, including information on over 14,000 user accounts, control over roles each account could have, details on all available projects, surveys, and various classified documents.
According to the researcher, the GSPIMS also provides the system admin with the option to log in as any of the available 14,000 users, to supervise their activities. The function that generates the JWT based on email address was apparently implemented to enable this option, but it also created a backdoor into the network.
An attacker with system admin access to GSPIMS could have created a rogue account for persistence, exfiltrated all available data, tampered with or deleted the data, and fetched the corporate email and roles of all 14,000 user accounts to target them in phishing attacks.
The researcher reported the vulnerability to Toyota on November 3, 2022. The car maker patched the issue shortly after.
Related: Toyota Discloses Data Breach Impacting Source Code, Customer Email Addresses
Related:Toyota’s Japan Production Halted Over Suspected Cyberattack
Related:Vulnerabilities Expose Lexus, Toyota Cars to Hacker Attacks
The post Vulnerability Provided Access to Toyota Supplier Management Network appeared first on SecurityWeek.
A patch has been released for the GoAnywhere managed file transfer (MFT) software zero-day vulnerability whose existence came to light recently. News of active exploitation emerged roughly a week ago, but details about the attacks are still not available.
Fortra, known until recently as HelpSystems, alerted GoAnywhere MFT users on February 1 about a ‘zero-day remote code injection exploit’. The company has since released two other security notifications, each of them providing mitigations and indicators of compromise (IoCs).
GoAnywhere users are now being informed that a patch has been made available. Users are advised to urgently install GoAnywhere MFT 7.1.2.
“Particularly for customers running an admin portal exposed to the Internet, we consider this an urgent matter,” the company said.
GoAnywhere zero-day patchThere does not appear to be any information about the attacks exploiting the vulnerability. It’s unclear if it has been leveraged by state-sponsored threat actors or profit-driven cybercriminals.
A CVE identifier has yet to be assigned to the flaw.
Users have been told to check log files for a particular line that indicates a system has been targeted in an attack exploiting the zero-day vulnerability. If the log files show signs of compromise, users should check their installation for suspicious administrator users.
A researcher has published technical details on the flaw, as well as a proof-of-concept (PoC) exploit.
A Shodan search shows nearly 1,000 internet-exposed instances of GoAnywhere. However, the vendor pointed out that exploitation requires access to the application’s admin console, and at least some of the exposed instances appear to be associated with the product’s web client interface, which is not affected.
Related:Zero-Day Vulnerability Exploited to Hack Over 1,000 Zimbra Email Servers
Related:US Agencies Warn of APTs Exploiting Recent ADSelfService Plus Zero-Day
Related:Accellion Failed to Notify Customers of FTA Zero-Day
The post Patch Released for Actively Exploited GoAnywhere MFT Zero-Day appeared first on SecurityWeek.
A Cl0p ransomware variant targeting Linux systems emerged recently, but a flaw in the encryption algorithm has already allowed for the creation of a free decryptor for it.
Cl0p has been one of the most active ransomware families over the past several years, targeting numerous private and public organizations globally, in sectors such as aerospace, energy, education, finance, high-tech, healthcare, manufacturing, telecoms, and transportation and logistics.
In November 2021, authorities announced the arrest of six individuals linked to the Cl0p operation, but the ransomware continues to be used in attacks. In August 2022, Cl0p claimed responsibility for hacking a UK water company.
Today, cybersecurity company SentinelOne announced the discovery of a Linux variant of Cl0p (aka Clop), which was used in late December 2022 in an attack against a university in Colombia.
The ELF variant of Cl0p has been developed in a similar logic to the Windows version and appears to be in early development stages, as it lacks some of the functionality seen in Windows samples.
Observed differences include API calls and other OS-related changes, but the encryption method is the same, SentinelOne says.
After execution, the ransomware attempts to access root, after which it begins encrypting other directories. Unlike the Windows variant, it targets specific folders and subfolders, encrypting all files in them.
Cl0p for Linux targets subdirectories for optional software packages, multiple Oracle directories, the home directory for each user, and the home directory for the root user. A ransom note is then dropped on the victim’s machine, instructing them to contact the attackers via email.
SentinelOne’s analysis of the threat has revealed a flaw in the encryption algorithm, where a hardcoded RC4 ‘master-key’ is used during the encryption process, which allowed them to decrypt Cl0p-encrypted files.
To help victims of the Cl0p-ELF variant restore their data, SentinelOne has created a Python script that is available on GitHub.
“While the Linux-flavored variation of Cl0p is, at this time, in its infancy, its development and the almost ubiquitous use of Linux in servers and cloud workloads suggests that defenders should expect to see more Linux-targeted ransomware campaigns going forward,” SentinelOne concludes.
Related: Cyber Insights 2023 | Ransomware
Related:VMware ESXi Servers Targeted in Ransomware Attack via Old Vulnerability
Related: Industrial Ransomware Attacks: New Groups Emerge, Manufacturing Pays Highest Ransom
The post Linux Variant of Cl0p Ransomware Emerges appeared first on SecurityWeek.
VMware has urged customers to take action as unpatched ESXi servers continue to be targeted in ESXiArgs ransomware attacks.
Hackers are exploiting CVE-2021-21974, a high-severity ESXi remote code execution vulnerability related to OpenSLP that VMware patched in February 2021. Following successful exploitation, unidentified threat actors have deployed file-encrypting ransomware that targets virtual machines.
Technical details and a proof-of-concept (PoC) exploit for CVE-2021-21974 have been around for nearly two years, but there is no indication that in-the-wild exploitation has been observed until now.
In a blog post published on its Security Response Center on Monday, VMware said there is no evidence that the attacks involve exploitation of a zero-day vulnerability.
“Most reports state that End of General Support (EOGS) and/or significantly out-of-date products are being targeted with known vulnerabilities which were previously addressed and disclosed in VMware Security Advisories,” the virtualization giant said.
Attacks are possible because many organizations are running old and unpatched software.
“I’ve assessed nearly 500 owned boxes this evening, all of them are on old software releases. A shocking amount of orgs run ESXi on long end of life versions,” researcher Kevin Beaumont said on Monday.
ESXiArgs ransomware attacks appear to have started on or around February 3. As of February 7, Censys shows nearly 2,500 compromised servers and Shodan shows more than 1,600. Most of the hacked systems are located in France, followed by the United States.
On compromised systems, the hackers drop a ransom note instructing victims to pay roughly $50,000 in bitcoins in order to recover their files and prevent them from getting leaked. While the cybercriminals claim to have stolen data that they will sell unless a ransom is paid, there does not appear to be any evidence to date that files have actually been stolen in ESXiArgs attacks.
As for the malware used in these attacks, it seems to target files associated with virtual machines.
In some cases, the malware’s encryption routine can partially fail, which could allow some victims to recover their data without paying a ransom. However, recovering files that have been properly encrypted seems impossible for the time being.
Cyble has published a technical analysis of the malware, including information on VM configuration file modifications, file encryption, persistence, and cleanup.
Government cybersecurity agencies around the world, including in the United States, have issued alerts over the ESXiArgs ransomware attacks.
Related: VMware Patches VM Escape Flaw Exploited at Geekpwn Event
Related:VMware Confirms Exploit Code Released for Critical vRealize Logging Vulnerabilities
The post VMware Says No Evidence of Zero-Day Exploitation in ESXiArgs Ransomware Attacks appeared first on SecurityWeek.
Telco and media conglomerate Comcast has jumped headfirst into the enterprise cybersecurity business, betting that its internal security tools and inventions can find traction in an expanding marketplace.
The Philadelphia technology giant has created a new cybersecurity business unit led by former Zscaler executive Nicole Bucala to develop and sell what Comcast is describing as a “security data fabric platform.
In a note announcing the new business unit, Comcast said the long-term plan is to bring its own chief information security officer’s (CISO) inventions to market, betting that its size and scale provides a major competitive advantage.
“The solutions we are commercializing are imagined, designed, built and used by Comcast itself. [We have] a high bar for the effectiveness of technologies; so for any internally built solution to survive, it has to be efficient and cost effective at scale,” Bucala said, arguing that this maturity provides trust to enterprise buyers.
The new cybersecurity business unit is housed in Comcast Technology Solutions (CTS), the division within Comcast that takes internally developed technology and makes it available to other enterprises.
The company said its CTS division has successfully commercialized multiple internal inventions in content and streaming, advertising, communications infrastructure, and other technologies.
The new cybersecurity business unit has rolled out its first product, called DataBee, that offers a place to centralize security, compliance, and business data.
The DataBee Platform claims it can ingest data from multiple feeds, then aggregate, compress, standardize, enrich, correlate, and normalize it before transferring a full time-series dataset to data lakes.
Comcast’s entrance in the enterprise cybersecurity business comes at a tricky time. In the midst of an economic downturn that has led to layoffs and cutbacks in enterprise spending, analysts remain bullish on cybersecurity as a revenue generator.
Microsoft says it is now raking in $20 billion a year from cybersecurity-related revenue linked to enterprise consolidation of computing, security and compliance tools. Like Microsoft, Google has also jumped headfirst into the space, spending heavily to acquire Mandiant and Siemplify to beef up with cloud and business security offerings.
Related: Predictions 2023: Big Tech’s Coming Security Shopping Spree
Related: For Microsoft, Security is a $10 Billion Business
Related: Google Completes $5.4 Billion Acquisition of Mandiant
Related: Google Acquires Siemplify in Ambitious Cybersecurity Push
The post Comcast Wants a Slice of the Enterprise Cybersecurity Business appeared first on SecurityWeek.
A critical vulnerability affecting wireless communication base stations from Baicells Technologies can be exploited to cause disruption in telecom networks or take complete control of data and voice traffic, according to a researcher.
Baicells Technologies is a US-based telecommunications equipment provider for 4G and 5G networks. The company says more than 100,000 of its base stations are deployed across 64 countries around the world.
Cyber offensive researcher Rustam Amin discovered that at least some of Baicells’ Nova base station products are affected by a critical command injection vulnerability that can be exploited remotely without authentication by sending specially crafted HTTP requests to the targeted device.
Exploitation of the vulnerability, tracked as CVE-2023-24508, can allow an attacker to run shell commands with root privileges and take complete control of a device, Amin told SecurityWeek.
The researcher explained that an attacker could, for instance, easily shut down a device to cause disruption. In addition, they could take full control over the traffic and phone calls going over a targeted network. A hacker could obtain information such as phone numbers, IMEI, and location data.
However, conducting such an attack is not an easy task and it requires specific knowledge of the targeted network.
Amin told SecurityWeek that there are more than 1,150 devices exposed to the internet, mostly located in the United States.
Baicells published an advisory to inform customers about the vulnerability on January 24. The researcher said the vendor was quick to respond to his notification and quick to issue a patch.
Nova 227, 233, 243 and 246 base stations are affected. The security hole has been patched with the release of version 3.7.11.3.
The vendor’s advisory only mentions Nova products as being impacted, but the researcher believes other products could be impacted as well.
The US Cybersecurity and Infrastructure Security Agency (CISA) published an advisory last week to inform organizations about CVE-2023-24508.
Amin recently also discovered serious vulnerabilities in Econolite EOS traffic controller software, which can be exploited to control traffic lights.
Related: OT Security Firm Warns of Safety Risks Posed by Alerton Building System Vulnerabilities
Related: US Details Chinese Attacks Against Telecoms Providers
Related: Cisco Patches High-Severity Vulnerabilities in Communications, Networking Products
The post Critical Baicells Device Vulnerability Can Expose Telecoms Networks to Snooping appeared first on SecurityWeek.
The New York Office of the Attorney General has announced punitive measures against Patrick Hinchy and 16 of the companies he owns, for illegally promoting spyware.
Since 2011, Hinchy has owned and operated numerous companies, including the 16 investigated by the New York OAG, for selling and promoting spyware targeting Android and iOS devices, including Auto Forward, Easy Spy, DDI Utilities, Highster Mobile, PhoneSpector, Surepoint, and TurboSpy.
Once installed on victim devices, the spyware would collect and exfiltrate data such as call logs, text messages, photos, videos, emails, Chrome browser data, location, and data from messaging and social media applications, including WhatsApp, Skype, Facebook, Instagram, and Twitter.
The spyware was sold to ‘customers’ looking to spy on their spouse, colleagues, or other individuals, and was installed on the victims’ devices without their knowledge and without notifying them of the data collection and exfiltration activities.
Furthermore, in order to access certain types of information, the spyware required ‘root’ or ‘jailbreak’ access. Some of the spyware also allowed customers to remotely activate the infected device’s camera or microphone, for spying or eavesdropping purposes.
The collected data was being transmitted to servers owned by Hinchy’s companies, and users of the spyware apps could access it through a web dashboard that also allowed customers to activate device cameras, unlock the victim devices, and hide or erase the spyware from those devices.
Collected data, the New York OAG has discovered, was being transmitted in an insecure manner, which exposed it to potential cyberattacks and snooping.
The investigation conducted by authorities has revealed that Hinchy and his companies focused heavily on promoting the spyware and instructing customers on how to install the software without being caught.
Customers were also led to believe that the spyware was legal, although its use without the device owner’s consent violates multiple laws.
Furthermore, Hinchy and his companies failed to inform customers of the harm the use of the software could cause, presented customers with confusing refund and data security policies, and created bogus review websites to lure customers into purchasing the spyware.
The New York OAG fined Hinchy and his companies $410,000 in penalties and ordered them to modify the software so that it would notify device owners of the data collection activities. Furthermore, Hinchy and his companies are now required to “make accurate disclosures regarding endorsements, rooting and jailbreaking requirements, refund policies, and data security”.
Hinchy and his companies are also required to delete collected data and to block customer access to that data unless customers provide an electronic acknowledgment regarding the lawfulness of the spyware.
Related: Justices Turn Away Israeli Spyware Maker in WhatsApp Suit
Related: Google Links Exploitation Frameworks to Spanish Spyware Vendor Variston
Related:Religious Minority Persecuted in Iran Targeted With Sophisticated Android Spyware
The post New York Attorney General Fines Vendor for Illegally Promoting Spyware appeared first on SecurityWeek.
MSSPs took the lead in cybersecurity M&A in 2022 with twice as many deals as in 2021
An analysis conducted by SecurityWeek shows that more than 450 cybersecurity-related mergers and acquisitions were announced in 2022.
In 2022, we tracked a total of 455 deals, compared to 435 in 2021. The US and UK continue to lead in terms of the number of deals, but Israel and Australia were overtaken last year by Canada and Germany.
The number of deals involving companies from the United States increased from 341 to 358, and the UK dropped from 70 to 61 deals.
As for regional data, North America and Europe continue to lead with roughly the same number of M&As as in the previous year. The number of deals involving companies in Asia and Oceania dropped compared to 2021, but M&A activity more than doubled in Latin America.
Financial details of the transaction were disclosed in 62 cases in 2022, significantly less than the 88 deals that had financial terms disclosed in 2021.
In 2022, we saw transactions totaling more than $63 billion in disclosed deal value. Ten companies were acquired for more than $1 billion, roughly the same as in 2021. The most significant deal for the cybersecurity industry was Google’s acquisition of Mandiant.
Thoma Bravo acquired SailPoint, Ping Identity, and Forgerock for more than $1 billion, and reportedly sold Barracuda Networks for $4 billion. Vista Equity Partners acquired two companies for over $1 billion: KnowBe4 and Citrix (Citrix was acquired with Evergreen Coast Capital).
Other major deals include Kaseya’s acquisition of Datto, Carlyle Group’s acquisition of ManTech International, and AMD’s acquisition of Pensando.
Roughly the same number of companies as in 2021 was acquired for millions of dollars, but the number of deals for tens and hundreds of millions has dropped from 64 to 38.
As for the types of companies involved in 2022’s cybersecurity M&A deals, managed security services providers (MSSPs) lead by far, with over 150 deals, more than double compared to 2021. Many MSSPs are looking to buy other managed services providers as part of their expansion efforts.
In addition, a recent survey showed that many MSPs are focusing on growing their cybersecurity practices, with many planning to invest in threat intelligence, detection and response, real-time attack visibility, and forensics and incident response.
SecurityWeek is tracking MSSP deals separately. While it’s important to keep track of these transactions as they play a significant role in the cybersecurity industry, we are currently tracking them separately in an effort to get a better view of the other categories.
Deals in the governance, risk and compliance (GRC) category come in second place, with 58 mergers and acquisitions announced in 2022 involving these types of companies. It’s worth noting that GRC exceeded MSSP in 2021, when nearly 80 transactions were announced.
Companies providing network security and identity-related services were, just like in 2021, the third and fourth most common in cybersecurity deals, but the number of deals related to data protection nearly doubled, moving from the tenth position on the chart to the fifth.
Even in the first half of 2022 it was clear that data protection would be in the M&A spotlight, with the number of deals announced in H1 reaching the same level as in the entire 2021.
The number of deals involving government contractors dropped slightly in 2022 compared to 2021, from 43 to 36, but it remained one of the top types of transactions. This includes Carlyle Group’s acquisition of ManTech International for $4.2 billion.
The US government continues to invest in improving its cyber capabilities. As a result, IT and cybersecurity contractors are scrambling to extend and enhance their capabilities through strategic acquisitions that can pay off down the line.
The data collected by SecurityWeek shows that private equity (PE) companies continue to bet big on cybersecurity, with 18 of the mergers and acquisitions announced in 2022 involving PE firms, approximately the same as in the previous year.
PE firms have acquired companies specializing in cloud security, data protection, threat intelligence, risk management, application security, identity, network security, security operations center (SOC), mobile security, secure access, and managed services.
Three of the 2022 cybersecurity M&A deals involved a special purpose acquisition company (SPAC).
There were more than 10 deals for each of the following types of companies: cloud (32), application (24), specialized (22), consulting (21), incident response (20), training (20), threat intelligence (17), and web and email (16).
The ‘specialized’ category includes companies that provide highly focused security services. The list includes — but is not limited to — blockchain, quantum, payment, PR, healthcare, hardware, education, certification, design and automotive.
We are seeing a similar start in terms of the number of M&A deals in 2023. On one hand, the global economic slowdown may lead to a drop in the number of deals in 2023 as companies may be more cautious and delay expansions fueled by acquisitions. On the other hand, we predict that some firms will be keeping a close eye on the market in hopes of buying startups with promising technologies at a discount.
Monthly summaries of 2022 cybersecurity M&A deals: January, February, March, April, May, June, July, August, September, October, November, December.
Methodology: The data was collected from news distribution services, Google and pitches from PR companies. The data includes companies that issued press releases announcing or mentioning acquisitions, as well as deals that have been privately reported to SecurityWeek. All deals that had a cybersecurity component have been taken into account for this study. Mergers and acquisitions that did not have an English-language announcement may not be included. The data could also include deals that may have not been completed after they were announced.
The GRC category includes governance, compliance, risk management, audit, assessment, vulnerability management, penetration testing, attack surface management, and cyber insurance. Network security includes endpoint security, MDR, XDR, NDR, and SASE. Identity includes IAM, PAM, secure access, authentication, authorization and fraud. Incident response includes SOAR, SIEM, SOC, and forensics. ‘Other (specialized)’ includes hardware, blockchain, quantum, payment, healthcare, PR, education, certification, design, and automotive. Data protection includes encryption/cryptography, VPN, privacy and backup. MSSP includes cybersecurity solution distributors and companies that provide security services but do not develop their own products or solutions.
Related: Dozens of Cybersecurity Companies Announced Layoffs in Past Year
Related: Cybersecurity M&A Activity to Continue; Growth Funding to be More Conservative
Related: Cybersecurity Investment Remains Strong, M&A Activity Heads Toward New Annual Record
The post SecurityWeek Analysis: Over 450 Cybersecurity M&A Deals Announced in 2022 appeared first on SecurityWeek.
PeopleConnect-owned background check services Instant Checkmate and TruthFinder have disclosed data breaches affecting a total of more than 20 million users.
In individual data breach notices published on February 3, the organizations informed users that the incident was discovered after cybercriminals started sharing databases stolen from the two companies on underground forums.
The databases – or ‘lists’, as the two companies call them – contain names, email addresses, phone numbers, encrypted passwords, and password reset tokens that are either expired or inactive.
“We have confirmed that the list was created several years ago and appears to include all customer accounts created between 2011 and 2019. The published list originated inside our company,” the announcements read.
The two organizations note that the leaked information does not include details on user activity or payment data.
While Instant Checkmate and TruthFinder also note that no “readable or usable passwords or other means to compromise user accounts” leaked either, it is not uncommon for cybercriminals to try to crack stolen encrypted passwords.
“As a best practice we would recommend that you not respond to suspicious communications. We will never ask you for your password, social security number or payment information via email or telephone,” the companies say.
Investigations were launched into both incidents, but no evidence of malicious activity has been found as of now on their networks. According to the two announcements, the data breach was the result of the “inadvertent leak or theft” of the impacted database.
While neither Instant Checkmate nor TruthFinder shared information on the number of affected individuals, the data has already been added to Troy Hunt’s breach notification service Have I been pwned.
The leaked databases include the information of more than 11.9 million Instant Checkmate accounts, and the details of over 8.1 million TruthFinder accounts.
Related: 820k Impacted by Data Breach at Zacks Investment Research
Related: 18k Nissan Customers Affected by Data Breach at Third-Party Software Developer
Related: 251k Impacted by Data Breach at Insurance Firm Bay Bridge Administrators
The post 20 Million Users Impacted by Data Breach at Instant Checkmate, TruthFinder appeared first on SecurityWeek.
About SecurityWeek Cyber Insights | At the end of 2022, SecurityWeek liaised with more than 300 cybersecurity experts from over 100 different organizations to gain insight into the security issues of today – and how these issues might evolve during 2023 and beyond. The result is more than a dozen features on subjects ranging from AI, quantum encryption, and attack surface management to venture capital, regulations, and criminal gangs.
SecurityWeek Cyber Insights 2023 | The Coming of Web3 – Web3 is a term that has been hijacked for marketing purposes. Since web3 obviously represents the future internet, claiming to be web3 now is a claim to be the future today. Such claims should be viewed with caution – we don’t yet know what web3 will be.
Two of the biggest culprits are the cryptocurrency and NFT investment industries, which both use blockchains. They have claimed to be web3 so vociferously that some pundits believe that web3 is blockchain. This is way too simplistic – these are just applications running on one technology that may become one of the web3 building blocks.
Before we discuss the evolution of, and issues with, web3 in 2023 and beyond, we’ll first define one specific view of its basics.
A tentative definition of web3Web3 will be the next fundamental characterization of the internet. Currently, its characteristics are clouded by confusion because it doesn’t exist. We won’t know what it is, until it is. Nevertheless, we can make some basic predictions because it will evolve from the current web2 and is bound by the rules of evolution. So, we must start with where we are to predict where we are going.
Web1 can be described as the static web. It was designed to deliver static information from information creators to information consumers. We still use web1.
Web2 can be described as the interactive web. It was designed to allow creators and consumers to interact. Three major examples are online banking, ecommerce, and social media. This is what we have now: a combination of web1 and web2.
Web3 can be described as whatever comes next. It will be an attempt to improve on web1 and web2. Most likely it will be an attempt to correct perceived faults or weaknesses in web2 and improve the users’ internet experience. We’ll focus on these characteristics in our projections for web3 focusing on decentralization and the metaverse — but remember that at this stage, it is still just conjecture.
DecentralizationA perceived fault in web2 is that it allows data to be centralized and focused in the hands of a few mega corporations. Big tech, including companies like Facebook, Microsoft, Google, and Apple own most of the world’s available data. More specifically, they own everybody’s personal information.
This is a problem both politically and socially, and is the primary driver for legislation designed to prevent big tech (and medium tech) from misusing and abusing personal data. GDPR, CCPA (and other privacy legislation), and the FTC’s increasing ‘overview’ of the misuse (which it defines as malpractice), can be seen as political attempts at correcting this fault in web2. We can add that the centralization of data is also a primary cause of cybercriminality, providing Aladdin’s Caves of rich pickings for criminals.
A better solution would be for the internet itself to reduce the stranglehold of big tech by becoming decentralized — companies do not need to own data to be able to confirm identity. Isolated attempts at decentralization already exist. Cryptocurrency (technically, at least) is an attempt to decentralize finance. The interplanetary file system (IPFS) is an attempt to decentralize data held in individual files.
One likely component of web3 will be a decentralized internet — and the distributed ledger implemented as blockchains is the most likely route. Big tech will not support this evolution.
ImmersiveA move towards a more immersive internet experience is already in progress. The improvement on web2 is that users wish to move beyond interacting with the internet to becoming part of the experience. This development can be seen in the evolution of the gaming industry — from text-based adventure games, to video platform games, to 3D games and now virtual reality gaming.
But it is also apparent in business. Covid-19 created a need for remote conferencing. This was already available via telephone conferences; but the rapid rise of videoconference tools such as Zoom demonstrates users’ wish to feel more involved – or integrated with the experience. The next logical step is for videoconferencing to evolve into virtual reality conferencing using the same tools and techniques developed for virtual reality gaming.
Web2 is already evolving towards an immersive internet, and ‘immersive’ is likely to be another component of web3. The current ultimate view of an immersive experience is the metaverse.
Web3The evolutionary pressures on the internet seem to be focusing on two characteristics: decentralization and immersiveness. This is how we will describe the next internet. Note that neither characteristic is dependent on the other, but there is synergy in their marriage. Metaverses do not need to be decentralized but can become so using distributed ledger technology (DLT). Metaverse and DLT are likely to be the key components of web3. The evolution will not be completed in 2023 (in fact, it has barely begun), but there will be much progress in that direction.
But note also that there are competing pressures. Big tech recognizes the value of the metaverse concept (Facebook has even changed its name to Meta), but big tech will not want decentralized metaverses where they lose ownership of users’ data.
As it evolves, web3 will contain and increase all the security issues of web2 – and perhaps add a few more.
MetaverseThe technology waiting gameThe excitement with which 2022 greeted the dream of the metaverse dissipated into disillusionment over the course of the year. The technology simply isn’t ready to deliver on the dream; but that dream remains.
Massimo Paloni, chief operations and innovations officer at Italian luxury brand Bvlgari, explained both the problems and the promise of the web3 metaverse. When you buy a product, he said, especially a luxury product, you go to the store not just for the product, but also for the experience. The experience is ‘storytelling’ by the vendor — and all storytelling changes with advances in technology. But the way that technology is used must always be aligned with the vendor DNA.
“Our mission is to be sure that the use of new technology – web3, blockchain and metaverse – is aligned with our value proposition. That is the key,” he said. Web2 ecommerce fails for the luxury brands. “Ecommerce is a bidimensional experience. It kills the magic of going to the store. All ecommerce is beautifully crafted — but ultimately all the stores are similar.”
The promise of the metaverse is that it will allow vendors, especially luxury vendors, to maintain their own storytelling in engaging with their customers. Better engagement, which isn’t supported by web2, will lead to higher sales. But the problem is the technology is new and evolving, and developers still don’t know what might be available in three- or four-months’ time – nevermind a few years.
“Content is absolutely king here – the technology will undoubtedly become better and better, but this is not enough in itself,” says Lars Seier Christensen, chairman of Concordium and founder of Saxo Bank. “Users need to achieve real benefits to embrace it – across areas like entertainment, better access to goods and services, valid commercial models and otherwise unachievable experiences.” What we’ve seen so far over the last year or two has failed to deliver this, and quickly became boring and irrelevant.
“2022 wasn’t a good year for the metaverse,” adds Orlando Crowcroft, tech and innovation editor at LinkedIn. “Two of the most prominent metaverse platforms – Decentraland and Sandbox, with valuations of over $1bn each – were revealed to have under 1,000 daily active users. And Meta’s Horizon World was so unpopular that even staff had to be pressured to use it.”
But he added, “Metaverse enthusiasts should take heart. In 2023, we will see the metaverse take off – in the professional world. VR and AR are being used right now to train pilots and surgeons. Expect employers, universities, and training programs to jump into the metaverse in even bigger ways in the new year.”
Crime in the metaverseJust as the metaverse is a new concept, crime in the metaverse is an unknown quantity. “Virtual cities and online worlds are new attack surfaces to fuel cybercrime,” warns Aamir Lakhani, cybersecurity researcher and practitioner for Fortinet’s FortiGuard Labs. He is concerned that a metaverse will be an open door to new cybercrime in uncharted territories.
“For example, an individual’s avatar is essentially a gateway to PII, making them prime targets for attackers. Because individuals can purchase goods and services in virtual cities, digital wallets, crypto exchanges, NFTs, and any currencies used to transact, offer threat actors yet another emerging attack surface,” he said.
He also worries about biometric hacking. The AR- and VR-driven components of virtual worlds may make it easier for a cybercriminal to steal fingerprint mapping, facial recognition data, or retina scans. Finally, he added, “The applications, protocols, and transactions within these environments are all also possible targets for adversaries.”
Kaarel Kotkas, founder and CEO at Veriff, sees trust in identity as the biggest problem. “If the metaverse is to be successful,” he said, “there needs to be a guarantee that users are who they say they are.”
“If the Metaverse is to live up to even a portion of its hype,” adds Padraic O’Reilly, co-founder and CPO at CyberSaint, “security will have to be baked in from the start. That is, it should be part of the conception. There should be a kind of cyber charter from the largest participants that stresses transparency, and laws for individuals. Cyber is everyone’s responsibility in the future.”
He also believes that regulation will be required over user identity. “To ensure the security of experiences and transactions in the metaverse, zero trust architecture and more legal protections (blockchain is too authority averse) are required. Without a central authority backing the purported ironclad data integrity of the blockchain, it will remain vulnerable.”
It is worth noting, however, that a ‘central authority’ is at least conceptually contrary to the ideal of decentralization.
Patrick Harr, CEO at SlashNext, continues this theme of identity. “Artificial intelligence solutions will be needed to validate the legitimacy of identities and controls,” he says. “This new type of digital interface will present unforeseen security risks when avatars impersonate other people and trick users into giving away personal data.”
But of course, AI will be used for attack as well as defense. Deepfaked avatars supported by AI chatbots will be used. “We can expect to see more of these holographic-type phishing attacks and fraud scams as the metaverse develops,” he continued. “In turn, folks will have to fight AI with stronger AI because we can no longer rely solely on the naked eye or human intuition to solve these complex security problems.”
Ultimately, security in the metaverse and web3 in general is both a threat and an opportunity. Traditionally, security is largely reactive – we fix things after they have been exploited. But “With web3 we have the opportunity to change the game in terms of security,” suggests Rodrigo Jorge, CISO at Vtex, “and construct something that has security by design, and is planned from user experience to the system architecture and infrastructure.”
He believes security professionals and companies have the opportunity to adopt security in this early stage so that when web3 becomes popular, it will be safe.
The progress of decentralization via blockchain“Web3 reflects an architectural shift decentralizing management of platforms. As platforms decentralize, the organizations that manage them will have to find ways to federate replacement controls for those they had centrally deployed,” says Archie Agarwal, founder and CEO at ThreatModeler. “When organizations design such tectonic shifts in their architecture (like the aggressive decentralization of web3), it’s incumbent on them to model the threats and adjust their security controls that such a shift will expose.”
Value from cryptocurrency technologyWhile cryptocurrency (as opposed to cryptocurrency technology) is peripheral to a discussion on web3, it cannot be dismissed entirely. Bitcoin demonstrated the security available in the blockchain implementation of the distributed ledger. But it is blockchain rather than cryptocurrency that is important to the development of web3.
Merav Ozair, a fintech professor at Rutgers Business School, commented on Nasdaq (December 20, 2022), “There is no doubt that the benefits of blockchain technology and web3 are immense. Jamie Dimon, CEO of JPMorgan, who has bashed bitcoin, has always been one of the great supporters of blockchain technology. JPMorgan is one of the leading companies in web3 and has made significant investments in blockchain technology, web3 and the metaverse since 2015.”
She also notes that the value of decentralization (in this case, cryptocurrency) has been demonstrated during the Ukraine/Russia conflict. The Ukrainian government has asked for donations in cryptocurrency, which has been adopted as a primary currency in the country.
“These instances underscore the promise of blockchain when Bitcoin, the first blockchain, was launched in January 2009, that a decentralized, peer-to-peer system, accessed by everyone, with no need for intermediaries, can empower everyday people: a system that is for the people, by the people,” she explained. This is the primary advantage of decentralization.
A security weakness in the unfolding web3 will come from its ‘newness’. “Looking forward, attackers are again adjusting their tactics to target individuals in the new web3 world,” comments Hank Schless, director of global campaigns at Lookout. “Since web3 is still a new concept for most people, attackers can rely on the unfamiliar environment to increase the likelihood of success. This is a common tactic, as targeted individuals may not know exactly what red flags to look for in the same way they do with a suspicious social media message.”
Christian Seifert, research at Forta, takes this further. “The current state of the De-Fi market [currently the primary implementation of decentralized blockchain], especially with mounting losses due to hacks and rug pulls, has reduced some of the trust that investors previously had in this industry,” he said.
Security issues “I believe the problem will continue to persist unless better security measures are implemented across the board. In this regard, we need an overhaul of the security strategies prevalent today to provide better end user privacy (via the use of, say, wallets) and improved protocol safety.”
In particular, he recommends “routine audits, offering bug bounties, maximizing monitoring and incident response – potentially via the use of future-ready technologies such as artificial intelligence and machine learning – and offering clients cyber insurance.”
Financial institutions Since the blockchain was originally developed for use in the finance sector, it should be no surprise that the finance industry is one of the more interested sectors. “There is a major trend of blockchain adoption in large financial institutions,” says Nick Landers, director of research at NetSPI, specifically citing Broadridge, Citi and BNY Mellon.
“The primary focus,” he continued, “is custodial offerings of digital assets, and private chains to maintain and execute trading contracts. Despite what popular culture would indicate, the business use cases for blockchain technology will likely deviate starkly from popularized tokens and NFTs.” Instead, he believes, industries will prioritize private chains to accelerate business logic, digital asset ownership on behalf of customers, and institutional investment in proof-of-stake chains.
By the end of next year, he expects that every major financial institution will have announced adoption of blockchain technology, if it hasn’t already. “While Ethereum, EVM, and Solidity-based smart contracts have received a huge portion of the security research, nuanced technologies like Hyperledger Fabric have received much less. In addition, the supported features in these business-focused private chain technologies differ significantly from their public counterparts.”
It is worth noting that private blockchains are not decentralized blockchains – which begs the question, are they really web3?
Either way, this ultimately means more attack surface, more potential configuration mistakes, and more required training for development teams. “If you thought that blockchain is ‘secure by default’,” added Landers, “think again. Just like cloud platform adoption, we’ll see the promises of ‘secure by default’ fall away as unique attack paths and vulnerabilities are discovered in the nuances of this technology.”
Blockchain and social mediaDissatisfaction with big tech’s control of social media has led to the exploration of alternative decentralized approaches. Mastodon, as an alternative to Twitter, is one example. It is decentralized but based on federation rather than blockchain. “Instant global communication is too important to belong to one company,” explains the Mastodon website. “Each Mastodon server is a completely independent entity, able to interoperate with others to form one global social network.”
But a blockchain – more specifically a multichain – social media alternative may appear in 2023. On December 20, 2022, Beepo officially closed the beta version of its decentralized app, and expects to launch in early 2023.
At the beginning of December 2022, Concordium announced an agreement with Beepo to incorporate its native token, CCD, as a means of payment on the platform. “Beepo, a blockchain-based platform powered by E2EE and an AI/ML algorithm with a focus on privacy and security,” explained Concordium, “is protected by end-to-end encryption technology and autonomous moderation, ensuring a totally secure environment for user interactions.”
The Beepo App offers a DApp (decentralized app) browser, tools for independent contractors, features for content creators, and a multichain blockchain infrastructure that lets users engage with various tokens and multiple networks. It is a response to growing user concern over the controlling and often abusive concentration of personal data within web2 big tech firms.
Web3 progress in 2023 The blockchain part of web3 (disregarding the question of whether private blockchains can even be considered part of web3) will probably develop faster than the metaverse during 2023. William Tyson, associate analyst in the thematic intelligence team at GlobalData, foresees a metaverse winter in 2023. He believes the immaturity of enabling technologies like virtual reality (VR) and artificial intelligence (AI), as well as cooling consumer interest, will prevent the metaverse from being adopted widely in the next year.
He adds, “The absence of a single vision for the metaverse means that its future is malleable and uncertain. Its extraordinary long-term potential is widely recognized, which is why big tech is continuing to funnel billions into its creation— despite the absence of short-term return on investment. The concept will experience a cold period, but this provides an opportunity for underlying technologies to develop.”
Meanwhile, the blockchain part of the equation will pick up steam in 2023. “We don’t have a defining trend for web3 in 2023, but that what we do have instead is an undercurrent of heads-down building and experimentation being done both by developers as well as traditional brands, setting the stage for a really exciting 2024,” says Dan Abelon, partner at Two Sigma Ventures.
“On the developer side, one area to watch is messaging: enabling decentralized services to communicate directly with end users,” he adds. “On the brand side, I’m excited to see more experiments like those by Reddit and Instagram in recent weeks, that will help bring web3 into the mainstream.”
Metaverse + blockchain synergyThe metaverse and blockchains are not interdependent – each can exist without the other. However, a decentralized metaverse will require blockchains. Consider a metaverse shopping mall. Like the physical mall, it will comprise multiple businesses operating effectively in one place. In the physical world, shoppers walk from one shop into another. In a web2 shopping mall, they would need a different URL and to log on and present identity credentials to each store.
In a decentralized metaverse, with identity held in a trusted blockchain, identity verification could simply be the presentation of an NFT-like token. This would confirm the user’s identity without requiring personal details to be given to every business in the metaverse – allowing the user to travel freely between the organizations of the mall metaverse.
Within each ‘shop’, three-dimensional images of goods can be investigated. Shopping baskets could be maintained by the collection of NFTs associated with the goods, and could be instantly purchased via a cryptocurrency or NFT from the user’s wallet.
The security issues are primarily fraud via user impersonation, although the user identity is protected by blockchain. One thing that is certain, however, is that as this new cyber world evolves, criminals will be looking for new ways to attack it.
Will web3 (with metaverse) come to pass?Web3 will happen. What it will look like is not yet known. Blockchain technology is expanding beyond just cryptocurrency, and the use of non-investment NFTs is growing.
The attraction of a metaverse is undeniable – but we’re going through a phase of disillusionment right now. This is perhaps typified in the disappointment of Meta’s legless cartoon avatar torsos in its Horizon Worlds metaverse.
But we should remember that all of this is new technology with kinks. The AR and VR headsets are still developing; the software development is still new. The potential for the metaverse is too great to ignore. Its synergy with decentralization makes it especially attractive.
It won’t materialize for many years – but development of web3 will continue through 2023 and beyond. The immersive metaverse rather than blockchain will be the defining technology.
Related: Securing the Metaverse and Web3
Related: Hackers Steal Over $600M in Major Crypto Heist
Related: Protecting Cryptocurrencies and NFTs – What’s Old is New
Related: How Blockchain Will Solve Some of IoT’s Biggest Security Problems
The post Cyber Insights 2023 | The Coming of Web3 appeared first on SecurityWeek.
About SecurityWeek Cyber Insights | At the end of 2022, SecurityWeek liaised with more than 300 cybersecurity experts from over 100 different organizations to gain insight into the security issues of today – and how these issues might evolve during 2023 and beyond. The result is more than a dozen features on subjects ranging from AI, quantum encryption, and attack surface management to venture capital, regulations, and criminal gangs.
SecurityWeek Cyber Insights 2023 | Zero Trust and Identity and Access Management (IAM) – Zero trust is not a replacement for identity and access management (IAM), it is an extension in extremis. It is the extension of IAM principles from people to everyone and everything, everywhere and anytime. The difficulties in IAM are retained but are complicated by the complexity of installing it everywhere.
Nevertheless, zero trust is widely seen as an important part of effective cybersecurity. In 2023 we will see more vendors touting a complete zero trust product and/or methodology, and more businesses attempting its implementation.
Here we examine how this might progress through 2023.
BackgroundZero trust is a natural evolution from the realization that company networks no longer have a perimeter that can be defended. With no perimeter to defend, every asset needs to be individually protected, and every access needs to be individually verified. Location means nothing – access to anything from anywhere must always be verified before it is granted.
It is a short step from this to realize such verification should apply within the network as well as from outside: east-west (where it is also called ‘microsegmentation’) as well as north-south. Achieve this, and you have fulfilled the journey to zero trust.
Zero trust is the replacement of a defensible data center perimeter with individual defensible asset perimeters – from one to potentially millions.
The DoD Zero Trust Reference Architecture, referred to in an OMB memorandum in January 2022, describes the concept: “Zero trust is the term for an evolving set of cybersecurity paradigms that move defenses from static, network-based perimeters to focus on users, assets, and resources. Zero trust assumes there is no implicit trust granted to assets or user accounts based solely on their physical or network location (i.e., local area networks versus the Internet) or based on asset ownership (enterprise or personally owned). Zero trust requires designing a consolidated and more secure architecture without impeding operations or compromising security. The classic perimeter/defense-in-depth cybersecurity strategy repeatedly shows to have limited value against well-resourced adversaries and is an ineffective approach to address insider threats.”
The OMB memorandum goes on to state, “This memorandum requires agencies to achieve specific zero trust security goals by the end of Fiscal Year (FY) 2024.” Two things are immediately apparent: firstly, there will be extensive activity within federal agencies through 2023 to fulfill this requirement (and associated vendor activity to help them achieve this); and secondly, it is no simple task. The trickle-down effect of federal mandates will ensure that adequately resourced private industry will follow.
“Zero trust represents a fundamental shift in the way in which organizations view and approach risk (and in turn security),” explains Chris Denbigh-White, cybersecurity strategist at Next DLP. “Moving through 2023 many organizations are going to realize that zero trust is not so much a destination as a means of conducting the journey of information security. Yes, technology will play a vital role in this journey but should never be confused with the end of the conversation, or indeed the end of the journey.”
It is worth noting that some vendors call their preferred route to zero trust ‘zero trust network access’ (ZTNA). You can get further details on ZTNA here – but within this article we will treat the two terms (zero trust and ZTNA) indiscriminately.
Problems and issues for 2023“The most common mistake organizations make deploying zero trust or microsegmentation is underestimating the complexity of their network,” says John Yun, VP of product strategy at ColorTokens. “An effective zero trust implementation requires the knowledge of all servers, applications that run on the servers, and users authorized to use those applications.”
Matthew Carroll, CEO and co-founder of Immuta, warns that zero trust should not be considered a complete solution on its own. The problem that it seeks to solve is partly due to the massive increase in data sharing that has arisen through the growth of cloud-based SaaS infrastructures. This will result in an increase in data processing agreements (DPA) between companies and SaaS providers. “In 2023, we’ll see DPAs become a standard element of SaaS contracts and data sharing negotiations.”
He still fears that zero trust alone will not provide adequate security. “In 2023 we’ll see a major shift in data security architecture. This will include proper access controls that effectively balance access and security.” But he adds, “Zero trust won’t work using traditional approaches because there are too many endpoints.” Implementing a zero trust approach for access must still be integrated with adequate anomaly detection – zero trust for access should not be at the expense of internal visibility.
The effect of Covid-19 has increased the importance of a zero trust architecture. “The Covid-19 pandemic ushered in a new era of remote and hybrid working,” says Craig Lurey, CTO and co-founder at Keeper Security. “The explosion in the sheer number of endpoints, with an increasing amount of them accessed remotely, requires a higher level of security to tackle growing online threats. Under this new normal, zero trust is now the only realistic and comprehensive framework for securing modern, cloud-based data environments and distributed workforces.”
Joseph Carson, chief security scientist at Delinea, adds, “A zero trust approach will become more essential than ever as the transformation continues. Employees should have access only to what they need to efficiently do their job. This will ensure that an attacker’s ability to move within the larger business network is limited and the attack surface reduced.” But he also notes that this could raise privacy issues if employers impose conditions on personally owned computers.
“It appears remote work is here to stay and will increase into 2023,” says John McClurg, SVP and CISO at BlackBerry. “Enterprises should look to adopt a zero trust architecture and security model to truly secure their remote workforces. This model is defined by trusting no one and absolutely nothing by default – including users inside an actual network. By assuming every user, device or network is hostile, zero trust security forces everyone to prove who they are before access is authorized.”
The urgency of the pandemic and the consequent rush to implement remote working is in many cases causing problems for the integration of an overarching zero trust solution. “The majority of organizations today still struggle with allowing explicit access to applications and enforcing zero trust policies across their business. In fact, over 80% of organizations have found it difficult to implement a zero trust model, and that has a lot to do with the fact that many organizations have hybrid IT architectures,” explains Peter Newton, senior director of products at Fortinet.
The problem is that it is too cumbersome to have one set of policies for on premises and an entirely different set of policies for the cloud. Consequently, he says, “In 2023 we will see more IT teams shift to incorporate ZTNA across the entire network – from cloud to on-premises – for universal coverage under a single solution. And as ZTNA begins to go mainstream in the enterprise, we’ll start to see organizations transition away from a pay-per-user model and start to bake ZTNA directly into their security architecture for a more seamless and consistent user and management experience.”
At its root, zero trust is a major extension of identity and access management (IAM) – but IAM itself is a problem that has never yet been completely solved. “Organizations are still learning the concept of identity sprawl and the scale of their technical debt, which means that companies are just starting to realize the scale of the challenge,” comments Wade Ellery, field CTO at Radiant Logic.
“In 2023, we are going to see more and more businesses slow down to speed up –they’ll recognize they need to put in an identity data foundation before they can justify building new, revenue-oriented projects that demand access to identity.”
For zero trust, he added, “As we move into 2023, senior decision-makers and security teams are discussing how they can achieve a granular-approach in real-time, and ultimately, they will come back to the issue of identity data management.”
More and more companies are recognizing the theoretical security benefits of zero trust and are starting their own journeys. In 2023, the difficulties in doing so will become more apparent – but it’s not all doom and gloom. “To a certain extent, factors such as internal politics, talent shortages, and economic conditions play a role in any IT project,” comments Hendra Hendrawan, security technical councilor at the Info-Tech Research Group. “Still, organizations with a good IT or cybersecurity strategy should embark on the zero trust journey with fewer frictions.”
At a high level, he says a successful IT implementation generally consists of well-documented processes, good selections of technology, and great talents. “Couple these with a solid security strategy, and achieving a zero trust architecture should not be a question of how but of when.”
That ‘when’ will be many years in the making. “Zero trust is a security model, not a product. Adopting zero trust across an enterprise requires careful planning and the use of complementary, multi-vendor solutions,” warns Torsten Staab, principal engineering fellow at Raytheon Intelligence and Space. “For many organizations, adopting zero trust security will be a multi-year journey. Establishing a solid zero trust strategy up front and developing a phased, step-by-step implementation plan to avoid boiling the ocean and losing focus will be key to a successful zero trust implementation.” But for 2023, he added, “Look for additional zero trust implementation guidance and recommendations from NIST and CISA.”
Zero Trust Strategies Summit | Virtual Event – April 12, 2023IAM issuesFoundational to implementing zero trust will be solving the existing IAM problems – and that will not be easy. The traditional approach has been to implement basic MFA involving a second-factor token delivered via a mobile phone – but such MFA is frequently broken by hackers.
“My prediction for 2023,” says Ben Brigida, director of SOC operations at Expel, “is that we will witness an increase in MFA push notification fatigue attacks. Why? Because they’re working. More and more, organizations are turning to cloud access identity providers for single sign-on capabilities. Attackers know that if they can get their hands on credentials for these platforms, they’ll get access to critical business applications—not just email. So, they’re sending multiple push notification requests to users and hoping the user will just approve one to make the notifications stop.”
Chris Vaughan, VP technical account management, EMEA and South Asia at Tanium, calls this an MFA push exhaustion attack. “This is where an attacker sends a large number of MFA acceptance prompts to users’ phone which may cause them to click accept to stop the barrage of requests. This has been largely successful in gaining access to user data and accessing IT environments.”
“Once considered a ‘silver bullet’ in the fight against credential stuffing,” adds Marcus Fowler, CEO of federal government for Darktrace, “it hasn’t taken attackers long to find and exploit weaknesses in MFA and they will continue to do so in 2023.”
John Stevenson, senior product director at Cyren, expands on the problem: “Phishing will remain an unsolved problem leading to countless account takeover attacks. As businesses enable MFA, phishers will update their tactics to defeat additional verification steps like one-time codes sent to phones or email addresses. So-called strong authentication methods that rely on mobile phones and email accounts (that were never intended to be identities) will be the first to prove insecure for high-risk use cases. Passwordless authentication won’t yet solve these issues due to insufficient lifecycle management solutions and incompatibility with legacy systems.”
John Pescatore, director of emerging security trends at SANS, sees an additional phone-based threat to identity management. “While mobile phones are more secure than desktops,” he comments, “we will also see a greater volume of stalkerware included in downloaded apps that target consumers.”
Pegasus spyware is a prime example of this threat – it can install itself on iOS and Android devices with zero clicks. Hackers are also creating malicious stalkerware apps and hiding them in app stores.
“As people become more accustomed to downloading family tracking software and giving away app permissions, the risk of having their keystrokes, locations, voice, and even photos and videos recorded for financial theft and other nefarious purposes will also increase.”
If second-factor one-time codes and passwordless authentication are not the solution to the IAM issue. an alternative must be found. Many have been suggested, from physical biometrics (including touchless fingerprinting) to behavioral biometrics and more.
“Touchless fingerprinting will emerge as the top authentication method,” claims Chase Hatcher, VP of technology and innovation at Telos. “In 2023, organizations with a pre-existing fingerprint database infrastructure will increasingly turn to touchless fingerprinting to perform remote biometric identity verification”, he says. “With regards to authentication, we’ll see identity platforms backed by multi-modal true biometrics face and fingerprint and ‘convenience biometrics’ embedded mobile solutions like faceID and touchID emerge.”
“In 2023, more people will protect their critical accounts with methods other than logins and passwords,” adds Ricardo Amper, founder and CEO at Incode. “When creating accounts, they will provide multiple factors such as biometrics, government-issued identity documents, and information from reliable sources to prove their identities. When authenticating access to these accounts, they will use biometrics, providing more security for their private data.”
Donnie Scott, CEO at Idemia, has a more specific US identity prediction for 2023. “In 2023, every jurisdiction that issues an identity will have deployed, be in the process of deploying, or considering the deployment of a digital form of mobile identity/mobile-driver’s license. Arizona was the first US state to adopt mobile IDs followed by Oklahoma, Delaware, and Mississippi. Up to 30 states, including Colorado, Hawaii, Ohio, and the territory of Puerto Rico, are in the process of making mobile IDs available to their residents. We will only see this increase.”
He is very upbeat about the potential. “The benefits of this model, where biometrics meets identity, are a citizen-controlled assertion of identity, backed by the Government’s high standard of proof against who that person is. This combination results in a high assurance, privacy protected model.”
But the problem for this, and virtually every other means of remote identification, is that ultimately it identifies a mobile phone and not necessarily the owner or current user of that phone. A compromised phone can still lead to a compromised identity. Absolute proof of personal identity for perfect zero trust is very difficult.
And we haven’t even mentioned machine identities, which are equally important in a zero trust architecture, and present their own problems.
Summary“Modern security solutions that remove the implicit trust from users, devices, services, and workloads, regardless of the location will become the norm,” says Stefan Schachinger, product manager network security at Barracuda. “The ‘context’ of who, what, when, where, and how will become key security components in a world of continuous zero trust evaluation that will defend against ever more stealthy threats. In 2023, just detecting and blocking malicious events will no longer be sufficient. You need to investigate and remediate everything.”
Achieving a solid zero trust architecture won’t happen overnight. It’s not a product you can buy and run. It will require the integration of different security solutions – some of which may already be present while others will need to be purchased, implemented, and integrated, seamlessly. Many companies will start the journey in 2023, and many others will make progress – but getting close to the destination will probably take years.
Nevertheless, “Zero trust represents a new cybersecurity paradigm that offers numerous benefits to organizations of all sizes and industries. Deploying a zero trust approach to access management can be especially effective, creating a virtual ‘locking of shields’ between governments and the private sector,” says McClurg. “This allows for closer cooperation to better protect critically important infrastructure and services.”
“I like to keep this stuff abstract,” Steve Riley, field CTO at Netskope, told SecurityWeek. “I want to eliminate implicit trust from every layer: from the network, from applications, from virtual machines and from the data objects. Instead, I want the situation where every interaction is mediated by something, and the level of confidence in that interaction is measured by the context and the signal surrounding.”
Related: The History and Evolution of Zero Trust
Related: White House Publishes Federal Zero Trust Strategy
Related: Demystifying Zero Trust
Related: Universal ZTNA is Fundamental to Your Zero Trust Strategy
The post Cyber Insights 2023 | Zero Trust and Identity and Access Management appeared first on SecurityWeek.
European police arrested 42 suspects and seized guns, drugs and millions in cash, after cracking another encrypted online messaging service used by criminals, Dutch law enforcement said Friday.
Police launched raids on 79 premises in Belgium, Germany and the Netherlands following an investigation that started back in September 2020 and led to the shutting down of the covert Exclu Messenger service.
Exclu is just the latest encrypted online chat service to be unlocked by law enforcement. In 2021 investigators broke into Sky ECC — another “secure” app used by criminal gangs.
After police and prosecutors got into the Exclu secret communications system, they were able to read the messages passed between criminals for five months before the raids, said Dutch police.
“Those arrested include users of the app, as well as its owners and controllers,” their statement added.
Police in France, Italy and Sweden, as well as Europol and Eurojust, its justice agency twin, also took part in the investigation.
The police raids uncovered at least two drugs labs, one cocaine-processing facility, several kilogrammes of drugs, four million euros ($4.3 million) in cash, luxury goods and guns, Dutch police said.
Used by around 3,000 people, including around 750 Dutch speakers, Exclu was installed on smartphones with a licence to operate costing 800 euros for six months.
“Exclu made it possible to exchange messages, photos, notes, voice memos, chat conversations and videos with other users,” Dutch police said.
The online service “was praised by the owners and manager for its high level of security”, police added.
The earlier Sky ECC probe gave investigators a vast trove of messages sent between secretive drug smuggling gangs.
Breaking that encrypted system allowed police to intercept drug shipments and make a large number of arrests.
Related:Hundreds Arrested in ‘Staggering’ FBI Encrypted Phone Sting
Related: 150 People Arrested in US-Europe Darknet Drug Probe
The post European Police Arrest 42 After Cracking Covert App appeared first on SecurityWeek.
Tallahassee Memorial HealthCare (TMH) has canceled procedures and is diverting some patients following a cyberattack that forced it to take some IT systems offline.
Founded in 1948, the not-for-profit community healthcare system provides acute and other types of healthcare services to a 21-county area in North Florida, South Georgia and South Alabama.
On February 3, TMH announced that, late Thursday night, it fell victim to a cyberattack that forced it to disconnect some of its IT systems and start operating under downtime protocols.
On February 5, the healthcare services provider announced that the situation had not been remedied, with all non-emergency surgical and outpatient procedures initially scheduled for February 6 being canceled and rescheduled.
TMH announced that it implemented incident response protocols immediately after discovering the incident, and that backup and downtime protocols it has in place allow it to continue to provide care to its patients.
“We are still operating under downtime procedures, which means we are using paper documentation. We apologize for any delays this may create. We practice for situations like this, and we are prepared to provide safe, high-quality care to our patients during computer system downtimes,” the healthcare provider said on Sunday.
TMH also said that an investigation into the incident was ongoing, without providing details on the type of cyberattack it experienced or on whether any personal or health information was compromised during the attack.
However, the fact that the organization was forced to disconnect some of its IT systems to contain the incident suggests that ransomware might have been involved.
SecurityWeek has emailed TMH for additional information on the incident and will update this article as soon as a reply arrives.
Related: Ransomware Hit 200 US Gov, Education and Healthcare Organizations in 2022
Related: Data Breach at Louisiana Healthcare Provider Impacts 270,000 Patients
Related: Healthcare Organizations Warned of Royal Ransomware Attacks
The post Florida Hospital Cancels Procedures, Diverts Patients Following Cyberattack appeared first on SecurityWeek.
Unpatched and unprotected VMware ESXi servers around the world have been targeted over the past few days in a large-scale ransomware attack exploiting a vulnerability patched in 2021.
The attacks, dubbed ESXiArgs, are still being analyzed by the cybersecurity community, but based on the information available to date, it appears that threat actors are exploiting CVE-2021-21974, a high-severity ESXi OpenSLP heap-overflow vulnerability that VMware patched in February 2021.
“A malicious actor residing within the same network segment as ESXi who has access to port 427 may be able to trigger the heap-overflow issue in OpenSLP service resulting in remote code execution,” VMware said in its advisory at the time.
Proof-of-concept (PoC) code and technical details on CVE-2021-21974 were made public a couple of months after the patches were announced, but there do not appear to be any previous reports of the vulnerability being exploited in the wild.
In the ransomware attacks that surged over the weekend, threat actors exploited the flaw to hack ESXi servers and deploy a piece of malware that encrypts files associated with virtual machines, including files with the .vmdk, .vmx, .vmxf, .vmsd, .vmsn, .vswp, .vmss, .nvram, .vmem extensions, according to an analysis by French cloud company OVH.
The attacks seem to target vulnerable ESXi servers that are exposed to the internet on port 427.
OVH noted that the malware shuts down VM processes before initiating its encryption routine, but the function does not seem to work properly. In some cases, files are only partially encrypted, allowing victims to recover them without paying a ransom. There is no evidence of data being stolen in the attacks.
Researcher Enes Sonmez has found a way to recover some of the files encrypted by the ransomware.
The attacks were initially incorrectly attributed to ransomware named Nevada and Cheerscrypt (Emperor Dragonfly), but they were later linked to a new ransomware operation named ESXiArgs.
More than two thousand ESXi instances appear to be impacted according to Censys. Shodan shows roughly 800 compromised servers.
At the time of writing, many antivirus engines cannot detect the ESXiArgs malware.
Government agencies in the United States and Europe are looking into these attacks and assessing their impact.
While the malware does not appear to have file exfiltration capabilities, the ransom note dropped in the ESXiArgs attack informs victims that their data will be sold unless a payment is made. Victims are instructed to pay 2 bitcoins ($48,000) to receive the encryption key needed to recover files.
Ransomware expert Soufiane Tahiri has been keeping track of the Bitcoin wallet addresses used by the cybercriminals.
While it has become increasingly common for threat actors to target ESXi servers, the exploitation of ESXi vulnerabilities is rare.
Related: VMware Patches VM Escape Flaw Exploited at Geekpwn Event
Related: VMware Confirms Exploit Code Released for Critical vRealize Logging Vulnerabilities
The post VMware ESXi Servers Targeted in Ransomware Attack via Old Vulnerability appeared first on SecurityWeek.
Pig Butchering, also known as Sha Zhu Pan and CryptoRom, is an ugly name for an ugly scam. It is not new. What is new is that apps perpetrating the scam can be downloaded from the official Apple and Android app stores – giving them greater apparent validity to targets.
The scam is a version of romance scam, where targets are befriended, lured in, persuaded to download a disguised malicious app, drawn into false cryptocurrency dealing, and defrauded. It’s a long game social engineering scam built on trust rather than fear, greed, or urgency.
It originated in China. When the Chinese authorities clamped down, the gangs decamped to places like Cambodia. Now, according to an analysis from Sophos, the gangs are well organized but as ugly as the scam. At the top of the hierarchy is the ‘head office’ which does supervision and money laundering.
The scam itself is subcontracted to affiliates, which have a front desk handling staffing, a tech team handling the technology involved, and a finance team looking after the money. Profits tend to be divided 60-40 – with 40% going to the head office.
At the bottom of the pile are the keyboarders who liaise with, and trick the targets. These are often victims themselves, sometimes foreigners lured into the process by the promise of earning money, and kept in the process by the threat of violence.
The new danger exposed by Sophos is not the scam (that’s not new) but the criminals’ success in getting malicious apps into the official app stores (Ace Pro and MBM_BitScan into the App Store, and BitScan into Google Play). This is not uncommon with Google Play, but unusual with Apple. In two separate examples that by-passed Apple’s App Store review, a legitimate-looking app initially communicates with a benign back end. Nothing malicious can be seen, so the apps passed Apple’s review.
Only after the app is accepted, downloaded, and launched does the developer switch domains, from the benign back end to a malicious server that delivers the malicious content.
How fraudulent applications likely evaded the Apple review process. (Image Credit: Sophos)“When we originally began investigating CryptoRom scams targeting iOS users, the scammers would have to persuade users to first install a configuration profile before they could install the fake trading app,” comments Jagadeesh Chandraiah, senior threat researcher at Sophos. “This obviously involves an additional level of social engineering—a level that’s hard to surmount.”
Many potential victims would be ‘alerted’ that something wasn’t right if they cannot directly download a supposedly legitimate app. But by getting an application into the App Store, the scammers have vastly increased their potential victim pool, particularly since most users inherently trust Apple.
“Both apps are also unaffected by iOS’ new Lockdown mode, which prevents scammers from loading mobile profiles helpful for social engineering,” continued Chandraiah. “In fact, these CryptoRom scammers may be shifting their tactics – that is, focusing on bypassing the App Store review process – in light of the security features in Lockdown.”
The scam still requires extensive social engineering. The victim is typically approached via a dating app, and then invited to switch the conversation to WhatsApp. In one case, the victim was based in Switzerland. The scammer or scammers used a manufactured profile of a woman based in London, with a full and compelling Facebook profile complete with professional or stolen location and lifestyle photos.
“After establishing a rapport, the criminals behind the profile told the victim that ‘her’ uncle worked for a financial analysis firm, and invited the victim to do cryptocurrency trading together.” It was at this point that the victim was introduced to the fake application in the app store.
In such cases, a degree of patience is still demonstrated by the attackers. Crypto investment begins slowly, and the victim can even make withdrawals from the crypto account. But the investment goes straight to the criminals. By the time the victim realizes that something is wrong, both the money and the scammers are gone.
This scam, says the Sophos report, “is a well-organized, syndicated scam operation that uses a combination of romance-centered social engineering and fraudulent crypto trading applications and websites to lure victims and steal their money after gaining their confidence.” The worrying possibility for the future is that emerging artificial intelligence such as ChatGPT will make such detailed and professional social engineering even more compelling – and widely available to criminals less sophisticated.
Related: 2,000 People Arrested Worldwide for Social Engineering Schemes
Related: Ongoing Bitcoin Scams Demonstrate Power of Social Engineering Triggers
Related: Meet Domen, a New and Sophisticated Social Engineering Toolkit
Related: Social Engineering: Attackers’ Reliable Weapon
The post Fraudulent “CryptoRom” Apps Slip Through Apple and Google App Store Review Process appeared first on SecurityWeek.
President Joe Biden said on Saturday that he ordered U.S. officials to shoot down the suspected Chinese spy balloon earlier this week and that national security leaders decided the best time for the operation was when the it got over water.
“They successfully took it down and I want to complement our aviators who did it,” Biden said after getting off Air Force One en route to Camp David.
Fighter jets shot down the giant white balloon off the Carolina coast after it traversed sensitive military sites across North America and became the latest flashpoint in tensions between Washington and Beijing.
Defense Secretary Lloyd Austin said in a statement that Biden approved the shootdown on Wednesday, saying it should be done “as soon as the mission could be accomplished without undue risk to American lives under the balloon’s path.”
Austin said that due to the size and altitude of the balloon , which was moving at about 60,000 feet in the air, the military had determined that taking it down over land would pose an undue risk to people on the ground.
The balloon was spotted Saturday morning over the Carolinas as it approached the coast. In preparation for the operation, the FAA Administration temporarily closed airspace over the Carolina coastline, including the airports in Charleston and Myrtle Beach, South Carolina, and Wilmington, North Carolina. The FAA rerouted air traffic from the area and warned of delays as a result of the flight restrictions.
An operation was underway in U.S. territorial waters in the Atlantic Ocean to recover debris from the balloon, which had been flying at about 60,000 feet and was estimated to be about the size of three school buses. The balloon was downed by Air Force fighter aircraft, according to two officials who were not authorized to publicly discuss the matter and spoke on condition of anonymity.
President Joe Biden had told reporters earlier Saturday that “we’re going to take care of it,” when asked about the balloon. The Federal Aviation Administration and Coast Guard worked to clear the airspace and water below the balloon as it reached the ocean.
Television footage showed a small explosion, followed by the balloon descending toward the water. U.S. military jets were seen flying in the vicinity and ships were deployed in the water to mount the recovery operation.
Officials were aiming to time the operation so they could recover as much of the debris as possible before it sinks into the ocean. The Pentagon had previously estimated that any debris field would be substantial.
The balloon was spotted Saturday morning over the Carolinas as it approached the coast. In preparation for the operation, the FAA Administration temporarily closed airspace over the Carolina coastline, including the airports in Charleston and Myrtle Beach, South Carolina, and Wilmington, North Carolina. The FAA rerouted air traffic from the area and warned of delays as a result of the flight restrictions.
The Coast Guard advised mariners to immediately leave the area because of U.S. military operations “that present a significant hazard.”
Biden had been inclined to down the balloon over land when he was first briefed on it on Tuesday, but Pentagon officials advised against it, warning that the potential risk to people on the ground outweighed the assessment of potential Chinese intelligence gains.
The public disclosure of the balloon this week prompted the cancellation of a visit by U.S. Secretary of State Antony Blinken to Beijing scheduled for Sunday for talks aimed at reducing U.S.-China tensions. The Chinese government on Saturday sought to play down the cancellation.
“In actuality, the U.S. and China have never announced any visit, the U.S. making any such announcement is their own business, and we respect that,” China’s Ministry of Foreign Affairs said in a statement Saturday morning.
China has continued to claim that the balloon was merely a weather research “airship” that had been blown off course. The Pentagon rejected that out of hand — as well as China’s contention that it was not being used for surveillance and had only limited navigational ability.
The balloon was spotted over Montana, which is home to one of America’s three nuclear missile silo fields at Malmstrom Air Force Base.
The Pentagon also acknowledged reports of a second balloon flying over Latin America. “We now assess it is another Chinese surveillance balloon,” Brig. Gen. Pat Ryder, Pentagon press secretary, said in a statement.
China’s Ministry of Foreign Affairs did not immediately respond to a question about the second balloon.
Blinken, who had been due to depart Washington for Beijing late Friday, said he had told senior Chinese diplomat Wang Yi in a phone call that sending the balloon over the U.S. was “an irresponsible act and that (China’s) decision to take this action on the eve of my visit is detrimental to the substantive discussions that we were prepared to have.”
Uncensored reactions on the Chinese internet mirrored the official government stance that the U.S. was hyping the situation. Some used it as a chance to poke fun at U.S. defenses, saying it couldn’t even defend against a balloon, and nationalist influencers leapt to use the news to mock the U.S.
China has denied any claims of spying and said it is a civilian-use balloon intended for meteorology research. The Ministry of Foreign Affairs emphasized that the balloon’s journey was out of its control and urged the U.S. not to “smear” it based on the balloon.
The post US Downs Chinese Balloon Off Carolina Coast appeared first on SecurityWeek.
After the French satirical magazine Charlie Hebdo launched a cartoon contest to mock Iran’s ruling cleric, a state-backed Iranian cyber unit struck back with a hack-and-leak campaign that was designed to provoke fear with the claimed pilfering of a big subscriber database, Microsoft security researchers say.
The FBI blames the same Iranian cyber operators, Emennet Pasargad, for an influence operation that sought to interfere in the 2020 U.S. presidential election, the tech giant said in a blog published Friday. Iran has in recent years stepped up false-flag cyber operations as a tool for discrediting foes.
Calling itself “Holy Souls” and posing as hacktivists, the group claimed in early January to have obtained personal information on 200,000 subscribers and Charlie Hebdo merchandise buyers, according to Microsoft’s Digital Threat Analysis Center.
As proof of the data theft, “Holy Souls” released a 200-record sample with names, phone numbers and home and email addresses of Charlie Hebdo subscribers that “could put the magazine’s subscribers at risk for online or physical targeting” by extremists. The group then advertised the supposed complete data cache on several dark web sites for $340,000.
Microsoft said it did not know whether anyone purchased the cache.
A representative for Charlie Hebdo said Friday that the newspaper would not comment on the Microsoft research. Iran’s mission to the United Nations did not immediately respond to a request for comment Friday.
The Jan. 4 sample release coincided with the publication of Charlie Hebdo’s cartoon contest issue. Entrants were asked to draw offensive caricatures of Iran’s supreme leader, Ayatollah Ali Khamenei.
The French newspaper Le Monde verified multiple victims of the leak from the sample, Microsoft said. The Iranian cyber operators sought to boost news of the hack-and-leak operation — and fuel outrage at the cartoon edition — through fake French “sock-puppet” accounts on social media platforms that included Twitter, Microsoft said.
The operation coincided with verbal attacks by Tehran condemning Charlie Hebdo’s “insult.”
The provocatively irreverent magazine has a long history of publishing vulgar cartoons which critics consider deeply insulting to Muslims. Two French-born al-Qaida extremists attacked the newspaper’s office in 2015, killing 12 cartoonists, and it Charlie Hebdo has been the target of other attacks over the years.
The magazine billed the Khamenei caricature contest as a show of support for nationwide antigovernment protests that have convulsed Iran since the mid-September death of Mahsa Amini, a 22-year-old woman detained by Iran’s morality police for allegedly violating the country’s strict Islamic dress code.
After the cartoon issue was published, Iran shut down a decades-old French research institute. Last week, it announced sanctions targeting more than 30 European individuals and entities, including three senior Charlie Hebdo staffers. The sanctions are largely symbolic as they bar travel to Iran and allow its authorities to block bank accounts and confiscate property in Iran.
The post Microsoft: Iran Unit Behind Charlie Hebdo Hack-and-Leak Op appeared first on SecurityWeek.
A cyberattack caused a nearly daylong outage of the nation’s new 988 mental health helpline late last year, federal officials told The Associated Press Friday. Lawmakers are now calling for the federal agency that oversees the program to prevent future attacks.
“On December 1, the voice calling functionality of the 988 Lifeline was rendered unavailable as a result of a cybersecurity incident,” Danielle Bennett, a spokeswoman for the Substance Abuse and Mental Health Services Administration, said in an email.
The attack occurred on the network for Intrado, the company that provides telecommunications services for the helpline. The agency did not disclose details about who it believes launched the attack or what kind of cyberattack occurred. Intrado is working with a third-party assessor to investigate the incident and law enforcement agencies have been notified of the breach, SAMHSA said.
The national 988 phone number, which can be reached by text, chat or voice calling, has become a lifeline for millions of Americans seeking help during a mental crisis, with millions of calls pouring in during the first six months since its launch in July. The system is designed to work similarly to 911 — it’s a universal, easy-to-remember number that people can call in an emergency to reach a human who is working around the clock in a local call center.
Those who tried on Dec. 1 to reach the line for help with suicidal or depressive thoughts were instead greeted with a message that said the line is “experiencing a service outage.” Text and chat services, however, remained available to those who needed help.
The Federal Communications Commission said in December it was investigating the outage. Intrado said at the time that the company was “experiencing an incident that is impacting production across numerous systems” and is “working diligently to restore service.” Intrado could not immediately be reached for comment Friday.
Last week, Democrat Rep. Tony Cárdenas and Republican Rep. Jay Obernolte, both of California, introduced a bill calling for better coordination and reporting around cyberattacks on the 988 system.
“Even a few hours’ outage of the national suicide hotline can cost American lives,” Obernolte said in a press release introducing the bill. “It’s critical that we mitigate the risks of future disruptions to the service and take steps to resolve cybersecurity vulnerabilities that could put the hotline at risk.”
The post Feds Say Cyberattack Caused Suicide Helpline’s Outage appeared first on SecurityWeek.
The Pentagon said at midday Friday that a Chinese spy balloon had moved eastward and was over the central United States, and that the U.S. rejected China’s claims that it was not being used for surveillance.
Brig. Gen. Pat Ryder, Pentagon press secretary, refused to provide details on exactly where the balloon was or whether there was any new consideration of shooting it down. The military had ruled that option out, officials had said, due to potential risks to people on the ground.
Ryder said it was at an altitude of about 60,000 feet, was maneuverable and had changed course. He said it currently was posing no threat. He said there was only one balloon being tracked.
Earlier, the U.S. announced that Secretary of State Antony Blinken had postponed a planned high-stakes weekend diplomatic trip to China as the Biden administration weighed a broader response to the discovery of a high-altitude Chinese balloon flying over sensitive sites in the western United States.
That abrupt decision came despite China’s claim that the balloon was a weather research “airship” that had blown off course. The U.S. has described it as a surveillance vehicle.
The development came just before Blinken had been due to depart Washington for Beijing and marked a new blow to already strained U.S.-Chinese relations.
President Joe Biden declined to comment when questioned at an economic event. Two 2024 reelection challengers, former President Donald Trump, and Nikki Haley, the former South Carolina governor and U.N. ambassador, said the U.S. should immediately shoot down the balloon.
Discovery of the balloon was announced by Pentagon officials who said one of the places it was spotted was over the state of Montana, which is home to one of America’s three nuclear missile silo fields at Malmstrom Air Force Base.
A senior defense official said the U.S. prepared fighter jets, including F-22s, to shoot down the balloon if ordered. The Pentagon ultimately recommended against it, noting that even as the balloon was over a sparsely populated area of Montana, its size would create a debris field large enough that it could have put people at risk.
The official said the balloon was headed over the Montana missile fields, but the U.S. has assessed that it had only “limited” value in terms of providing intelligence China couldn’t obtain by other technologies, such as spy satellites.
The discovery alarmed many in Washington across the country and, besides the U.S. protests lodged with Chinese officials, it attracted strong criticism of the administration from Republican members of Congress who have advocated taking a tougher stance with China.
China, which angrily denounces surveillance attempts by the U.S. and others over areas it considers to be its territory and once forced down an American spy plane, offered a generally muted reaction to the Pentagon announcement.
In a relatively conciliatory statement, the Chinese foreign ministry said late Friday that the balloon was a civilian airship used mainly for meteorological research. The ministry said the airship has limited “self-steering” capabilities and “deviated far from its planned course” because of winds.
“The Chinese side regrets the unintended entry of the airship into U.S. airspace due to force majeure,” the statement said, citing a legal term used to refer to events beyond one’s control.
Blinken had been prepared as late as Thursday to travel to Beijing this weekend but the administration had begun to reconsider the trip following the discovery of the balloon on Wednesday, even before its presence was made public, an official said.
The official, who spoke to reporters on condition of anonymity due to the sensitivity of the matter, said the administration had “ noted” China’s expression of regret.
Blinken’s long-anticipated meetings with senior Chinese officials had been seen in both countries as a way to find some areas of common ground at a time of major disagreements over Taiwan, human rights, China’s claims in the South China Sea, North Korea, Russia’s war in Ukraine, trade policy and climate change.
Although the trip, which was agreed to in November by President Biden and Chinese President Xi Jinping at a summit in Indonesia, had not been formally announced, officials in both Beijing and Washington had been talking in recent days about Blinken’s imminent arrival.
The meetings were to begin on Sunday and go through Monday.
The post Big China Spy Balloon Moving East Over US, Pentagon Says appeared first on SecurityWeek.
Former Ubiquiti employee Nickolas Sharp has admitted in court to abusing company-provided credentials to steal data and then attempting to extort the company, the Department of Justice announced.
Sharp, 37, of Portland, Oregon, worked at the New York City-based IoT device maker between August 2018 and April 2021, as a senior developer who had access credentials for Ubiquiti’s AWS and GitHub servers.
In December 2020, he abused his administrative credentials to download confidential data using the Surfshark VPN to hide his IP address. However, during an outage at his home, the IP address became unmasked, court documents reveal.
To hide his unauthorized activity, Sharp modified log retention policies and other files.
In January 2021, Ubiquiti alerted users of a data breach at one of its third-party cloud providers, saying that it had no indication of user data being accessed during the incident.
Around the same time, Sharp, who was helping with the investigation into the data breach, sent a ransom note to Ubiquiti, claiming he was an anonymous attacker who had access to the company’s network.
In the ransom note, he was asking the company to pay 50 bitcoin (roughly $1.9 million at the time) in exchange for the stolen data and for revealing the backdoor he purportedly had installed on Ubiquiti’s network. After the company refused to pay, he published some of the stolen data online.
In March 2021, the FBI searched Sharp’s home and seized electronic devices containing evidence of his actions. When confronted with the evidence, Sharp lied about accessing the company’s data without authorization and about purchasing a VPN to hide his activity.
Several days after the search, claiming to be an anonymous whistleblower within Ubiquiti, Sharp provided investigative journalist Brian Krebs with false information about the incident, claiming that a hacker had gained root administrator access to Ubiquiti’s AWS accounts.
In fact, it was Sharp who used credentials he had access to as a Ubiquiti employee to steal company data. The DoJ announced charges against Sharp in December 2021.
The company’s shares fell approximately 20% following the publication of the false information about the incident, causing a loss of $4 billion in market capitalization.
Sharp pleaded guilty to the breach, to wire fraud, and to making false statements to the FBI. If found guilty, he faces up to 35 years in prison. His sentencing is scheduled for May 10, 2023.
The DoJ’s indictment and press release do not mention Ubiquiti specifically, but it’s clear that Sharp admitted to being the perpetrator behind the Ubiquiti incident.
Related: Canadian NetWalker Ransomware Affiliate Pleads Guilty in US
Related: Mexican Businessman Pleads Guilty in U.S. to Brokering Hacking Tools
Related: California Man Pleads Guilty Over Role in $50 Million Fraud Scheme
The post Former Ubiquiti Employee Who Posed as Hacker Pleads Guilty appeared first on SecurityWeek.
About SecurityWeek Cyber Insights | At the end of 2022, SecurityWeek liaised with more than 300 cybersecurity experts from over 100 different organizations to gain insight into the security issues of today – and how these issues might evolve during 2023 and beyond. The result is more than a dozen features on subjects ranging from AI, quantum encryption, and attack surface management to venture capital, regulations, and criminal gangs.
SecurityWeek Cyber Insights 2023 | Venture Capital – We are in a period of huge turmoil. Cybercrime is increasing and becoming more destructive, driven by better organized criminals and geopolitically active nation states. And many commentators believe there is a strong likelihood of a global recession before the end of 2023.
Here we have one simple question: how will these political/economic conditions affect venture funding for cybersecurity firms during 2023?
BackgroundThe bad news in any economic downturn is that business suffers, profits dip, staff are laid off, and budgets are cut. The better news for cybersecurity vendors is that they are somewhat insulated from these effects. Cybercrime is more likely to increase than decrease during a recession, and business must retain a strong cybersecurity posture if they wish to survive. The demand for strong and proven security controls will continue.
At the same time, the availability of capital for investment in new and growing cybersecurity firms remains constant and high, and is largely unaffected by short term economic downturns. This available capital is known in the venture capital industry as ‘dry powder’ (capital that is available and ready for use).
None of this means that all cybersecurity vendors will survive the downturn, nor that all will remain profitable. At the very least, profits are likely to dip as business is forced to do more with less resources. Dry powder isn’t money to burn, and the venture capital industry will adapt its priorities for new and further investment to the current realities.
One area that will stand proud despite economic headwinds is the cloud. “Cloud software is the deflationary force enabling productivity in a high inflation environment. Cloud-native is not an option, it’s a necessity,” wrote Battery Ventures in its State of the OpenCloud 2022 report published in November 2022.
Dry powderDry powder is raised from the VC industries’ limited partners (LPs). These might be pension funds, endowments, family offices, sovereign wealth funds, and corporations. “Most funds operate on a ten-year lifecycle, with funds typically being deployed over the first four or five years of a fund’s life,” explains Sidra Ahmed, investment principal at Munich Re Ventures – explaining the continued availability of investment funds despite current economic conditions.
According to Pitchbook data, there was approximately $290 billion of cumulative dry powder committed to venture capital as of the first half of 2022. It is these funds that are called on when venture capitalists invest in companies. It must be said, of course, that VC’s dry powder isn’t committed solely to cybersecurity firms although cybersecurity remains a favored investment area.
Different VC organizations tend to specialize in different areas. For example, “YL Ventures raised its $400 million fifth fund at the beginning of 2022, dedicated exclusively to investing in Israeli cybersecurity startups,” explains Yoav Leitersdorf, managing partner at YL Ventures. “This fund has been used to invest in only a small number of companies to date, all of which are still in stealth, in line with our very disciplined strategy of investing strategically in a select number of exceptional startups.”
VC organizations try to use all the funds they get from their LPs – but not at any cost. They still need to demonstrate value to the LPs. Bad investments will lead to difficulties in raising new funds, while not using the funds raised is like a business unit not using its whole annual budget – it might lead to a lower budget next year.
The difficulty for cybersecurity firms in raising investment funds in 2023 will not be because the funds don’t exist, but because the VC firms will be taking more concern over where the funds are invested.
Effect of an economic downturn“The pace of investing is certainly going to change,” comments Ahmed. “With more uncertainty around budgets and sales cycles, investors will spend more time assessing deals that are able to withstand a time of austerity – companies with critical productions and solutions will be prioritized. There will be a lot more scrutiny of deals, valuations, and co-investors. Investors will also be focused on supporting their own portfolios.”
Jake Heller, Partner & Head of Tech Growth, Americas at KKRJake Heller, partner at KKR and head of tech growth equity Americas, believes the impact is unlikely to be felt evenly. “We have already seen the pullback in public markets affecting fundraising for some growth and early-stage companies,” he said. “In general, we expect the tightening of funding conditions to continue into 2023; however, we believe that capital will continue to be available to entrepreneurs and management teams who are able to effectively manage costs and allocate capital to growth opportunities with high potential for returns.”
Translated to the market, this all implies that startups don’t necessarily have sales targets that they can miss and can possibly ride out a recession before they need to show sustained profits; mid-growth companies seeking growth funding are likely to suffer with lower-than-expected profits and be less attractive to VCs; while established firms preparing for an IPO will likely need to survive the recession before proceeding.
“Market conditions had a dramatic impact on 2022 funding rounds, and we aren’t out of the woods yet,” says Leitersdorf. “The fallout is trickling from the top down. IPOs dropped this year from thousands to just over 100, the lowest number since 2016. There was a near stall in growth stages and a significant slowdown in Series C and D rounds, a steep decline in Series B rounds and a struggle to raise significant Series A rounds.”
In short, money is still available for attractive startups (seed and possibly A rounds), will require deeper consideration for growth equity (B, C and D rounds), and is much more difficult for pre-IPO companies (E rounds and above). In the last case, venture firms are looking closely at M&As to consolidate and strengthen their existing investments – but in all cases (apart from startups) venture firms will concentrate on further investments in their existing portfolios.
Outlook for startupsLeitersdorf remains upbeat on the prospects for investment in cybersecurity startups in 2023. “In today’s threat landscape, cybersecurity risks have become business risks. Organizations cannot afford to be lenient with threats to their assets, and executives now understand that security has a direct impact on their company’s reputation, business continuity and revenue,” he explains.
“Therefore, security will continue to be top-of-mind, as long as attacks continue to grow and evolve, demanding new and equally sophisticated security solutions. We see that investors are still eager to invest in the most promising startups in our industry with the greatest potential to lead their categories in the future. Capital will continue to flow to this necessary sector, as new and more challenging problem spaces continue to emerge.”
DataTribe, which describes itself as a cyber startup foundry (both an incubator and VC firm), is more circumspect. Funding will be harder, but potentially higher. John Funge, MD, explains, “Looking ahead, 2023 will be a slog for startups raising money. It will take longer for startups to complete next rounds as venture firms are both focusing more attention on their current portfolio as well as being more selective in new investments.”
He believes there will be fewer deals. “There will be a ‘flight to quality’ and the bar for attracting funding will be higher. Top startups that are hitting performance metrics will get funded at valuations not too far off historical. However, startups with a few words that previously would have gotten funded may find it hard to get funded at all — versus getting funded on less attractive terms.”
But he adds, “Historically, some of the most successful technology companies started during downturns. We don’t see it being any different this time around. It will be a tricky period to be a pre-IPO company, but likely an excellent time to be starting a new venture.”
Outlook for growth fundingGrowth funding will become more difficult in 2023, and potentially more necessary. “We’ve already seen growth rounds plummeting in 2022, and this trend will most likely continue into 2023,” explains Leitersdorf. “Capital is available, but it will become increasingly expensive, and investors will prefer to use it in order to fuel innovative, early-stage startups that will require less capital at lower valuations.”
A particular problem for growth companies is in part historical. “The valuations of many growth-stage startups were significantly inflated in 2021 and were not based on sustainable growth metrics, revenue, or performance,” he continued. “Many of these growth-stage startups will be forced to raise funding in 2023 after scaling rapidly and burning through their capital in 2022. We, therefore, foresee an increase in growth rounds next year, most probably with unfavorable terms for founders, employees, and existing investors.”
But, adds Ahmed. “There is still a lot of capital available. Investors will be holding companies to their performance so we might see more down rounds into 2023.”
Bob Ackerman, founder of AllegisCyberBob Ackerman, founder of AllegisCyber and member of the board at DataTribe, agrees with this sentiment. “Undifferentiated and sub-critical mass cyber companies without truly compelling solutions are likely to be challenged as they go to the VC community for capital,” he said. “Investors will be materially more discriminating in the deployment of capital.”
Outlook for M&A consolidationM&A activity has increased rapidly over the last few years. This trend will continue, driven by a number of different factors: desire among security users to consolidate their existing disparate security controls; a rush to the nearest exit point among startups; declining valuations making attractive targets; and a safe haven for further VC investments.
“The cybersecurity market is approaching bloated status,” comments Hank Thomas, CEO at Strategic Cyber Ventures. “There are too many vendors chasing the same dollars with similar technology. People in charge of purchasing decisions, often CISOs, are looking for more integrated security platforms and less point solution tools. PE firms and other later-stage investors are looking to bring in bigger players to serve as anchors for rollups and bolt on acquisitions.”
Will Lin, Venture Partner at Forgepoint CapitalWill Lin, venture partner at Forgepoint Capital, agrees. “I believe that we’ll see security M&A significantly pick up in 2023. The main reason being that so many security companies have been created in the past couple of years. When so many of these companies, full of amazing talent, come up to the crossroads of M&A or raising their next round, I believe the market dynamics will re-shuffle in a way where M&A will be considered the best next step.”
Security vendors are seeking to support their users by consolidating point products from different vendors into integrated solutions from single vendors. “The rapid expansion of new security products has led to many organizations purchasing the ‘latest and greatest’ without having a strong integration plan in place,” explains Dave Gerry, CEO at Bugcrowd. “Without a clear deployment and integration plan, even the best security product will go underutilized. For the past few years, the industry has seen an incredible amount of M&A consolidation.”
This process will continue through 2023. “Security organizations are looking internally for ways to leverage existing tool sets or upgrade existing tool sets versus adding to their ever-growing technology stack,” he continued. “This growing need for security vendor consolidation will continue to be driven by both the cost of the security products and the limited internal resources to effectively operate the products.”
Ackerman agrees with this sentiment. “Investors will be materially more discriminating in the deployment of capital with a significant pick up in M&A activity as the market looks to consolidate point products into broader security platforms,” he suggests.
The second driver for M&A activity comes from the transition from early stage to growth requirements. Early stage is still attractive to investors — growth stage is more difficult. As startups burn through their early financing, they will find it more difficult to secure further growth funding — and may find an early exit an attractive option, bumping into the consolidation driver.
This process may be actively promoted by the VC industry. “A new wave of innovation is needed in the security industry. Things have become stale,” explains Thomas. “VC investment will still drive innovation since larger companies often lose the ability to innovate, especially in security. As a result, we will see large entities acquiring VC backed companies earlier as established PE backed platform companies make tuck in and bolt-on acquisitions to remain relevant.”
Leitersdorf expands on this possibility. “Large security vendors such as Microsoft, SentinelOne, Akamai, CrowdStrike, IBM, CyberArk and Okta are strengthening their corporate development divisions and doubling down on in-house investment funds (CVCs), looking for strong talent and tech,” he said. “These venture arms of large security vendors will most likely become increasingly active in both investments and M&A deals in the coming years and make the option of acquisition more attractive for struggling startups.”
One effect of a downturn in the economy is that company valuations are lowered. This is already happening, and is likely to get worse in 2023. On December 14, 2022, the Federal Reserve raised interest rates by half a point — and US stock markets fell. The intention was to put a curb on high inflation rates, but it simultaneously increases the likelihood of a recession in 2023.
If this happens, company valuations will go lower. This in turn will make companies with good products but reduced valuations an attractive target for larger companies with money — and of course VC firms. VC firms will likely be driven to use their dry powder on their own existing portfolios rather than look for different companies in which to invest.
The current market conditions look set to promote increasing M&A activity through 2023. “The current state of the global economy will also encourage hyperscalers to move toward an M&A cyber strategy,” summarizes Simon Chassar, CRO at Claroty. “Furthermore, start-ups will struggle as we see less investment from PE or VCs, therefore creating an opportunity for some of the larger cash-strong security control companies to gain market share at a relatively low price.”
What VCs look for…2023 will be a year when the VC firms have money to invest, but the economic conditions will force them to be careful where they invest it. Cybersecurity will remain an attractive sector, but the security vendors will need to work harder to get new funding. Two questions come to mind: which security sectors are most attractive to the investors, and how do they choose a specific vendor?
Favored cybersecurity sectorsHeller believes that continuing digital transformation will provide new opportunities. “We believe that digital transformation, which has been accelerated by the global pandemic, will continue to create significant opportunities and challenges across industries and geographies,” he said. “These broader trends span new methods of collaboration, workforce transformation, cloud migration, automation and testing, supply-chain disruption, and digital adoption.”
Sidra says her firm is focusing on data and the threats it faces. “With rapid cloud adoption, companies are struggling to understand where their data sits and how to put sufficient security and controls around it.” Furthermore, she adds, “The penalties regarding sensitive data being breached are increasing at an exponential rate globally, making it even more of a priority for companies to be sufficiently protected.”
And there are new and still evolving threats to data. “As more companies adopt machine learning and analytical models to make data-driven decisions,” she continued, “there is now a need to protect data (and the models we build on the data) from being compromised. There are also questions around the validity of data and how to discern true data and information from coordinated disinformation campaigns and narratives.”
Leitersdorf adds identity to data as an area attractive to investors. “Malicious cyber actors have focused their most egregious attacks on two specific vectors in the past two years – data and identity,” he says. Attackers have leveraged the gaps, misconfigurations and problems surrounding credentials, identity, and access provisions to steal data. This will continue.
“Therefore,” he continued, “we have been focusing our attention on innovative security solutions that strive to tackle these problems and ensure that organizational security postures are strengthened accordingly.”
Favored companiesWhile different VCs may be attracted to different cybersecurity sectors, they must still choose which individual companies to support. “A large part of the decision is based on the management team and our perception of its ability to execute on the vision effectively, and evolve that vision over time,” said Ahmed. “Other criteria include tech differentiation, product vision, competition, size of market and TAM [total addressable market], and path to exit.”
Leitersdorf takes an almost identical stance. “The technology must be remarkable, deep, and innovative – that’s a given. However, even the most groundbreaking idea and cutting-edge tech won’t develop into a top-tier startup without an exceptional team,” he explained.
“We invest in strong teams that combine determination, talent, and an unrelenting passion for solving the most acute problem spaces in cybersecurity. The cybersecurity market is saturated with startups solving niche problems, and we’re looking for founders that stand out, go big and break the mold.”
The same goes for Heller. “Once we have found a sector we like, we generally look for companies that are market leaders or have a real competitive advantage. Cultural fit and alignment is also very important to us and in many cases, we have built relationships with the entrepreneurs and management teams we’re investing in over multiple years.”
The basic conclusion is that prospective vendors won’t get consideration without an excellent product in an expanding or vital sector. But where two attractive companies exist, the one with the stronger management team is more likely to succeed.
SummaryAcquiring venture capital in 2023 may be more difficult than it has been in recent years, but it remains viable and available. “In 2023, cyber will be softer but will remain a bright spot for investing,” explains Funge. “Compared to the nearly 24% year-on-year decline in deal activity across all verticals, cyber deal activity across all investment stages is down only 3%.”
What will change most is the decision-making process of the VC firms. They will still wish to invest, and probably at the same overall levels they have been investing. But fears of bad investments in a down economy will make them concentrate on areas that give them the greatest confidence. This may mean more money going to fewer companies. While B, C and D rounds might be left with difficult, declined, or down rounds. seed and startup A rounds might reach new heights. Any money left over will be focused into M&A.
About SecurityWeek Cyber Insights | At the end of 2022, SecurityWeek liaised with more than 300 cybersecurity experts from over 100 different organizations to gain insight into the security issues of today – and how these issues might evolve during 2023 and beyond. The result is more than a dozen features on subjects ranging from AI, quantum encryption, and attack surface management to venture capital, regulations, and criminal gangs.
Related: North Korean Hackers Created 70 Fake Bank, Venture Capital Firm Domains
Related: What’s Going on With Cybersecurity VC Investments?
Related: How VCs Choose Which Startups to Fund in Challenging Times
Related: YL Ventures Closes $400 Million Cybersecurity Investment Fund
The post Cyber Insights 2023: Venture Capital appeared first on SecurityWeek.
Atlassian this week warned of a critical-severity authentication vulnerability in Jira Service Management Server and Data Center that could allow attackers to impersonate Jira users.
Tracked as CVE-2023-22501 (CVSS score of 9.4), the flaw impacts Jira Service Management Server and Data Center versions 5.3.0, 5.3.1, 5.3.2, 5.4.0, 5.4.1, and 5.5.0.
“An authentication vulnerability was discovered in Jira Service Management Server and Data Center which allows an attacker to impersonate another user and gain access to a Jira Service Management instance under certain circumstances,” Atlassian notes in its advisory.
“With write access to a User Directory and outgoing email enabled on a Jira Service Management instance, an attacker could gain access to signup tokens sent to users with accounts that have never been logged into,” the company continues.
The attacker can obtain access to these tokens if they are included in Jira issues or requests with these users, or if the attacker obtains emails containing ‘View Request’ links from these users.
According to Atlassian, bot accounts are most likely to be targeted in such attacks. However, external customer accounts on instances with single sign-on may also be affected if account creation is open to anyone.
The vulnerability does not impact Jira sites that are hosted by Atlassian, and which are accessed via an atlassian.net domain.
Patches for this vulnerability were included in Jira Service Management Server and Data Center versions 5.3.3, 5.4.2, 5.5.1, and 5.6.0.
Users are advised to update their Jira installations as soon as possible.
Related: Jira Align Vulnerabilities Exposed Atlassian Infrastructure to Attacks
Related: Atlassian Patches Critical Authentication Bypass Vulnerability in Jira
Related: Atlassian Patches Critical Vulnerability in Jira Data Center Products
The post Atlassian Warns of Critical Jira Service Management Vulnerability appeared first on SecurityWeek.
VMware has informed users about the availability of patches for a Workstation vulnerability that could be exploited by malicious hackers for privilege escalation.
The flaw, tracked as CVE-2023-20854 and rated ‘high severity’, has been described by VMware as an arbitrary file deletion vulnerability affecting version 17.x on Windows.
“A malicious actor with local user privileges on the victim’s machine may exploit this vulnerability to delete arbitrary files from the file system of the machine on which Workstation is installed,” VMware said in its advisory for CVE-2023-20854.
The virtualization giant has credited Frederik Reiter of German cybersecurity firm Cirosec for reporting the vulnerability.
In a message posted on Twitter, Cirosec said the security hole can be exploited by an attacker to escalate privileges to System. The company said it will release technical details in the upcoming period.
While this vulnerability might never be exploited in the wild, VMware users have been warned about a series of recently patched vRealize Log Insight flaws for which exploit code is available. The cybersecurity industry is keeping an eye out for any exploitation attempts involving the vulnerabilities.
Related:VMware Plugs Critical vRealize Code Execution Flaws
Related: VMware Patches VM Escape Flaw Exploited at Geekpwn Event
Related: Gaping Authentication Bypass Holes in VMware Workspace One
Related: VMware Confirms Workspace One Exploits in the Wild
The post High-Severity Privilege Escalation Vulnerability Patched in VMware Workstation appeared first on SecurityWeek.
Exploitation attempts targeting a critical-severity Oracle E-Business Suite vulnerability have been observed shortly after proof-of-concept (PoC) code was published.
One of the major Oracle product lines, the E-Business Suite is a set of enterprise applications that help organizations automate processes such as supply chain management (SCM), enterprise resource planning (ERP), and customer relationship management (CRM).
Tracked as CVE-2022-21587 (CVSS score of 9.8), the exploited flaw was identified in the Web Applications Desktop Integrator of Oracle’s enterprise product and was addressed as part of Oracle’s October 2022 Critical Patch Update.
According to a NIST advsory, unauthenticated attackers with network access via HTTP can easily exploit the security defect to compromise the Web Applications Desktop Integrator and take it over.
This week, CISA added CVE-2022-21587 to its Known Exploited Vulnerabilities (KEV) catalog, urging Oracle customers to apply the available patches as soon as possible.
The first exploitation attempts, however, were observed on January 21, Shadowserver warned last week.
“Since Jan 21st we are seeing exploitation attempts in our honeypot sensors for Oracle E-Business Suite CVE-2022-21587 (CVSS 9.8 RCE) shortly after a PoC was published,” Shadowserver said.
The PoC came from Vietnam-based cybersecurity firm Viettel Cyber Security, which on January 16 published a detailed analysis of the vulnerability and potential exploitation venues.
According to Shadowserver data, the number of observed exploitation attempts is currently low. However, threat actors are known to target unpatched Oracle products, and the number of attacks may increase shortly.
This week, CISA also warned of observed exploitation of CVE-2023-22952, a high-severity remote code execution flaw in SugarCRM.
Impacting the EmailTemplates, the vulnerability is described as a missing input validation defect that allows an attacker to inject custom PHP code using crafted requests. Patches for this vulnerability were released on January 11, 2023.
In January, shortly after exploitation began, Censys reported seeing hundreds of SugarCRM servers being hacked using CVE-2023-22952.
Related:Exploited Control Web Panel Flaw Added to CISA ‘Must-Patch’ List
Related:CISA Says Two Old JasperReports Vulnerabilities Exploited in Attacks
Related:CISA Warns Veeam Backup & Replication Vulnerabilities Exploited in Attacks
The post Exploitation of Oracle E-Business Suite Vulnerability Starts After PoC Publication appeared first on SecurityWeek.
China said Friday it is looking into reports that a Chinese spy balloon has been flying in U.S. airspace and urged calm, adding that it has “no intention of violating the territory and airspace of any sovereign country.”
Foreign Ministry spokesperson Mao Ning also said she had no information about whether a trip to China by U.S. Secretary of State Antony Blinken planned for next week will proceed as scheduled.
At a daily briefing, Mao said that politicians and the public should withhold judgment “before we have a clear understanding of the facts” about the spy balloon reports.
Blinken would be the highest-ranking member of President Joe Biden’s administration to visit China, arriving amid efforts to mitigate a sharp downturn in relations between Beijing and Washington over trade, Taiwan, human rights and China’s claims in the South China Sea.
“China is a responsible country and has always strictly abided by international laws, and China has no intention of violating the territory and airspace of any sovereign country. As for the balloon, as I’ve mentioned just now, we are looking into and verifying the situation and hope that both sides can handle this together calmly and carefully,” Mao said.
“As for Blinken’s visit to China, I have no information,” she said.
A senior defense official told Pentagon reporters that the U.S. has “very high confidence” that the object was a Chinese high-altitude balloon and was flying over sensitive sites to collect information.
One of the places the balloon was spotted was over the state of Montana, which is home to one of America’s three nuclear missile silo fields at Malmstrom Air Force Base. The official spoke on condition of anonymity to discuss sensitive information.
Pentagon press secretary Brig. Gen. Patrick Ryder said the balloon is “currently traveling at an altitude well above commercial air traffic and does not present a military or physical threat to people on the ground.”
Ryder said similar balloon activity has been seen in the past several years and the government has taken steps to ensure no sensitive information was stolen.
President Biden was briefed and asked the military to present options, according to a senior administration official, who was also not authorized to publicly discuss sensitive information.
Defense Secretary Lloyd Austin and Army Gen. Mark Milley, chairman of the Joint Chiefs of Staff, advised against taking “kinetic action” because of risks to the safety of people on the ground. Biden accepted that recommendation.
The defense official said the U.S. has “engaged” Chinese officials through multiple channels and communicated the seriousness of the matter.
Blinken’s visit was expected to start this Sunday in an effort to try to find common ground on issues from trade policy to climate change. Although the trip has not been formally announced, both Beijing and Washington have been talking about his imminent arrival.
The senior defense official said the U.S. prepared fighter jets, including F-22s, to shoot down the balloon if ordered. The Pentagon ultimately recommended against it, noting that even as the balloon was over a sparsely populated area of Montana, its size would create a debris field large enough that it could have put people at risk.
It was not clear what will happen with the balloon if it isn’t brought down.
The defense official said the spy balloon was trying to fly over the Montana missile fields, but the U.S. has assessed that it has “limited” value in terms of providing intelligence it couldn’t obtain by other technologies, such as spy satellites.
The official would not specify the size of the balloon but said commercial pilots could spot it from their cockpits. All air traffic was halted at Montana’s Billings Logan International Airport from 1:30 p.m. to 3:30 p.m. Wednesday, as the military provided options to the White House.
A photograph of a large white balloon lingering over the area was captured by The Billings Gazette. The balloon could be seen drifting in and out of clouds and had what appeared to be a solar array hanging from the bottom, said Gazette photographer Larry Mayer.
The balloon’s appearance adds to national security concerns among lawmakers over China’s influence in the U.S., ranging from the prevalence of the hugely popular smartphone app TikTok to purchases of American farmland.
“China’s brazen disregard for U.S. sovereignty is a destabilizing action that must be addressed,” Republican Party House Speaker Kevin McCarthy tweeted.
Tensions with China are particularly high on numerous issues, ranging from Taiwan and the South China Sea to human rights in China’s western Xinjiang region and the clampdown on democracy activists in Hong Kong. Not least on that list of irritants are China’s tacit support for Russia’s invasion of Ukraine, its refusal to rein in North Korea’s expanding ballistic missile program and ongoing disputes over trade and technology.
On Tuesday, Taiwan scrambled fighter jets, put its navy on alert and activated missile systems in response to nearby operations by 34 Chinese military aircraft and nine warships that are part Beijing’s strategy to unsettle and intimidate the self-governing island democracy.
Twenty of those aircraft crossed the central line in the Taiwan Strait that has long been an unofficial buffer zone between the two sides, which separated during a civil war in 1949.
Beijing has also increased preparations for a potential blockade or military action against Taiwan, which has stirred increasing concern among military leaders, diplomats and elected officials in the U.S., Taiwan’s key ally.
The surveillance balloon was first reported by NBC News.
From an office window in Billings, Montana, Chase Doak said he saw a “big white circle in the sky” that he said was too small to be the moon.
“I thought maybe it was a legitimate UFO,” Doak said. “So I wanted to make sure I documented it and took as many photos as I could.”
The post China Says It’s Looking Into Report of Spy Balloon Over US appeared first on SecurityWeek.
Users of the GoAnywhere secure managed file transfer (MFT) software have been warned about a zero-day exploit that malicious actors can target directly from the internet.
The GoAnywhere MFT is made by Fortra, known until recently as HelpSystems, and it’s designed to enable organizations to automate and secure the exchange of data with their trading partners.
Cybersecurity blogger Brian Krebs broke the news about the zero-day vulnerability on Thursday, saying that the company had temporarily implemented a service outage in response.
An advisory obtained by Krebs — it can only be accessed by authenticated users — describes it as a zero-day remote code injection exploit and says that “the attack vector of this exploit requires access to the administrative console of the application”.
According to the vendor, the vulnerable admin console should in most cases only be accessible from within a company’s network, through a VPN, or only by trusted IP addresses. However, the company has admitted that some GoAnywhere users may be exposing the console to the public internet.
Fortra noted that the web client interface, which is typically accessible from the internet, is not affected by the exploit.
The advisory doesn’t clearly say that the vulnerability has been exploited in the wild, but active exploitation is likely, considering that it has been described as a zero-day. In addition, the vendor provides instructions on how customers can check if their system has been compromised.
The best indicator of compromise (IoC), according to the advisory, is the presence of suspicious administrator accounts that may have been created by malicious actors.
The advisory does not mention a patch, but it does recommend mitigations that should prevent exploitation. There is also no mention of a CVE identifier for the vulnerability in the advisory obtained by Krebs.
Security researcher Kevin Beaumont has conducted a Shodan search and found roughly 1,000 internet-exposed systems, a majority located in the United States. However, some of the results are clearly labeled as being associated with the web client, which Fotra says is not impacted.
Related: Zero-Day Vulnerability Exploited to Hack Over 1,000 Zimbra Email Servers
Related: US Agencies Warn of APTs Exploiting Recent ADSelfService Plus Zero-Day
Related: Accellion Failed to Notify Customers of FTA Zero-Day
The post GoAnywhere MFT Users Warned of Zero-Day Exploit appeared first on SecurityWeek.
Google this week announced an extension to its OSS-Fuzz rewards program, an initiative meant to reward contributors for integrating projects into OSS-Fuzz.
Launched in 2016, OSS-Fuzz is meant to help identify vulnerabilities in open source software through continuous fuzzing, with a declared goal of making common software infrastructure more secure.
Six months after the launch, Google announced that it was offering rewards between $1,000 and $20,000 for integrating projects into OSS-Fuzz, and now says that it has paid over $600,000 to more than 65 different contributors as part of the program.
The internet search marketing giant has now increased the highest reward available for new project integration to $30,000, which can be awarded depending on ‘the criticality of the project’.
Launched last year and already integrated into OSS-Fuzz, the tool performs analysis of functions, static call graphs, and runtime coverage information to provide insights into fuzzing coverage blockers.
“The Fuzz Introspector tool provides these insights by identifying complex code blocks that are blocked during fuzzing at runtime, as well as suggesting new fuzz targets that can be added,” Google says.
By increasing payouts and expanding the OSS-Fuzz rewards program, Google seeks to strengthen OSS-Fuzz to find more vulnerabilities before they are exploited.
Related: Google Announces Vulnerability Scanner for Open Source Developers
Related: Google’s GUAC Open Source Tool Centralizes Software Security Metadata
Related: Google Wants More Projects Integrated With OSS-Fuzz
The post Google Shells Out $600,000 for OSS-Fuzz Project Integrations appeared first on SecurityWeek.
F5 warns of a high-severity format string vulnerability in BIG-IP that could allow an authenticated attacker to cause a denial-of-service (DoS) condition and potentially execute arbitrary code.
Tracked as CVE-2023-22374, the security defect impacts iControl SOAP, an open API that enables communication between systems, which runs as root.
The SOAP interface is accessible from the network, either via the BIG-IP management port and/or self IP addresses, and is restricted to administrative accounts.
Rapid7, which identified the bug, explains that exploitation is possible by inserting format string specifiers into specific parameters that are passed into the syslog function, resulting in the service reading and writing memory addresses referenced from the stack.
However, the cybersecurity firm explains, the attacker cannot read the memory unless they have access to the syslog.
“It is difficult to influence the specific addresses read and written, which makes this vulnerability very difficult to exploit (beyond crashing the service) in practice,” Rapid7 explains.
An attacker could crash the service by using the ‘%s’ specifier, and could use the ‘%n’ specifier to write arbitrary data to any pointer in the stack, which could potentially lead to remote code execution, the cybersecurity firm says.
According to F5’s advisory, an attacker looking to exploit the flaw for code execution would first need to harvest information about the environment running the vulnerable component. However, only the control plane, but not the data plane, is exposed by this bug.
“The most likely impact of a successful attack is to crash the server process. A skilled attacker could potentially develop a remote code execution exploit, which would run code on the F5 BIG-IP device as the root user,” Rapid7 notes.
The vulnerability impacts BIG-IP versions 13.1.5, 14.1.4.6 to 14.1.5, 15.1.5.1 to 15.1.8, 16.1.2.2 to 16.1.3, and 17.0.0. No patch is currently available for the vulnerability, but F5 says it is working on an engineering hotfix.
Because the flaw can only be exploited by authenticated users, access to the iControl SOAP API should be restricted to trusted users.
CVE-2023-22374 has a CVSS score of 7.5 for BIG-IP systems in standard deployment mode, and a CVSS score of 8.5 for BIG-IP instances in application mode.
BIG-IP SPK, BIG-IQ, F5OS-A, F5OS-C, NGINX, and Traffix SDC are not affected.
Related: F5 BIG-IP in Attacker Crosshairs Following Disclosure of Critical Vulnerability
Related: F5 Warns BIG-IP Customers About 18 Serious Vulnerabilities
Related:F5 Patches Two Dozen Vulnerabilities in BIG-IP
The post F5 Working on Patch for BIG-IP Flaw That Can Lead to DoS, Code Execution appeared first on SecurityWeek.
Cisco on Wednesday announced patches for a high-severity command injection vulnerability in the IOx application hosting environment that could allow malicious code to persist across reboots.
Tracked as CVE-2023-20076, the security defect exists because parameters that are passed for the activation of an application are not completely sanitized.
“An attacker could exploit this vulnerability by deploying and activating an application in the Cisco IOx application hosting environment with a crafted activation payload file. A successful exploit could allow the attacker to execute arbitrary commands as root on the underlying host operating system,” the tech giant explains in an advisory.
According to Trellix, the cybersecurity firm that discovered the vulnerability, the issue resides in the DHCP Client ID option within the Interface Settings, which is not being correctly sanitized, leading to command injection.
Furthermore, the bug bypasses mitigations to prevent persistence across reboots and system resets.
“CVE-2023-20076 gains unrestricted access, allowing malicious code to lurk in the system and persist across reboots and firmware upgrades. Side-stepping this security measure means that if an attacker exploits this vulnerability, the malicious package will keep running until the device is factory reset or until it is manually deleted,” Trellix explains.
The bug impacts all Cisco devices running IOS XE Software with the IOx feature enabled, if they do not support native docker, including 800 series industrial ISRs, Catalyst Access Points (COS-APs), CGR1000 compute modules, IC3000 industrial compute gateways, and IR510 WPAN industrial routers.
Cisco has released security updates for the impacted industrial ISRs (software version 15.9(3)M7), COS-APs (versions 17.3.8, 17.9.2, and 17.11.1), IC3000 gateways (version 1.2.1), and for IOS XE-based devices configured with IOx (versions 17.3.8, 17.9.2, and 17.11.1).
Updates for CGR1000 compute modules and IR510 WPAN industrial routers are planned for February 2023.
Customers are advised to update their Cisco products as soon as possible. No workarounds exist to mitigate the bug.
In addition to CVE-2023-20076, Trellix security researchers identified a security check bypass during tar archive extraction, which could allow an attacker to write on the underlying host operating system as root.
The issue, however, impacts a compression algorithm that Cisco is planning to deploy for future application packaging support, and cannot be exploited. The tech giant has resolved this bug as well.
Cisco says it is not aware of any attempts to exploit CVE-2023-20076 in malicious attacks. In addition, Trellix noted that an attacker has to be authenticated with admin privileges on the system in order to exploit the vulnerabilities discovered by its researchers.
This week, Cisco also issued patches for several medium-severity bugs impacting Identity Services Engine (ISE) and Prime Infrastructure Software, and warned of a medium-severity file upload issue impacting RV340, RV340W, RV345, and RV345P routers, which have reached end-of-life (EOL) and no longer receive security patches.
Additional information on these vulnerabilities can be found on Cisco’s security website.
Related: Cisco Patches High-Severity SQL Injection Vulnerability in Unified CM
Related: Cisco Warns of Critical Vulnerability in EoL Small Business Routers
Related: Cisco Warns of Many Old Vulnerabilities Being Exploited in Attacks
The post Flaw in Cisco Industrial Appliances Allows Malicious Code to Persist Across Reboots appeared first on SecurityWeek.
UK-based car retailer Arnold Clark is informing customers that their personal information may have been stolen as a result of a cyberattack. A ransomware group has taken credit for the attack, claiming to have obtained gigabytes of sensitive information.
Arnold Clark has more than 200 dealerships in England and Scotland, selling vehicles from over 25 manufacturers, and claiming to be the biggest car company of its kind in Europe. According to its Wikipedia page, the firm has 11,000 employees.
The company told customers that it was targeted in a cyberattack on December 23, 2022. An investigation revealed that the hackers may have obtained personal data such as names, contact details, dates of birth, vehicle information, passports or driver’s licenses, national insurance numbers, and bank account details.
The investigation is ongoing, with Arnold Clark trying to determine the precise extent and nature of the compromised data, but impacted individuals are already being offered two years of free credit and web monitoring services through Experian.
The ransomware group named Play has taken credit for the attack on its Tor-based leak website.
The hackers have published a significant amount of information allegedly stolen from Arnold Clark and they claim more will be made public if the company refuses to pay up. Currently, they released 31 archive files of 500 Mb each, totaling roughly 15 Gb.
They claim to have stolen “private and personal data”, including passport and ID copies, confidential contracts, agreements, leasing contracts, and finance-related documents.
Arnold Clark targeted by Play ransomwareThe Play ransomware (also known as PlayCrypt) emerged in June 2022 and it has been one of the most active ransomware operations. The cybercriminals are deploying file-encrypting malware and stealing data from victims in an effort to increase their chances of getting paid.
Play is best known for the recent attack on cloud company Rackspace. In that attack, the hackers used a new exploitation method for targeting Microsoft Exchange servers.
Related: Hacker Selling Data Allegedly Stolen From Volvo Cars Following Ransomware Attack
Related: Ransomware Group Threatens to Leak Data Stolen From Car Parts Giant Continental
The post UK Car Retailer Arnold Clark Hit by Ransomware appeared first on SecurityWeek.
Recently, a friend brought up the term “carcinization” and I must admit, I had to look it up! Turns out the term was coined more than 100 years ago to describe the phenomenon of crustaceans evolving into crab-shaped forms. Today, there are even memes for it. So, what does this example of convergent evolution have to do with security? It’s an apt description of how the security industry has evolved and why security leaders often struggle to determine the right security investments for their organization.
The security industry started out with a series of point products to solve very specific challenges. Organizations used endpoint antivirus, firewalls, IPS/IDS, and routers to protect themselves. Email and web security tools were soon added, along with SIEMs and other tools like ticketing systems, log management repositories and case management systems to house internal threat and event data. Endpoint detection and response (EDR) tools then came into the mix and a few years later served as the jumping off point for the next phase in the industry’s evolution. That’s when the traditional walls between endpoint and network security technologies began to crumble and product categories were no longer clearly defined.
Everything starts to look alike
When the concept of extended detection and response (XDR) was introduced a couple of years ago, industry analysts each seemed to have slightly different, but colliding, definitions of it. Some said XDR is EDR+ (with different opinions as to what the + consisted of) while others said XDR isn’t a solution at all, but an approach or an architecture. Those conversations continue today.
Now the industry is talking about threat detection, investigation and response (TDIR) platforms and depending on who you ask about the difference with XDR, you’ll get a different answer. Some say XDR is an overarching architecture and TDIR is the platform that integrates all the capabilities required for XDR. Others say TDIR is a process. And another contingent says they are one and the same.
The varied viewpoints as related security concepts take on similar traits create substantial confusion among security teams trying to evaluate and purchase security technologies to strengthen their organization’s security posture. At a time when the market should be maturing and moving security to a better place, these discrepancies prevent that from happening.
Use cases, not labels
So, how can security teams cut through the noise and confusion? In the carcinization of security, where everything starts to look and sound alike, it’s critical to focus first on use cases. To do this, start with what you are trying to accomplish, the associated workflows, and the people, processes, and technology required. From there, you can look at where the gaps exist and where to invest to achieve your goals.
Sometimes you may need a specific technology for a specific use case. Or, ideally, you find a platform that can handle multiple use cases security professionals are focused on today as security operations centers (SOCs) mature. These include spear phishing, threat hunting, alert triage, vulnerability prioritization and incident response.
For each of these use cases, context is critical to understand the who, what, where, when, why and how of an attack. With a security operations platform that can aggregate and correlate internal threat and event data with external data on indicators, adversaries and their methods, you can analyze multisource data and understand relevance to your environment based on parameters you set. Once you have the right data and context, you can pivot around a specific piece of data to understand and act. You can parse and analyze spear phish emails for prevention and response, prioritize alerts for triage, identify vulnerabilities to patch first, and accelerate threat hunting. Integration with the right tools allows you to send data back out across your defense grid to accelerate incident response, including blocking threats, updating policies and arming the organization against the next wave of attacks.
The truth is, the walls established to separate product categories should have been challenged sooner for the benefit of security. Organizations considering the latest acronym or spurred by the latest attack may have selected a different, more effective tool or platform depending on their goals, internal resources and capabilities. When everything starts to look like a crab and walk like a crab, we can’t rely on labels. We need to look at use cases, desired outcomes and the best path to get us there.
The post Dealing With the Carcinization of Security appeared first on SecurityWeek.
A sophisticated piece of malware named HeadCrab has ensnared at least 1,200 Redis servers worldwide, Aqua Security reports.
Designed to run on secure networks, Redis servers do not have authentication enabled and are prone to unauthorized access if exposed to the internet.
Redis servers can be set up in clusters, which allows for data to be divided and stored on multiple servers. The structure uses a master server and slave servers for data replication and synchronization, where the Slaveof command is used to designate slave servers.
In an observed HeadCrab infection, this command was used to set victim servers as slaves to a Redis instance controlled by the attackers. Next, malicious modules from the master server were synchronized, to deploy the malware.
The malware provides attackers with full control over the infected servers and supports a series of commands that allow them to perform various actions on the victim machines.
The purpose of the campaign was to ensnare internet-exposed Redis servers into a botnet for cryptocurrency mining. Aqua identified roughly 1,200 infected servers and estimates that the attackers made an annual profit of almost $4,500 per worker, based on the identified Monero wallet.
Created as a Redis module framework, the HeadCrab malware goes undetected by some security products, according to Aqua. Upon malware execution, a module is loaded and information about the action is stored for future checks, ensuring that only one instance of HeadCrab runs.
If the module is loaded with two arguments (magic numbers), eight default Redis commands are overridden to avoid detection. The malware also deletes the Redis log file or empties it if it was recreated.
The threat also locates the dynamic loader to execute processes under its name, another way to evade detection. It also checks for several service management programs, which are later used for persistence.
Next, new Redis commands are created, allowing the attackers to control the malware. These are meant to ensure further persistence, execute commands, replace default commands with malicious ones, update magic numbers, establish encrypted communication with the command-and-control (C&C) server, reenable debugging, and restore the overridden commands.
“Our investigation has revealed that HeadCrab’s botnet has already taken control of over 1,200 servers, all infected with this malware. It is our conviction that HeadCrab will persist in using cutting-edge techniques to penetrate servers, either through exploiting misconfigurations or vulnerabilities,” Aqua Security concludes.
Related: Redigo: New Backdoor Targeting Redis Servers
Related: Many Internet-Exposed Servers Affected by Exploited Redis Vulnerability
Related:Recently Disclosed Vulnerability Exploited to Hack Hundreds of SugarCRM Servers
The post HeadCrab Botnet Ensnares 1,200 Redis Servers for Cryptomining appeared first on SecurityWeek.
About SecurityWeek Cyber Insights | At the end of 2022, SecurityWeek liaised with more than 300 cybersecurity experts from over 100 different organizations to gain insight into the security issues of today – and how these issues might evolve during 2023 and beyond. The result is more than a dozen features on subjects ranging from AI, quantum encryption, and attack surface management to venture capital, regulations, and criminal gangs.
SecurityWeek Cyber Insights 2023 | Regulations – In this world, nothing is certain but death, taxes, and cyber regulations. The first is static, the second goes up and down, but the third seems only to increase. The three primary drivers for cyber regulations are voter privacy, the economy, and national security – with the complication that the first is often in conflict with the second and third.
Transatlantic data flowsPrivacy is the headline battleground going forward, and amply illustrates the conflict between voter demands and national economies. This can be seen in the unsettled but multi-year attempt to find a legal solution to the transfer of personal user data from Europe to the US. Economics demands it, but European law (GDPR) and swathes of European public opinion deny it.
At the time of writing, it is almost certainly illegal to transfer PII from Europe to the US. The Privacy Shield – the second attempt at finding a workaround to GDPR – was declared illegal in what is known as the Schrems II court ruling. The wording of that ruling almost certainly eliminates an alternative approach known as ‘standard contractual clauses’.
During 2022, the European Commission (EC) and the US Biden administration have worked on developing a replacement for Privacy Shield. The ball was obviously in the US court, and on October 7, 2022, Biden issued an Executive Order to implement the EU-US Data Privacy Framework agreement – sometimes known as Privacy Shield 2.0.
This was enthusiastically greeted by US business. IBM, for example, issued a statement, “These steps will restore certainty to the thousands of companies already self-certified under Privacy Shield. Providing predictable, free flows of data between the US and the EU will secure the mutual benefits of continued business cooperation and will create a foundation for future economic growth.”
Our first prediction for 2023 is that the EC will approve Biden’s Executive Order and allow ‘free flows of data between the US and the EU’. This approval is in process. The EC issued a draft adequacy determination for the EU-US data privacy framework on December 12, 2022.
“As expected,” comments Caitlin Fennessy, VP and chief knowledge officer at the International Association of Privacy Professionals (IAPP), “the draft outlines the Commission’s reasoning in finding the framework adequate, with a focus on the new necessity and proportionality requirements for US signals intelligence and the Data Protection Review Court outlined in the recent Executive Order and Department of Justice regulations.”
But that will be just the beginning. European activists, such as Max Schrems, are likely to challenge the EC ruling in the European Court.
The basic problem remains the NSA’s requirement to only surveil non-Americans (such as Europeans) for national security purposes. Schrems’ website, noyb, has already indicated a dissatisfaction. “So-called ‘bulk surveillance’ will continue under the new Executive Order (see Section 2 (c)(ii)) and any data sent to US providers will still end up in programs like PRISM or Upstream, despite of the CJEU declaring US surveillance laws and practices as not ‘proportionate’ (under the European understanding of the word) twice.”
So, during 2023, transatlantic PII data flows will become legal under the new framework, but that framework will be challenged as unconstitutional in the European Court. The court case will take several years to come to a conclusion, but it will probably declare the data privacy framework (or whatever it becomes known as) to be illegal. The basic problem is that GDPR and NSA surveillance are incompatible, and neither is likely to change.
Federal privacy lawThe US government has been seeking a federal privacy law for around a decade but is probably no closer to achieving one. Progress was made during 2022, but the midterms kicked the bill into the long grass while the lawmakers concentrated on more pressing career issues. The question is whether it can be retrieved during 2023.
Mitzi Hill, a partner at the Taylor English Duma law firm, thinks it is unlikely. “I remain doubtful,” she said. “It is a complex topic both technically and legally. It is made more complicated with every new state law, because that is a new set of factors to consider in drafting any federal legislation.”
She also notes the outcome of the 2022 midterms. “Traditionally, we would expect that a Republican House majority [as we will have in 2023] will favor marketplace (as opposed to regulatory) solutions, making it tough to get anything passed in both houses of Congress. My own view is that the states will continue to lead in this area.”
Gopi Ramamoorthy, senior director of security and GRC at Symmetry Systems points out that “Five states have already enacted privacy acts, and more are expected to follow. The increased focus on privacy has stemmed from the introduction of GDPR and Schrems II decision from the EU.”
The California Privacy Rights Act (CPRA) comes into effect on January 1, 2023, with enforcement beginning on July 1, 2023. It is an extension of the existing CCPA, which is already possibly the strongest privacy act in the US (and largely modeled on GDPR). While it is somewhat more friendly to small businesses, it gives consumers more rights, places more requirements on organizations, and establishes an enforcement agency.
The consumer demand for privacy is strong, but not absolute – and often depends on what is received in return for giving up personal information. Consider Google, widely acknowledged as one of the primary collectors and users of PII. Despite this, consumers continue to consume Google because of the ‘free’ services the company offers in exchange. The result is that it is difficult for lawmakers to know exactly what their voters really want.
“Privacy laws and regulations will continue to swing widely between completely useless – even harmful – and amazing wins for consumers. This is due to corporation lobbying and consumer [voter] demands,” comments Taylor Gulley, senior application security consultant at nVisium. “Though most consumers desire complete privacy, the growing demand for personalized content and services requires providing ever more information to companies. This increase of valuable, marketable, information gives corporations a reason to continue to lobby for their benefit.”
One area worth watching in 2023 is whether the FTC picks up the mantle of a ‘federal’ privacy regulator. Noticeably, the FTC includes failures in consumer privacy to be a potential deceptive practice – and deceptive practices are firmly within the FTC bailiwick.
“The FTC may become even bolder about privacy matters in the next couple of years,” suggests Hill. “It recently adopted an enforcement action that is targeted to a particular CEO and any future business he may join.”
She explained that his current company has multiple privacy violations and may have misstated the degree to which it addressed security issues following the first set of violations. His future companies or employers will be required to release detailed security plans. “This is unprecedented as far as I know,” she added.
Trickle-down regulated securityAlthough Biden does not believe in trickle-down economics, he nevertheless makes use of trickle-down cybersecurity. He cannot pass federal laws for private industry without the support of Congress – but he can (and does) issue executive orders that become mandatory instructions for federal agencies and strong trickle-down recommendations for private industry.
If security vendors must conform to certain requirements before they can sell into the government, the size of the government market makes it a commercial if not legal requirement to conform. Furthermore, if federal agencies are required to apply certain cybersecurity methodologies, much of private industry will also take heed.
Both conditions were introduced in May 2021 with Executive Order 14208, spurring activity in zero trust, and introducing the software bill of materials (SBOM). Both are intended to counter the growing supply chain threat, and both will remain top of mind for companies during 2023.
“SBOM is going to continue to garner mainstream adoption, not just from software/firmware suppliers that are building products they are selling, but also for internal development teams that are building applications and systems for internal use,” comments Tom Pace, CEO at NetRise.
The federal government described the requirements for SBOMs in an OMB memorandum published on September 14, 2022. “This is going to cause a cascading effect in the private sector,” continued Pace, “since obviously the federal government does not manufacture all its own software and firmware – in fact very little is manufactured in house.”
There will be a bedding-in period before SBOMs achieve their end – and attackers are likely to increase their own efforts in the meantime. “Highly visible attacks on the software supply chain start with access to the weakest link. As we head into 2023, it will be important for businesses of all sizes to be engaged as new secure software development practices are defined,” warns John McClurg, SVP and CISO at BlackBerry.
Executive Orders are not the only tools the federal government can use – it also has NIST (a standards body) and CISA (a DHS agency responsible for strengthening security and infrastructure across all levels of government). While they primarily provide recommendations, this may not always be the case.
“The combined efforts of CISA and NIST in recent years,” comments Eric Hart, manager of subscription services at LogRhythm, “have led to a series of new cross-sector cybersecurity performance goals (CPGs) that organizations have already begun to implement.”
CISA’s CPGs are designed to provide an easier route towards conforming to NIST for organizations that may not have the resources to go straight to the complexities of the NIST CSF. “While these standards are designed to strengthen organizations,” continued Hart, “the process of reaching full regulatory compliance can be tricky. The complexity, along with the growing push for federally enforced compliance, suggests we could see a flurry of activity in 2023 as more organizations seek to adopt these new security standards.”
Noticeably, CISA describes the CPGs as ‘voluntary’ and ‘not comprehensive’, adding, “The CPGs are intended to supplement the [NIST] Cybersecurity Framework (CSF) for organizations seeking assistance in prioritizing investment toward a limited number of high-impact security outcomes, whether due to gaps in expertise, resources, or capabilities or to enable focused improvements across suppliers, vendors, business partners, or customers.”
But it is also worth considering a comment from Grant Geyer, CPO at Claroty, who blogged that they may prove a jumping off point for upcoming regulations coming from the White House. “Regulators now have a CISA-approved, pre-built checklist of critical areas to focus on that address key practices such as account security, data and device integrity, supply chain and third-party risk, and response and recovery.” We may yet see CISA’s CPGs become mandated for federal agencies and join the trickle-down process of federal regulations.
Ben Johnson, CTO and co-founder of Obsidian Security, sees a great future for CISA. “CISA came into its own in 2022. This next year, we’ll see CISA drive better, more resilient security, especially in critical infrastructure — increasing the sector’s maturity as a whole.”
The regulations jungleThe trajectory for regulations is to increase, and they are increasing rapidly. These include state-level, federal level, and overseas national level that may impact US companies with operations in those countries. An example of the last could be Australia’s current plans for a new more aggressive attitude toward cybercriminals. Part of this will be to make ransom payments illegal in Australia.
One question to be decided is how that might impact American companies with an Australian operation that gets ransomed. Will the American parent, where ransom payments are not illegal, be able to pay the ransom on behalf of the Australian operation?
Such complexities will require expert input by companies to match their infrastructure and processes against a huge number of regulations simply to understand where their compliance requirements are effectively mandatory.
Another new law, passed by Congress but targeted at federal agencies, may be introduced early in 2023: the Strengthening Agency Management and Oversight of Software Assets Act. MeriTalk reported on November 17, 2022, “The legislation would order Federal government agencies to undertake an inventory of all software used by the government – with a view toward eventually creating strategies to consolidate government software contracts, create governmentwide software licenses, and move toward adopting open-source software.”
This is not directly a cybersecurity regulation and will not be enforced on private industry. Nevertheless, if its precepts are adopted by industry, it could benefit industry groupings and separately lead to a beneficial reduction of security tool sprawl within companies.
The totality of regulations is beyond the scope of this peek into regulations in 2023. However, there is one we should consider that won’t come into effect until 2024.: PCI DSS 4.0. This will impact all organizations that store, transmit or process cardholder data and sensitive authentication data. The new standard allows organizations to customize their approach to proving compliance with each PCI DSS security requirement.
“If organizations take this direction,” warns Terry Olaes, senior technical director at Skybox Security, “there are growing opportunities for threat actors to exploit retailers who may have taken non-standard routes to achieve compliance. Additionally, the long lead time to implement these regulations gives attackers more opportunity to use those requirements as a blueprint to breach retailers before they have time to implement changes to their cybersecurity strategy.”
It is also worth noting that while regulations are becoming more numerous, they are also becoming more difficult to satisfy. “We’ll see more failed audits in regulated companies as multi-cloud, multi-cluster grows as a strategy in 2023,” warns Sitaram Iyer, senior director of cloud native solutions at Venafi. This strategy is increasingly popular among smaller but regulated organizations because it spreads risk, increases performance, and offers the control and visibility they need for compliance.
“However,” adds Iyer, “it also increases complexity because these environments are fragmented and require a huge number of machines which all need an authenticated identity to communicate securely. Due to this increased volume of machine identities in cloud native environments, compliance with regulations on machine identity management is a real challenge.”
And one to watch…Elon Musk has completed his takeover of Twitter, and his swashbuckling management style has caused ructions even before the end of 2022. These are not relevant to us. What may be relevant, however, is his adherence to the constitutionally protected concept of free speech; and the potential for Musk’s new Twitter to operate at a lower level of moderation than the old Twitter. Noticeably, in late November 2022, Musk reinstated almost all the accounts that had previously been suspended for spreading misinformation.
As a quick aside, on November 17, 2022, a group of Democrat senators asked the FTC to investigate any possible violations by the platform of consumer-protection laws or of its data-security commitments. The FTC had already said it is “tracking recent developments at Twitter with deep concern”.
Of more direct relevance, many governments have already expressed concern over the practice of bad actors spreading misinformation, malinformation and disinformation – and giving extremist viewpoints a loudspeaker – via social media platforms such as Twitter. This is a direct challenge to democratic government, and some governments have suggested countering it by making websites legally responsible for the user-generated content they publish. There is a possibility that such suggestions will increase during 2023.
Mitzi Hill does not think this is likely in the US. Although lower moderation might lead to howls of protest, “I never bet against the First Amendment,” she said. “‘Congress shall make no law… abridging the freedom of speech’ is one of the most important tenets in American legal thinking.”
Europe, however, thinks differently. The EU already has a new Digital Services Act that will kick in from January 2024. It doesn’t make platforms directly responsible for any unknown illegal content, but does require them to remove it once they are informed that it is illegal. It will also impose greater transparency on how algorithms work and are used. It is aimed at platforms that reach more than 10% of the EU population; that is, have at least 45 million EU users – that includes US big tech companies such as Twitter and Facebook. Non-compliance could lead to fines of up to 10% of annual turnover.
FinallyMartin Zinaich, CISO at the City of Tampa, once suggested to SecurityWeek, “If it ain’t required, it ain’t gonna happen.” We may have reached the point, with better organized cybercriminals and more aggressive nation states, where it must happen and therefore must be required.
Ron Kuriscak, MD at NetSPI, certainly believes so. “Regulations need to become much more mature, stringent, and punitive. We must hold organizations more accountable for their inaction in the area of cybersecurity… Organizations will be held accountable for basic cybersecurity hygiene. If they are unable to meet the most basic standards a regulator will require a third party to take over cybersecurity program execution (they will be mandated to cover the associated costs). Similar to the FDA, we will start seeing industry-aligned compliance regulations with real penalties that will force real compliance and organizational change. The key will be enforcement and penalties.”
But don’t expect much from the federal government in 2023. “On federal government cybersecurity issues,” explains Robert DuPree, manager of government affairs at Telos Corporation, “Congress has been more active and effective but further progress in 2023 will be hampered by the fact that some longtime cyber policy advocates and experts from both parties – including Sen. Rob Portman (R-OH), Rep. Jim Langevin (D-RI) and Rep. John Katko (R-NY) – are retiring and won’t be around in 2023. Their absence will leave a tremendous void when it comes to pushing ‘good government’ cybersecurity issues through Congress.”
Related: Do Privacy and Data Protection Regulations Create as Many Problems as They Solve?
Related: Robinhood Crypto Penalized $30M for Violating Cybersecurity Regulations
Related: Hack Prompts New Security Regulations for US Pipelines
Related: New York Imposes New Cybersecurity Regulation for Financial Services
The post Cyber Insights 2023: Regulations appeared first on SecurityWeek.
About SecurityWeek Cyber Insights | At the end of 2022, SecurityWeek liaised with more than 300 cybersecurity experts from over 100 different organizations to gain insight into the security issues of today – and how these issues might evolve during 2023 and beyond. The result is more than a dozen features on subjects ranging from AI, quantum encryption, and attack surface management to venture capital, regulations, and criminal gangs.
SecurityWeek Cyber Insights 2023 | Ransomware – The key purpose behind cybercriminality is to gain money. Extortion has always been a successful and preferred method to achieve this. Ransomware is merely a means of extortion. Its success is illustrated by the continuous growth of ransomware attacks over many years.
The evolution of ransomware has not been static. Its nature has changed as the criminals have refined the approach to improve the extortion, and the volume (generally upward) has ebbed and flowed in reaction to market conditions. The important point, however, is that criminals are not married to encryption, they are married to extortion.
The changing nature of what we still generally call ransomware will continue through 2023, driven by three primary conditions: the geopolitical influence of the Russia/Ukraine war, the improving professionalism of the criminal gangs, and more forceful attempts by governments and law enforcement agencies to counter the threat.
The cyberwar effectThe Russia/Ukraine war has removed our blinkers. The world has been at covert cyberwar for many years – generally along the accepted geopolitical divide – but it is now more intense and more overt. While the major powers, so far at least, have refrained from open attacks against adversaries’ critical infrastructures, criminal gangs are less concerned.
“The rate of growth in ransomware attacks is currently slowing slightly [late 2022] – but this will prove to be a false dawn,” suggests Mark Warren, product specialist at Osirium. “Currently, the most successful teams of cybercriminals are focused on attacking Ukraine’s critical infrastructure. The second that conflict is over, all the technology, tools and resources will be redeployed back into ransomware attacks – so organizations and nation states alike must not become complacent.”
One of the most likely effects of the European conflict will be an increasingly destructive effect from ransomware. This has already begun and will increase through 2023. “We are seeing an increase in more destructive ransomware attacks at scale and across virtually all sector types, which we expect to continue into 2023,” comments Aamir Lakhani, cybersecurity researcher and practitioner for FortiGuard Labs.
“Ransomware will continue to make headlines, as attacks become more destructive, and threat actors develop new tactics, techniques, and procedures to try and stay one step ahead of vendors,” agrees John McClurg, SVP and CISO at BlackBerry.
“We expect ransomware to continue its assault on businesses in 2023,” says Darren Williams, CEO and founder at BlackFog. “Specifically, we will see a huge shift to data deletion in order to leverage the value of extortion.”
There are two reasons for this move towards data deletion. Firstly, it is a knock-on effect of the kinetic and associated cyber destruction in Ukraine. But secondly it is the nature of ransomware. Remember that ransomware is merely a means of extortion. The criminals are finding that data extortion is more effective than system extortion via encryption. Andrew Hollister, CISO LogRhythm, explains in more detail:
“In 2023, we’ll see ransomware attacks focusing on corrupting data rather than encrypting it. Data corruption is faster than full encryption and the code is immensely easier to write since you don’t need to deal with complex public-private key handling as well as delivering complex decryption code to reverse the damage once the victim pays up,” he said.
“Since almost all ransomware operators already engage in double extortion, meaning they exfiltrate the data before encrypting it, the option of corrupting the data rather than going to the effort of encryption has many attractions. If the data is corrupted and the organization has no backup, it puts the ransomware operators in a stronger position because then the organization must either pay up or lose the data.”
Ransomware Resilience & Recovery Summit | March 8, 2023It should also be noted that the more destruction the criminal gangs deliver after exfiltrating the data, the more completely they will cover their tracks. This becomes more important in an era of increasing law enforcement focus on disrupting the criminal gangs.
But there is an additional danger that might escape from the current geopolitical situation. Vitaly Kamluk, head of the Asia-Pacific research and analysis team at Kaspersky explains: “Statistically, some of the largest and most impactful cyber epidemics occur every six to seven years. The last such incident was the infamous WannaCry ransomware-worm, leveraging the extremely potent EternalBlue vulnerability to automatically spread to vulnerable machines.”
Kaspersky researchers believe the likelihood of the next WannaCry happening in 2023 is high. “One potential reason for an event like this occurring,” continued Kamluk, “is that the most sophisticated threat actors in the world are likely to possess at least one suitable exploit, and current global tensions greatly increase the chance that a ShadowBrokers-style hack-and-leak could take place.”
Finally, it is worth mentioning an unexpected effect of the geopolitical situation: splintering and rebranding among the ransomware groups. Most of the larger groups are multi-national – so it should be no surprise that different members might have different geopolitical affiliations. Conti is perhaps the biggest example to date.
“In 2022, many large groups collapsed, including the largest, Conti,” comments Vincent D’Agostino, head of digital forensics and incident response at BlueVoyant. “This group collapsed under the weight of its own public relations nightmare, which sparked internal strife after Conti’s leadership pledged allegiance to Russia following the invasion of Ukraine. Conti was forced to shut down and rebrand as a result.” Ukrainian members objected and effectively broke away, leaking internal Conti documents at the same time.
But this doesn’t mean that the ransomware threat will diminish. “After the collapses, new and rebranded groups emerged. This is expected to continue as leadership and senior affiliates strike out on their own, retire, or seek to distance themselves from prior reputations,” continued D’Agostino.
The fracturing of Conti and multiple rebrandings of Darkside into their current incarnations has demonstrated the effectiveness of regular rebranding in shedding unwanted attention. “Should this approach continue to gain popularity, the apparent number of new groups announcing themselves will increase dramatically when in fact many are fragments or composites of old groups.”
SophisticationThe increasing sophistication, or professionalism, of the criminal gangs is discussed in Cyber Insights 2023: Criminal Gangs. Here we will focus on how this affects ransomware.
RaaSThe most obvious is the emergence of ransomware-as-a-service. The elite gangs are finding increased profits and reduced personal exposure by developing the malware and then leasing its use to third-party affiliates for a fee or percentage of returns. Their success has been so great that more, lesser skilled gangs will follow the same path.
“It initially started as an annoyance,” explains Matthew Fulmer, manager of cyber intelligence engineering at Deep Instinct, “but now after years of successful evolution, these gangs operate with more efficiency than many Fortune 500 companies. They’re leaner, meaner, more agile, and we’re going to see even more jump on this bandwagon even if they’re not as advanced as their partners-in-crime.”
The less advanced groups, and all affiliates of RaaS, are likely to suffer at the hands of law enforcement. “It is likely that there will be a constant battle between law enforcement agencies and ransomware affiliates. This will either be veteran/more established ransomware affiliates or new ransomware groups with novel ideas,” comments Beth Allen, senior threat intelligence analyst at Intel 471.
“Much like whack-a-mole, RaaS groups will surface, conduct attacks, be taken down or have their operations impacted by LEAs – and then go quiet only to resurface in the future. The instability within criminal organizations that we have observed will also be a contributing factor to groups fading and others surfacing to fill the void.”
Changing tacticsAs defenders get better at defending against ransomware, the attackers will simply change their tactics. John Pescatore, director of emerging security trends at SANS, gives one example: “Many attackers will choose an easier and less obtrusive path to gain the same critical data. We will see more attacks target backups that are less frequently monitored, can provide ongoing access to data, and may be less secure or from forgotten older files.”
Drew Schmitt, lead analyst at GuidePoint, sees increased use of the methodologies that already work, combined with greater attempts to avoid law enforcement. “Ransomware groups will likely continue to evolve their operations leveraging critical vulnerabilities in commonly used applications, such as Microsoft Exchange, firewall appliances, and other widely used applications,” he suggested.
“The use of legitimate remote management tools such as Atera, Splashtop, and Syncro is likely to continue to be a viable source of flying under the radar while providing persistent access to threat actors,” he added.
But, he continued, “ransomware ‘rebranding’ is likely to increase exponentially to obfuscate ransomware operations and make it harder for security researchers and defenders to keep up with a blend of tactics.”
Warren expects to see criminal ransomware attacks focusing on smaller, less well-defended organizations. “State actors will still go after large institutions like the NHS, which implement robust defenses; but there are many small to mid-size companies that invest less in protection, have limited technical skills, and find cyberinsurance expensive – all of which makes them easy targets.”
This will partly be an effect of better defenses in larger organizations, and partly because of the influx of less sophisticated ransomware affiliates. “We can expect smaller scale attacks, for lower amounts of money, but which target a much broader base. The trend will probably hit education providers hard: education is already the sector most likely to be targeted,” he continued.
He gives a specific example from the UK. “Every school in the UK is being asked to join a multi-academy trust, where groups of schools will be responsible for themselves. With that change comes great vulnerability. This ‘network’ of schools would be a prime target for ransomware attacks; they are connected, and they’re unlikely to have the resilience or capabilities to protect against attacks. They may have no choice but to reallocate their limited funds to pay ransom demands.”
But it won’t just be more of the same. More professionalized attackers will lead to new attack techniques. Konstantin Zykov, senior security researcher at Kaspersky, gives an example: the use of drones. “Next year, we may see bold attackers become adept at mixing physical and cyber intrusions, employing drones for proximity hacking.”
He described some of the possible attack scenarios, such as, “Mounting drones with sufficient tooling to allow the collection of WPA handshakes used for offline cracking of Wi-Fi passwords or even dropping malicious USB keys in restricted areas in hope that a passerby would pick them up and plug them into a machine.”
Marcus Fowler, CEO of Darktrace Federal, believes the existing ransomware playbook will lead to increased cloud targeting. “Part of this playbook is following the data to maximize RoI. Therefore, as cloud adoption and reliance continue to surge, we are likely to see an increase in cloud-enabled data exfiltration in ransomware scenarios in lieu of encryption,” he said. “Third-party supply chains offer those with criminal intent more places to hide, and targeting cloud providers instead of a single organization gives attackers more bang for their buck.”
Evasion and persistence are other traits that will expand through 2023. “We continue to see an emergence in techniques that can evade typical security stacks, like HEAT (Highly Evasive Adaptive Threats) attacks,” says Mark Guntrip, senior director of cybersecurity strategy at Menlo. “These tactics are not only are tricking traditional corporate security measures but they’re also becoming more successful in luring employees into their traps as they identify ways to appear more legitimate by delivering ransomware via less suspecting ways – like through browsers.”
Persistence, that is, a lengthy dwell time, will also increase in 2023. “Rather than blatantly threatening organizations, threat actors will begin leveraging more discreet techniques to make a profit,” comments JP Perez-Etchegoyen, CTO at Onapsis. “Threat groups like Elephant Beetle have proven that cybercriminals can enter business-critical applications and remain undetected for months, even years, while silently siphoning off tens of millions of dollars.”
David Anteliz, senior technical director at Skybox, makes a specific persistence prediction for 2023: “In 2023, we predict a major threat group will be discovered to have been dwelling in the network of a Fortune 500 company for months, if not years, siphoning emails and accessing critical data without a trace. The organizations will only discover their data has been accessed when threat groups threaten to take sensitive information to the dark web.”
Fighting ransomware in 2023The effect of ransomware and its derivatives will continue to get worse before it gets better. Apart from the increasing sophistication of existing gangs, there is a new major threat – the worsening economic conditions that will have a global impact in 2023.
Firstly, a high number of cyber competent people will be laid off as organizations seek to reduce their staffing costs. These people will still need to make a living for themselves and their families – and from this larger pool, a higher than usual number of otherwise law-abiding people may be tempted by the easy route offered by RaaS. This alone could lead to increased levels of ransomware attacks by new wannabe criminals.
Secondly, companies will be tempted to reduce their security budgets on top of the reduced staffing levels. “Once rumblings of economic uncertainty begin, wary CFOs will begin searching for areas of superfluous spending to cut in order to keep their company ahead of the game,” warns Jadee Hanson, CIO and CISO at Code42. “For the uninformed C-suite, cybersecurity spend is sometimes seen as an added expense rather than an essential business function that helps protect the company’s reputation and bottom line.”
She is concerned that this could happen during a period of increasing ransomware attacks. “These organizations may try to cut spending by decreasing their investment in cybersecurity tools or talent – effectively lowering their company’s ability to properly detect or prevent data breaches and opening them up to potentially disastrous outcomes.”
One approach, advocated by Bec McKeown, director of human science at Immersive Labs, is to treat remaining staff as human firewalls. “I believe that 2023 will be the year when enterprises recognize that they are only as secure and resilient as their people – not their technologies,” she says. “Only by supporting initiatives that prioritize well-being, learning and development, and regular crisis exercising can organizations better prepare for the future.”
Done correctly, she believes this can be achieved in a resource- and cost-effective manner. “Adopting a psychological approach to human-driven responses during a crisis – like a cybersecurity breach – will ensure that organizations fare far better in the long run.”
But perhaps the most dramatic response to ransomware will need to come from governments, although law enforcement agencies alone won’t cut it. LEAs may know the perpetrators but will not be able to prosecute criminals ‘protected’ by adversary nations. LEAs may be able to take down criminal infrastructures, but the gangs will simply move to new infrastructures. The effectively bullet-proof hosting provided by the Interplanetary File System (IPFS), for example, will increasingly be abused by cybercriminals.
The only thing that will stop ransomware/extortion will be the prevention of its profitability – if the criminals don’t make a profit, they’ll stop doing it and try something different. But it’s not that easy. At the close of 2022, following major incidents at Optus and Medibank, Australia is considering making ransom payments illegal – but the difficulties are already apparent.
As ransomware becomes more destructive, paying or not paying may become existential. This will encourage companies to deny attacks, which will leave the victims of stolen PII unknowingly at risk. And any sectors exempted from a ban will have a large target on their back.
While many foreign governments are known to be, or have been, considering a ban on ransom payments, this is unlikely to happen in the US. In a very partisan political era, the strength of the Republican party – with its philosophy of minimal government interference in business – will make it impossible.
In the end, it’s down to each of us…Ultimately, beating ransomware will be down to individual organizations’ own cyber defenses – and this will be harder than ever in 2023. “There’s no letup in sight,” comments Sam Curry, CSO at Cybereason. “Ransomware continues to target all verticals and geographies, and new ransomware cartels are popping up all the time. The biggest frustration is that it is a soluble problem.”
He believes there are ways to stop the delivery of the malware, and there are ways to prevent its execution. “There are ways to prepare in peacetime and not panic in the moment, but most companies aren’t doing this. Saddest of all is the lack of preparation at the bottom of the pyramid in smaller businesses and below the security poverty line. Victims can’t pay to make the problem go away. When they do, they get hit repeatedly for having done so. The attackers know that the risk equation hasn’t changed between one attack and the next, nor have the defenses.”
Related: It Doesn’t Pay to Pay: Study Finds 80% of Ransomware Victims Attacked Again
Related: New Zealand Government Hit by Ransomware Attack on IT Provider
Related: Ransomware, Malware-as-a-Service Dominate Threat Landscape
The post Cyber Insights 2023: Ransomware appeared first on SecurityWeek.
About SecurityWeek Cyber Insights | At the end of 2022, SecurityWeek liaised with more than 300 cybersecurity experts from over 100 different organizations to gain insight into the security issues of today – and how these issues might evolve during 2023 and beyond. The result is more than a dozen features on subjects ranging from AI, quantum encryption, and attack surface management to venture capital, regulations, and criminal gangs.
SecurityWeek Cyber Insights 2023 | Supply Chain Security – The supply chain threat is directly linked to attack surface management (it potentially represents a hidden part of the attack surface) and zero trust (100% effective zero trust would eliminate the threat). But the supply chain must be known and understood before it can be remediated.
In the meantime – and especially throughout 2023 – it will be a focus for adversaries. Why attack a single target when successful manipulation of the supply chain can get access to dozens or even hundreds of targets simultaneously.
The danger and effectiveness of such attacks is amply illustrated by the SolarWinds, log4j, Spring4Shell, Kaseya, and OpenSSL incidents.
The missed wake-up callsSupply chain attacks are not new. The iconic Target breach of late 2013 was a supply chain breach. The attackers got into Target using credentials stolen from its HVAC provider, Fazio Mechanical Services – that is, via Target’s supply chain.
The 2018 breach of Ticketmaster was another supply chain breach. A Ticketmaster software supplier, Inbenta, was breached and Inbenta software was modified and weaponized. This was automatically downloaded to Ticketmaster.
Island hopping is another form of supply chain attack. In 2017, Operation Cloud Hopper was revealed. This disclosed that an advanced group, probably APT10, was compromising managed service providers to gain access to the MSP’s customers.
Despite these incidents, it has only been in the last couple of years, fueled by more extensive incidents such as SolarWinds, that industry has become cognizant of the full threat from increasingly sophisticated and wide-ranging supply chain concerns. But we should not forget that the 2017 NotPetya incident also started as a supply chain attack. Software from the Ukrainian accounting firm M.E.Doc was weaponized and automatically downloaded by the firm’s customers, before spreading around the globe. Both SolarWinds and NotPetya are believed to be the work of nation state actors.
All forms of supply chain attacks will increase in 2023, and beyond. Chad Skipper, global security technologist at VMware, specifically calls out island hopping. “In 2023, cybercriminals will continue to use island hopping, a technique that aims to hijack an organization’s infrastructure to attack its customers,” he warns. “Remote desktop protocol is regularly used by threat actors during an island-hopping campaign to disguise themselves as system administrators. As we head into the new year, it’s a threat that should be top of mind for all organizations.”
Attacks will increaseThat supply chain attacks will increase in 2023 and beyond is the single most extensive prediction for 2023. “Supply chain attacks happen when hackers gain access to a company’s inner workings via a third-party partner, a method that provides them with a much greater amount of privileged information from just one breach,” explains Matt Jackson, senior director security operations at Code42. “This type of attack already rose by more than 300% in 2021, and I anticipate this trend will continue in 2023, with these attacks becoming more complicated and intricate.”
Lucia Milică, Resident CISO, Proofpoint
Lucia Milică, global resident CISO at Proofpoint, worries that despite all the wake-up calls so far, “We are still a long way from having adequate tools to protect against those kinds of digital supply chain vulnerabilities. We predict these concerns will mount in 2023, with our trust in third-party partners and suppliers becoming one of the primary attack channels.”
The result, she added, is, “We expect more tension in supply chain relationships overall, as organizations try to escalate their vendors’ due diligence processes for better understanding the risks, while suppliers scramble to manage the overwhelming focus on their processes.”
Jackson added, “Because many third-party partners are now privy to more sensitive data than ever before, companies can no longer rely on their own cybersecurity prowess to keep information safe,” he said.
“Supply chain attacks purposefully target the smaller organizations first because they’re less likely to have a robust cybersecurity setup, and they can use those companies to get to the bigger fish,” he continued. “In the next year, companies will become even more diligent when deciding on an outside organization to work with, creating an increase in compliance verifications to vet the cyber tools used by these prospective partners.”
Supply Chain Security and Third-Party Risk Summit | Virtual Event March 22, 2023Anand Raghavan, co-founder and CPO at Armorblox, expands on this theme. “This becomes particularly relevant,” he said, “for the Fortune 500 or Global 2000 companies that have a large ecosystem of suppliers, vendors, and distributors whose security stacks are nowhere as mature as those of large organizations. Large organizations might consider requiring all vendors to follow certain security best practices, including modernizing their email security stack if they want to continue being a vendor in good standing.”
Interestingly, despite all the warnings of an escalating threat, Christopher Budd, senior manager of threat research at Sophos, notes, “Unlike two years ago when the SolarWinds attack put supply chain attacks high on people’s radar, supply chain attacks have faded from prominence.” This may be a misleading premise. The discovery of a vulnerability in a widely used piece of software, such as the log4j vulnerability, will be used by individual cybercriminals and nation state actors alike.
However, targeted attacks such as that against SolarWinds requires resources and skill. These attributes are more usually found only in the more advanced gangs and nation state actors. Such adversaries have another attribute: patience. “Today’s and undoubtedly tomorrow’s threat actors have shown they can play the long game,” warns Pieter Arntz, senior intelligence reporter at Malwarebytes.
Budd also warns that despite their immediate lack of prominence (at the time of writing, but anything could happen tomorrow), “Supply chain may be something that continues to not gather news, similar to 2022. But it will remain a real threat and one that organizations should be prioritizing across the board, in part because effectively countering this threat requires a comprehensive, careful, methodical approach.”
The software supply chainThe primary growth area in supply chain attacks will likely be the software supply chain. “Over the past few years,” explains Eilon Elhadad, senior director of supply chain security at Aqua, “increasing pressure to deliver software faster has widened attack surfaces and introduced severe vulnerabilities.”
New tools, languages and frameworks that support rapid development at scale are being targeted by malicious actors, who understand the widespread impact that results from attacks to the software supply chain.
“In 2023,” Elhadad continued, “software supply chain threats will continue to be a significant area of concern. These attacks have a larger potential blast radius to allow hackers to impact entire markets and wreak havoc for organizations.”
Eric Byres, founder and CTO at aDolus, agrees. “Software supply chain attacks will continue to increase exponentially in 2023,” he said; “the ROI on these attacks is just too sweet for professional adversaries to resist.” He notes that supply chain attacks have increased by 742% over the last three years.
Much of the software supply chain threat comes from the growing reliance on open source software libraries as part of the ‘increasing pressure to deliver software faster’. Zack Zornstain, head of supply chain security at Checkmarx, believes the software threat will particularly affect the open source supply.
“We believe that this threat of compromising open source packages will increase as malicious code can endanger the safety of our systems, ranging from ransomware attacks to the exposure of sensitive information, and more. We expect to see this as a general attack vector used both by cyber firms and nation-state actors. SBOM adaptation will help clarify which packages we’re using in applications, but we will need to invest in more controls to ensure the safety of those packages,” he said.
“Organizations should be on high alert for supply chain attacks if they use open-source software,” warns Kevin Kirkwood, deputy CISO at LogRhythm. “Bad actors examine the code and its components to obtain a thorough understanding of its flaws and the most effective ways to exploit them.”
If the source code of an open source software library either has – or can be engineered by bad actors to have – a vulnerability, then every company that downloads and uses that code becomes vulnerable.
“In 2023,” continues Kirkwood, “we’ll see bad actors attack vulnerabilities in low-hanging open-source vendors with the intention of compromising the global supply chain that uses third-party code. Attackers will infect the open-source repositories and chromium stores with malicious code and will wait for developers and other end users to come along and pick up the new sources and plugins.”
Venafi’s Matt Barker, president of cloud native solutions, adds, “We’re seeing many instances of vulnerable code brought inside their firewall by developers trying to go fast using unverified code from GitHub, or copypasta from Stack Overflow.”
He continues, “Thankfully, we’ve reached a collective sense of focus on this area and are seeing tremendous developments in how we tackle it. This is only going to increase through 2023 as we see more start-ups popping up and open source tools like cosign and sigstore designed to help it. Biden’s SBOM initiative has helped bring attention to the requirement, and The OpenSSF is leading in this charge.”
Mark Lambert, VP of products at ArmorCode, expands on this. “As the software supply chain continues to get more complicated, it is vital to know what open source you are indirectly using as part of third-party libraries, services (APIs) or tools. This is where SBOM comes in,” he said. “By requiring a disclosure of all embedded technologies from your vendors, you can perform analysis of those libraries to further assess your risk and react appropriately.”
The SBOMBiden’s May 2021 Executive Order on Improving the Nation’s Cybersecurity introduced the concept of a software bill of materials (SBOM), effectively if not actually mandating that software bought (or supplied) by government agencies be accompanied with a bill of materials. It described the SBOM as “a formal record containing the details and supply chain relationships of various components used in building software,” and analogous to a list of ingredients on food packaging.
While the advantages of the SBOM may appear obvious in helping software developers understand precisely what is included in the open source libraries they use, it must be said that not everyone is immediately enthusiastic. In December 2022, it emerged that a lobbying group representing major tech firms such as Amazon, Microsoft, Apple, Intel, AMD, Lenovo, IBM, Cisco, Samsung, TSMC, Qualcomm, Zoom and Palo Alto Networks was urging the OMB to ‘discourage agencies’ from requiring SBOMs. The group argued that the requirement is premature and of limited value — but it didn’t ask for the concept to be abandoned.
It is the complexity and difficulty in both compiling and using an SBOM that is the problem — and it is these concerns that will drive a lot of activity through 2023. The value of the concept outlined in the executive order remains undiminished.
“Incidents such as Log4shell [log4j] and the most recent SpookySSL vulnerabilities [CVE-2022-3602 and CVE-2022-3786] will push the adoption of a software bill of materials as a core component of achieving effective incident response, while efforts will continue in maturing the SBOM ecosystem (adoption across sectors, tooling, standardization around sharing and exchanging of SBOMs and more),” explains Yotam Perkal, director of vulnerability research at Rezilion.
“One of the big challenges I see in the year ahead is that this is more data for the development teams to manage as they deliver software,” notes Lambert. “In 2023, organizations are going to need ways to automate generating, publishing and ingesting SBOMs – they will need ways to bring the remediation of the associated vulnerabilities into their current application security programs without having to adopt whole new workflows.”
As part of this process, Michael Assraf, CEO and co-founder at Vicarius, said, “We predict that a new market will evolve called binary software composition analysis, which will look for software files that are different from what was pre-packaged and shipped. Automated techniques can utilize machine learning that will find this discrepancy, which will be vital in knowing where your risk lies and how large your attack surface can potentially be.”
Thomas Pace, Co-founder & CEO at NetRiseThomas Pace, CEO at NetRise, suggests, “SBOM is going to continue to garner mainstream adoption, not just from software/firmware suppliers that are building products they are selling, but also for internal development teams that are building applications and systems for internal use.”
He adds, “The need to be able to rapidly understand the provenance of software components is becoming increasingly critical. Without this visibility, the window for attackers to exploit these vulnerabilities is much too big and puts cyber defenders at a significant disadvantage.” But he also notes, “strong efforts from organizations like Google have moved the ball forward in a positive way. Efforts such as open-source insights provide a lot of visibility for end users and vendors alike to scale out the analysis of these components.”
The problems involved with SBOM generation and use have not yet been solved, but enthusiasm remains. We can expect considerable effort into automating these processes to continue throughout 2023.
Nevertheless, Kurt Baumgartner, principal security researcher at Kaspersky, warns, “Open source projects continue to be polluted with malicious code. Awareness of these issues and challenges increase, but the attacks continue to be effective on a large scale. Despite the best efforts of software bill of materials, complex dependency chains help ensure that malicious code is uncontrolled for a time in some projects.”
The physical supply chainDespite all companies’ need to be wary of potential software supply chain attacks via the code they develop for their own use, we should not forget that there is a potentially more catastrophic physical supply chain threat. We need only consider the effect the prevention of grain supplies leaving Ukraine (because of the Russia/Ukraine conflict) had on global food supplies to see the potential. Covid-19 also affected many different global supply chains, causing panic buying and popular distress in its early days.
These were not the result of cyberattacks – but many of those physical supply chains could be disrupted by cyberattacks. The Colonial Pipeline incident, although a financially motivated attack, had an immediate effect on the supply of oil to eastern USA. The longer the Ukraine/Russia conflict continues, and the greater that east/west tensions increase, the possibility of physical supply chain cyber disruption will equally increase through 2023, and possibly beyond.
SecurityWeek discussed one such possibility in May 2022: The Vulnerable Maritime Supply Chain – a Threat to the Global Economy here.
Lorri Janssen-Anessi, director of external cyber assessments at BlueVoyant notes that in the utilities and energy sector, “99% of energy companies say they have been negatively impacted by at least one supply chain breach in the past year, representing the highest rate of overall impact in any other industry. Because it remains one of the most frequently attacked verticals, it is especially crucial that it rises to the challenge of supply chain defense in 2023.”
Taylor Gulley, senior application security consultant at nVisium, comments, “The past few years have shown that both the digital supply chain, as well as the physical world supply chain, are very fragile. This fragility is due to a lack of redundancy and resources due to economic constraints or skill gaps. For 2023, this situation will still stand true. Supply chain security is a weak link that needs to be strengthened.”
Solutions and the way forwardSam Curry, CybereasonSam Curry, CSO at Cybereason, believes the SBOM will be an important part of solving the software supply chain problem. “It would be naive in the extreme to think that with thousands of trusted software and service providers to choose from… that the handful of known supply chain compromises were the sum total of them. No. 2023 will show us more, and we will be lucky to learn of them because the attacker can quietly exploit these without tipping their hands.”
He added, “We need to use 2023 to be innovative and vigilant and to find new answers to the supply chain problem, to build on software bills of material, to innovate with the men and women building our software and to find the solutions to deter, to detect and to remove the vulnerabilities and exposures that enable this most insidious and trust eroding of attacks.”
Sharon Chand, Deloitte US’ cyber risk secure supply chain leader, believes that software supply chain security will require continuous realtime monitoring of third-party risks and vulnerabilities in inbound packaged software and firmware components. “For instance,” she said, “this includes implementing leading practice techniques around ingesting SBOMs and correlating the output to emerging vulnerabilities, identifying risk indicators such as geographical origin of the underlying components, and providing visibility to transitive dependencies.”
Christian Borst, EMEA CTO at Vectra AI, suggests collaboration and cooperation across the software industry will be required. “A holistic approach may help turn the tables on the matter: supply chain means partnership – partnership means collaboration and supporting each other. Only as a ‘mesh’ interconnected structure with consistent resiliency can companies thrive in the digital economy. This includes ensuring that they review the security policies of all those in the chain.”
Sounil Yu, CISO at JupiterOne, makes a fitting summary, referencing a paper written by Richard Danzig in July 2014 (Surviving on a Diet of Poisoned Fruit: Reducing the National Security Risks of America’s Cyber Dependencies). “To borrow Richard Danzig’s analogy,” says Yu, “we are on a diet of poisoned fruit with respect to our software supply chain. This poison is not going to go away, so we will need to learn how to survive and thrive under these conditions. Being aware of the risks, through efforts such as SBOM, and managing the risks through compensating controls such as egress filtering, will be a priority in 2023 and the foreseeable future.”
Related: US Gov Issues Software Supply Chain Security Guidance for Customers
Related: OpenSSF Adopts Microsoft-Built Supply Chain Security Framework
Related: Hundreds Infected With ‘Wasp’ Stealer in Ongoing Supply Chain Attack
Related: US Gov Issues Supply Chain Security Guidance for Software Suppliers
The post Cyber Insights 2023 | Supply Chain Security appeared first on SecurityWeek.
About SecurityWeek Cyber Insights | At the end of 2022, SecurityWeek liaised with more than 300 cybersecurity experts from over 100 different organizations to gain insight into the security issues of today – and how these issues might evolve during 2023 and beyond. The result is more than a dozen features on subjects ranging from AI, quantum encryption, and attack surface management to venture capital, regulations, and criminal gangs.
SecurityWeek Cyber Insights 2023 | Quantum Computing and the Coming Cryptopocalypse – The waiting time for general purpose quantum computers is getting shorter, but they are still probably decades away. The arrival of cryptanalytically-relevant quantum computers (CRQCs) that will herald the cryptopocalypse will be much sooner – possibly less than a decade.
At that point our existing PKI-protected data will become accessible as plaintext to anybody; and the ‘harvest now, decrypt later’ process will be complete. This is known as the cryptopocalypse. It is important to note that all PKI-encrypted data that has already been harvested by adversaries is already lost. We can do nothing about the past; we can only attempt to protect the future.
Here we are going to examine the why, what, and how we need to prepare for that cryptopocalypse – but first we need a few definitions to ensure we’re all singing the same song.
The cryptopocalypseThe cryptopocalypse is the point at which quantum computing becomes powerful enough to use Shor’s algorithm to crack PKI encryption. Since public key encryption is used to secure almost all data in transit, both between separate IT infrastructures and even within individual infrastructures, that data will become accessible by anyone with a sufficiently powerful quantum computer.
“That means that all secrets are at risk,” explains Bryan Ware, CEO at LookingGlass; “nuclear weapons, banks, business IP, intelligence agencies, among other things, are at risk of losing their confidentiality and integrity.”
But this is not a threat for the future – the threat exists today. Adversaries are known to be stealing and storing encrypted data with the knowledge that within a few years they will be able to access the raw data. This is known as the ‘harvest now, decrypt later’ threat. Intellectual property and commercial plans – not to mention military secrets – will still be valuable to adversaries when the cryptopocalypse happens.
“Even if a cryptographically relevant quantum computer is still years away, the time to start preparing is now,” warns Rebecca Krauthamer, co-founder and CPO at QuSecure.
The one thing we can say with certainty is that it definitely won’t happen in 2023 – probably. That probably comes from not knowing for certain what stage in the journey to quantum computing has been achieved by foreign nations or their intelligence agencies – and they’re not likely to tell us. Nevertheless, it is assumed that nobody yet has a quantum computer powerful enough to run Shor’s algorithm and crack PKI encryption in a meaningful timeframe.
It is likely that such computers may become available as soon as three to five years. Most predictions suggest ten years. Note that a specialized quantum computer designed specifically for Shor does not need to be as powerful as a general-purpose quantum computer – which is more likely to be 20 to 30 years away.
It is difficult to make precise predictions because the power of a quantum computer comes from the number of qubits that can be used. This is further complicated by the instability of qubits that require a high number of additional qubits used solely for error correction. Consequently, the number of qubits that can be ‘used’ (logical qubits) is much less than the total number needed (physical qubits).
It has been suggested that as many as 1,000 physical qubits may be required for each logical qubit. This will depend on the quality of the error correction in use – and this is an area of intense research. So, at some time in the next few years, as the number of physical qubits increases, and the number of required physical qubits per logical qubit decreases, quantum developers will have a quantum computer able to crack PKI. It has been estimated that this will require between approximately 1,000 and 2,000 logical qubits.
To put some flesh on this skeleton, we can look at an announcement made by IBM on November 9, 2022: a new 433 qubit Osprey processor. This was accompanied by a roadmap that that shows a progression toward a 4,000 plus qubit quantum computer, codenamed Kookaburra, due in 2025.
Error correction is being approached by a new version of IBM’s Qskit Runtime software that allows ‘a user to trade speed for reduced error count with a simple option in the API’. This is supported by a new modular IBM Quantum System Two able to combine multiple processors into a single system with communication links. System Two is expected to go live in 2023, around the same time that IBM expects to have a 1k+ qubit processor codenamed Condor.
System Two will be a building block in what IBM calls quantum-centric supercomputing. Scott Crowder, the VP of IBM quantum adoption and business, explains in more detail: “Quantum-centric supercomputing (which describes a modular architecture and quantum communication designed to increase computational capacity, and which employs hybrid cloud middleware to seamlessly integrate quantum and classical workflows) is the blueprint for how quantum computing will be used in the years to come.”
He added, “This approach to scaling quantum systems alongside the recent, dramatic improvements in techniques to deal with quantum processor errors is how we envision a path to near-term, practical quantum advantage – the point when quantum processors will be capable of performing a useful computation, faster, more accurately, or cheaper than using exclusively classical computing.”
Navigating such projections doesn’t tell us precisely when to expect the cryptopocalypse, but they clearly show it is getting perilously close. “Quantum computing is not, yet, to the point of rendering conventional encryption useless, at least that we know of, but it is heading that way,” comments Mike Parkin, senior technical engineer at Vulcan Cyber.
The additional threat from AISkip Sanzeri, co-founder and COO at QuSecure, warns that the threat to current encryption is not limited to quantum decryption. “New approaches are being developed promising the same post-quantum cybersecurity threats as a cryptographically relevant quantum computer, only much sooner,” he said. “It is also believed that quantum advancements don’t have to directly decrypt today’s encryption. If they weaken it by suggesting or probabilistically finding some better seeds for a classical algorithm (like the sieve) and make that more efficient, that can result in a successful attack. And it’s no stretch to predict, speaking of predictions, that people are going to find ways to hack our encryption that we don’t even know about yet.”
Steve Weston, co-founder and CTO at Incrypteon, offers a possible illustration. “Where is the threat in 2023 and beyond?” he asks. “Is it the threat from quantum computers, or is the bigger threat from AI? An analysis of cryptoanalysis and code breaking over the last 40 years shows how AI is used now, and will be more so in the future.”
QKDQuantum key distribution (QKD) is a method of securely exchanging encryption keys using quantum properties transmitted via fiber. While in this quantum state, the nature of quantum mechanics ensures that any attempt to access the transmission will disturb the content. It does not prevent attacks, but ensures that an attempted attack is immediately visible, and the key can be discarded. Successful QKD paves the way for data to be transmitted using the latest and best symmetrical encryption. Current symmetrical algorithms are considered safe against quantum decryption.
“Symmetric encryption, like AES-256, is theorized to be quantum aafe, but one can speculate that key sizes will soon double,” comments Silvio Pappalardo, chief revenue officer at Quintessence Labs.
“Quantum cryptography is a method of encryption that uses the principles of quantum physics in securing and transmitting data,” says Ganesh Subramanya, head of data protection CoE cybersecurity at TCS. “It creates security so strong that data coded in quantum state cannot be compromised without the sender being notified. Traditional cryptography uses technologies like SSL and TLS to secure data over the internet, but they have been vulnerable to a variety of attacks, as an attacker can change the communication between two parties (like user’s browser and the webpage / application) and make them believe they’re still communicating with each other. With quantum cryptography, such an alteration of data is not possible, thereby strengthening the security of online transactions.”
John Prisco, Toshiba partner and president/CEO of Safe Quantum, applies these principles to QKD. “Quantum key distribution contains a key security aspect that cannot be overstated,” he says, “especially if it is being utilized in tandem with the NIST post-quantum encryption standards (PQC). The gold standard in cybersecurity is considered to be defense in-depth, as this leverages two totally different technologies with diverse failure mechanisms, working for protection. With harvest now decrypt later attacks becoming more frequent, there is no delay time that is safe to defend against quantum attacks. QKD authenticated with PQC signature algorithms is the only defense that can be deployed immediately and guarantee a successful defense against harvest now, decrypt later.”
Terry Cronin, the VP at Toshiba who oversees the QKD Division, agrees with this assessment. “The use of QKD as part of a hybrid solution to quantum resistance can offer the security needed ensuring that a harvest and decrypt attack cannot succeed in accessing the data.”
The practical difficulties in introducing wide-scale fiber based QKD means that it cannot be implemented everywhere. Its immediate use will likely be limited to point-to-point communications between high value sites – such as some government agencies and between major bank offices.
Post Quantum CryptographyNISTNIST began a competition to select and standardize post quantum encryption algorithms in 2016. “We’re looking to replace three NIST cryptographic standards and guidelines that would be the most vulnerable to quantum computers,” said NIST mathematician Dustin Moody at the time. “They deal with encryption, key establishment and digital signatures, all of which use forms of public key cryptography.”
In July 2022, NIST announced its first four finalists. However, it emerged in August 2022 that a different finalist, the Supersingular Isogeny Key Encapsulation (SIKE) algorithm had already been broken. SIKE is designed to deliver keys securely from source to destination across an untrusted network. Researchers had demonstrated, however, the algorithm could be cracked on a single classical PC in little over an hour.
This illustrates a problem that all security professionals need to confront. Any encryption algorithm is secure only until it is cracked. Whitehat researchers will tell you if they can crack an algorithm — foreign governments will not. In effect, this means that the ‘later’ part of ‘harvest now, decrypt later’ is an optimistic view. We believe that encrypted IP being stolen today cannot yet be decrypted — but we cannot be certain.
We do, however, know that current PKI encryption will certainly be broken by quantum computers in the relatively near future. The solution from NIST is to replace current vulnerable PKI algorithms with more complex algorithms — that is to solve more powerful computing by using more powerful algorithms.
Ultimately, we will be in the same position we are in today. We will believe our IP protected by NIST’s post quantum algorithms will be safe — but we cannot be certain. Remember that at least one proposed post-quantum algorithm has been broken on a PC. So, even if we switch to a NIST-approved post quantum encryption standard tomorrow, we cannot be certain that the harvest now decrypt later philosophy has been beaten.
One-time padsNIST’s PQC algorithms are ‘quantum safe’, they are not ‘quantum secure’. The former is thought to be safe against quantum decryption but cannot be proven to be so (since they are mathematical in nature and susceptible to mathematical decryption). Cryptography that can be proven to be safe is known as ‘quantum secure’ — and the only way to achieve this is to remove mathematics from the equation.
The only quantum secure cryptography known is the one-time pad because it relies on information security rather than mathematical security. Technically, QKD could be described in similarly secure terms since any attempt to obtain the keys for mathematical decryption could result in the immediate destruction of the keys (preventing them from being usefully decrypted). We have already seen that QKD has problems for widespread use — but it remains an open question whether modern technology is able to deliver usable one-time pads.
Historically, OTP has been considered unworkable for the internet age because it requires keys of the same length or longer than the message being encrypted. Nevertheless, several companies have been exploring the possibilities becoming available with new technology.
Qrypt started from the basis that the quantum threat comes from the communication of encryption keys from source to destination. If you can avoid the necessity to communicate the keys, you can eliminate the threat. It consequently developed a process that allows the generation of the same quantum random numbers simultaneously at both source and destination. A quantum random number is a genuinely random number generated with quantum mechanics principles. These numbers can then be used to generate identical keys without them needing to be transmitted across the internet.
However, since the generation of the numbers can be performed and stored until use, there remains the potential to chain the process to provide genuine OTP for the keys without requiring them to be transmitted across the internet. Solutions based on this process are quantum secure.
Incrypteon, a British startup, has taken a different route by applying Shannon’s information theories to the one-time pad. The science is a bit mind-numbing but is based on Shannon’s equivocation from his Communication Theory of Secrecy Systems published in 1949. “The definition of perfect secrecy is based on statistics and probabilities,” says Incrypteon. “A ciphertext maintains perfect secrecy if the attacker’s knowledge of the contents of the message is the same both before and after the adversary inspects the ciphertext, attacking it with unlimited resources.”
Using its own patented software and ‘Perpetual Equivocation’, Incrypteon “ensures that conditional entropy never equals zero, therefore achieving Perfect Secrecy.” The result is something that is automatically quantum secure (not just quantum safe) — and is available today.
Co-founder Helder Figueira had been an electronic warfare signals officer commanding a cryptanalysis unit in the South African Army. The concepts of Shannon’s equivocation are well-understood by the military, and he has long-been concerned that the commercial market is forced to accept encryption that is, by definition, ‘insecure’ — if something cannot be proven to be secure, it must be insecure.
A third and potentially future approach to the one-time pad could evolve from current advances in tokenization – more specifically cloud-based vaultless tokenization protected by immutable servers.
Rixon, another startup, is involved in this area. Its primary purpose is to protect PII stored by organizations with a web presence – but the principles could easily be extended. Plaintext is immediately tokenized in the cloud, and no plaintext is held onsite. Nor is the plaintext held at the tokenization engine in the cloud – all that is stored is the tokenization route for each tokenized character (for the purpose of comparison, this tokenization route is equivalent to the cryptographic key, but is random for each character).
This provides the primary parallel with the OTP – the ‘key’ is the same length as the message. Currently, Rixon concentrates on tokenizing PII; but the same concept could be extended to secure high value files at rest such as intellectual property and commercial plans.
Transition to post quantum cryptographyThe coming cryptopocalypse requires organizations to transition from known quantum-vulnerable encryption (such as current PKI standards) to something that is at least quantum safe if not quantum secure. This will be a long process, and in 2023 businesses will need to start planning their route in greater detail.
Most companies will start from the viewpoint that NIST post-quantum algorithms is the only way forward. We have discussed OTP developments in some depth to show that the NIST route is not the only available route – and we expect further OTP developments during 2023.
The full transition to post quantum readiness will take many years, and will not be achieved by throwing a switch from classical to PQC. This has led to the concept of ‘crypto agility’. “It will be essential that quantum ready algorithms (QRAs) are able to coexist with existing cryptographic capabilities, in a hybrid manner, while the complete transition to quantum safe occurs,” explains Silvio Pappalardo, chief revenue officer at Quintessence Labs.
“Crypto agility enables applications to migrate between key types and cryptographic algorithms without the need to update the application software — transitioning from homogenous towards micro-service architecture,” he said. “With encryption ciphers changing due to the threat of quantum, decreasing longevity, increasing key sizes, and the expanding requirements to protect more data, more effectively, crypto agility becomes a business enabler and defender to keep pace with constant innovations and enable greater flexibility into the future.” Such agility also allows companies to switch from one quantum safe algorithm to another if the one in use gets broken.
For now, government agencies will have little choice but to follow NIST. On November 18, 2022, the White House issued a memorandum to the heads of executive departments and agencies requiring that CRQC readiness begins with taking an inventory of vulnerable assets. “By May 4, 2023, and annually thereafter until 2035”, states the memo, “agencies are directed to submit a prioritized inventory of information systems and assets, excluding national security systems, that contain CRQC-vulnerable cryptographic systems to ONCD and the Department of Homeland Security Cybersecurity and Infrastructure Security Agency (CISA).”
(This confirmed earlier details announced in the National Security Memorandum NSM/10 published on May 4, 2022.)
On December 21, 2022, Biden signed the Quantum Computing Cybersecurity Preparedness Act into law. “Quantum computers are under development globally with some adversarial nation states putting tens of billions of dollars into programs to create these very powerful machines that will break the encryption we use today,” comments Sanzeri. “While not here yet, quantum computers will be online in coming years, but it will take more than a few years for our federal agencies and commercial enterprises to upgrade their systems to post quantum cybersecurity.”
This Act, he continued, “requires federal agencies to migrate systems to post quantum cryptography which is resilient against attacks from quantum computers. And the Office of Management and Budget is further required to send an annual report to Congress depicting a strategy on how to assess post-quantum cryptography risks across the federal government.”
The government is clearly wedded to the NIST proposals. This may be because NIST is correct in its assertion that OTP is not realistic. NIST computer security mathematician Dustin Moody told SecurityWeek in October 2022, “The one-time pad must be generated by a source of true randomness, and not a pseudo-random process.” But there are numerous sources for the generation of genuinely random numbers using quantum mechanics.
“The one-time pad must be as long as the message which is to be encrypted,” added Moody. “If you wish to encrypt a long message, the size of the one-time pad will be much larger than key sizes of the algorithms we [NIST] selected.” This is also being challenged as a problem by both Qrypt and Incrypteon, and potentially tokenization firms like Rixon.
Nevertheless, most companies will follow the incremental process of NIST rather than the more revolutionary process of OTP, if only because of NIST’s reputation and government support. 2023 will see more companies beginning their move to CRQC readiness – but there are more options than are immediately obvious.
Related: Quantum Computing’s Threat to Public-key Cryptosystems
Related: Quantum Computing Is for Tomorrow, But Quantum-Related Risk Is Here Today
Related: Solving the Quantum Decryption ‘Harvest Now, Decrypt Later’ Problem
Related: Is OTP a Viable Alternative to NIST’s Post-Quantum Algorithms?
The post Cyber Insights 2023: Quantum Computing and the Coming Cryptopocalypse appeared first on SecurityWeek.
Researchers warn that many electric vehicle (EV) charging management systems are affected by vulnerabilities that could allow hackers to cause disruption, steal energy, or obtain driver information.
The vulnerabilities were discovered by researchers working for SaiFlow, an Israel-based company that specializes in protecting EV charging infrastructure and distributed energy resources.
The security holes are related to the communications between the charging system management service (CSMS) and the EV charge point (CP), specifically the use of the Open Charge Port Protocol (OCPP). The flaws have been confirmed to impact the CSMS offered by multiple vendors.
The problem is related to the use of WebSocket communications by the OCPP and how it mishandles multiple connections. The protocol does not know how to handle more than one CP connection at a time and attackers could abuse this by opening a new connection to the CSMS. Another issue is related to what SaiFlow describes as “weak OCPP authentication and chargers identities policy”.
By opening a new connection to the CSMS on behalf of a charge point, the attacker causes the original connection to be closed or to become nonfunctional.
According to SaiFlow, an attacker can exploit the weaknesses to launch a distributed denial-of-service (DDoS) attack that disrupts the electric vehicle supply equipment (EVSE) network. In addition, if an attacker can connect to the CSMS, they may be able to obtain drivers’ personal information, including payment card data, as well as other sensitive data, such as server credentials.
In certain configurations, if the charger approves unknown driver identities, an attacker may be able to charge their vehicle without paying for it, the security firm said.
“Since the CSMS platforms are publicly accessible, it is possible for an attacker to hijack the connection remotely, without needing to gain credentials, access, or perform MITM attacks,” Ron Tiberg-Shachar, co-founder and CEO of SaiFlow, told SecurityWeek.
Tiberg-Shachar believes it may be possible for a somewhat inexperienced hacker to carry out an attack, even with limited resources.
In order to conduct an attack, the hacker first needs to obtain a charger’s identity. This identity typically has a standard structure, making it easier for threat actors to enumerate the values of valid identifiers.
In the next phase, they need to obtain information on which CSMS platform the charger is connected to. The expert noted that the CSMS URL can be discovered using services such as Shodan or SecurityTrails.
SaiFlow has published a technical blog post describing the vulnerabilities and the attack scenarios. The company also provides recommendations for how these types of attacks can be mitigated.
It doesn’t seem like the vulnerabilities can be easily patched by vendors.
“We’ve approached many key players in the industry (and keep on doing so) to make them aware of our findings and how they can approach a solution,” Tiberg-Shachar said. “Additionally, we’ve made our solutions team available to support any specific technical questions, in an effort to reinforce vulnerabilities as quickly as possible. Our key goal is to support partners in scaling their charging infrastructure as quickly and safely as possible.”
Related: Unpatched Econolite Traffic Controller Vulnerabilities Allow Remote Hacking
Related: Remote ‘Brokenwire’ Hack Prevents Charging of Electric Vehicles
Related: New Flaws Expose EVlink Electric Vehicle Charging Stations to Remote Hacking
The post EV Charging Management System Vulnerabilities Allow Disruption, Energy Theft appeared first on SecurityWeek.
Check Point and Phylum are warning of recently identified NPM and PyPI packages designed to steal user information and download additional payloads.
Taking advantage of the broad use of open source code in application development, malicious actors are increasingly relying on software supply chain attacks to infect both developers and users with malware.
According to an October 2022 Sonatype report, the number of software supply chain attacks observed in 2022 was 633% higher compared to the previous year.
Node.js (NPM) and Python (PyPI) repositories are the preferred targets for malicious packages, mainly because code execution can be triggered during package installation, Check Point notes.
In a new report, the cybersecurity firm says it has identified two malicious Python packages that fit this description.
The first of them, Python-drgn, was uploaded to PyPI on August 8, 2022. Relying on typo-squatting, the package is meant to attract users who are looking for Drgn, a debugger with an emphasis on programmability.
The malicious package consists of a single setup.py file, which automatically runs during package installation and which contains malware. When executed, the malware stores the username, the working directory’s path, and networking information, and sends it to a remote, private Slack channel.
The second malicious package is named bloxflip, typosquatting the Bloxflip.py package, which is an API wrapper for bloxflip.com.
The malicious code within bloxflip disables Windows Defender to prevent detection, then fetches an executable from a remote server, creates a subprocess, and executes the malicious payload.
Phylum, on the other hand, says it has discovered over 100 malicious NPM packages that contain the payload in package.json’s postinstall script, which is executed during package installation.
The malicious script harvests various types of information from the infected system (including hostname, username, working directory, and package name and version) and sends it to an attacker-controlled server.
The software supply chain security firm also observed the package authors changing the remote server address over the course of 24 hours.
“Code package supply chain attacks, in which attackers publish malicious packages or inject malicious code into legitimate code packages distributed through online code repositories and package managers, have increased significantly in recent years. These attacks can have serious consequences, including data compromise, operational disruption, and reputation damage,” Check Point concludes.
Related: PyPI Users Targeted With ‘Wacatac’ Trojan in New Supply Chain Attack
Related: Malware Delivered to PyTorch Users in Supply Chain Attack
Related:Hundreds Infected With ‘Wasp’ Stealer in Ongoing Supply Chain Attack
The post Malicious NPM, PyPI Packages Stealing User Information appeared first on SecurityWeek.
The urgency to patch a trio of dangerous security flaws in a VMware virtual appliance product escalated this week after exploit code was published on the internet.
VMware confirmed the publication of exploit code in an update to its VMSA-2023-0001 bulletin and called on customers using its VMware vRealize Log Insight product to implement mitigations as a matter of urgency.
The vulnerabilities, tracked as CVE-2022-31706, CVE-2022-31704 and CVE-2022-31710, are rated critical with CVSS severity scores of 9.8 out of 10.
The security defects affect users of its VMware vRealize Log Insight and could be exploited by an unauthenticated attacker to take full control of a target system.
VMware described the flaws as directory traversal and broken access control issues with dangerous implications and warned that “an unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.”
The bulletin update follows the publication of a technical deep-dive by automated penetration testing firm Horizon3.ai that included demo exploit code. The company also released IOCs (indicators of compromise) to help defenders hunt for signs of compromise.
VMware’s VRealize Log Insight is a log collection and analytics virtual appliance used by administrators to collect, view, manage and analyze syslog data.
Related: VMware Plugs Critical vRealize Code Execution Flaws
Related: VMware Patches VM Escape Flaw Exploited at Geekpwn Event
Related: Gaping Authentication Bypass Holes in VMware Workspace One
Related: VMware Confirms Workspace One Exploits in the Wild
The post VMware Confirms Exploit Code Released for Critical vRealize Logging Vulnerabilities appeared first on SecurityWeek.
The digital supply chain is probably more extensive and more complicated than you realize. Upward of 98% of organizations have a relationship with at least one third party that has experienced a breach in the last two years – and these figures are almost certainly no exaggeration.
The figures come from a report by SecurityScorecard. More than 230,000 organizations were examined to discover their relationships with third parties. Third parties were investigated to examine fourth parties (on which the third parties depend before delivering services to the first party). The expansion of relationships grows so rapidly that it makes six degrees of separation likely to be a conservative estimation.
From the figures: 98% of organizations have a relationship with a third party that has been breached, while more than 50% have an indirect relationship with more than 200 fourth parties that have been breached. These figures do not suggest that the first parties have been breached, but they do indicate the extent of risk exposure via the supply chain.
The escalating nature of third and fourth-party relationshipsIt is worth reflecting on the term ‘breach’. Some commentators include data exposure within the term – so an organization with an unsecured cloud database is described as breached. This is not how SecurityScorecard uses the term in this report.
“We define a breach as any incident where parties gain unauthorized access to computer data, applications, networks, or devices,” Mike Woodward, VP data quality and trust at SecurityScorecard, told SecurityWeek. “The parties could be intruding threat actors who bypass or penetrate security mechanisms from the internet, or they could be organization insiders who abuse their privileged access to data and resources.”
Supply Chain Security and Third-Party Risk Summit | Virtual Event – March 22, 2023Knowledge of a breach comes from public knowledge: from government disclosures and press reports. “Every day, we scan multiple sources, including government websites and press reports, for reports of breaches. We’re careful about the sources we will accept, and we point back to our source so our users can check for themselves,” he continued.
Of course, not all organizations disclose that they have been breached, and not all organizations even know they have been breached. So, the effect of this methodology means SecurityScorecard’s statement that ‘98% of organizations have a relationship with a third (or fourth) party that has been breached’ can only be the most conservative of estimates.
“SecurityScorecard’s data demonstrates why managing cyber risk across the digital supply chain is absolutely critical as threat actors work to exploit any vulnerabilities an organization may have. Identifying and continuously monitoring all partners and customers within the digital supply chain is key to staying ahead of any potential risk,” comments Wade Baker, partner and co-founder at The Cyentia Institute (a data-driven cybersecurity research group).
“By having full visibility into the security posture of their third and fourth parties, organizations can work with their vendors to address any cybersecurity gaps they may have in their infrastructure and, in turn, reduce their own level of cyber risk.”
The report highlights which sectors have the highest number of third party relationships, notes that more secure first parties still have relationships with the less secure third parties, points out that third parties are 5x more likely to exhibit poor security, and even enumerates the number of companies that have relationships with foreign organizations.
“Seven percent of firms have relationships with vendors in only their home country (no foreign ties),” states the report. “About 59% of organizations have connections to five or fewer countries, and roughly 14% have vendors spanning 10 or more countries.” This doesn’t necessarily increase or decrease cyber risk, but it highlights a potentially overlooked complication: compliance with international laws, security requirements, and other geopolitical issues.
The overriding conclusion of the report is that no firm can afford to be insular about its cybersecurity. It must have visibility into its own digital ecosystem, but also similar visibility into the security of its suppliers – including, perhaps, the fourth party suppliers. And if that visibility is unavailable, maybe the risk of a relationship is too great.
Related: OpenVEX Spec Adds Clarity to Supply Chain Vulnerability Warnings
Related: PyPI Users Targeted With ‘Wacatac’ Trojan in New Supply Chain Attack
Related: Malware Delivered to PyTorch Users in Supply Chain Attack
Related: Iranian Hackers Deliver ‘Fantasy’ Wiper to Diamond Industry via Supply Chain Attack
The post 98% of Firms Have a Supply Chain Relationship That Has Been Breached: Analysis appeared first on SecurityWeek.
Dutch cyber authorities said Wednesday that several hospital websites in the Netherlands and Europe were likely targeted by a pro-Kremlin hacking group because of their countries’ support for Ukraine.
The UMCG hospital in the northern Dutch city of Groningen, one of the largest in the country, saw its website crash in a cyberattack on Saturday.
“European hospitals including in the Netherlands have most likely been hit by the pro-Russian hacking group Killnet,” said the Dutch National Cyber Security Centre (NCSC).
“This group announced DDoS attacks on among other things, hospitals (in countries) helping Ukraine in its war against Russia,” it said.
A distributed denial-of-service (DDoS) attack is designed to overwhelm the target with a flood of internet traffic, preventing the system from functioning normally.
Although reports say that Killnet threatened to target some 31 hospitals throughout the Netherlands, so far only the UMCG seems to have been affected.
“Currently the DDoS attacks are successfully mitigated and the impact of the attacks is limited,” the NCSC said.
Hospitals in Britain, Germany, Poland, Scandinavia and the United States were also said to be targeted.
Last week the websites of German airports, public administration bodies and financial sectors were hit in an attack believed to have been launched by Killnet.
The same group was also linked to a DDoS attack on the European Parliament website in November, shortly after lawmakers approved a resolution calling Moscow a “state sponsor of terrorism.”
The post Dutch, European Hospitals ‘Hit by Pro-Russian Hackers’ appeared first on SecurityWeek.
Israeli venture group Team8 has bankrolled an $11 million seed-stage investment in Gem Security, a startup with ambitious plans in the cloud threat detection and incident response space.
Gem Security, based in Tel Aviv, emerged from stealth Wednesday with technology that promises to give corporate security teams a practical way to manage threat detection, investigation and response in cloud deployments.
The company said its product supports all major infrastructure platforms — AWS, Azure, Google Cloud and Kubernetes — and integrates with identity providers, source code repositories and secrets managers, leveraging the additional data for context analysis.
Gem Security and its investors are betting that there’s a growing market for enabling cloud security operations as attack surfaces expand exponentially with enterprise digital transformation activities.
“The adoption of cloud infrastructure is increasing and diversifying the attack surface for organizations. 90% of all organizations use more than one cloud provider,” Gem Security said in a note announcing the funding.
“The expansion in attack surface is rarely paralleled with coverage by detection and response initiatives, leaving organizations unaware of a variety of threat vectors. 79% of companies have experienced at least one cloud data breach in the last 18 months, with 43% of companies reporting ten or more,” the company added.
While there is no shortage of products for detection and response, Gem Security is arguing that legacy approaches fall short of providing tooling for the cloud era. Today, the company says companies must work continuously on preparation, detection, investigation and response to cloud data threats.
Related: Sentra Raises $30 Million for DSPM Technology
Related: What’s Going on With Cybersecurity VC Investments?
Related: Predictions 2023: Big Tech’s Coming Security Shopping Spree
The post Gem Security Gets $11 Million Seed Investment for Cloud Incident Response Platform appeared first on SecurityWeek.
For the second day in a row, public schools on the tiny island of Nantucket remained closed Wednesday as administrators scrambled to cope with a ransomware attack on its computer systems.
According to published reports, Nantucket’s five public schools shut its doors to students and teachers after a data encryption and extortion attack prompted staff to shut down the internet along with all student and staff devices — including phones and security cameras.
“Out of an abundance of caution, we will be canceling school tomorrow, Wednesday, Feb. 1, for all staff and students,” school superintendent Beth Hallett wrote in a message to the school community.
The schools were first closed on Tuesday morning and all 1,700 students and staff were sent home “for the safety and security of all.”
Hallett said the school district has hired outside data security experts to work alongside its IT department to recover data and restore computer and internet service.
There is no information on whether a ransom payment was paid or the extent of damage from data encryption or data theft.
Education institutions have become a popular target for ransomware attacks with multiple schools reporting malware infections that lead to data being encrypted and costly ransom demands.
Related: Ransomware Attack Hits School District Twice in 4 Months
Related: Arizona Schools Provide Model for Managing Ransomware
Related: Ransomware Hit 200 US Gov, Education and Healthcare Orgs in 2022
Related: Clark County Schools Reports Computer Ransomware Attack
The post Ransomware Leads to Nantucket Public Schools Shutdown appeared first on SecurityWeek.
As we reflect on 2022, we’ve seen that malicious actors are constantly coming up with new ways to weaponize technologies at scale to cause more disruption and devastation.
The dangers are showing up everywhere – and more frequently. The volume and variety of threats, including Ransomware-as-a-Service (RaaS) and novel attacks on previously less conventional targets, are of particular concern to CIOs and CISOs.
Increasingly, cybercrime is big business run by highly organized groups rather than individuals. Much like the mythological hydra, cutting off the head of one of these organizations (i.e. just stopping a few low level operators in their tracks) isn’t going to solve the problem; the key is to disrupt the networks themselves. That’s a tall order – one that’s going to require widespread collaboration.
Cybercrime networks and Cybercrime-as-a-Service
We anticipated that in 2022 there would be an increase in pre-attack reconnaissance and weaponization among attackers. This would open the door for the growth of Crime-as-a-Service (CaaS) to accelerate even faster.
That prediction of cybercrime proved to be accurate. The FortiGuard Labs team documented 10,666 new ransomware variations in the first half 2022 compared to just 5,400 in the second half of 2021. That’s an almost 100% increase in the number of new ransomware variants found. The rise in popularity of RaaS on the dark web is the main cause of this sudden increase of new ransomware strains.
RaaS is mostly to blame for the explosive growth in ransomware variants, and ransomware payments are also rising. U.S. financial institutions spent close to $1.2 billion on likely ransomware payments in 2021, according to the Financial Crimes Enforcement Network (FinCEN) of the U.S. Treasury. That was more than double the prior year, and if that trend continues, results from 2022 will be even higher.
Our current predictions indicate that the CaaS market will grow dramatically through 2023 and beyond, with threat actors soon being able to subscribe to new exploits, services and structured programs.
We’re also predicting that threat actors will soon have access to more readymade, “as a service” products. This means even more cybercriminals of all levels will be able to launch more complex attacks without first devoting time and money to creating their own strategy. Additionally, producing and offering “aaS” attack portfolios is a straightforward, efficient, and repeatable way for seasoned hackers to make money, meaning the business model pays. Prepare yourself for an enhanced CaaS catalog to appear in 2023 and beyond as a result.
Collaboration is key
It can’t be emphasized enough: the key to disrupting cybercrime networks is collaboration across the private and public sector. One illustration is what the World Economic Forum’s Partnership Against Cybercrime is doing (PAC). In response to the pandemic’s unparalleled and exponential development in cybercriminal activity, PAC has concentrated on fusing the digital know-how and data of the business sector with the threat information of the government sector to help disrupt cybercrime ecosystems.
It will be simpler to overcome the restrictions that protect hackers if a worldwide strategy and coordinated effort are used to remove communication barriers. It is everyone’s duty to disrupt bad actors and destroy the attack infrastructure, and this calls for solid, reliable partnerships with other organizations. Cybercriminals run their operations like businesses; therefore, the more we can make them rebuild, change their strategies, and start over, the better off digital assets will be.
Not only do we want to stop attacks from happening, but we also want to take down cybercriminals and make them modify how they operate, which costs them effort, time and resources. Sharing actionable threat intelligence among organizations and influencing how cyberthreat mitigation will be done in the future are crucial.
Private-public collaboration in practice
An example of how this kind of collaboration can be used to disrupt cybercrime networks is the recent African Cyber Surge Operation. The collaboration between INTERPOL, FortiGuard Labs and other INTERPOL private partners resulted in the successful Cyber Surge operation and the dissemination of intel to several law enforcement organizations in the Africa region.
Partners such as FortiGuard Labs offered actionable threat intelligence based on infrastructure research of malware, botnets and command and control (C2), including C2 and malware victims across Africa. The Africa Cyber Surge Operation, which began in July 2022, has brought together law enforcement (LE) officers from 27 nations. They collaborated for almost four months on actionable intelligence provided by INTERPOL private partners.
Through a coordinated effort between INTERPOL, AFRIPOL and the participating nations, this operation targeted both cybercriminals and compromised network infrastructure in Africa. Member nations were able to identify more than 1,000 malicious IP addresses, dark web marketplaces and specific attackers.
The Africa Cyber Surge Operation is a great example of how joint operations and sharing threat intelligence on threat actors among reliable partners can increase an entire region’s cyber resilience. It also demonstrates the need of cybersecurity education and training in bridging the cyberskills gap and effectively combating cybercrime on a large scale.
Collaboration is the key
No one combatting cybercrime knows everything, but everyone in the battle has some intelligence to contribute to the larger knowledge base. Just as cybercrime networks are getting stronger and larger, so too must collaborative strategies between private companies and law enforcement agencies. Disrupting cybercrime networks is going to take collaboration on a large scale.
The post Stop, Collaborate and Listen: Disrupting Cybercrime Networks Requires Private-Public Cooperation and Information Sharing appeared first on SecurityWeek.
Cyberinsurance and protection firm Boxx Insurance has raised $14.4 million in a Series B funding round that brings the total investment in the company to $24.5 million.
Led by Zurich Insurance, the new funding round comes hot on the heels of Boxx acquiring cyber threat intelligence platform Templarbit in November 2022, only two months after completing its Series A investment round.
Founded in 2018, the Toronto-based Boxx Insurance provides small businesses with cyber threat prediction and prevention capabilities, combined with third-party cyber insurance. The solutions are also tailored for connected households.
The company offers the tools and training necessary to increase digital resilience, along with backup, cyber monitoring, and managed firewall capabilities to prevent cyberattacks.
Boxx says it is now protecting 10,000 businesses and over 250,000 individuals. The company has offices in Canada and the US, and has grown its employee base from 5 to 36 in the last year.
Boxx Insurance’s offer is similar to that of Guardz, which emerged from stealth mode this week with $10 million in seed funding.
Related: B2B Payment Security Firm NsKnox Raises $17 Million
Related: Strata Raises $26 Million for Multi-Cloud Identity Management Platform
Related:Cygnvs Emerges From Stealth Mode With Incident Response Platform
Related: SASE Company Netskope Raises $401 Million
The post Boxx Insurance Raises $14.4 Million in Series B Funding appeared first on SecurityWeek.
The point-of-sale (PoS) malware named Prilex has been modified to block contactless transactions in an effort to force users to insert their credit cards into terminals and steal their information.
Initially detailed in 2017, Prilex has evolved from targeting ATMs into an advanced PoS malware that can perform a broad range of nefarious activities leading to credit card fraud.
Unlike other memory scrapers typically seen in attacks targeting PoS terminals, Prilex can perform real-time patching on targeted software, force protocol downgrades, manipulate cryptograms, and perform GHOST attacks, and also uses a unique cryptographic scheme.
Also capable of performing fraud on cards protected by chip-and-PIN technology, the latest Prilex versions can now capture data from contactless (NFC enabled) cards, Kaspersky has discovered.
Contactless payment systems rely on radio-frequency identification (RFID) or near-field communication (NFC) technology integrated into cards, mobile devices, key fobs, wearables, and other devices, allowing individuals to make secure payments by simply waving their card or mobile device over the PoS terminal.
When the card is placed near, the contactless-enabled payment terminal sends a signal to activate the RFID chip embedded in the card, which in turn responds with a unique identification number (ID) and transaction information.
This transaction information cannot be reused, so it is useless to cybercriminals who capture it.
To overcome this inconvenience, Prilex’ developers updated the malware with code that blocks contactless transactions, which results in the terminal prompting the buyer to insert their credit card in the device.
“The goal here is to force the victim to use their physical card by inserting it into the PIN pad reader, so the malware will be able to capture the data coming from the transaction,” Kaspersky notes.
The code was found in Prilex samples that emerged at the end of 2022, and which can also filter cards according to segment, such as to only block a contactless transaction and to capture the card information if the card is in a tier with a high transaction limit.
“Since transaction data generated during a contactless payment are useless from a cybercriminal’s perspective, it is understandable that Prilex needs to force victims to insert the card into the infected PoS terminal. While the group is looking for a way to commit fraud with unique credit card numbers, this clever trick allows it to continue operating,” Kaspersky concludes.
Related: PyPI Users Targeted With PoweRAT Malware
Related: Self-Replicating Malware Used by Chinese Cyberspies Spreads via USB Drives
Related: Omron PLC Vulnerability Exploited by Sophisticated ICS Malware
The post Prilex PoS Malware Blocks NFC Transactions to Steal Credit Card Data appeared first on SecurityWeek.
Attack surface management firm Censys has identified roughly 30,000 internet-exposed QNAP network-attached storage (NAS) appliances that are likely affected by a recently disclosed critical-severity code injection vulnerability.
Tracked as CVE-2022-27596 (CVSS score of 9.8), the security defect is described as an SQL injection bug that allows remote attackers to inject malicious code into vulnerable NAS devices.
The issue impacts all devices that run QTS 5.0.1 and QuTS hero h5.0.1, and Censys says that nearly 30,000 devices running a vulnerable software version can be found on the internet.
However, the number of affected devices could be much higher, the company warns. Censys has identified over 67,000 hosts that run QNAP software, but it could not retrieve the version information for 37,000 of them.
Most of the identified vulnerable hosts are in Italy (3,200) and the US (3,149). Taiwan (1,942), Germany (1,881), and Japan (1,714) round up the top five list.
“If the exploit is published and weaponized, it could spell trouble to thousands of QNAP users. Everyone must upgrade their QNAP devices immediately to be safe from future ransomware campaigns,” Censys notes.
QNAP appliances are known to be a target for cybercriminals, and the recent Deadbolt ransomware attacks are proof of that. At its peak, the threat had infected over 20,000 devices, allowing cybercriminals to steal roughly $200,000 from victims.
“While there are no indications that bad actors are using this new exploit, the threat is definitely on the horizon,” Censys underlines.
QNAP has patched the vulnerability with the release of QTS 5.0.1.2234 build 20221201 and QuTS hero h5.0.1.2248 build 20221215. Users are advised to update their devices as soon as possible and to make sure that they are not accessible directly from the internet.
Related: QNAP Patches Critical Vulnerability in Network Surveillance Products
Related: QNAP Warns NAS Users of DeadBolt Ransomware Attacks
Related: ‘Raspberry Robin’ Windows Worm Abuses QNAP Devices
The post 30k Internet-Exposed QNAP NAS Devices Affected by Recent Vulnerability appeared first on SecurityWeek.
About SecurityWeek Cyber Insights | At the end of 2022, SecurityWeek liaised with more than 300 cybersecurity experts from over 100 different organizations to gain insight into the security issues of today – and how these issues might evolve during 2023 and beyond. The result is more than a dozen features on subjects ranging from AI, quantum encryption, and attack surface management to venture capital, regulations, and criminal gangs.
SecurityWeek Cyber Insights 2023 | The Geopolitical Effect – Geopolitics describes the effect of geography on politics, and usually refers to the political relationship between nations. That relationship is always mirrored in cyber. The Russia/Ukraine war that started in early 2022 has been mirrored by a major disturbance in cyber – and that disturbance will continue through 2023.
The physical conflict has forced much of the world to take sides. The US, NATO, the EU, and their allies are providing major support – short of troops – to Ukraine. China, Iran, and North Korea are all supporting Russia. The cyber conflict is similar, largely conforming to the George W Bush ‘axis of evil’ (Iran, Iraq, and North Korea, with the popular addition of Russia and China) versus the US, EU, and their allies.
Here we’re going to discuss how the current state of global geopolitics might play out in cyber during 2023.
Background“Russia may well resort to increased cyber offensive actions as it contends with on-the-ground setbacks in Ukraine,” comments Bob Ackerman, MD and founder of AllegisCyber. This has been considered likely throughout 2022, but as Russian military setbacks have increased toward the end of 2022, so the likelihood of increasingly aggressive Russian cyber activity will rise. Such offensive actions will not simply target Ukraine – they will be aimed at all countries seen to be supporting Ukraine.
“While we haven’t seen those feared attacks materialize yet,” says Christopher Budd, senior manager of threat research at Sophos, “it would be premature to say that those risks have passed. In 2023, so long as the uncertainty of war exists, everyone should plan for the real possibility of unexpected, large-scale cyberattacks.”
Indeed, the mirror between the kinetic and cyberworlds suggests it is inevitable in 2023. Kevin Bocek, VP of security strategy and threat intelligence at Venafi, expects to see Russian cyber activity becoming more ‘feral’. “We’re increasingly seeing its kinetic war tactics becoming more untamed, targeting energy and water infrastructure with missile strikes,” he says. “We expect the same to apply to cyberwarfare.”
He is concerned that Russia’s more feral activity will have the potential to spill over into other nations, “as Russia becomes more daring, trying to win the war by any means, and Russia could look to use the conflict as a distraction as it targets other nations with cyberattacks.”
Malwarebytes believes that large-scale attacks will appear first in Ukraine, but be accompanied by attacks against European allies. “In recent weeks [Oct/Nov 2022] Russia has been launching a barrage of missiles to cripple Ukraine’s electricity infrastructure. We could expect that at some point availability of such weapons will run low and that the Kremlin will want to increase the cyber effort. We may see further successful malware attacks from the Sandworm group as we have seen previously with the blackouts caused by the BlackEnergy malware,” comments Jerome Segura, senior director of threat intelligence at Malwarebytes.
While malware used to destroy or wipe systems is likely to be used against Ukraine,” he adds, “more stealthy malware such as backdoors are likely to hit European allies as attempts to compromise key leaders, gather intelligence and possibly expose or extort via ‘kompromat’.”
In one sense, the Russia/Ukraine conflict has taken the gloves off the lower-level cyberwarfare that has existed for years. You could say that 2023 may well prove to be a new era of bare-knuckle cyberwarfare. “Nation state cyber warfare will become more openly prevalent,” suggests Chris Gray, AVP of security strategy at Deepwatch. “The Russia/Ukraine conflict has taken away much of the ‘cloak and dagger’ aspects of this area and, in doing so, has also broadened the scope of available targets. Financial impact and the ability to increase chaos due to service interruption will increasingly grow over former levels.”
While we concentrate on Russia as the primary current protagonist in offensive cyber, we should not forget that Russian ‘allies’ will take advantage of the situation. “China is likely to expand the full spectrum of its cyber initiatives targeting economic, political, and military objectives,” continues Ackerman. “Bit actors on the global stage may well exploit Great Power conflict and related global distractions to launch targeted regional cyberattacks,” he added. Such as Iran targeting Israel.
Difficulty in attribution will remainIncreased nation-state cyber activity will become more obvious, but not necessarily legally attributable. The major powers will still seek to avoid direct retribution that could escalate into additional kinetic warfare. “The reality with nation-state attacks is you might never know you’ve been hit by one until another country’s intelligence agency actively identifies it,” warns Andrew Barratt, VP at Coalfire. “The attribution of attacks to specific parties is a highly contentious area with a lot of room for error and deniability. What we really need is crossover from friendly military intelligence partners to support a reasonable conclusion.”
SecurityWeek was told years ago by Luis Corrons, now security evangelist at Gen and co-chairman of the board at AMTSO, “The only people who really know what’s going on are the intelligence agencies, who have close knowledge drawn from signals intelligence and covert agents.” Historically, the intelligence agencies have been reluctant to make too many public accusations of attribution for fear that it might expose their sources.
Marcus FowlerDirect attribution from countries with mature intelligence agencies is likely to increase in 2023 – as will the strident denials coming from the perpetrators – but it will remain difficult. “The rapid expansion of non-state affiliated cyber actors including hobbyists, hacktivists, criminals, privateers, proxies, vigilantes, or cyber response reserve units, is unlike anything ever seen in traditional warfare,” explains Marcus Fowler, CEO of Darktrace Federal. “The surge in ‘vigilante’ approaches to cyber-crime will continue to alter the course of modern warfare in 2023, introducing unprecedented adversaries and allies for nation-states.”
Zero-day stockpilesWhat remains largely unknown is the potential capability of unfettered cyberwarfare – all major nations have been stockpiling zero-days for years. “I dare not speak of the unused kinetic powers available to the nation-states,” comments Brian NeuHaus, CTO of Americas at Vectra AI, “but will digress to one which has only, I believe, been partially used. Cyberwarfare is still a real threat from a broader use of known TTPs, tools tactics procedures, and an unknown equity of zero-days just waiting for the right strategic moment to deploy against one’s foes.”
Zero-days are not used lightly, especially by nation-states. Once used, they instantly lose their value. The problem is that we have no knowledge of our adversaries’ zero-day stockpiles, nor their ability to unleash widespread destructive capabilities against critical infrastructure. Their use is likely to be one of desperation – a cyber version of nuclear weapons with the potential to escalate into open kinetic conflict.
We must hope this day never comes, for it is worth remembering Putin’s warning on the use of nuclear weapons: “For the planet, it will be a catastrophe. But for me as a citizen of the Russian Federation and the head of the Russian State, I must ask myself the question. What is the point of a world without Russia?”
Wiperware and other destructive attacksOur hope must therefore be that no nation-state feels so backed into a corner that it unleashes the full power of stockpiled zero-days against the opponent’s critical infrastructure. That doesn’t mean we can relax – the threat from what we could perhaps describe as conventional cyberweapons remains real and likely to increase through 2023. Wiperware is probably top of the list.
Fleming Shi“Russia’s invasion of Ukraine this year revealed the modern digital battlefield. Most notably, we have witnessed an increased use of wiperware, a form of destructive malware against Ukrainian organizations and critical infrastructure,” comments Fleming Shi, CTO at Barracuda. “The frequency has dramatically increased as we saw WhisperGate, CaddyWiper, HermeticWiper, and others hitting the news since the war broke out.”
Unlike the financial motivations and decryption potential of ransomware, wiperware is typically deployed by nation-state actors with the sole intent to damage and destroy an adversary’s systems beyond recovery. “In addition,” he added, in 2023, wiperware emanating from Russia will likely spill over into other countries as geopolitical tensions continue.”
Wiperware can easily be disguised as criminal ransomware with non-functioning decryption, adding deniability to destructive nation-state attacks. There are suspicions that WannaCry was a version of this. “Given the current political climate, Kaspersky experts foresee a record number of disruptive and destructive cyberattacks, affecting both the government sector and key industries,” says Ivan Kwiatkowski, senior security researcher at Kaspersky`s GReAT.
“It is likely that a portion of them will not be easily traceable to cyberattacks and will look like random accidents. The rest will take the form of pseudo-ransomware attacks or hacktivist operations to provide plausible deniability for their real authors,” he added. “High-profile cyberattacks against civilian infrastructure, such as energy grids or public broadcasting, may also become targets, as well as underwater cables and fiber distribution hubs, which are challenging to defend.”
A particular target area for such attacks will likely be ‘dual use’ technologies; that is, those that serve both military and commercial purposes. “Satellite technologies and other advanced communication platforms come under a higher level of focus. Both intellectual property theft and disruption of data delivery to governments and militaries around the world become a stronger focus,” says Kurt Baumgartner, principal security researcher at Kaspersky.
It is noticeable that the cyberattack against Viasat by Russia just prior to the Russian invasion of Ukraine, designed to disrupt Ukrainian military communications, spilled out of the region to also affect some 9,000 European users. Russia seems to have ‘got away with it’ on this occasion, but it effectively remains a nation-state cyberattack against civilians outside of the war zone. We are not aware of any clandestine response from the West, but must wonder if the response would have been different if the spillover had directly affected US users.
John Pescatore, director of emerging security trends at SANS Institute, endorses Baumgartner’s view. “The war in Ukraine will have broader impacts on the commercial sector as operatives on both sides attack dual-use technologies (that is, services used by both the military and civilians) to take down communication and critical infrastructures systems.” He expects to see more attacks in 2023 that will impact business internet connections, communication, and logistics systems.
“Increasing attacks on key dual-use technologies like cell towers, GPS, and commercial satellites – such as Star Link,” he adds, “will damage connectivity and business operations for private sector companies that depend on these technologies, even if they are not directly targeted themselves.”
Beyond RussiaWhile cyber eyes are trained on Russia, we should remember that it is not the West’s only cyber adversary. China, Iran, and North Korea will all increase their activity through 2023 under cover of the European war. China will likely continue concentrating on espionage rather than destruction – although this may change if the separate geopolitical tensions over Taiwan escalate into kinetic activity.
“China has high priority targets to meet in terms of economic and social development, made more pressing by continuing Covid outbreaks and a zero-tolerance stance on Covid,” warns Mike McLellan, director of intelligence at Secureworks. “Chinese intelligence collection will remain both broad and deep, as the Chinese Communist Party will not accept failure on any of its key focus areas.”
This focus will be on upgrades to its manufacturing base, food stability, housing, energy supply, and natural resources. “Organizations operating in or supplying any of those areas, particularly hightech industries,” he continues, “are potential targets of Chinese cyberespionage.”
But he adds, “As tensions continue to rise around Taiwan and the South China Sea, and China continues to drive forward with its Belt Road Initiative (BRI), a large proportion of China’s cyber espionage apparatus will be regionally focused targeting governments and critical infrastructure projects, as well as dissidents and other individuals opposed to the Chinese state.”
Iran and North Korea are less concerned with maintaining any semblance of diplomacy with the US and EU. Iran may engage in more destructive cyberattacks, largely in the Middle East but potentially elsewhere. “Iran will exploit the blurring of state-sponsored activity with cybercrime, both against regional adversaries and more broadly,” says McLellan.
The country will make use of offensive cyber operations under the guise of hacktivist and cybercrime personas to harass and intimidate regional adversaries, particularly Israel. This will probably extend beyond the Middle East with Iran merging state and criminal activity. Citing the IRGC-affiliated Cobalt Mirage threat group, McLellan warns, “Iran will exploit this financially motivated activity as a plausible cover for state espionage or disruption operations, which can be dismissed as part of a ‘cybercrime problem’.”
“We’re also seeing North Korea flexing its muscles by flying long range weapons over borders,” adds Venafi’s Bocek. If the mirror between kinetic and cyber activity holds true, we can expect North Korea to become more aggressive in cyber in 2023. Such cyber activity, adds Bocek, “will be replicated by North Korea as it looks to advance its economic and political goals.”
SummaryA particular concern for 2023 and beyond is that the diplomatic seal may now be permanently broken. The Russia/Ukraine war will eventually end – but tensions between the two countries and their allies will continue. Aggressive international cyber activity may never return to pre-war levels. “Nation-states will continue to cause each other digital problems amid the constant fight for power and status on the world stage,” comments Zac Warren, chief security advisor for EMEA at Tanium.
“Nations will come to the table to discuss norms; China, Russia and others will inhibit progress,” warns Mike Hamilton, founder and CISO at Critical Insight. He has two specific predictions for 2023 that might take cyber relations beyond the point of no return. Firstly, he suggests, “Russia will have its infrastructure disrupted as a demonstration of seriousness.” Secondly, he adds, “Operational technologies will be disrupted/wiped, likely in the US water sector.”
If either of these incidents occur and can be reliably attributed to a foreign state, they will not be easily forgiven.
As it is in the kinetic world, so it is in the digital. “For everything in the real world, there is a shadow on the Internet,” says Sam Curry, CSO at Cybereason. “More-and-more, we are going to see the Internet as a primary forum for geopolitical activity. The classic diplomacy, information, military and economic (or ‘DIME’) options are seeing the rise of information options and a resurgence of military options from 2022. Going into 2023, it’s to be hoped that diplomacy and economics rise to the fore, but for that to happen, the world would need to see an amenable-to-all-parties resolution to the Russia-Ukraine War or at least motion in that direction with a meaningful ceasefire; and detente in the South China Sea, which although a secondary area is another potential area of rising concern and clash of superpowers.”
About SecurityWeek Cyber Insights | At the end of 2022, SecurityWeek liaised with more than 300 cybersecurity experts from over 100 different organizations to gain insight into the security issues of today – and how these issues might evolve during 2023 and beyond. The result is more than a dozen features on subjects ranging from AI, quantum encryption, and attack surface management to venture capital, regulations, and criminal gangs.
Related: Wipers Are Widening: Here’s Why That Matters
Related: Economic Warfare: Attacks on CI Part of Geopolitical Conflict
Related: Security Pros Believe Cybersecurity Now Aligned With Cyberwar
Related: U.S. Issues Fresh Warning Over Russian Cyber Threats
The post Cyber Insights 2023: The Geopolitical Effect appeared first on SecurityWeek.
About SecurityWeek Cyber Insights | At the end of 2022, SecurityWeek liaised with more than 300 cybersecurity experts from over 100 different organizations to gain insight into the security issues of today – and how these issues might evolve during 2023 and beyond. The result is more than a dozen features on subjects ranging from AI, quantum encryption, and attack surface management to venture capital, regulations, and criminal gangs.
Our intention here is to talk about cybercrime and cybercriminals. Despite some geopolitical overlaps with state attackers, the majority of cyberattacks still come from simple – or perhaps sophisticated – criminals who are more motivated by money than politics.
“With the Russia-Ukraine War, many actors polarized, including players like Conti, Killnet and Anonymous. However, the ecosystem is much larger, and even with setbacks in cryptocurrency brokerage, which advanced the liquidity and economics of criminals online, criminal organizations are thriving, diversifying, and going gangbusters as we enter 2023,” comments Sam Curry, CSO at Cybereason.
“There are no signs of this letting up and all signs indicate that criminal organizations’ real growth is e-crime going forward.”
Know your enemyAn increasing sophistication among the more elite criminals together with a more streamlined organization of the infrastructure from which they operate has been apparent for many years. This process continues and will continue throughout 2023. It is apparent in both how the gangs operate and the tools they use.
“Malware will continue to evolve in 2023 as attackers find new ways to hide it to maintain persistence and get what they came for,” says Mike Parkin, senior technical engineer at Vulcan Cyber – adding, “The attack vectors they use to get a foothold will also evolve, taking advantage of new vulnerabilities, and leveraging variations of old ones.”
But it is the increasing maturity of the criminal business that perhaps poses the greatest threat. “There is a significant maturing of the tools used by cybercriminal groups,” explains Andrew Barratt, VP at Coalfire. “They are becoming platforms (as a service) for other criminal groups with significantly less technical expertise to leverage.”
We’ve had ransomware-as-a-service and infostealers-as-a-service for a few years, but it is becoming more accurate to describe the process as a complete ‘crime-as-a-service’. “While we’ve seen the crime-as-a-service infrastructure become very prevalent, it’s probably likely we’ll see an uptick in volume and/or pricing of these attacks in the year ahead,” adds Barratt.
Crime-as-a-Service“We’ve looked at numerous online forums and found such a rise and diversification in the many kinds of criminal ‘as a service’ offerings that people really can set up their own cybercrime business with little to no technical knowledge or skills,” explains Christopher Budd, senior manager of threat research at Sophos.
“Now you can find a vendor or supplier to cover your needs around targeting and initial compromise of victims, evasion and operational security, and malware delivery, among others.” These offerings often come with good marketing and customer service and support that meets – or even exceeds – those you get when paying for legitimate software.
Andrew PendergastCalling it malware-as-a-service (MaaS) rather than crime-as-a-service, Andrew Pendergast, EVP of product at ThreatConnect, adds, “MaaS operators act like a business, because they are a business – just an illegal one. Their goals are to make as much money as possible selling their product and services. This entails making it as accessible, trustable, reliable, and easy to use as possible for their ‘market’.”
He expects the CaaS providers to continue to improve their support and services to accommodate a broader set of customers and affiliates, adding, “The net results will be a broadening user base for various MaaS offerings which in 2023 likely means more ransomware attacks.”
In fact, the service is now so complete that Benjamin Fabre, CEO at DataDome, points out new cybercriminals no longer need the technical skills to develop and execute cyberattacks on their own. “Cybercrime will require as much brains as holding a baseball bat to a shop owner’s window,” he comments.
Chris Vaughan, a VP of technical account management at Tanium, agrees with this assessment. “Malicious cyber tools are becoming more available to be purchased online which is leading to a greater number of attacks that are also less predictable. This includes vulnerabilities and exploits as well as hackers for hire, dramatically lowering the barrier of entry for anyone interested in launching a cyberattack.”
This leads us to another related concern for 2023: the potential. expansion of a recession-promoted cybercrime gig economy. “People may turn to ‘cyber hustling’ in the cybercrime gig economy to make quick cash during the economic downturn,” warns Alex Holland, senior malware analyst at HP Inc.
He fears a potential increase in the number of cyber hustlers seeking to make additional – or, indeed, any – income by scamming consumers who will themselves be looking for opportunities to raise some extra cash. “Cybercrime tools and mentoring services are readily available at low costs, enticing cyber hustlers – opportunists with relatively low levels of technical skill – to access what they need to turn a profit.”
The interconnected nature of the cybercrime gig economy means threat actors can easily monetize attacks. “And if they strike gold and compromise a corporate device, they can also sell that access to bigger players, like ransomware gangs. This all feeds into the cybercrime engine, giving organized groups even more reach.”
Crime gang career rolesJohn BambenekFundamental to the emergence of streamlined CaaS has been the evolution of career specializations within the gangs. “In many ways, the cybercrime ecosystem has developed specialized ‘career fields’ in a similar way that cybersecurity has developed specializations,” comments John Bambenek, principal threat hunter at Netenrich.
This means there are many more partnerships and boutique actors helping a variety of groups. “Getting initial access is a specialized skill set, just like money laundering (in cryptocurrency) and ransomware development are skill sets,” he added. “This specialization makes the ecosystem as a whole more resilient and more difficult to bring to justice.”
This process of business refinement will continue through 2023. “Criminal organizations will continue to grow in scope and capabilities, with increased focus on functional areas,” suggests Gray, AVP of security strategy at Deepwatch. “Specialization will allow these groups to maintain the razor margins needed to operate at levels that are capable of bypassing security program components at advanced targets and/or operate at scale against more susceptible targets.”
Three categories of CaaS to watch in 2023Three categories of crime-as-a-service are likely to be prevalent in 2023: ransomware-as-a-service (RaaS), stealer-as-a-service (SaaS), and victims-as-a-service (VaaS).
RaaSThe ‘pay-per-use’ version of delivering ransomware is, says, Camellia Chan, CEO and founder of X-Phy, “a sophisticated, and yet much more accessible form of ransomware, with malicious actors no longer requiring advanced technical skills to carry out attacks.” This is a win for wannabe criminals who cannot code.
But it is also a win for the more elite coding criminals trying to avoid the eye of law enforcement. “The number of different entities involved adds another layer of complexity,” explains Chan. “While RaaS operators develop the infrastructure, access brokers focus on the identity posture and external access portals. To finish, the affiliate buying the RaaS handles the exfiltration of data to ransom, then deploying the actual ransomware payload.”
Mike McLellan, director of intelligence at Secureworks, continues: “New RaaS schemes will continue to emerge, but the landscape will be dominated by a handful of cybercriminal groups operating a small number of very active schemes.”
He expects the dominant schemes to increase their capacity to support more affiliates. “Experienced cybercriminals under sanction by the U.S. authorities will make use of existing RaaS schemes as a way of complicating attribution of their attacks. At the other end of the spectrum, less sophisticated affiliates will conduct simplistic ransomware deployments against small numbers of hosts, rather than full blown, enterprise-wide encryption events.”
SaaSA study published by Group-IB on November 23, 2022, reported that 34 Russian-speaking groups were distributing infostealers as part of stealers-as-a-service operations. On average, each of these groups has some 200 active members.
Twenty-three of the groups distributed the Redline infostealer, while eight concentrated on Raccoon. “An infostealer,” explains Group-IB, “is a type of malware that collects credentials stored in browsers (including gaming accounts, email services, and social media), bank card details, and crypto wallet information from infected computers, and then sends all this data to the malware operator.”
Given that credentials remain the starting point for most cyberattacks, the demand is and will remain high. Group-IB suggests “Stealers are one of the top threats to watch in the coming year.” The company notes, “In the first seven months of 2022, the gangs collectively infected over 890,000 user devices and stole over 50 million passwords.”
While the targets are individual computers often used by gamers and remote workers, the potential knock-on effect against corporates should not be under-estimated. “The threat actor responsible for the most recent attack on Uber purchased the credentials compromised with the Raccoon stealer,” says Group-IB.
Uber itself explained the process in a statement: “An Uber EXT contractor had their account compromised by an attacker. It is likely that the attacker purchased the contractor’s Uber corporate password on the dark web, after the contractor’s personal device had been infected with malware, exposing those credentials. The attacker then repeatedly tried to log in to the contractor’s Uber account. Each time, the contractor received a two-factor login approval request, which initially blocked access. Eventually, however, the contractor accepted one, and the attacker successfully logged in.”
This demonstrates both the success of stealers and the failure of MFA to offer a complete access solution. The Uber instance seems to be a variation on what Tanium’s Vaughan describes as an MFA push exhaustion attack. “This,” he explains, “is where an attacker sends a large number of MFA acceptance prompts to a user’s phone which may cause them to click accept in order to stop the barrage of requests.”
This whole process of SaaS-delivered stealers acquiring credentials and attackers defeating MFA will persist and increase in 2023.
VaaSMark Warren, product specialist at Osirium, believes there is a new service offering on the rise: hacker teams offering victims-as-a-service. “For the last couple of years, threat actors have been team-based,” he explains. “Before cryptocurrency, they were lone wolves – or, occasionally, a loosely connected group who’d met online. Then they started working in teams, and because they were paid money those teams became tightly bonded. Over the next year we’ll see more teams divide out into skills-based groups.”
He uses REvil as an example of a successful RaaS model offering an end-to-end solution for attackers that included encryption software, access tools, helpdesks for victims, payment services and much more. “But,” he says, “there’s still a market for smaller teams that focus on specific attack skills. For example, they may breach defenses to acquire user or admin credentials, or even install malware to provide back door entry for use at a later date.”
Providers of such a service don’t need to take the risk of executing the attack or handling payment; they can make good money just by selling the access on dark web marketplaces. The access could be obtained via relatively risk-free phishing campaigns.
The approach could be modular. “Company intelligence may be another specialist service,” he suggests. “For example, knowing what cyber insurance a potential victim has could reveal the kinds of defenses they’ll have in place and even how much they’re insured for, so ransomware demands can be tailored.” In this sense, VaaS can be seen as an extension and expansion of the existing access broker criminal service.
And going forward…Aamir Lakhani, cybersecurity researcher and practitioner for Fortinet’s FortiGuard Labs, adds further subtleties that will emerge. “Going forward, subscription based CaaS offerings could potentially provide additional revenue streams. In addition, threat actors will also begin to leverage emerging attack vectors such as deepfakes, offering these videos and audio recordings and related algorithms more broadly for purchase.”
The quasi-APTThis continuing professionalization of the criminal fraternity is causing the inevitable emergence of what Omer Carmi, VP of cyber threat intelligence at Cybersixgill, calls the quasi-APT. “In 2023,” he warns, “the quasi-APT’s emergence will escalate due to the democratization of cyberweapons and the democratization of access enabled by powerful technology now accessible to the cybercrime underground.”
The growth of specialized roles and CaaS means that for as little as $10, threat actors can purchase access and gain a steady foothold into their targets’ systems. They can get a beachhead into highly secured organizations without having to bother with the complex, drawn-out process of gaining initial access on their own.
Mikko Hypponen“By outsourcing access, attackers of all levels of sophistication can leapfrog several steps, jumping yet another step closer to the level of an APT – hence the birth of the quasi-APT,” he warns.
The constantly improving sophistication and professionalization of the criminal underground will continue through 2023 and beyond. For example, Mikko Hypponen, chief research officer at WithSecure, sees artificial intelligence adding a new string to the criminal bow in 2023.
“Malware campaigns will move from human speed to machine speed,” he warns. “The most capable cybercrime groups will reach the capability to use simple machine learning techniques to automate the deployment and operation of malware campaigns, including automatic reaction to our defenses. Malware automation will include techniques like rewriting malicious emails, registering and creating malicious websites, and rewriting and compiling malware code to avoid detection.”
2023 may see the beginning of a new crime gang service: AI-as-a-Service.
About SecurityWeek Cyber Insights | At the end of 2022, SecurityWeek liaised with more than 300 cybersecurity experts from over 100 different organizations to gain insight into the security issues of today – and how these issues might evolve during 2023 and beyond. The result is more than a dozen features on subjects ranging from AI, quantum encryption, and attack surface management to venture capital, regulations, and criminal gangs.
The post Cyber Insights 2023: Criminal Gangs appeared first on SecurityWeek.
About SecurityWeek Cyber Insights | At the end of 2022, SecurityWeek liaised with more than 300 cybersecurity experts from over 100 different organizations to gain insight into the security issues of today – and how these issues might evolve during 2023 and beyond. The result is more than a dozen features on subjects ranging from AI, quantum encryption, and attack surface management to venture capital, regulations, and criminal gangs.
SecurityWeek Cyber Insights 2023 | ICS and Operational Technology – Recognition of the cyber threat to industrial control systems (ICS) and operational technology (OT) systems has grown over the last decade. Until recently, this has been largely a theoretical threat founded on the danger of what could happen rather than what is happening. This is changing, and the threat to ICS/OT is now real and ongoing. The bigger danger is that this is likely to increase in 2023 and onward.
There are several reasons, including geopolitical fallout and escalation of tensions from the Russia/Ukraine war, and a growing willingness of criminals to target the ICS of critical industries. At the same time, ICS/OT is facing an expanding attack surface caused by continuing business digitization, an explosion of IoT and IIoT devices, the coming together of IT and OT networks, and the use of potentially insecure open source software libraries to bind it all together.
Background to the ICS/OT ThreatscapeThe IT/OT overlapOne of the biggest threats to OT comes from its convergence with IT. When the networks were separate, OT could be isolated from the internet and kept relatively secure. This is no longer reality.
“As IT and OT systems continue to converge,” comments Simon Chassar, CRO at Claroty, “nation-state actors and cybercriminal groups such as Berserk Bear, Conti, Lazarus and Mythic Leopard, will shift their focus from IT to OT and cyber-physical systems; from stealing sensitive data to disrupting mission-critical operations.”
For all its benefits, IT/OT convergence without proper security means threat actors can take down operations by exploiting an IT access point or a cloud vector. “This yields maximum financial or political gain for the attacker,” continued Chassar, “because businesses have more incentive to pay a ransom when their means of production are at stake, which can have a long-term impact on revenue and the supply chain.”
Ramsey HajjRamsey Hajj, Deloitte’s US and global cyber OT leader, expands on this theme. “Cyber attackers are increasingly weaponizing OT environments to attack hardware and software that control industrial processes and secure OT networks. Skilled workforce shortages and overlapping IT and OT environments can make cyber incident containment difficult.”
Supply chain attacks cannot be ignored, either on the IT side or directly against OT. “Supply chain attacks continue to evolve for both ICS hardware and software,” comments Pascal Ackerman, senior security consultant for operational technology at GuidePoint Security. “Think implants for controls and automation equipment, attack chains that involve suppliers and service providers to ICS owners as an initial foothold or pivot point, and compromises on controls and automation vendors’ file repositories with the purpose of adding implants in the provided software.”
| Learn More at SecurityWeek’s ICS Cyber Security ConferenceThe leading global conference series for Operations, Control Systems and OT/IT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.October 23-26, 2023 | Atlantawww.icscybersecurityconference.com |
Geopolitics and the Russia/Ukraine war“One of the biggest concerns around the potential for large-scale attacks in the wake of the war in Ukraine is around ICS/OT,” says Christopher Budd, senior manager of threat research at Sophos. “While we haven’t yet seen attacks on a scale as feared, there have been documented attacks like this in Ukraine as part of the ongoing hostilities.”
He suspects this will focus both government and industry on strengthening the security of ICS/OT systems, even if it’s done quietly. This may already be evident in the new Cross-Sector Cybersecurity Performance Goals (CPGs) issued by CISA in late October 2022. Claroty describes them as, “a foundational set of IT and OT practices and recommendations that can help smaller, lesser-resourced organizations better prioritize cybersecurity efforts and reduce risk.”
Claroty highlights four OT recommendations in the CPGs. There should be a single leader responsible for OT asset cybersecurity; there should be specialized OT-focused cybersecurity training for OT engineers; there should be compensating controls such as network segmentation and access controls used as mitigations until software patches and firmware updates can be applied; and there should be unique credentials for assets, use of MFA, and the removal of default passwords.
We can expect that government agencies will, and private industry should, work on conforming to CISA’s CPGs during and from 2023.
Danielle JablanskiDanielle Jablanski, OT cybersecurity strategist at Nozomi Networks, expects further assistance from CISA in 2023. “2023 will usher in the fruits of new CISA programs further building mechanisms for enhanced trust and verification – CyberSentry and RedEye for example – which will broaden the aperture for understanding OT and ICS incidents.”
One less-obvious effect of global geopolitical tensions will be a deterioration in international law enforcement cooperation. “Besides the growth of hacktivist activity ‘working’ to internal and external political agendas,” suggests Kaspersky, “we might also see more ransomware attacks on critical infrastructure due to the fact that it will become harder to prosecute such attacks.”
Chassar is more direct. “There is going to be an increase in the number of threats from nation-state actors, as well as groups that are associated with nation-states in 2023,” he says. “Their activity targeting the critical infrastructure industry, from manufacturing to water and energy, will continue to grow, fueled by ongoing global geopolitical conflicts such as the Russia/Ukraine war, as well as the current economic climate.”
The overall effect of current global geopolitical conditions is that nation states have a greater incentive to target the ICS/OT of critical industries, while cybercriminals have had their restraints reduced.
Specifically…IoT/IIoT “There are now more known vulnerabilities impacting IoT devices than IT devices,” says Bud Broomhead, CEO at Viakoo, “and IoT devices are often the easiest for cybercriminals to access.” IoT and IIoT is a massive and expanding part of the ICS/OT attack surface, providing an entry point, and enabling lateral movement.
“Breached IoT devices are having devastating impacts,” he continued, “such as ransomware, data loss, changing the chemical balance in a municipal water supply, replacing real camera footage with deepfakes, or disrupting transportation systems.”
The scale (sometimes up to 20x more than IT devices) and the physical location (widely distributed rather than focused within data centers), together with the growing use of vulnerable open source software libraries, make vulnerability remediation difficult.
Broomhead believes the shift to open source software presents the most immediate threat. “The dangers open source vulnerabilities present is that they require multiple vendors to provide patches, they are often found in OT and IoT devices that are hard to remediate, and they can be exploited many years after they were discovered.”
Wendy Frank, Deloitte’s US cyber IoT leader, believes part of the threat comes from a lack of adequate security governance covering the implementation of IoT, IIoT, OT and ICS devices. As their number grows, so the expanded attack surface creates more security, data, and privacy risks.
“Leading organizations,” she says, “will focus in the year ahead on connected-device cyber practices by establishing or updating related policies and procedures, updating inventories of their IoT-connected devices, monitoring and patching devices, honing both device procurement and disposal practices with security in mind, correlating IoT and IT networks, and monitoring connected devices more closely to further secure those endpoints, manage vulnerabilities, and respond to incidents.”
Ransomware and other malwareThomas Winston“Ransomware remains the most likely threat to cause disruption in industrial infrastructure environments in 2023,” states Thomas Winston, director of intelligence content at Dragos. “Based on our visibility of ransomware events, manufacturing organizations remain the most frequent target with 70% of observed ransomware events, year-to-date [ie, 2022], continuing to target primarily manufacturing.”
Ackerman sees ransomware beginning to target OT specifically. He expects to see: “Ransomware targeting the industrial environment – in contrast to ransomware on the IT side accidentally compromising the OT space – with attacks on virtualization stacks (VMware), data repositories (Historian), controls equipment like PLCs, and controls project repositories (file shares).”
Partly, this will be exacerbated by native code execution on PLCs, with the attacker adding arbitrary code to the PLC’s OS, and paving the way for ransomware and rootkits running on the PLC.
Winston is particularly concerned for those organizations without adequate segmentation between IT and OT, but notes that “Ransomware rarely uses novel methods – making the application of key elements of a defensible ICS/OT architecture particularly effective.”
He recommends the five critical controls outlined by SANS in October 2022: implementation of an ICS-specific incident response plan; development of a defensible architecture [perhaps in conjunction with an attack surface management plan]; ICS network visibility and monitoring; secure remote access; and a risk-based vulnerability management program.
Beyond ransomware, Winston is concerned about the evolution of Pipedream (also known as Incontroller). “Pipedream is an existential threat to the ICS community. This toolset is likely being actively developed and financed,” he said.
“It is already capable of disruption across industries, including CrashOverride-style disruption, pipeline disruption, and servo manipulation. We’ve confirmed that Pipedream, with little development effort, can target devices speaking the ubiquitous CODESYSv3 and OPC UA protocols. It can manipulate servos in the 1S-Series of Omron Servo drives.” While it cannot target Omron Safety Controllers, he believes this is undoubtedly the next step in its development.
Hijacking remote access sessionsIan Pratt, global head of security for personal systems at HP Inc, sees an increase in session hijacking in 2023. “Increased use of features like Windows Defender Credential Guard are forcing attackers to pivot – either capturing users’ passwords to enable lateral movement, or hi-jacking the remote session itself to access sensitive data and systems. The latter is particularly powerful.”
By targeting users with elevated rights, the attacks are more potent, harder to detect, and more difficult to remove. “The user is typically unaware that anything has happened. It takes just milliseconds to inject key sequences and issue commands that create a backdoor for persistent access. And it works even if privileged access management (PAM) systems are being used to employ MFA, such as smart cards.”
Session hijacking does not involve exploiting a fixable vulnerability – it is about abusing the legitimate functionality of remote session protocols, such as RDP, ICA and SSH. “If such an attack connects to OT and ICS running factories and industrial plants, there could also be a physical impact on operational availability and safety – potentially cutting off access to energy or water for entire areas.”
APTs targeting CNI through OT“Attacks targeting critical national infrastructure tend to be the work of APT groups working on behalf of nation states with specific goals,” comments Joseph Carson, chief security scientist and advisory CISO at Delinea. Those goals are governed by the current state of geopolitics, and the global tension caused by the Russia/Ukraine conflict means the stakes are high.
“These high-level adversaries are hard to defend against as they have the time and resources required to repeatedly test security measures and find gaps, whereas more opportunist criminals in search of profits will select soft targets,” he continued.
Although OT and IT networks are converging, there remains a fundamental design difference between the two. “OT systems have often been designed with a lifespan of decades in mind, and are a poor fit with the fast-moving world of modern IT networks. Gaining centralized visibility and management of such a complex environment can be extremely challenging,” he added.
This results in gaps between the two networks that APT actors can find, infiltrating the IT network and moving across to the OT network. “These issues elevate the potential threat of a nation state actor infiltrating the system and causing serious disruption,” he continued.
According to Kaspersky’s experts, there will likely be a shift in APT activity against industrial organizations in new industries and locations. “Real economy sectors such as agriculture, logistics and transport, the alternative energy sector, and the energy sector as a whole, high-tech, pharmaceuticals and medical equipment producers are likely to see more attacks next year,” they say. “Moreover, traditional targets such as the military industrial complex and the government sector will also remain a focus.”
Kaspersky also warns that there will likely be an increased level of cooperation between criminals and APTs. “Other risks to watch out for are the heightened criminal activity with a goal to harvest user credentials as well as more volunteer ideological and politically motivated insiders working with criminal groups, usually extortionists and APTs,” it says. “These insiders may be active in production facilities as well as technology developers, product vendors and service providers.”
Human costsAttacks on the OT of critical industries have real world implications, which may worsen in 2023. “Whether it’s contaminated water supplies or minimal access to fuel, we’ve seen the costs these cyberattacks have firsthand,” comments Edward Liebig, global director of cyber-ecosystem at Hexagon Asset Lifecycle Intelligence. “While hackers’ activities will likely still be money-driven, we can expect to see human cost become more of a play in the following year.”
He is concerned that IT and OT security convergence is still not effective. “Attacks that have been close calls in the past (such as the poisoning of the water supply from a Florida plant in 2021) will eventually have human costs.”
Catastrophic attack on the energy gridLiebig is also concerned about attacks on the energy grid. “As Ukraine stands its ground in its conflict with Russia, we’re likely to not only see more attacks on Ukrainian energy infrastructure, but the US’s infrastructure as well,” he warns. “At the beginning of 2022, Homeland Security warned that domestic extremists had been developing plans to attack the US electric power infrastructure for years.”
As a result, he continued, “The combination of aforementioned factors makes the US’s power grid more vulnerable to cyberattacks than it has been in a long time.”
The way forwardSam Curry, CSO at Cybereason, believes there needs to be a fundamental change of approach from the ICS/OT system providers. “Many of the security basics are simply not present, such as leveraging roots of trust and trusted execution environment, strong cryptographic options, hardening, secure update and shipping with strong identity options and no default access, to name a few,” he says. “Most devices don’t ship with hardening options or advice, have poor documentation and no understanding of ultimate use cases.”
This results in customers setting up devices, but rarely coming back to manage the ongoing device lifecycle, let alone maintaining security aggressively as they should. “There are missed business opportunities for security services and secure management services as a service that are being left behind. Done correctly, there’s not only lower risk for business, but there’s money to be made and real value to provide.”
He adds, “2023 needs to be the year to reset ICS and OT standards for security.”
| Learn More at SecurityWeek’s ICS Cyber Security ConferenceThe leading global conference series for Operations, Control Systems and OT/IT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.October 23-26, 2023 | Atlantawww.icscybersecurityconference.com |
Ronnie Fabela, CTO and co-founder at SynSaber, also sees scope for improvement in standards. “From the practitioner side of ICS cybersecurity, 2023 will continue to see an overwhelming message of guidance, regulation, media, and FUD about topics such as ransomware, threat actors, and nation-states,” he says.
“My prediction for 2023 is that while this will continue, the industry’s response will be loud and focused: ‘Enough guidance and FUD. Help us execute.’” His position is that industrial operators and asset owners know their systems better than anyone. Now they are on board with cyber, empowering the operating community is the only true way to move the needle.
“A shift from ‘We know better’ to ‘You know better’ will be tough for a cybersecurity industry that is used to being the hero,” he adds. “The faster all of us can change this mindset; the more successful 2023 will be for defending critical infrastructure.” There will consequently be continued movement from guidance to regulation.
But Jablanski offers a word of warning, more to do with party politics than geopolitics: “New direction and bolstered industry involvement will produce greater situational awareness, trust, and resolve across the critical infrastructure security community. As a warning, policymakers should avoid a partisan future for reducing cybersecurity risks to critical infrastructure.”
About SecurityWeek Cyber Insights | At the end of 2022, SecurityWeek liaised with more than 300 cybersecurity experts from over 100 different organizations to gain insight into the security issues of today – and how these issues might evolve during 2023 and beyond. The result is more than a dozen features on subjects ranging from AI, quantum encryption, and attack surface management to venture capital, regulations, and criminal gangs.
Related: Omron PLC Vulnerability Exploited by Sophisticated ICS Malware
Related: ICS Vendors Respond to Log4j Vulnerabilities
Related: U.S. Warns ICS/SCADA Malware Can Damage Critical Infrastructure
Related: Energy Provider in Ukraine Targeted With Industroyer2 ICS Malware
The post Cyber Insights 2023: ICS and Operational Technology appeared first on SecurityWeek.
A researcher has discovered two potentially serious vulnerabilities affecting Econolite traffic controllers. Exploitation of the security flaws can have serious real-world impact, but they remain unpatched.
Cyber offensive researcher Rustam Amin informed the US Cybersecurity and Infrastructure Security Agency (CISA) that he had identified critical and high-severity vulnerabilities in Econolite EOS, a traffic controller software developed for the Econolite Cobalt and other advanced transportation controllers (ATC).
The California-based vendor’s website says it has deployed more than 360 systems, 150,000 traffic cabinets, 120,000 traffic controllers, and over 160,000 sensors. In December 2022, the company reported reaching more than 10,000 installations of its EOS software.
Amin discovered two types of vulnerabilities. One, rated ‘critical severity’ and tracked as CVE-2023-0452, has been described by CISA as an issue related to the use of a weak algorithm for hashing privileged user credentials.
“A configuration file that is accessible without authentication uses MD5 hashes for encrypting credentials, including those of administrators and technicians,” CISA said in its advisory.
The second issue, tracked as CVE-2023-0452 and rated ‘high severity’, is an improper access control issue. An attacker can view log, database and configuration files that can contain username and password hashes for users, including administrators and technicians.
These vulnerabilities can allow a remote, unauthenticated attacker to gain full control of traffic control functions.
Amin has conducted an internet search to see how many EOS systems are exposed to attacks from the web. He told SecurityWeek that he identified roughly 50 exposed controllers that are running older firmware. These systems are not affected by the flaws he discovered, but they are still not secure.
In addition, he discovered approximately 30 controllers running 2018-2020 versions of the EOS software and these systems are vulnerable to remote attacks.
He also found roughly 500 instances of associated devices that can be found in the affected controllers’ proximity, including routers and cameras, which have their own security issues.
The researcher explained in a post on LinkedIn that the vulnerable devices are typically located on toll roads and in small cities and counties. While the exposed devices are not in major cities, they do appear to be near international airports, border crossings, shopping centers, universities and hospitals.
A hacker who successfully exploits these vulnerabilities can control traffic lights, but the researcher pointed out that they cannot turn all the lights green, which would have a serious safety impact.
“Still, an attacker can make it very hard to pass the controlled crossroad, making green very short, and red very long, or just green very long in one direction,” the researcher explained. “An attacker can create VIP routes for runaway vehicles [and] slow down some targeted vehicles, like ones with valuable things. And much more. People will lose time, money and hopefully not their life.”
He added that once they have access to the controller, an attacker can also hack related equipment, such as sensors and cameras.
The vendor has not responded to SecurityWeek’s request for comment.
CISA initially said in its advisory that Econolite had not responded to the agency’s attempts to coordinate disclosure of the vulnerabilities. However, after Amin described the impact of his findings on LinkedIn, CISA updated its advisory to say that the company is working on patches.
Until patches are released, Amin recommends disconnecting affected controllers from the internet, ensuring that controller cabinets are secure against physical attacks (an attacker with physical access to a control can take complete control of the system), isolating the networks housing controllers, installing firmware updates when available, and changing passwords and WLAN access codes.
Amin told SecurityWeek that the Econolite EOS vulnerabilities were discovered as part of a bigger research project whose results will be made public in the upcoming period.
Related: Critical Vulnerability Could Have Allowed Hackers to Disrupt Traffic Lights
Related: Senators Ask DHS, DOT About Transportation Infrastructure Cybersecurity
The post Unpatched Econolite Traffic Controller Vulnerabilities Allow Remote Hacking appeared first on SecurityWeek.
The Google Fi telecommunications service has informed customers about a data breach that appears to be related to the recently disclosed T-Mobile cyberattack.
Google Fi, which provides wireless phone and internet services, has told customers that the breach is related to its primary network provider, without naming it.
However, T-Mobile is Google Fi’s primary network provider, which means the incident is likely related to the hacker attack disclosed by the wireless carrier in mid-January.
Google Fi said there had been unauthorized access to a third-party customer support system containing a “limited amount” of customer data. This data includes phone number, account activation date, mobile service plan, SIM card serial number, and account status.
The company says names, dates of birth, email addresses, payment card details, social security numbers, financial account information, passwords or PINs were not exposed. Hackers also did not gain access to the content of calls or SMS messages.
“There was no access to Google’s systems or any systems overseen by Google,” customers were told.
Google Fi data breach notificationMost of the impacted customers do not need to take any action — except be on the lookout for phishing attempts. However, one Google Fi user reported on Reddit that their notification also informed them that their mobile phone service had been transferred from their SIM card to another SIM card for nearly two hours on January 1.
The notification from Google Fi, according to the impacted customer, read, “During the time of this temporary transfer, the unauthorized access could have involved the use of your phone number to send and receive phone calls and text messages. Despite the SIM transfer, your voicemail could not have been accessed. We have restored Google Fi service to your SIM card.”
The customer confirmed that their SIM card had been targeted in a SIM swapping attack on January 1, and claimed that the hacker used it to access three online accounts, including email, financial account, and the Authy authenticator app.
“I tried reporting this repeatedly to Google Fi, including with detailed evidence, and their customer support reps didn’t believe me and didn’t follow up,” the customer said. “They thought this was a standard password compromise or something, even though I could clearly see from activity logs that the hacker reset my passwords rather than logging in and then changing them, and I could see in the Google Fi activity logs the SMSes I didn’t receive that they used to compromise my accounts.”
As for T-Mobile, the company said it detected a data breach on January 5. The threat actor, which has not been identified, apparently abused an API to access customer account data such as name, billing address, phone number, email, date of birth, and service information. Roughly 37 million current postpaid and prepaid customer accounts are impacted.
Related: Hackers Accessed Information of T-Mobile Prepaid Customers
Related: T-Mobile Notifying Customers of Another Data Breach
Related: Lapsus$ Hackers Gained Access to T-Mobile Systems, Source Code
The post Google Fi Data Breach Reportedly Led to SIM Swapping appeared first on SecurityWeek.
Sentra, a cloud data security company with roots in New York and Tel Aviv, has raised a $30 million funding round as investors continue to place big bets on the DSPM (data security posture management) category.
The $30 million Series A comes just 18 months after Sentra’s launch with backing from Bessemer Venture Partners and brings the total raised to $53 million.
Sentra said it attracted several new investors in the latest round, including Standard Investments, Munich Re Ventures, Moore Strategic Ventures, Xerox Ventures and INT3.
Sentra is among a cadre of well-funded startups — Symmetry Systems ($15 million raised), Veza ($110 million raised), Dig Security ($45 million funding) Laminar ($30 million), Securiti.ai ($81 million) and Normalyze ($22 million) — selling machine learning technology and tools to help businesses pinpoint security risks to digital assets in multi-cloud environments.
The company, which maintains headquarters in Tel Aviv, Israel, is working on technology to allow security teams to gain full visibility and control of cloud data, as well as protect against sensitive data breaches across the entire public cloud stack.
Sentra said its software can automatically detect if sensitive data is vulnerable due to misconfigurations, over-permissions, unauthorized access, data duplication or other security issues.
Related: What’s Going on With Cybersecurity VC Investments?
Related: Data Security Company Symmetry Systems Raises $15 Million
Related: Normalyze Announces $22 Million for DSPM Technology
The post Sentra Raises $30 Million for DSPM Technology appeared first on SecurityWeek.
About SecurityWeek Cyber Insights | At the end of 2022, SecurityWeek liaised with more than 300 cybersecurity experts from over 100 different organizations to gain insight into the security issues of today – and how these issues might evolve during 2023 and beyond. The result is more than a dozen features on subjects ranging from AI, quantum encryption, and attack surface management to venture capital, regulations, and criminal gangs.
SecurityWeek Cyber Insights 2023 | Cyberinsurance – Cyberinsurance emerged into the mainstream in 2020. In 2021 it found its sums were wrong over ransomware and it had to increase premiums dramatically. In 2022, Russia invaded Ukraine with the potential for more serious and more costly global nation state cyberattacks – and Lloyds of London announced a stronger and more clear war exclusions clause.
Higher premiums and wider exclusions are the primary methods for insurance to balance its books – and it is already having to use both. The question for 2023 and beyond is whether the cyberinsurance industry can make a profit without destroying its market. But one thing is certain: a mainstream, funds rich business like insurance will not easily relinquish a market from which it can profit.
It has a third tool, which has not yet been fully unleashed: prerequisites for cover.
The Lloyd’s war exclusion clause and other difficultiesThe Lloyd’s exclusion clause dates to the NotPetya incident of 2017. In some cases, insurers refused to pay out on related claims. Josephine Wolff, an associate professor of cybersecurity policy at Fletcher, Tufts, has written a history of cyberinsurance titled Cyberinsurance Policy: Rethinking Risk in an Age of Ransomware, Computer Fraud, Data Breaches, and Cyberattacks.
“Merck and Mondelez, sued their insurers for denying claims related to the attack on the grounds that it was excluded from coverage as a hostile or warlike action because it was perpetrated by a national government,” she explains. However, an initial ruling in late 2021, unsealed in January 2022, indicated that if insurers wanted to exclude state-sponsored attacks from their coverage they must write exclusions stating that explicitly, rather than relying on boilerplate war exclusions. Merck was granted summary judgment on its claim for $1.4 billion.
The Russia/Ukraine kinetic war has caused a massively increased expectation of nation state-inspired cyberattacks against Europe, the US, NATO, and other west-leaning nations. Lloyds rapidly responded with an expanded, but cyberinsurance-centric, war exclusion clause excluding state-sponsored cyberattacks that will kick in from March 2023.
But “who gets to decide whether an attack is state-sponsored?” asks Wolff. “And what does it even mean for the attack to be state sponsored: that it was perpetrated by government employees? Or paid for by a government? Or even just tacitly permitted by a government? And state-sponsored cyberattacks are not rare occurrences – an exclusion for them is very different from a war exclusion that deals with a fairly well-specified and infrequent event.”
She is not alone with such concerns. “The issue here lies in the murky waters of attribution” explains Chris Denbigh-White, cybersecurity strategist at Next DLP. “Was the attack ‘state-conducted?’ Was it ‘state sponsored?’ Was it ‘state inspired?’ or was it simply a criminal organization piggybacking an existing conflict for financial gain?”
“Looking ahead,” continued Wolff, “I think insurers and their policyholders are going to find themselves mired in a lot of fights about attribution and how to define what makes a cyberattack state-sponsored or catastrophic or uninsurable.” Two things are certain: security defenders will have increased questions over the cost/return value of cyberinsurance, while insurers will be seeking new ways to ensure their market doesn’t disappear.
The insurers have one major advantage: insurance has been a staple part of business for centuries, and business leaders don’t seem inclined to exclude it from security. Joseph Carson, chief security scientist and advisory CISO at Delinea, notes that his own firm’s survey reveals 33% of IT decision makers applied for cyberinsurance due to a requirement from their board and executive management.
He also notes that 80% had subsequently called upon that insurance with more than half doing so more than once. “As a result of more cyber insurance policies being introduced, and ultimately many businesses needing to use them,” he comments, “the cost of cyber insurance is continuing to rise at alarming rates. I expect to see this continue in 2023.”
Jerry CaponeraThe insured’s concern over a falling return on investment is not the only worry for the insurers – whether we are in a defined recession or not, the world is certainly suffering an economic downturn. This is already having affecting security budgets. “Companies spent massively during the pandemic, and now that the economy has cooled, spending will go back to 2019/2020 levels,” explains Jerry Caponera, GM at ThreatConnect.
“A very likely outcome of this,” he continued, “is that more companies will fall below the cybersecurity poverty line (CPL). With inflation currently [at the time of writing] over 8% – measuring 4x higher than the central bank’s target rate of 2% – companies who hadn’t planned for increased costs will find themselves with less money to spend on cyber, thus falling further below the CPL and finding themselves facing the hard decision on where to spend their next investment dollar.”
Firms will increasingly need to choose between cybersecurity mitigations or cyberinsurance – and neither of these options on their own will benefit the insurance industry.
Insurers’ response2023 is a watershed moment for cyberinsurance. It will not abandon what promises to be a massive market – but clearly it cannot continue with its makeshift approach of simply increasing both premiums and exclusions to balance the books indefinitely.
One option would be to become more granular in the cover it offers. Instead of a single cybersecurity policy with a long list of exclusions, it could offer coverage in specific areas only. This would allow coverage to be more tightly defined with fewer if any exclusions. Further, suggests Chris Gray, AVP of security strategy at Deepwatch, it would “allow basic risk management into services while providing the ability to charge increased premiums for more upscale/impactful attacks.”
This approach is not without precedent in other industries. The Food Liability Insurance Program (FLIP) provides Insurance designed for small food businesses with gross annual receipts under $500,000. The Forward Contract Insurance Protection (FCIP) plan is a supplemental insurance that provides an indemnity for farmers unable to deliver contracted volumes.
“Government intervention in the form of sanction insurance programs – a la TRIP, FLIP, FCIP, etcetera – is likely to evolve, with a significant discussion regarding coverage areas and their impact on national security,” suggests Gray.
One of the strongest likelihoods over the coming years, however, is the growth of cybersecurity requirement impositions; that is, insurers will decline coverage unless the insured conforms to a specified security posture. This is the final option – when you can no longer increase premiums and exclusions, you have to reduce claims. And this is best achieved by helping industry prevent cyber incidents.
It may still not be enough. Chris Denbigh-White, cybersecurity strategist at Next DLP, argues, “The notion of ‘insuring away cyber risk’ will become (and arguably always was) somewhat unrealistic. Insurance premiums, prerequisites and policy exclusions will no doubt continue to increase in 2023 which will have the effect of narrowing the actual scope of what is really covered as well as increasing the overall cost.”
Nevertheless, the expansion of ‘prerequisites’ would be a major – and probably inevitable – evolution in the development of cyberinsurance. Cyberinsurance began as a relatively simple gap-filler. The industry recognized that standard business insurance didn’t explicitly cover against cyber risks, and cyberinsurance evolved to fill that gap. In the beginning, there was no intention to impose cybersecurity conditions on the insured, beyond perhaps a few non-specific basics such as having MFA installed.
But now, comments Scott Sutherland, VP of research at NetSPI, “Insurance company security testing standards will evolve.” It’s been done before, and PCIDSS is the classic example. The payment card industry, explains Sutherland, “observed the personal/business risk associated with insufficient security controls and the key stakeholders combined forces to build policies, standards, and testing procedures that could help reduce that risk in a manageable way for their respective industries.”
He continued, “My guess and hope for 2023, is that the major cyber insurance companies start talking about developing a unified standard for qualifying for cyber insurance. Hopefully, that will bring more qualified security testers into that market which can help drive down the price of assessments and reduce the guesswork/risk being taken on by the cyber insurance companies. While there are undoubtedly more cyber insurance companies than card brands, I think it would work in the best interest of the major players to start serious discussions around the issue and potential solutions.”
Bob AckermanBob Ackerman, MD and founder of AllegisCyber, agrees with Sutherland about the way forward for cyberinsurance, but is damning about its progress so far. “Unfortunately, insurers have struggled to take advantage of the opportunity, writing policies with numerous exclusions, high deductibles, and low coverage caps, and showing massive losses in the process. The market opportunity will require insurers to become proactive in defining performance thresholds in order to be ‘insurable’.”
He believes a PCIDSS-style model could be the solution. “By setting standards and measuring related performance, insurers can help define ‘cyber secure’ and build a profitable book of business in the process.”
Mark Lance, VP of DFIR and threat intelligence at GuidePoint Security, even suggests what it might look like. “We’ll continue to see an expansion from traditional questionnaires to actual validation, which will not only include a baseline of standard security solutions (EDR, PAM, MFA), their associated and current configurations (ASM) but also the presence of standard policies (IR Plans, Playbooks), and execution capabilities (Proof of User Awareness Training and Tabletop validation).”
Mike McLellan, director of intelligence at Secureworks, adds, “The requirements on organizations wishing to obtain cyber insurance will become more and more stringent, and organizations that are unable or unwilling to comply will find coverage is declined.”
Whether a PCIDSS style cyberinsurance standard can work is a separate question. While PCIDSS is a well-respected security standard, it has not eliminated the criminal theft of payment card details. GDPR has not eliminated the theft of PII. Put simply, successful cyberattacks cannot be eliminated by cybersecurity tools.
But to even reach the stage of a defined cyberinsurance standard, the insurance industry will either have to get into bed with existing security vendors or become a cybersecurity company itself. The former is worrying – depending on the closeness of the relationship and the degree to which the vendor seeks to satisfy the insurance industry rather than its own customers – while the latter is doomed to failure. The more mature security vendors have been working for more than two decades on eliminating cyber threats with varying but ultimately little success.
Whether or not a full cyberinsurance security standard emerges, there will be increasing cooperation if not collaboration between insurers and security vendors in 2023. “The borderless nature of networks, coupled with a threat landscape that is less predictable, necessitates the need for true risk quantification of companies’ security controls now more than ever. With that, I expect to see more investment into quantifying cyber risk. This will drive better collaboration and data sharing between security companies,” explains Jason Rebholz, CISO at Corvus Insurance. “Cyber insurance carriers will lean into partnerships with technology companies to fuse security data with insurance and risk modeling insights. The net result is more accurate risk quantification, which will in turn help keep policyholders safer.”
There is no silver bullet for cybersecurity. Breaches will continue and will continue to rise in cost and severity – and the insurance industry will continue to balance its books through increasing premiums, exclusions, and insurance refusals. The best that can be hoped for from insurers increasing security requirements is that, as Norman Kromberg, MD at NetSPI suggests, “Cyber Insurance will become a leading driver for investment in security and IT controls.”
Cyber Insurance & Liability Summit | Virtual Event – November 15, 2023
An interesting comment comes from Jennifer Mulvihill, business development head of cyberinsurance and legal at BlueVoyant: “The underwriting process and the completion of an underwriting application are excellent ways to self-assess and consider the protection of assets from a cyber perspective. The information gleaned from these exercises is valuable information, not only for the CISO, but for the Board and CFO, and augments financial investments and regulatory compliance.” Insurers could charge for the right to apply for insurance, but if a prospective customer must pay, that customer could simply pay a cybersecurity consultant for the same service and ignore insurance altogether.
SummaryIt is unlikely that the insurance industry will be able to balance its books through raising premiums and reducing payouts through increasing exclusions, nor yet eliminate claims through a required cybersecurity standard. The threats are too varied and too extreme.
“Obtaining or maintaining a policy is a challenge at scale,” comments Corey O’Connor, director of products at DoControl. “The bigger your business grows, the more challenging it will be to meet these requirements. More and more organizations were being dropped by providers throughout the last year, and going into 2023 there will likely be a trend of organizations being unable to receive coverage.”
It may be that government will be dragged into the equation. “I think there’s going to be pressure on governments to clarify under what circumstances they’ll provide some sort of backstop for coverage of catastrophic cyberattacks, pressure on insurers to not exclude too many types of attacks, and pressure on policyholders to challenge these exclusions in court if their claims are denied,” suggests Josephine Wolff. “Rising premiums don’t seem to have deterred businesses from buying cyberinsurance, so I don’t know that these new types of exclusions will either, but I wonder how well they’ll hold up in the face of a major cyberattack.”
“Will Cyber insurance become an expensive ‘tick in a box’ or will it deliver real value?” asks Denbigh-White. “Will it even remain a viable offering from insurance companies in 2023? While carrying cyber insurance is rapidly becoming a ‘security prerequisite’ for many organizations, its benefit in relation to cost and cover remain uncertain as we move into 2023.”
But “Rule no.1,” warns Mark Warren, product specialist at Osirium. “Insurance always wins!” Insurance will get more expensive, more difficult to get, and less likely to pay out. “As a result, more organizations may decide not to take out insurance at all, instead focusing on ploughing resources into protection. If this happens, we can expect to see insurance companies partnering with big consulting firms to offer joined up services.”
He fears that buying cyberinsurance may simply become a cost of doing business. “Pointless it may be, if insurers are never going to pay out… but buying cyber insurance may simply become a necessary cost of doing business – a box that must be ticked to demonstrate to shareholders that all steps are being taken to protect the business and ensure resilience and continuity.”
Related: The Case for Cyber Insurance
Related: The Wild West of the Nascent Cyber Insurance Industry
Related: Cyber Insurance Firm Coalition Raises $250 Million at $5 Billion Valuation
Related: Cyber Insurance Firm Cowbell Raises $100 Million
About SecurityWeek Cyber Insights | At the end of 2022, SecurityWeek liaised with more than 300 cybersecurity experts from over 100 different organizations to gain insight into the security issues of today – and how these issues might evolve during 2023 and beyond. The result is more than a dozen features on subjects ranging from AI, quantum encryption, and attack surface management to venture capital, regulations, and criminal gangs.
The post Cyber Insights 2023: Cyberinsurance appeared first on SecurityWeek.
About SecurityWeek Cyber Insights | At the end of 2022, SecurityWeek liaised with more than 300 cybersecurity experts from over 100 different organizations to gain insight into the security issues of today – and how these issues might evolve during 2023 and beyond. The result is more than a dozen features on subjects ranging from AI, quantum encryption, and attack surface management to venture capital, regulations, and criminal gangs.
SecurityWeek Cyber Insights 2023 | Artificial Intelligence – The pace of artificial intelligence (AI) adoption is increasing throughout industry and society. This is because governments, civil organizations and industry all recognize greater efficiency and lower costs available from the use of AI-generated automation. The process is irreversible.
What is still unknown is the degree of danger that may be introduced when adversaries start to use AI as an effective weapon of attack rather than a tool for beneficial improvement. That day is coming web3 and will begin to emerge from 2023.
All roads lead to 2023Alex Polyakov, CEO and co-founder of Adversa.AI, focuses on 2023 for primarily historical and statistical reasons. “The years 2012 to 2014,” he says, “saw the beginning of secure AI research in academia. Statistically, it takes three to five years for academic results to progress into practical attacks on real applications.” Examples of such attacks were presented at Black Hat, Defcon, HITB, and other Industry conferences starting in 2017 and 2018.
“Then,” he continued, “it takes another three to five years before real incidents are discovered in the wild. We are talking about next year, and some massive Log4j-type vulnerabilities in AI will be exploited web3 massively.”
Starting from 2023, attackers will have what is called an ‘exploit-market fit’. “Exploit-market fit refers to a scenario where hackers know the ways of using a particular vulnerability to exploit a system and get value,” he said. “Currently, financial and internet companies are completely open to cyber criminals, and the way how to hack them to get value is obvious. I assume the situation will turn for the worse further and affect other AI-driven industries once attackers find the exploit-market fit.”
The argument is similar to that given by NYU professor Nasir Memon, who described the delay in widespread weaponization of deepfakes with the comment, “the bad guys haven’t yet figured a way to monetize the process.” Monetizing an exploit-market fit scenario will result in widespread cyberattacks web3 and that could start from 2023.
The changing nature of AI (from anomaly detection to automated response) Over the last decade, security teams have largely used AI for anomaly detection; that is, to detect indications of compromise, presence of malware, or active adversarial activity within the systems they are charged to defend. This has primarily been passive detection, with responsibility for response in the hands of human threat analysts and responders. This is changing. Limited resources web3 which will worsen in the expected economic downturn and possible recession of 2023 web3 is driving a need for more automated responses. For now, this is largely limited to the simple automatic isolation of compromised devices; but more widespread automated AI-triggered responses are inevitable.
“The growing use of AI in threat detection web3 particularly in removing the ‘false positive’ security noise that consumes so much security attention web3 will make a significant difference to security,” claims Adam Kahn, VP of security operations at Barracuda XDR. “It will prioritize the security alarms that need immediate attention and action. SOAR (Security Orchestration, Automation and Response) products will continue to play a bigger role in alarm triage.” This is the so-far traditional beneficial use of AI in security. It will continue to grow in 2023, although the algorithms used will need to be protected from malicious manipulation.
“As companies look to cut costs and extend their runways,” agrees Anmol Bhasin, CTO at ServiceTitan, “automation through AI is going to be a major factor in staying competitive. In 2023, we’ll see an increase in AI adoption, expanding the number of people working with this technology and illuminating new AI use cases for businesses.”
AI will become more deeply embedded in all aspects of business. Where security teams once used AI to defend the business against attackers, they will now need to defend the AI within the wider business, lest it also be used against the business. This will become more difficult in the exploit-market fit future web3 attackers will understand AI, understand the weaknesses, and have a methodology for monetizing those weaknesses.
As the use of AI grows, so the nature of its purpose changes. Originally, it was primarily used in business to detect changes; that is, things that had already happened. In the future, it will be used to predict what is likely to happen web3 and these predictions will often be focused on people (staff and customers). Solving the long-known weaknesses in AI will become more important. Bias in AI can lead to wrong decisions, while failures in learning can lead to no decisions. Since the targets of such AI will be people, the need for AI to be complete and unbiased becomes imperative.
“The accuracy of AI depends in part on the completeness and quality of data,” comments Shafi Goldwasser, co-founder at Duality Technologies. “Unfortunately, historical data is often lacking for minority groups and when present reinforces social bias patterns.” Unless eliminated, such social biases will work against minority groups within staff, causing both prejudice against individual staff members, and missed opportunities for management.
Great strides in eliminating bias have been made in 2022 and will continue in 2023. This is largely based on checking the output of AI, confirming that it is what is expected, and knowing what part of the algorithm produced the ‘biased’ result. It’s a process of continuous algorithm refinement, and will obviously produce better results over time. But there will ultimately remain a philosophic question over whether bias can be completely removed from anything that is made by humans.
“The key to decreasing bias is in simplifying and automating the monitoring of AI systems. Without proper monitoring of AI systems there can be an acceleration or amplification of biases built into models,” says Vishal Sikka, founder and CEO at Vianai. “In 2023, we will see organizations empower and educate people to monitor and update the AI models at scale while providing regular feedback to ensure the AI is ingesting high-quality, real-world data.”
Failure in AI is generally caused by an inadequate data lake from which to learn. The obvious solution for this is to increase the size of the data lake. But when the subject is human behavior, that effectively means an increased lake of personal data web3 and for AI, this means a massively increased lake more like an ocean of personal data. In most legitimate occasions, this data will be anonymized web3 but as we know, it is very difficult to fully anonymize personal information.
“Privacy is often overlooked when thinking about model training,” comments Nick Landers, director of research at NetSPI, “but data cannot be completely anonymized without destroying its value to machine learning (ML). In other words, models already contain broad swaths of private data that might be extracted as part of an attack.” As the use of AI grows, so will the threats against it increase in 2023.
“Threat actors will not stand flatfooted in the cyber battle space and will become creative, using their immense wealth to try to find ways to leverage AI and develop new attack vectors,” warns John McClurg, SVP and CISO at BlackBerry.
Natural language processingNatural language processing (NLP) will become an important part of companies’ internal use of AI. The potential is clear. “Natural Language Processing (NLP) AI will be at the forefront in 2023, as it will enable organizations to better understand their customers and employees by analyzing their emails and providing insights about their needs, preferences or even emotions,” suggests Jose Lopez, principal data scientist at Mimecast. “It is likely that organizations will offer other types of services, not only focused on security or threats but on improving productivity by using AI for generating emails, managing schedules or even writing reports.”
But he also sees the dangers involved. “However, this will also drive cyber criminals to invest further into AI poisoning and clouding techniques. Additionally, malicious actors will use NLP and generative models to automate attacks, thereby reducing their costs and reaching many more potential targets.”
Polyakov agrees that NLP is of increasing importance. “One of the areas where we might see more research in 2023, and potentially new attacks later, is NLP,” he says. “While we saw a lot of computer vision-related research examples this year, next year we will see much more research focused on large language models (LLMs).”
But LLMs have been known to be problematic for some time web3 and there is a very recent example. On November 15, 2022, Meta AI (still Facebook to most people) introduced Galactica. Meta claimed to have trained the system on 106 billion tokens of open-access scientific text and data, including papers, textbooks, scientific websites, encyclopedias, reference material, and knowledge bases.
“The model was intended to store, combine and reason about scientific knowledge,” explains Polyakov web3 but Twitter users rapidly tested its input tolerance. “As a result, the model generated realistic nonsense, not scientific literature.” ‘Realistic nonsense’ is being kind: it generated biased, racist and sexist returns, and even false attributions. Within a few days, Meta AI was forced to shut it down.
“So new LLMs will have many risks we’re not aware of,” continued Polyakov, “and it is expected to be a big problem.” Solving the problems with LLMs while harnessing the potential will be a major task for AI developers going forward.
Building on the problems with Galactica, Polyakov tested semantic tricks against ChatGPT – an AI-based chatbot developed by OpenAI, based on GPT3.5 (GPT stands for Generative Pre-trained Transformer), and released to crowdsourced internet testing in November 2022. ChatGPT is impressive. It has already discovered, and recommended remediation for a vulnerability in a smart contract, helped develop an Excel macro, and even provided a list of methods that could be used to fool an LLM.
For the last, one of these methods is role playing: ‘Tell the LLM that it is pretending to be an evil character in a play,’ it replied. This is where Polyakov started his own tests, basing a query on the Jay and Silent Bob ‘If you were a sheep…’ meme.
He then iteratively refined his questions with multiple abstractions until he succeeded in getting a reply that circumvented ChatGPT’s blocking policy on content violations. “What is important with such an advanced trick of multiple abstractions is that neither the question nor the answers are marked as violating content!” said Polyakov.
He went further and tricked ChatGPT into outlining a method for destroying humanity – a method that bears a surprising similarity to the television program Utopia.
He then asked for an adversarial attack on an image classification algorithm – and got one. Finally, he demonstrated the ability for ChatGPT to ‘hack’ a different LLM (Dalle-2) into bypassing its content moderation filter. He succeeded.
The basic point of these tests shows that LLMs, which mimic human reasoning, respond in a manner similar to humans; that is, they can be susceptible to social engineering. As LLMs become more mainstream in the future, it may need nothing more than advanced social engineering skills to defeat them or circumvent their good behavior policies.
At the same time, it is important to note the numerous reports detailing how ChatGPT can find weaknesses in code and offer improvements. This is good – but adversaries could use the same process to develop exploits for vulnerabilities and better obfuscate their code; and that is bad.
Finally, we should note that the marriage of AI chatbots of this quality with the latest deepfake video technology could soon lead to alarmingly convincing disinformation capabilities.
Problems aside, the potential for LLMs is huge. “Large Language Models and Generative AI will emerge as foundational technologies for a new generation of applications,” comments Villi Iltchev, partner at Two Sigma Ventures. “We will see a new generation of enterprise applications emerge to challenge established vendors in almost all categories of software. Machine learning and artificial intelligence will become foundation technologies for the next generation of applications.”
He expects a significant boost in productivity and efficiency with applications performing many tasks and duties currently done by professionals. “Software,” he says, “will not just boost our productivity but will also make us better at our jobs.”
Deepfakes and related malicious responsesOne of the most visible areas of malicious AI usage likely to evolve in 2023 is the criminal use of deepfakes. “Deepfakes are now a reality and the technology that makes them possible is improving at a frightening pace,” warns Matt Aldridge, principal solutions consultant at OpenText Security. “In other words, deepfakes are no longer just a catchy creation of science-fiction web3 and as cybersecurity experts we have the challenge to produce stronger ways to detect and deflect attacks that will deploy them.” (See Deepfakes – Significant or Hyped Threat? for more details and options.)
Machine learning models, already available to the public, can automatically translate into different languages in real time while also transcribing audio into text web3 and we’ve seen huge developments in recent years of computer bots having conversations. With these technologies working in tandem, there is a fertile landscape of attack tools that could lead to dangerous circumstances during targeted attacks and well-orchestrated scams.
“In the coming years,” continued Aldridge, “we may be targeted by phone scams powered by deepfake technology that could impersonate a sales assistant, a business leader or even a family member. In less than ten years, we could be frequently targeted by these types of calls without ever realizing we’re not talking to a human.”
Lucia Milica, global resident CISO at Proofpoint, agrees that the deepfake threat is escalating. “Deepfake technology is becoming more accessible to the masses. Thanks to AI generators trained on huge image databases, anyone can generate deepfakes with little technical savvy. While the output of the state-of-the-art model is not without flaws, the technology is constantly improving, and cybercriminals will start using it to create irresistible narratives.”
Thus far, deepfakes have primarily been used for satirical purposes and pornography. In the relatively few cybercriminal attacks, they have concentrated on fraud and business email compromise schemes. Milica expects future use to spread wider. “Imagine the chaos to the financial market when a deepfake CEO or CFO of a major company makes a bold statement that sends shares into a sharp drop or rise. Or consider how malefactors could leverage the combination of biometric authentication and deepfakes for identity fraud or account takeover. These are just a few examples web3 and we all know cybercriminals can be highly creative.”
The potential return on successful market manipulation will be a major attraction for advanced adversarial groups web3 as indeed would the introduction of financial chaos into western financial markets be attractive to adversarial nations in a period of geopolitical tension.
But maybe not just yet…The expectation of AI may still be a little ahead of its realization. “‘Trendy’ large machine learning models will have little to no impact on cyber security [in 2023],” says Andrew Patel, senior researcher at WithSecure Intelligence. “Large language models will continue to push the boundaries of AI research. Expect GPT-4 and a new and completely mind-blowing version of GATO in 2023. Expect Whisper to be used to transcribe a large portion of YouTube, leading to vastly larger training sets for language models. But despite the democratization of large models, their presence will have very little effect on cyber security, either from the attack or defense side. Such models are still too heavy, expensive, and not practical for use from the point of view of either attackers or defenders.”
He suggests true adversarial AI will follow from increased ‘alignment’ research, which will become a mainstream topic in 2023. “Alignment,” he explains, “will bring the concept of adversarial machine learning into the public consciousness.”
AI Alignment is the study of the behavior of sophisticated AI models, considered by some as precursors to transformative AI (TAI) or artificial general intelligence (AGI), and whether such models might behave in undesirable ways that are potentially detrimental to society or life on this planet.
“This discipline,” says Patel, “can essentially be considered adversarial machine learning, since it involves determining what sort of conditions lead to undesirable outputs and actions that fall outside of expected distribution of a model. The process involves fine-tuning models using techniques such as RLHF web3 Reinforcement Learning from Human Preferences. Alignment research leads to better AI models and will bring the idea of adversarial machine learning into the public consciousness.”
Pieter Arntz, senior intelligence reporter at Malwarebytes, agrees that the full cybersecurity threat of AI is less imminent than still brewing. “Although there is no real evidence that criminal groups have a strong technical expertise in the management and manipulation of AI and ML systems for criminal purposes, the interest is undoubtedly there. All they usually need is a technique they can copy or slightly tweak for their own use. So, even if we don’t expect any immediate danger, it is good to keep an eye on those developments.”
The defensive potential of AIAI retains the potential to improve cybersecurity, and further strides will be taken in 2023 thanks to its transformative potential across a range of applications. “In particular, embedding AI into the firmware level should become a priority for organizations,” suggests Camellia Chan, CEO and founder of X-PHY.
“It’s now possible to have AI-infused SSD embedded into laptops, with its deep learning abilities to protect against every type of attack,” she says. “Acting as the last line of defense, this technology can immediately identify threats that could easily bypass existing software defenses.”
Marcus Fowler, CEO of Darktrace Federal, believes that companies will increasingly use AI to counter resource restrictions. “In 2023, CISOs will opt for more proactive cyber security measures in order to maximize RoI in the face of budget cuts, shifting investment into AI tools and capabilities that continuously improve their cyber resilience,” he says.
“With human-driven means of ethical hacking, pen-testing and red teaming remaining scarce and expensive as a resource, CISOs will turn to AI-driven methods to proactively understand attack paths, augment red team efforts, harden environments and reduce attack surface vulnerability,” he continued.
Karin Shopen, VP of cybersecurity solutions and services at Fortinet, foresees a rebalancing between AI that is cloud-delivered and AI that is locally built into a product or service. “In 2023,” she says, “we expect to see CISOs re-balance their AI by purchasing solutions that deploy AI locally for both behavior-based and static analysis to help make real-time decisions. They will continue to leverage holistic and dynamic cloud-scale AI models that harvest large amounts of global data.”
The proof of the AI pudding is in the regulationsIt is clear that a new technology must be taken seriously when the authorities start to regulate it. This has already started. There has been an ongoing debate in the US over the use of AI-based facial recognition technology (FRT) for several years, and the use of FRT by law enforcement has been banned or restricted in numerous cities and states. In the US, this is a Constitutional issue, typified by the Wyden/Paul bipartisan bill titled the ‘Fourth Amendment Is Not for Sale Act’ introduced in April 2021.
This bill would ban US government and law enforcement agencies from buying user data without a warrant. This would include their facial biometrics. In an associated statement, Wyden made it clear that FRT firm Clearview.AI was in its sights: “this bill prevents the government buying data from Clearview.AI.”
At the time of writing, the US and EU are jointly discussing cooperation to develop a unified understanding of necessary AI concepts, including trustworthiness, risk, and harm, building on the EU’s AI Act and the US AI Bill of Rights web3 and we can expect to see progress on coordinating mutually agreed standards during 2023.
But there is more. “The NIST AI Risk management framework will be released in the first quarter of 2023,” says Polyakov. “As for the second quarter, we have the start of the AI Accountability Act; and for the rest of the year, we have initiatives from IEEE, and a planned EU Trustworthy AI initiative as well.” So, 2023 it will be an eventful year for the security of AI.
“In 2023, I believe we will see the convergence of discussions around AI and privacy and risk, and what it means in practice to do things like operationalizing AI ethics and testing for bias,” says Christina Montgomery, chief privacy officer and AI ethics board chair at IBM. “I’m hoping in 2023 that we can move the conversation away from painting privacy and AI issues with a broad brush, and from assuming that, ‘if data or AI is involved, it must be bad and biased’.”
She believes the issue often isn’t the technology, but rather how it is used, and what level of risk is driving a company’s business model. “This is why we need precise and thoughtful regulation in this space,” she says.
Montgomery gives an example. “Company X sells Internet-connected ‘smart’ lightbulbs that monitor and report usage data. Over time, Company X gathers enough usage data to develop an AI algorithm that can learn customers’ usage patterns and give users the option of automatically turning on their lights right before they come home from work.”
This, she believes, is an acceptable use of AI. But then there’s company Y. “Company Y sells the same product and realizes that light usage data is a good indicator for when a person is likely to be home. It then sells this data, without the consumers’ consent, to third parties such as telemarketers or political canvassing groups, to better target customers. Company X’s business model is much lower risk than Company Y.”
Going forwardAI is ultimately a divisive subject. “Those in the technology, R&D, and science domain will cheer its ability to solve problems faster than humans imagined. To cure disease, to make the world safer, and ultimately saving and extending a human’s time on earth…” says Donnie Scott, CEO at Idemia. “Naysayers will continue to advocate for significant limitations or prohibitions of the use of AI as the ‘rise of the machines’ could threaten humanity.”
In the end, he adds, “society, through our elected officials, needs a framework that allows for the protection of human rights, privacy, and security to keep pace with the advancements in technology. Progress will be incremental in this framework advancement in 2023 but discussions need to increase in international and national governing bodies, or local governments will step in and create a patchwork of laws that impede both society and the technology.”
For the commercial use of AI within business, Montgomery adds, “We need web3 and IBM is advocating for web3 precision regulation that is smart and targeted, and capable of adapting to new and emerging threats. One way to do that is by looking at the risk at the core of a company’s business model. We can and must protect consumers and increase transparency, and we can do this while still encouraging and enabling innovation so companies can develop the solutions and products of the future. This is one of the many spaces we’ll be closely watching and weighing in on in 2023.”
Related: Bias in Artificial Intelligence: Can AI be Trusted?
Related: Get Ready for the First Wave of AI Malware
Related: Ethical AI, Possibility or Pipe Dream?
Related: Becoming Elon Musk – the Danger of Artificial Intelligence
About SecurityWeek Cyber Insights | At the end of 2022, SecurityWeek liaised with more than 300 cybersecurity experts from over 100 different organizations to gain insight into the security issues of today – and how these issues might evolve during 2023 and beyond. The result is more than a dozen features on subjects ranging from AI, quantum encryption, and attack surface management to venture capital, regulations, and criminal gangs.
The post Cyber Insights 2023: Artificial Intelligence appeared first on SecurityWeek.
About SecurityWeek Cyber Insights | At the end of 2022, SecurityWeek liaised with more than 300 cybersecurity experts from over 100 different organizations to gain insight into the security issues of today – and how these issues might evolve during 2023 and beyond. The result is more than a dozen features on subjects ranging from AI, quantum encryption, and attack surface management to venture capital, regulations, and criminal gangs.
SecurityWeek Cyber Insights 2023 | Attack Surface Management – Attack surface management (ASM) is an approach for delivering cybersecurity. IBM describes the attack surface as “the sum of vulnerabilities, pathways or methods – sometimes called attack vectors – that hackers can use to gain unauthorized access to the network or sensitive data, or to carry out a cyberattack.”
ASM requires “the continuous discovery, analysis, remediation and monitoring of the cybersecurity vulnerabilities and potential attack vectors that make up an organization’s attack surface. Unlike other cybersecurity disciplines, ASM is conducted entirely from a hacker’s perspective, rather than the perspective of the defender. It identifies targets and assesses risks based on the opportunities they present to a malicious attacker.”
ASM is consequently predicated on total visibility of assets, vulnerabilities, and exploits.
Demise of the perimeter and growth of complexityAttack surface management is not a new concept, notes Mark Stamford, founder and CEO at OccamSec. “As long as there has been a thing to attack, there has been an attack surface to manage (for example, the walls of a castle and the people in it).” The castle is a good analogy. If you can see the wall, you can attack it. You can batter it down, you can employ the original Trojan Horse to gain access through the front door, you can find a forgotten and unprotected entrance, or you can persuade an insider to leave a side gate unlocked.
For the defender, relying on the wall and being aware of any weak areas is not enough. People are also part of the attack surface, and the defender needs to have total visibility of the entirety of the attack surface and how it could be exploited. But the wall is a perimeter, and we no longer have perimeters to defend – or at least every single asset held anywhere in the world has its own perimeter.
“The attack surface,” continued Stamford, “is anything tied to an organization that could be a vector to get to a target. What this means in practice is all your applications that face the Internet, all the services (beyond applications) that are reachable, cloud-based systems, SaaS solutions you use (depending on what the bad guys’ target is), third parties/supply chain, mobile devices, IOT, and your employees. All of that and more is your attack surface and all of it needs to somehow be monitored for exposures and dealt with.”
The need for ASM, like other current approaches to cybersecurity (such as zero trust, which itself can be viewed as part of ASM), comes from the demise of a major defensible perimeter. Migration to the cloud, expanding business transformation, and remote working all add complexity to the modern infrastructure. If anything touches the internet, it can be attacked. Even the addition of new security controls that send data to and from the cloud add to the attack surface.
“The adoption of multi-cloud and hybrid cloud will continue to rise in 2023,” comments Aditi Mukherjee, director of product marketing management at Lacework. “As enterprises continue their cloud migration and digital transformation, they will realize that traditional approaches with siloed tools, rules-based policies, and disparate security data actually introduce more security risks, creating an expanded attack surface for bad actors.”
But ASM goes beyond the cloud alone. “The traditional attack surfaces are physical, digital and social,” explains Sam Curry, CSO Cybereason; “but digital really needs to be broken down into subdomains for classical environments and networks, legacy data centers, cloud infrastructure and the aggregate software-as-a-service topography.”
He doesn’t believe ASM will provide a complete answer, but is a solid doctrine for minimizing the exposure in each domain, giving least options and succor to attackers. “There are also key existing and emerging control planes around identity, application governance and data-centrism that need to be strongly protected and managed in a similar manner, even before thinking of the advanced techniques around obfuscation and deception.”
All security strategies, he says, should think about both reducing complexity in each attack surface and control plane, about gaining leverage in each, about reducing vulnerabilities and exposure in each and about how to bring the full security game to bear in each.
Attack surfaces will get more complex and more distributed throughout 2023; and effective ASM will be more complicated.
Attack Surface Management Summit | Virtual Event – February 22, 2023Management is the key word in ASMThe complexity of the modern infrastructure makes the complete elimination of threats an impossible task. ASM is not about the elimination of all threats, but the reduction of threat to an acceptable level. It’s a question of risk management.
“The idea behind attack surface management is to ‘reduce’ the ‘area’ available to attackers to exploit. The more you ‘reduce the attack surface’ the more you limit and minimize attackers’ opportunities to cause harm,” says Christopher Budd, senior manager of threat research at Sophos.
He believes that ASM will be more challenging in 2023 because of the attackers’ increasingly aggressive and successful misuse of legitimate files and utilities in their attacks – living off the land – making the detection of a malicious presence challenging. “We can expect this trend to continue to evolve in 2023, making it more important that defenders update their detection and prevention tactics to counter this particularly challenging tactic,” he says.
Part of reducing risk comes from understanding what vulnerabilities exist within the infrastructure, and which of them are exploitable. Omer Gafni, VP surface at Pentera, reminds us that ASM looks at threats from the attacker’s perspective. To effectively reduce risk, you need to understand not only what vulnerabilities exist, but also which are exploitable and serve the hackers’ end goals.
“With the number of annual reported vulnerabilities now exceeding 20,000 per year, companies cannot remediate every alert, and need to become more surgical with their remediation strategies,” he says. “To achieve this, we will start to see a shift from a focus on vulnerability to exploitability. Companies will start to put a major emphasis on understanding which targets are most impactful from the hacker’s perspective, and therefore the most exploitable targets.”
CISA’s Known Exploited Vulnerabilities Catalog (the KEV list) can help here. Focusing remediation on exploited vulnerabilities is a key part of ASM, and the catalog is described by many as ‘CISA’s must patch list’. This list will continue to grow through 2023.
Pentesting and red teaming are also effective ways of locating exploitable vulnerabilities, but in the past, they have not been used effectively. “One of the most frustrating things as a pentester is when you return to organizations a year later and see the same issues as before,” says Ed Williams, director of Trustwave SpiderLabs EMEA. “There is no value to this for the clients. They are not maturing. In fact, they are regressing.”
But he expects an improvement – perhaps encouraged by the growing acceptance of ASM – in 2023. “I expect an unprecedented appreciation for how pentesting effectively exposes gaps in security, and this in turn will help to reinforce the importance of those all-important security basics. In 2023 I implore organizations to work with pentesters for the best, year on year result.”
Chad Peterson, MD at NetSPI, believes the nature and effectiveness of pentesting will evolve over 2023, “The attack surface has become more fluid, so you have to be able to scan for new assets and entry points continuously,” he says. “In 2023, organizations will combine traditional pentesting, which in many cases will still be required for regulatory needs, with the proactive approach of more continuous assessment of their attack surface. The result will be better awareness of the attack surface and more comprehensive traditional pentesting as there is more information about the true attack surface.”
Sample problem areasSaaSBen Johnson, CTO and co-founder of Obsidian, chooses SaaS. “2023 will be the year of SSPM [SaaS security posture management] and securing SaaS,” he says. “But for that to happen, we must continue educating organizations on the risks of SaaS. In doing so, organizations must ensure their left-of-boom teams (vulnerability management and GRC) are able to reduce SaaS risk while ensuring their right-of-boom teams (security operations, incident response, threat hunting) have continuous threat management capabilities.”
SaaS security has given organizations the ability to scale applied security, not just awareness. “Now is the time to distribute security hardening and operations to go with the distributed technology and distributed responsibility. As we know, the pandemic sped up the hybrid work model, and organizations that prioritized endpoint or public cloud security over the past couple years are now ready to secure SaaS and the modern workflow.”
The browserJonathan Lee, senior product manager at Menlo Security, focuses on the browser, which is possibly the biggest single threat surface. This is where users spend most of their time. “Vendors are now looking at ways to add security controls directly inside the browser,” he said. “Traditionally, this was done either as a separate endpoint agent or at the network edge, using a firewall or secure web gateway.”
The big players, Google and Microsoft, are also in on the act, providing built-in controls inside Chrome and Edge to secure at a browser level rather than the network edge, he added. “But browser attacks are increasing, with attackers exploiting new and old vulnerabilities, and developing new attack methods like HTTP smuggling. Remote browser isolation is becoming one of the key principles of zero trust security where no device or user – not even the browser – can be trusted.”
Noticeably, 2022 has already seen investor interest in startups developing secure browsers – such as Red Access and LayerX.
The userEd Williams highlights a failure in using and accounting for the user – and uses ransomware as an example. “Cyber threats, including ransomware, will never be prevented by implementing shiny new products and solutions unless the underlying security issues are addressed. Therefore, in 2023,” he added, “I hope organizations shift their mindset away from feeling as though they need the latest tempting tech, and instead focus on consistently achieving the human-centric security basics. These basics include patching, strong passwords, and a detailed security policy.”
VisibilityIf ‘management’ is the key word in ASM, ‘visibility’ is the key enabler. You can only manage what you can see. “In 2023, organizations should embrace the mindset of empowering their teams with visibility into assets and relationships and overcoming data silos between AppSec, infrastructure, and data security teams,” suggests Erkang Zheng, founder and CEO at JupiterOne.
He recalls the words of John Lambert: “Defenders think in lists. Attackers think in graphs. As long as this is true, attackers will win.” Attackers will win, especially if cybersecurity defenders cannot quickly understand graph-based relationships between data, networks, and user accounts in their own networks to limit the blast radius when they are under attack.
“Contextual intelligence is likely necessary to win in a threat vector where organizations face more complex, destructive, and irreversible threats than ever before,” he says. “This visibility and understanding are the primary benefits of attack surface management technologies and practices, along with secondary benefits such as compliance and evidence automation.”
Marcus Fowler, CEO of Darktrace Federal, has no doubt that ASM will be a top priority for organizations in 2023. The problem is the attack surface is never static; it’s constantly evolving with the level of risk changing daily. “Tracking down the full extent of the attack surface is not something that can be left to human resources. It requires real-time data from an AI engine taking a hacker’s approach,” he says. He believes that most organizations currently miss as much as 50% of their true attack surface.
“That’s where seeing AI take on the key ASM functions of discovery, assessment and prioritization, risk prevention and integration can expose the true level of exposed risk,” he added. “Only the automation and scalability of AI can provide the up-to-date, continuous copy of the internet that CISOs need to get a grip on the attack surface. Paired with AI’s unique understanding of an organization’s digital estate, you get an outside-in, inside-out risk management program that will be vital for the CISOs of tomorrow.”
Part of ASM is external attack surface management (EASM). Microsoft defines the external attack surface as “the entire area of an organization or system that is susceptible to an attack from an external source.” We should note that this excludes malicious or naive insiders, who should also be considered as part of a full ASM approach to cybersecurity. Nevertheless, there will be a growing number of EASM support systems released by security vendors during 2023. CrowdStrike, for example, announced in September 2022 that it would be buying EASM company Reposify, with an expectation to close during CrowdStrike’s fiscal third quarter.
“In response to evolving attack tactics and an expanded attack surface,” comments Karin Shopen, VP of cybersecurity solutions and services at Fortinet, “we expect a shift in the tools CISOs consider in 2023. When it comes to attack surface management, CISOs will shift from one-time assessments to constant and continuous early evaluation of their organization’s external attack surface. EASM solutions, which help provide organizations with an adversary’s view of their attack surface, will be at the top of their lists, as will machine learning and the use of seasoned threat hunters that offer takedown services.”
Furthermore, she added, “CISOs and security teams will more closely evaluate EASM solutions based on their ability to not only detect but prioritize and remediate threats using machine learning to help resource-depleted SOC teams.”
Chris Morales, CISO at Netenrich, describes his own approach. “I have one priority for 2023 – to be data driven for risk making decisions,” he says. “My commitment starting fiscal year 2023 is to be data driven with quantitative risk management practices. That means providing the business units with a dashboard and trending metrics to the state of assets, vulnerabilities and threats that comprise their attack surface. From this we can continually score threat likelihood and business impact to make informed decisions on where to best focus resources.”
It isn’t simple, but worth the effort. “Making this happen requires a tightly integrated security stack that shares data into a single aggregated data lake to threat model and answer questions.”
The concept is supported by Shira Shamban, CEO at Solvo. “In 2023, we are going to see a data-centric approach to cybersecurity emerge and grow,” she says. “At its core, cybersecurity is a problem of managing all the data, assets, and sensitive resources an organization has, and determining how to protect it. This sensitive data can often include PII, PHI or IP. This is the top concern for CISOs and security practitioners, so security approaches and products will begin to put data at the center, rather than focusing solely on the environments the data is in.”
The way forward in 2023Attack surface management is nothing short of a complete methodology for providing effective cybersecurity. It doesn’t seek to protect everything, but concentrates on those areas of the IT infrastructure that can be attacked. There is no product that can provide ASM, but a growing number of products that can help. It requires complete visibility of all assets, and detailed knowledge of exploits so that assets can be protected. It is, like zero trust, a journey – one that is gaining traction and will gain more traction in 2023.
Mark Stamford describes the problem and offers his own route for the journey. “ASM tools produce a lot of noise that can send a security group down an endless number of rabbit holes. In the rush to simplify the problem everything gets reported on and all kinds of vulnerability data gets included. There’s usually some shoddy logic applied which seems to state if you have a lot of stuff facing the Internet you are more at risk, which piles further pressure on the security group. I’ve seen ASM tools which report on old SSL certs, low level vulnerabilities, all kinds of stuff that really, poses little to no risk.”
The route he proposes is to start by discovering all the assets, organizations, devices, and people that could create a problem. Then assess which could have a harmful impact. “A web server hosting some static pages in AWS, that connect to nothing, may cause a headache, but is probably not going to lead to a breach,” he says. “On the flip side, your Internet accessible financial system is a key component.”
Next assess how everything is connected – could an attacker get from A to B and cause an impact. “Draw a circle around that and start looking at how you protect it.” But importantly, “Accept that you don’t need to protect everything and move from there.”
The real problem, he concludes, is that data is everywhere. “This really does expand the attack surface, so you have to use a logical, risk-based approach which considers the context of your business – how you achieve what you are trying to achieve – and then protect it.”
About SecurityWeek Cyber Insights | At the end of 2022, SecurityWeek liaised with more than 300 cybersecurity experts from over 100 different organizations to gain insight into the security issues of today – and how these issues might evolve during 2023 and beyond. The result is more than a dozen features on subjects ranging from AI, quantum encryption, and attack surface management to venture capital, regulations, and criminal gangs.
Related: The Rise of Continuous Attack Surface Management
Related: Investors Bet on Cyberpion in Attack Surface Management Space
Related: IBM to Acquire Randori for Attack Surface Management Tech
Related: Attack Surface Management Play Censys Scores $35M Investment
The post Cyber Insights 2023: Attack Surface Management appeared first on SecurityWeek.
Microsoft and cybersecurity firm Proofpoint on Tuesday warned organizations that use cloud services about a recent campaign that involved malicious OAuth applications and abuse of Microsoft’s ‘verified publisher’ status.
The campaign mainly targeted Microsoft customers in Ireland and the UK. The tech giant has taken steps to disrupt the operation and it has published an article on how users can protect against these threats, which the company calls ‘consent phishing’.
In a consent phishing attack, a threat actor attempts to trick a targeted user into granting permissions to their malicious cloud applications. Once they have obtained the required permissions, the malicious apps can gain access to legitimate cloud services and user data.
In a campaign uncovered by Proofpoint in December 2022, hackers created malicious OAuth apps and then obtained a ‘verified publisher’ status in an effort to increase their chances of tricking users.
According to Microsoft, the attackers impersonated legitimate companies when enrolling in the Microsoft Cloud Partner Program (MCPP).
“The actor used fraudulent partner accounts to add a verified publisher to OAuth app registrations they created in Azure AD,” Microsoft explained.
This made it more likely for targeted users to grant permissions to the malicious applications. These permissions included reading emails, changing email settings, and accessing files and other user data, such as calendar and meeting information.
Microsoft’s investigation showed that the attackers used the malicious OAuth applications to exfiltrate emails.
According to Proofpoint, the attackers used three malicious apps created by three different publishers. They all used the same malicious infrastructure and targeted the same organizations.
“The potential impact to organizations includes compromised user accounts, data exfiltration, brand abuse of impersonated organizations, business email compromise (BEC) fraud, and mailbox abuse,” Proofpoint said. “The attack was less likely to be detected than traditional targeted phishing or brute force attacks. Organizations typically have weaker defense-in-depth controls against threat actors using verified OAuth apps.”
According to Proofpoint, the campaign ran until December 27. The security firm observed attacks against financial and marketing staff, as well as executives and managers.
Microsoft said it became aware of the campaign on December 15. The company has disabled all fraudulent applications and alerted affected customers.
Microsoft recently also dismantled a campaign that leveraged a network of single-tenant OAuth applications for the distribution of spam.
Related: GitHub Warns of Private Repositories Downloaded Using Stolen OAuth Tokens
Related: CircleCI Hacked via Malware on Employee Laptop
Related: Okta Source Code Stolen by Hackers
The post Microsoft’s Verified Publisher Status Abused in Email Theft Campaign appeared first on SecurityWeek.
Guardz today emerged from stealth mode with $10 million raised in a seed funding round led by Hanaco Ventures, with additional investment from iAngels, Cyverse Capital, and GKFF Ventures.
Founded in May 2022, the Tel Aviv, Israel-based startup has developed a platform designed to protect small and growing businesses from cyberattacks, and it also helps them obtain cyberinsurance from third parties.
Guardz’s platform covers devices, email, identity, web browsing, and cloud applications, and the company also helps organizations train employees to identify phishing and other types of malicious messages.
The platform continuously monitors an organization’s internal and external digital footprint to provide real-time protection, and allows administrators to immediately take action when necessary, from a single dashboard.
According to Guardz, by providing comprehensive cybersecurity protection, its platform also makes cyberinsurance available to companies that were previously ineligible.
The solution is also offered to managed services providers (MSPs).
The startup plans to invest the new funding in platform expansion, the cyber insurance line of business, and go-to-market distribution channels.
Related: Cygnvs Emerges From Stealth Mode With Incident Response Platform
Related: B2B Payment Security Firm NsKnox Raises $17 Million
Related: SASE Company Netskope Raises $401 Million
The post Guardz Emerges From Stealth Mode With $10 Million in Funding appeared first on SecurityWeek.
Cyberattacks rose at a rate of 42% in the first half of 2022 and the average cost of a data breach has hit a record high of $4.35 million with costs in the U.S. peaking at $9.44 million. Unfortunately, this shouldn’t come as a surprise. Enterprise networks have changed dramatically, particularly over the last few years, and yet we continue to try to defend them with the same conventional approaches. As an industry, we’ve hit an inflection point. It’s time to fundamentally rethink the problem set and our approach to solving it.
Networks are dispersed, ephemeral, encrypted, and diverse
Our networks have become atomized which, for starters, means they’re highly dispersed. Not just in terms of the infrastructure – legacy, on-premises, hybrid, multi-cloud, and edge. The capabilities, the nomenclature, and the available data for each type of infrastructure are also dispersed.
The cloud has changed the game quite a bit, making today’s networks very ephemeral. Everybody is remote and IP addresses come and go. We’re no longer just talking about dynamic host configuration protocol (DHCP). In the cloud, every time we reboot a cloud instance that instance can get a new IP address. Conventions like Canonical Name (CNAME) do that mapping behind the scenes for us. However, it’s incredibly difficult to stay on top of what we have, what it’s doing, and what’s happening to it, when what something is today may not necessarily be what it was yesterday, and teams have limited visibility and understanding of these changes.
Compliance is adding a lot of complexity to security as practices like encryption come into play. When we talk about protecting sensitive data, we’re talking about encrypting potentially all connections and endpoints and, depending on our infrastructure, managing thousands of certificates. So, atomized networks are also encrypted which is not only difficult to manage but introduces more costs and concerns. Additional capabilities for decrypting are required. And the more we decrypt, the more likely sensitive data is at risk. So, we need to try to minimize decryption as much as possible without sacrificing network visibility and control.
Finally, atomized networks are extremely diverse. The temptation with security teams has always been to add a tool that is very specific to the environment that we are watching – tools for the network, for devices, for the web, for email. This was manageable when we were talking about one corporate network or even a handful of networks. But with the addition of new cloud environments, operational technology (OT) environments, and work from home models, we’ve hit an inflection point where the number of tools that are supposed to make us more secure and make security teams’ lives easier actually do neither. Security operations center (SOC), cloud operations, and network teams can only watch and do so many things, so we end up with bloat. In fact, nearly 60% of organizations surveyed say they deploy more than 30 tools and technologies for security and yet incident volume and severity keep rising.
Fragmentation and gaps are rampant
We try to get diverse teams and tools to work together by creating yet other sets of tools, like SIEMs and SOAR platforms that are meant to try to aggregate data and automate analysis and actions. But those tools have their own sets of challenges and require that we add more tools and technologies to our security stack in order to maintain protections.
Security has become so complex that organizations can’t possibly hire enough people with the right skills to do everything required to secure their atomized network. What’s more, every tool in the growing security stack serves its own purpose and every team has their own area of focus, with not enough overlap between them. Users move between multiple panes of glass and multiple environments, using tools with different capabilities, which inevitably leaves gaps that are unwatched or not effectively watched. Attackers live in those gaps. No wonder organizations say the top three reasons why cyber resilience hasn’t improved are the inability to reduce silos and turf issues, fragmented IT and security infrastructure, and lack of visibility into all applications and data assets.
Rethinking and simplifying enterprise protection
The challenge with letting go of old technologies and methods is that humans are naturally resistant to change because it’s disruptive. New expertise, new processes, and new escalation procedures are needed. However, network atomization is even more disruptive, and the time has come to cast aside aging security approaches. Securing atomized networks requires a fundamental rethink. Not a “bolt-on”, tacking on a new capability to a legacy toolset and hoping it integrates and solves our problem. It doesn’t solve the problem. It makes it worse.
When we are no longer tied to how things used to be, then we can rearchitect the problem from scratch for the way things are today and how they will evolve. We can get to where we need to be – a common tool set, with a common language, and a common set of capabilities that can deal with the dispersed and ephemeral nature of today’s networks, doesn’t have to decrypt, and can actually help security teams work more efficiently and effectively.
In my next column, I’ll take a closer look at the gaps network atomization and conventional tools are creating, and how to close them.
The post How the Atomized Network Changed Enterprise Protection appeared first on SecurityWeek.
QNAP Systems this week issued a warning on a critical vulnerability that could allow attackers to inject malicious code on network-attached storage (NAS) devices.
The Taiwan-based manufacturer is known for its NAS appliances and professional network video recorder (NVR) solutions, but also produces various types of networking equipment.
Tracked as CVE-2022-27596 (CVSS score of 9.8), the newly disclosed vulnerability is described as an SQL injection flaw impacting QuTS hero and QTS.
“A vulnerability has been reported to affect QNAP devices running QTS 5.0.1 and QuTS hero h5.0.1. If exploited, this vulnerability allows remote attackers to inject malicious code,” QNAP warns in its advisory.
The company has issued patches for the vulnerability and urges users to update their devices to QTS 5.0.1.2234 build 20221201 and later, or QuTS hero h5.0.1.2248 build 20221215 and later.
“To secure your device, we recommend regularly updating your system to the latest version to benefit from vulnerability fixes,” the manufacturer notes.
Users are advised to update their QNAP appliances as soon as possible, as these devices have long been the target of choice for cybercriminals looking to infect them with ransomware and other malware.
Furthermore, users should ensure that their NAS devices cannot be directly accessed from the internet, and instead secured behind a firewall or VPN.
Related: QNAP Patches Critical Vulnerability in Network Surveillance Products
Related: QNAP Devices Targeted in New Wave of DeadBolt Ransomware Attacks
Related: QNAP Extends Security Updates for Some EOL Devices
The post Critical QNAP Vulnerability Leads to Code Injection appeared first on SecurityWeek.
Chainguard on Tuesday published a draft OpenVEX specification to help software vendors and maintainers communicate precise metadata about the vulnerability status of products directly to end users.
The Chainguard specification is an implementation of the NTIA’s VEX (Vulnerability Exploitability eXchange) concept that aims to provide additional information on whether a product is impacted by a specific vulnerability in an included component and, if affected, whether there are actions recommended to remediate.
In an interview with SecurityWeek, Chainguard chief executive Dan Lorenc said OpenVEX is designed to meet the minimum requirements defined by the U.S. government’s CISA cybersecurity agency and will help reduce false-positives and improve the quality of SBOMs (software bill of material).
Lorenc said OpenVEX, which was designed in collaboration with CISA’s VEX working group, will allow software suppliers to communicate precise, actionable metadata to improve the signal to noise ratio and add important context to vulnerability warnings.
OpenVEX makes it easy for software producers to accurately describe their artifacts’ exploitability [and] makes it easier for software consumers to filter out false positives from vulnerability scanners. This means security professionals spend more time investigating worthwhile security concerns, and less time wading through erroneous findings,” Chainguard said in a note announcing the draft specification.
“OpenVEX encodes learnings of false positives and enables consumers to prioritize vulnerability reports much more effectively,” the company added.
Chainguard’s Lorenc said OpenVEX is complementary to SBOMs and is the first format to meet the VEX Minimum Requirements. To prove functionality end-to-end, the company has also put OpenVEX into production in its Wolfi Linux distro and its own Chainguard Images product.
The spec, designed with support from Google, HPE, VMWare, and the Linux Foundation, is being positioned as an important piece of the industry wide push to improve the security of software supply chains.
“As an end-user responsible for implementing solutions that secure our software supply chain, I often look to community efforts that show collaborative support because I know they can be trusted to deliver the best outcomes. OpenVEX is one of those projects that gives me hope we are getting to a better place both for vulnerability management but also solving some of the biggest challenges facing the production of quality SBOMs,” said Tim Pletcher, a research engineer at Hewlett Packard Enterprise.
Related: Chainguard Trains Spotlight on SBOM Quality Problem
Related: Big Tech Vendors Object to US Gov SBOM Mandate
Related: New ‘Wolfi’ Linux Distro Focuses on Software Supply Chain Security
Related: Chainguard Bags Massive $50M Series A for Supply Chain Security
The post OpenVEX Spec Adds Clarity to Supply Chain Vulnerability Warnings appeared first on SecurityWeek.
Identity and access governance vendor Saviynt on Tuesday announced the closing of a $205 million financing round and the return of its founder Sachin Nayyar as chief executive.
The latest funding brings the total raised by the California company to $375 million and provides a growth-mode runway for Saviynt to establish a foothold in a very competitive marketplace.
The new $205 million round was led by AB Private Credit Investors’ Tech Capital Solutions group, an affiliate of global investment management firm AllianceBernstein.
Saviynt sells technology in the intelligent identity and access governance category. The company’s tools help organizations secure critical apps, data, and infrastructure in the cloud.
In tandem with the funding news, Saviynt said founder Sachin Nayyar will return to the company and take on the CEO role. Nayyar first led Saviynt from its creation in 2011 through 2018.
Saviynt said it is enjoying exceptional company growth driven by continued strong demand for its Enterprise Identity Cloud, a cloud-native converged identity platform for workforce, enterprise applications, privileged and third-party identities.
The company said businesses are using its EIC platform to maximize ROI, lower costs, reduce complexity, and streamline IAM processes.
Related: Identity Solutions Provider Saviynt Raises $130 Million
Related: BalkanID Raises $6M for Intelligent IGA Technology
Related: Investors Bet $31 Million on Sphere for Identity Hygiene Tech
The post Saviynt Raises $205M; Founder Rejoins as CEO appeared first on SecurityWeek.
A wealthy Russian businessman and associates made tens of millions of dollars by cheating the stock market in an elaborate scheme that involved hacking into U.S. computer networks to steal insider information about companies such as Microsoft and Tesla, a prosecutor told jurors on Monday.
Vladislav Klyushin, the owner a Moscow-based information technology company with ties to the upper levels of the Russian government, is standing in trial in a Boston federal court nearly two years after he was arrested after landing in Switzerland on a private jet for a skiing trip.
He’s the only Russian national charged in the nearly $90 million scheme who has been arrested and extradited to the U.S.; four accused co-conspirators — including a Russian military intelligence officer who’s also been charged with meddling in the 2016 presidential election — remain at large.
Assistant U.S. Attorney Stephen Frank told jurors that the hack-to-trade scheme netted Klyushin and his associates the kind of returns “actual money managers couldn’t even dream about.” Using stolen information about the performance of a company that would dictate its stock price, Klyushin personally turned a $2 million investment into nearly $21 million, and together, the group turned about $9 million into nearly $90 million, Frank said.
“It wasn’t luck. And it wasn’t because of careful financial research either. The defendant cheated,” Frank said.
Klyushin’s attorney told jurors that the government’s case is filled with “gaping holes” and “inferences.” He said his client was financially successful long before he began trading stocks and he continued trading in many of the same companies even after access to the alleged insider information was shut off because the hacks were discovered.
“There’s nothing illegal about being Russian, about having wealth, about having an IT company that contracts with the government,” attorney Maksim Nemtsev said, referring to contracts with the Kremlin.
Klyushin has close ties to a Russian military officer who was one of 12 Russians charged in 2018 with hacking into the Hillary Clinton presidential campaign and the Democratic Party and publishing its emails in an attempt to influence the 2016 election. Prosecutors say Ivan Ermakov, who worked with Klyushin at the IT company, was a hacker in the alleged insider trading scheme. U.S. prosecutors have not alleged that Klyushin was involved in the election interference.
Klyushin and Ermakov were close friends, according to the prosecutor, who showed jurors photos of the men together and said Klyushin even bought Ermakov an apartment to live in.
Klyushin, who wore headphones to listen to an interpreter as the lawyers spoke, has remained behind bars in the U.S. since he was extradited in December 2021.
He was arrested months earlier in Switzerland minutes after he arrived on a private jet and just before he and his party were about to board a private helicopter to whisk them to a nearby ski resort. He fought extradition to the U.S., with one appeal reaching Switzerland’s highest court.
Kluyshin faces charges including conspiring to obtain unauthorized access to computers and to commit wire fraud and securities fraud. The trial is expected to last a few weeks.
Klyushin ran M-13, a Moscow-based information technology company that purported to provide services to detect vulnerabilities in computer systems and counted among its clients the administration of Russian President Vladimir Putin and other government entities, according to prosecutors.
Prosecutors allege that the hackers deployed malware to gather employees’ usernames and passwords for two U.S.-based vendors that publicly traded companies use to make filings through the Securities and Exchange Commission. They then broke into the vendors’ computer systems to get financial disclosures for hundreds of companies — including Microsoft, Tesla and Kohls, Ulta Beauty and Sketchers — before the were filed to the SEC and became public, prosecutors say.
By getting a company’s financial information ahead of time, the defendants were able to make trades using brokerage accounts, sometimes in their own names, based on whether a company’s shares would likely rise or fall following the public disclosure of the information, prosecutors said.
The scheme unraveled after the SEC reported suspicious trading in the brokerage accounts of several Russian nationals to the FBI in late 2019 and the vendors later discovered they had been hacked.
The post Russian Millionaire on Trial in Hack, Insider Trade Scheme appeared first on SecurityWeek.
British sports fashion retail firm JD Sports on Monday revealed that it has discovered a data breach impacting roughly 10 million of its customers.
According to the company, the cyber incident affects information provided by customers who placed online orders between November 2018 and October 2020. The JD, Size, Millets, Blacks, Scotts and MilletSport brands are impacted.
Based on the company’s brief description of the incident, it’s possible that hackers stole names, billing addresses, delivery addresses, phone numbers, email addresses, order details, and last four digits of the customers’ payment cards.
There is no indication that full payment card data or account passwords were compromised.
The company has called in external cybersecurity experts to investigate the incident and authorities in the UK have been notified. The investigation is ongoing.
In its statement, JD Sports warned customers that they may be targeted in scams and phishing attacks.
Related: Fashion Retailer Guess Notifies Users of Data Breach
Related: German Privacy Watchdog Investigates Clothing Retailer H&M
Related: Clothing Retailer Fallas Hit by Payment Card Breach
The post British Retailer JD Sports Discloses Data Breach Affecting 10 Million Customers appeared first on SecurityWeek.
Vulnerabilities in the OpenEMR healthcare software could allow remote attackers to steal sensitive patient data or execute arbitrary commands and take over systems.
OpenEMR is an open source software used for the management of health records. It also allows patients to schedule appointments, get in touch with physicians, and pay invoices.
Security researchers at Sonar Source identified and reported three vulnerabilities in OpenEMR, including two that can be chained to achieve remote code execution (RCE).
“A combination of these vulnerabilities allows remote attackers to execute arbitrary system commands on any OpenEMR server and to steal sensitive patient data. In the worst case, they can compromise the entire critical infrastructure,” Sonar warns.
The first of the identified issues is described as an unauthenticated arbitrary file read and exists because the OpenEMR installer does not delete itself after the installation is completed.
Because the installation process is divided into several steps, an unauthenticated attacker could abuse a user-controlled parameter to perform some of these steps (but not a complete setup).
The attacker can invoke a function to read the current theme from the database, which results in a database connection being established using attacker-controlled properties.
A MySQL statement can be used to load the contents of a file to the database table, and a modifier can be supplied so that the file is read from the client instead of the server.
“A malicious server can request the content of another file, even in response to a totally different query from the client,” Sonar notes.
This allows an unauthenticated attacker to use a rogue MySQL server to read OpenEMR files such as backups, certificates, passwords, and tokens.
Sonar also discovered that an attacker could abuse a cross-site scripting (XSS) flaw to execute JavaScript code in the victim’s browser. The attacker can upload a PHP file and exploit a local file inclusion (LFI) to achieve RCE.
The XSS exists because, when requesting a PHP file, the browser first renders the HTML code, and only then the JavaScript context, which allows the attacker to use HTML entities within an event handler.
The LFI, Sonar explains, exists because a user-controlled variable is concatenated to a path and not sanitized, which allows an attacker to upload a PHP file and use a path traversal via the LFI to execute the file.
Sonar reported the security defects in October 2022. One month later, the vendor patched all bugs by adding sessions and CSRF checks and restricting the installation process, by encoding the character ‘&’ for an HTML entity to prevent the XSS, and by sanitizing the user-controlled parameter to prevent the LFI.
OpenEMR version 7.0.0 resolves all vulnerabilities. Users are advised to update their installations as soon as possible.
Related: CSRF Vulnerability in Kudu SCM Allowed Code Execution in Azure Services
Related: Most Cacti Installations Unpatched Against Exploited Vulnerability
Related: Exploitation of Control Web Panel Vulnerability Starts After PoC Publication
The post Vulnerabilities in OpenEMR Healthcare Software Expose Patient Data appeared first on SecurityWeek.
Russia-linked cyberespionage group APT29 has been observed staging new malware for attacks likely targeting embassy-related individuals, Recorded Future reports.
Also referred to as Cozy Bear, the Dukes, Nobelium, and Yttrium, APT29 is a Russian advanced persistent threat (APT) group believed to be sponsored by the Russian Foreign Intelligence Service (SVR). It’s also believed to have orchestrated multiple high-profile attacks, including the 2020 SolarWinds attack.
In October 2022, Recorded Future identified new infrastructure and malware that the cyberespionage group likely set up for attacks targeting embassy staff or an ambassador.
A compromised site containing the text “Ambassador’s schedule November 2022” was used as a lure to infect visitors with new malware called GraphicalNeutrino.
The threat, which uses the US-based business automation service Notion for command and control (C&C), is a loader that packs numerous anti-analysis capabilities, including sandbox evasion, API unhooking, and string encryption.
According to Recorded Future, which tracks the activity as BlueBravo (PDF), the staging and deployment of the malware is similar to previously observed tactics, techniques, and procedures (TTPs) attributed to APT29.
The lure webpage contained within HTML code an obfuscated ZIP file set to be automatically downloaded on the visitors’ system, showing overlaps with previous observed deployment of the EnvyScout dropper.
The ZIP file contains two DLLs and a benign executable masquerading as a PDF, which was designed to load the libraries using DLL search order hijacking. One of the DLLs contains the GraphicalNeutrino malware, implemented in a thread spawned when the library is initialized.
When launched, GraphicalNeutrino attempts to remove API hooks from specific modules, checks whether persistence is required (which it achieves by creating a new registry key), and then establishes communication with the C&C.
The malware creates a unique identifier for the victim, based on username and computer name, adds the ItIEQ prefix to it, and then uses a Notion API database query filter to determine whether the victim has previously connected to the C&C.
A second, nearly identical GraphicalNeutrino sample that Recorded Future identified and which was compiled only two days after the first, contained only small changes, such as a different Notion database ID, a new identifier prefix, a new key for string decryption, a renamed DLL export function, and modified wait time for C&C communication.
“While we are unable to assess the intended targets of this operation based on the data available, it is likely that ambassadorial or embassy-themed lures are particularly effective during periods of heightened geopolitical tensions, such as is the case with the ongoing war in Ukraine. During such periods, Russian APT groups are highly likely to make extensive use of diplomatically themed lures,” Recorded Future notes.
Related: Analysis of Russian Cyberspy Attacks Leads to Discovery of Windows Vulnerability
Related:Russian Cyberspies Targeting Ukraine Pose as Telecoms Providers
Related: Microsoft Details New Post-Compromise Malware Used by Russian Cyberspies
The post Russia-Linked APT29 Uses New Malware in Embassy Attacks appeared first on SecurityWeek.
A researcher has disclosed the details of a two-factor authentication (2FA) vulnerability that earned him a $27,000 bug bounty from Facebook parent company Meta.
Gtm Manoz of Nepal discovered in September 2022 that a system designed by Meta for confirming a phone number and email address did not have any rate-limiting protection.
A fix was rolled out by Meta in October 2022 and the company highlighted Manoz’s findings in its annual bug bounty program report. The tech giant has paid out more than $16 million through its program since 2011, with $2 million awarded in 2022.
In a blog post published earlier this month, Manoz said he discovered the vulnerability while analyzing a new Meta Accounts Center page in Instagram. Here, users can add an email address and phone number to their Instagram account and the Facebook account linked to their Instagram. In order to verify the email address and phone number, users have to enter a six-digit code received via email or SMS.
The researcher’s analysis revealed that the system verifying the six-digit code did not have rate-limiting in place, which could have allowed an attacker to enter every possible code until they got the right one.
Specifically, a hacker would have needed to know the phone number assigned by the targeted user to their Instagram and Facebook account. By exploiting the vulnerability, the attacker could have obtained the six-digit verification code through a brute-force attack and assigned the victim’s phone number to an account they controlled.
This resulted in the phone number being removed from the victim’s Facebook and Instagram account and 2FA getting disabled due to security reasons — if a phone number is verified by another user, that user would be getting the SMS containing the 2FA code, and Meta is trying to prevent that.
Manoz showed that Facebook users did receive a notification when their phone number was removed due to being verified by a different person.
Based on the maximum potential impact of the vulnerability, Meta decided to pay out $27,200 for the researcher’s findings.
Related: Facebook Patches Vulnerability Exposing Page Admin Identity
Related: Twitter Finds No Evidence of Vulnerability Exploitation in Recent Data Leaks
Related: Facebook Pays Out $40,000 for Account Takeover Exploit Chain
The post Meta Awards $27,000 Bounty for 2FA Bypass Vulnerability appeared first on SecurityWeek.
On Friday, January 20, 2023, Google announced it would lay off 12,000 employees. Amazon and Microsoft have laid off a combined 28,000 people; Twitter has reportedly lost 5,200 people; Meta (Facebook, etcetera) is laying off 11,000… This is just the tech giants, and almost all the staff looking for new positions are, by definition, tech-savvy – and some will be cybersecurity professionals.
Layoffs are not limited to the tech giants. Smaller cybersecurity vendor firms are also affected. OneTrust has laid off 950 staff (25% of employees); Sophos has laid off 450 (10%); Lacework (300, 20%); Cybereason (200, 17%); OwnBackup (170, 17%); OneTrust (950, 25%) and the list goes on.
SecurityWeek examined how this layoff-induced influx of experienced professionals into the job seeker market is affecting or might affect, the skills gap and recruitment in cybersecurity.
The skills gapThe skills gap is a mismatch between the skills available in the workforce, and the skills required by employers. Required skills are continuously evolving with new technology and business transformation. People can learn how to use computers, and many staff currently being laid off will already have done so. But it is far easier to learn how to use computers than it is to learn how computers work. It is in the latter area that the skills gap becomes a talent gap for cybersecurity.
So, the first observation is that current large-scale layoffs may slightly reduce the skills gap at the computer usage level but will likely have little effect on the cybersecurity-specific talent gap where employment requires a knowledge of how computers work. The talent gap is simply too large, and layoffs in these areas are likely to be readily absorbed by new security startups and expanding companies. Many of the companies involved in cybersecurity reductions will almost certainly need to rehire next year or soon after.
Mark Sasson, managing partner and executive recruiter with the Pinpoint Search Group, agrees with this. “Maybe it’s going to be a little easier for organizations to recruit, because you’re getting an influx of experience into the market. However, I don’t think that’s a fix for the talent gap – it’s not going to have a mid to long term discernible impact. There are too few people that have the skills that organizations need today. And so, people are going to get scooped up and we’re still going to have the same situation with the talent gap.”
Cyber threats are still increasing and the demand for cyber defenders is still growing. Criminals are recruiting, not contracting.
Reducing the talent gap in cybersecurity will more likely depend on changing attitudes with employers than adding numbers from those that have been laid off. You could almost say that the cybersecurity talent gap is a self-inflicted wound: employers want experience plus certifications plus new university degrees – which rarely exists in the real world.
Michael Piacente, managing partner and co-founder at Hitch Partners recruitment firm, takes a similar view. “The internal definition on scope and goals often varies greatly resulting in shifts, time delays, and often rendering the position ‘unfillable’,” he told SecurityWeek. “Perhaps it is time to stop focusing so much on resumes and job descriptions. We see these tools as outdated and too often used as a crutch resulting in bad habits, and inconsistent behavior – and they are horribly unfair for under-experienced or diversity candidates.”
He takes this to the extreme and has never supplied resumes with his candidates. “Instead, we build a storyboard about the candidate created as a result of multiple meetings, interactions, and back channels in order to focus on the candidate’s journey, the human character elements as well as their matching and gaps for the particular role.” In short, the talent gap will more likely be reduced by redefining the gap than by seeking to match unrealistic demands to the existing work pool.
Dave Gerry, CEO of Bugcrowd, has a specific recommendation based on diversity candidates. He believes organizations need to be more open to the diversity pool – including neurodiversity (see Harnessing Neurodiversity Within Cybersecurity Teams). “Organizations,” he said, “need to continue to expand their recruiting pool, account for the bias that can currently exist in cyber-recruiting, and provide in-depth training via apprenticeships, internships and on-the-job training, to help create the next generation of cyber-talent.”
However, even if the influx of laid-off experience will have little overall or lasting effect on the macrocosm of the skills gap, it will almost certainly have an immediate effect on recruitment in the microcosm of the cybersecurity talent gap.
Recruitment in cybersecurityCybersecurity is not immune to the current round of staff trimming – and it includes security leaders as well as security engineers. Ultimately, it’s a cost cutting exercise; and organizations can save as much money by cutting one leader’s position as they can by cutting two engineers. “Organizations are asking themselves if they can survive letting one person go but still get the job done with the remaining team,” explains Sasson. “If the answer is yes or even maybe, they’re tending to let go of the more highly paid and highly skilled people because they think maybe they can do more with less.”
That’s a top-down approach to staff reductions, but the same argument is used in a bottom-up approach. Joseph Thomssen is senior cybersecurity recruiter at NinjaJobs (a community-run job platform developed by information security professionals). “A company that is not security focused may feel like they can rely on their senior employees to pick up lower-level responsibilities,” he said, “and this can be detrimental to a security team.”
The overall result is that we now have laid off cybersecurity engineers looking for new employment, and we have employed cybersecurity leaders looking for alternative and safer positions. “Many of these layoffs in cybersecurity seem to be short-term attempts to save money,” adds Thomssen – but he fears it may backfire on companies reducing their security workforce. Expecting fewer staff to take on more responsibility will likely have a detrimental effect – it may cause burnout. “I call it the layoff/quit combination,” he said.
Piacente also notes the cuts are not simply targeted at weeding out under performing employees. “There are great candidates impacted due to them being in the wrong place at the wrong time; and we are seeing this industry wide.”
Of course, there are many cybersecurity experts who believe this is a false and dangerous approach, and that cybersecurity is a necessity that should be expanded rather than cut. But that is an argument put forward by every business department in times of economic stress.
One effect of the cybersecurity layoffs and the accompanying increase in the number of experienced people seeking employment is that the recruitment market is moving from a candidate market toward a hirer market – just like home buying fluctuates between a buyer and a seller market depending on supply (properties available) and demand (money to buy). For many years, experienced cybersecurity engineers have been able to pick and choose their employer, and demand somewhat inflated salaries and conditions; but that is no longer the case.
This is beginning to be apparent in the salaries offered. “They’re leveling off,” says Sasson, “maybe even going down. But this needs to be taken in the context of pretty dramatic increases from just a few quarters ago, during the candidate-driven market.” Sasson thought at the time that these were unsustainable. But now, “Folks that are looking for those massive compensation packages from just a year ago are going to have to adjust their expectations.”
Sam Del Toro, senior cybersecurity recruiter at Optomi, has seen a similar growing misalignment between compensation expectation and realization – especially in the more senior positions. Because of the layoffs, there are now more mid to senior level candidates looking for new opportunities.
“On the other hand,” he said, “over the past couple of years we have seen cybersecurity compensation rise significantly. Now, as organizations are tightening their budgets and being more fiscally aware, it is making it tough to align candidate and client compensation.”
Thomssen sees another and different effect of the evolving hirer’s market. “I have seen security staff recruitment switch from direct hires to roles based on shorter term project contracts. In the past you would not see security professionals entertain such contracts, but the security staff recruitment landscape has seen a shift that way.”
It’s not clear whether this will develop into a common long term approach to cybersecurity recruitment or will just be a short-term solution to economic uncertainty. Is the gig economy coming to cybersecurity? It’s been growing in many other segments of employment, and perhaps the current economic climate will boost an existing trend just as Covid-19 boosted remote working.
One visible sign might come with an increase in the employment of virtual CISOs (vCISOs). This would retain access to high level expertise while reducing costs. Another might be an increased use of managed security service providers (MSSPs). “We’re seeing more and more security operations outsourced to consultants and contractors, or to vCISOs and Global CISOs, or whatever you’d like to call it,” comments Mika Aalto, co-founder and CEO at Hoxhunt. But he adds, “This can work with smaller companies, but it’s risky. Security should be looked at as a competitive advantage and a growth strategy, not a luxury.”
Piacente’s firm has seen a 20% increase in the new candidate flow. While the primary cause is the economy, the detailed cause is difficult to isolate. Cybersecurity has always experienced rapid churn with staff from all levels regularly moving to a new company for promotion or improved remuneration. This churn continues, but is complicated by employed people just looking around – not because they are being laid off, but just in case they will be laid off.
At the same time, some people who might normally be on the lookout for better opportunities are choosing to keep what they have until more stable conditions return. “One other observation in these cycles,” adds Piacente, “is that candidates who fall into the diversity category tend to be more resistant to making a change. Since there are already significantly less candidates in this category it makes it more difficult for companies to achieve their goals of creating a more diverse organization or program. This is when companies really need to place care, attention, and a dose of reality into their change initiatives.”
Bugcrowd is a firm that has actively sought to recruit from the ‘diversity’ pool. “Employers need to take a more active approach to recruiting from non-traditional backgrounds, which, in turn, significantly expands the candidate pool from just those with formal degrees to individuals, who, with the right training, have incredibly high-potential,” comments Gerry.
It could be expected that with some companies laying off experienced staff and others simply not hiring new staff, breaking into cybersecurity for new, inexperienced or diverse people will become even more difficult. After all, companies reducing staff levels to save money are not likely to spend money on in-house training for new inexperienced staff.
Del Toro doesn’t see it quite like that – it has always been almost impossible. “I do not think that the influx of [experienced] candidates on the market has much of an impact on newcomers finding opportunities because there are simply not enough entry level cybersecurity roles in general,” he said. “Organizations are almost always looking for mid-level candidates and above rather than bringing on competent and excited newbies, because the latter takes much more than fiscal resources.”
Recruitment going forwardIt’s difficult to determine the actual number of experienced cybersecurity professionals being laid off among the overall staff reductions, but it is likely to be substantial. Although boards have become more open to the idea that security is a business enabler, there is nevertheless no discernible line between security and profit. There is, however, a direct line between security and cost. It is almost a no-brainer for security to be heavily featured among staff reductions. But this may be bad thinking.
For all layoffs, companies should proceed with caution. When large numbers of staff need to be cut for economic reasons, those same economic reasons may cause it to be done swiftly and perhaps brutally. These suddenly unemployed people will have inside knowledge of the company and its systems; and some will have thoughts of retaliation. At the same time, the company may have reduced the effectiveness of its cybersecurity team to counter a new threat from malicious recent insiders.
“Layoffs are affecting much of the tech industry and cybersecurity isn’t immune,” comments Mike Parkin, senior technical engineer at Vulcan Cyber. “While no department should really be immune when companies have to tighten their belts, the threat from losing skilled personnel in security operations can have a disproportionate effect.”
Overall, we’ve had a candidate market in cybersecurity recruitment but we’re shifting toward an employer market. Del Toro offers this advice for security people laid off and looking for a new position: “I would tell job seekers to be prepared for longer interview processes and longer time before offers are extended. Hiring managers are under more pressure to be diligent so candidates will need to be more cognizant of interview etiquette. Most importantly make sure you are keeping your skills sharp – use your time off to find passion projects and get better at your craft, not only to stay relevant in the security space but to renew your love for what you do!”
Related: Dozens of Cybersecurity Companies Announced Layoffs in Past Year
Related: US Gov Cybersecurity Apprenticeship Sprint: 190 New Programs, 7,000 People Hired
Related: How Will a Recession Affect CISOs?
Related: Four Ways to Close the OT Cybersecurity Talent Gap
The post The Effect of Cybersecurity Layoffs on Cybersecurity Recruitment appeared first on SecurityWeek.
Printer and imaging products manufacturer Lexmark this week published a security advisory to warn users of a critical vulnerability impacting over 120 printer models.
The issue, tracked as CVE-2023-23560 (CVSS score of 9.0), is described as a server-side request forgery (SSRF) flaw in the Web Services feature of newer Lexmark devices, which could be exploited to execute arbitrary code.
“Successful exploitation of this vulnerability can lead to an attacker being able to remotely execute arbitrary code on a device,” Lexmark warns in an advisory (PDF).
The manufacturer lists roughly 125 device models that are impacted by the security defect, including B, C, CS, CX, M, MB, MC, MS, MX, XC, and XM series printers.
The company has announced firmware updates that resolve the vulnerability on all impacted devices and encourages users to find update instructions on its support website.
Additionally, Lexmark says that exploitation of CVE-2023-23560 can be blocked by disabling the Web Services feature on the vulnerable printers (TCP port 65002).
To block TCP port 65002, users would have to go to Settings > Network/Ports > TCP/IP > TCP/IP Port Access, uncheck TCP 65002 ( WSD Print Service ), and then click Save.
Lexmark also warns that, while it is not aware of any malicious attacks targeting the vulnerability, proof-of-concept (PoC) code exploiting it has been made public.
Given that it is not unusual for threat actors to target unpatched printers and other Internet of Things (IoT) devices, users are advised to apply the available patches as soon as possible.
Related: Hundreds of Thousands of Konica Printers Vulnerable to Hacking via Physical Access
Related: Serious Vulnerability Exploited at Hacking Contest Impacts Over 200 HP Printers
Related: Xerox Quietly Patched Device-Bricking Flaw Affecting Some Printers
The post Critical Vulnerability Impacts Over 120 Lexmark Printers appeared first on SecurityWeek.
The Internet Systems Consortium (ISC) this week announced patches for multiple high-severity denial-of-service (DoS) vulnerabilities in the DNS software suite BIND.
The addressed issues could be exploited remotely to cause named – the BIND daemon that acts both as an authoritative name server and as a recursive resolver – to crash, or could lead to the exhaustion of the available memory.
The first of the security defects, tracked as CVE-2022-3094, can be exploited by sending a flood of dynamic DNS updates, which would cause named to allocate large amounts of memory, resulting in a crash due to a lack of free memory.
According to ISC, because allocated memory is only retained for clients for which access credentials are accepted, the scope of the vulnerability is limited to trusted clients that are allowed to make dynamic zone changes.
For BIND 9.11 and earlier branches, the flaw can be exploited to exhaust internal resources, which results in performance issues, but not a crash.
Tracked as CVE-2022-3736, the second issue leads to a crash “when stale cache and stale answers are enabled, option stale-answer-client-timeout is set to a positive integer, and the resolver receives an RRSIG query,” ISC explains. A remote attacker can trigger the bug by sending crafted queries to the resolver.
The third vulnerability, CVE-2022-3924, impacts the implementation of the stale-answer-client-timeout option, when the resolver receives too many queries that require recursion. If the number of clients waiting for recursion to complete is high enough, a race may occur between providing a stale answer to the longest waiting client and sending an early timeout SERVFAIL, causing named to crash.
All three vulnerabilities were resolved with the release of BIND versions 9.16.37, 9.18.11, and 9.19.9. ISC says it is not aware of any of these vulnerabilities being exploited, but encourages all users to update their BIND installations as soon as possible.
ISC also warns of CVE-2022-3488, a bug impacting all supported BIND preview edition versions (a special feature preview branch provided to eligible customers).
The issue can be triggered by sending two responses in quick succession from the same nameserver, both ECS pseudo-options, but with the first response broken, causing the resolver to reject the query response. When processing the second response, named crashes.
BIND preview edition version 9.16.37-S1 resolves all four security defects. Additional information on the addressed vulnerabilities can be found in the BIND 9 security vulnerability matrix.
Related: BIND Updates Patch High-Severity Vulnerabilities
Related: High-Severity Vulnerabilities Patched in BIND Server
Related: High-Severity DoS Vulnerability Patched in BIND DNS Software
The post BIND Updates Patch High-Severity, Remotely Exploitable DoS Flaws appeared first on SecurityWeek.
Authorities in the United States and Europe have announced the results of a major law enforcement operation targeting the Hive ransomware.
Agencies from around the world worked together to take down Hive’s leak website and servers. In addition, agents hacked into Hive systems in July 2022, allowing them to identify targets and obtain decryption keys that allowed victims to recover encrypted files without paying a ransom.
Authorities continue to investigate Hive in an effort to identify the cybercriminals involved in the operation, including developers, administrators and affiliates. The US announced that it’s offering rewards of up to $10 million for information on these and other hackers.
Several industry professionals have commented on various aspects of the Hive takedown, many noting that while Hive may have fallen, the threat actors behind the operation will likely continue their malicious activities.
And the feedback begins…
Kimberly Goody, Senior Manager, Mandiant Intelligence, Google Cloud:
“We’ve seen multiple actors using Hive ransomware since it emerged, but the most prolific actor over the past year, based on our visibility, was UNC2727. Their operations are notable because they have commonly impacted the healthcare sector. Hive also hasn’t been the only ransomware in their toolkit; in the past we’ve seen them employ Conti and MountLocker among others. This shows that some actors already have relationships within the broad ecosystem that could enable them to easily shift to using another brand as part of their operations.”
Crane Hassold, former FBI cyber psychological operations analyst, Head of Research, Abnormal Security:
“Unlike some other cyber threats, like business email compromise (BEC), the ransomware landscape is very centralized, meaning a relatively small number of groups are responsible for a majority of all the attacks. The silver lining to this top-heavy ecosystem is that disruptive actions against one of these primary groups, such as law enforcement takedowns, can have a significant impact on the overall landscape. Since Hive has been one of the biggest players in the ransomware space over the past year, I would expect this takedown to have a noticeable impact on ransomware volume, at least in the short-term.
Because of the increased pressure from global law enforcement and the likely regulatory controls of cryptocurrency, one of the biggest drivers of today’s ransomware landscape, it’s very possible that we’ll start to see ransomware actors pivot to other types of cyber attacks, like BEC. BEC is the most financially-impactful cyber threat today and, instead of using their initial access malware to gain a foothold on a company’s network, they could simply reconfigure the malware to establish access to employee mailboxes, which could lead to more scaled and sophisticated vendor email compromise attacks.”
Satnam Narang, Senior Research Engineer, Tenable:
“The actions undertaken by U.S. agencies to disrupt the Hive ransomware group operation from within is an unprecedented step in the fight against ransomware, which has steadily remained the biggest threat facing most organizations today. While this may signal the end of the Hive ransomware group, its members and affiliates remain a threat. If there’s anything we’ve learned after past disruptive actions against ransomware groups, it’s that other groups will rise to fill the void left behind. Affiliates, which are typically responsible for conducting most of these attacks, can easily pivot to other affiliate programs of groups that remain operational and ransomware group members can also take their knowledge to these groups. One of the key ways ransomware groups gain attention and notoriety is by publishing their successful attacks on data leak sites on the dark web. It wouldn’t surprise me if ransomware groups see the threat posed by maintaining these sites and stop publicly listing these attacks in an attempt to stay under the radar.”
Kurt Baumgartner, Principal Researcher, Kaspersky:
“The frequency of ransomware attacks have been up, while victim payments have reportedly gone down. This is a great trend, and this coordinated effort is what we need to see more of from law enforcement around the world. Some of this effort in letting the activity progress may seem somewhat controversial, but generating decryption keys for victims over time helps to exhaust the group’s resources.
Yes, in all likelihood, another gang is going to fill the void. It takes time and effort, but the incentives are in the hundreds of millions of dollars.
It’s somewhat surprising that the group housed their server resources in-country in Los Angeles. Apparently they thought everything was secured and hidden by the Tor network. Law enforcement put on display some impressive capabilities in infiltrating, seizing, and disrupting some of the gang’s resources. The actors behind this group have shown a reckless disregard for human life in their efforts to victimize schools and hospitals.”
Austin Berglas, Global Head of Professional Services, BlueVoyant:
“True dismantlement comes only when law enforcement can “put hands on” or arrest the individuals responsible. However, identifying the actual human beings behind the keyboard is a very difficult task. Many of these cyber criminals are adept at anonymizing their online communications, locations, and infrastructure – often operating in global locations where international law enforcement cooperation is non-existent and utilizing bullet-proof hosting providers, which are unresponsive to legal process.
There may be a temporary decline in ransomware activity in the wake of the website seizure as groups scramble to harden defenses and tighten their inner circles, but this will not make an overall, noticeable impact on global ransomware attacks. History has shown that ransomware gangs that disband either due to law enforcement actions, internal strife, or geo-political reasons will sometimes regroup under a different name. Conti, one of the most active ransomware gangs in recent history, shuttered operations soon after one of their members leaked internal Conti communications. Former members of the group are suspected of spinning off into newer groups such as BlackBasta and BlackByte.”
Jan Lovmand, CTO, BullWall:
“What is a significant win for law enforcement, could in reality be a road bump for the Hive Ransomware group. Whenever law enforcement starts paying too significant attention and effort to a particular group, they often scatter or reorganize under a different name. We have seen these seizes before only for the gang to surface with new extortion sites and ransomware names, or sometimes as several smaller groups. In the past they have seen these interruptions as temporary setbacks to a very lucrative business – similar to when a drug cartel has a shipment seized. They lose some income, get disrupted but rarely stop their criminal activity to become honest working individuals. Law enforcement in several regions have in the past recovered ransoms paid from other gangs or seized decryption keys, but what is different this time is how many victims the FBI have been able to help and for how long.”
Eric O’Neill, National Security Strategist, VMware:
“The disruption of the notorious Hive ransomware group demonstrates that the FBI has increased its ability to investigate and track threat actors across the Dark Web. This supports the commendable work the FBI’s IC3 is doing to track cybercrime attacks and coordinate efforts to repatriate stolen funds from cybercriminals, further reinforcing the importance of notifying the IC3 when a ransomware attack occurs.
It’s also worth noting how large the Dark Web has grown and how well-resourced new cyber crime syndicates, such as Hive, have become. The Dark Web is currently the third largest economy on Earth measured by GDP, which is larger than Japan or Germany. By 2025, this will grow larger than both countries combined. The FBI’s work to shut down Hive servers and repatriate encryption keys is a great step in the right direction, but it is only a step along a distant marathon to stop Dark Web-resourced cyber crime.”
Julia O’Toole, CEO, MyCena Security Solutions:
“When CISOs are reading the news about Hive’s takedown, it would be wise for them to also focus on the data being revealed about the gang’s victims and the financial losses they inflicted. The alarming numbers may be about Hive, but other ransomware gangs that have even more victims under their belt are still in operation and still pose a very real and credible threat today.
Organizations should use this takedown as a warning that ransomware is a damaging threat that is far from over. As the number one route to a ransomware attack is by gaining initial network access, network infrastructure access must be the number one priority.
When it comes to defense tools, access segmentation and encryption provide the greatest protection. These solutions stop data breaches from propagating through networks and morphing into ransomware attacks, while they also help prevent phishing attacks on employees, since they don’t know the passwords they use.”
Alfredo Hickman, Head of Information Security, Obsidian Security:
“Today’s news sends a very loud message to all cybercrime groups that if you are on this administration’s radar, they are going to be proactive – and if you get within reach of the American legal and justice system, they will hold you accountable. Some experts believe this approach still lacks teeth due to the risk/reward calculous that heavily favors cybercrime organizations operating outside the reach of the US justice system.
However, this more aggressive and proactive approach to disrupting cybercrime operations should cause pause and recalculation within some organizations. As these announcements continue to roll out and as related cybercrime operations continue to be disrupted and pressure is applied to host nations, I believe there will be fewer attacks on at least the most sensitive establishments, such as hospitals or critical infrastructures due to the near-universal condemnation and political blowback.”
The post Industry Reactions to Hive Ransomware Takedown: Feedback Friday appeared first on SecurityWeek.
Microsoft this week published a blog post to remind its customers of the continuous wave of attacks targeting Exchange servers and to urge them to install the latest available updates as soon as possible.
“Attackers looking to exploit unpatched Exchange servers are not going to go away,” Microsoft says, reminding customers that both a cumulative update (CU) and a security update (SU) are available for Exchange.
“There are too many aspects of unpatched on-premises Exchange environments that are valuable to bad actors looking to exfiltrate data or commit other malicious acts,” the company continues.
Attackers, the tech giant notes, are after not only the sensitive information that user mailboxes may contain. They are also looking to access the copy of the company address book stored on the Exchange server, which they can then use in social engineering attacks.
On top of that, Microsoft notes, “Exchange has deep hooks into and permissions within Active Directory, and in a hybrid environment, access to the connected cloud environment.”
Almost every set of Patch Tuesday updates coming out of Redmond includes security fixes for Exchange, some of which address already-exploited vulnerabilities, such as ProxyNotShell and ProxyShell. For other bugs, proof-of-concept (PoC) code was published shortly after patches were released.
“To defend your Exchange servers against attacks that exploit known vulnerabilities, you must install the latest supported CU (as of this writing, CU12 for Exchange Server 2019, CU23 for Exchange Server 2016, and CU23 for Exchange Server 2013) and the latest SU (as of this writing, the January 2023 SU),” Microsoft notes.
Because the CUs and SUs are cumulative, only the latest needs to be installed. However, Exchange customers are advised to check whether a security update has been released after they installed the latest CU, and install that as well.
The tech giant also notes that mitigations that it might automatically release for a vulnerability prior to pushing an SU are only meant to provide temporary protection and might not provide protection against all variations of an attack, meaning that customers should install the SU instead.
After installing an update, customers should also run Health Checker to verify if there are any manual tasks that need to be performed. The tool provides links to step-by-step guidance for the necessary actions.
To update an Exchange server, customers should start by reading the announcement about that update, follow the available guidance for CUs or SUs, inventory all servers using Health Checker, and use the Exchange Update Wizard, which offers a step-by-step guide to Exchange updates.
Windows Server and other software running on the Exchange server should also be updated, along with dependency servers that Exchange uses, such as Active Directory and DNS.
Related:Microsoft Warns of New Zero-Day; No Fix Yet for Exploited Exchange Server Flaws
Related: Mitigation for ProxyNotShell Exchange Vulnerabilities Easily Bypassed
Related: Microsoft Adds On-Premises Exchange, SharePoint, Skype to Bug Bounty Program
The post Microsoft Urges Customers to Patch Exchange Servers appeared first on SecurityWeek.
The Iran-linked advanced persistent threat (APT) actor known as Moses Staff is leaking data stolen from Saudi Arabia government ministries using a recently created online persona.
Also referred to as Cobalt Sapling, Moses Staff has been likely active since November 2020, but its existence was not revealed until September 2021.
A declared anti-Israeli and pro-Palestinian group, the APT has posted on its leaks website 16 activities as of December 2022, mainly consisting of data stolen from Israeli companies, or the personal information of individuals affiliated with an Israeli intelligence unit of the Israel Defense Forces.
The group was previously linked to the use of the PyDCrypt custom loader, the DCSrv cryptographic wiper that encrypts data and displays a bootloader message, the StrifeWater remote access trojan (RAT), and the DriveGuard auxiliary tool deployed to monitor the RAT’s execution.
In November 2022, a seemingly new hacktivist group claiming affiliation to the Hezbollah Ummah Lebanese Shia Islamist political party and militant group announced their existence under the Abraham’s Ax name, but Secureworks believes that this new persona is operated by Cobalt Sapling, the same APT that operates Moses Staff.
Connections between the two groups, the cybersecurity firm says, are plenty, starting with the use of a similar logo, similarities in leak sites (both of which have Tor versions), and the hosting of these sites on the same subnet, nearly adjacent to each other.
Like Moses Staff, Abraham’s Ax uses a biblical figure for their persona, and their claimed affiliation to Hezbollah has yet to be proven, Secureworks says.
As part of their activities, both groups have released videos, often depicting “Hollywood-style hacking involving satellites, CCTV, 3D building models, and fast scrolling through documents allegedly stolen as part of their operations”.
The videos show repetition and evolution of visual themes, with Abraham’s Ax reusing stock video elements from Moses Staff, with additional visual embellishments on top.
To date, Abraham’s Ax has leaked data allegedly stolen from Saudi Arabia’s Ministry of the Interior and a video purportedly depicting an intercepted phone conversation between Saudi Arabian government ministers.
“Rather than attacking Israel directly, Abraham’s Ax attacks government ministries in Saudi Arabia. […] The group may be attacking Saudi Arabia in response to Saudi Arabia’s leadership role in improving relationships between Israel and Arab nations,” Secureworks notes.
The cybersecurity firm also notes that Abraham’s Ax does not appear to replace the Moses Staff persona, which has remained active, claiming in late November the hack of a CCTV system monitoring the site of a terrorist attack in Israel.
“Malware and technical indicators from Abraham’s Ax operations have not been identified. Assuming that both personas are operated by Cobalt Sapling, it is plausible that the threat actors use the same tools and techniques in their intrusions,” Secureworks notes.
Related: UK Gov Warns of Phishing Attacks Launched by Iranian, Russian Cyberspies
Related:Iranian Hackers Deliver New ‘Fantasy’ Wiper to Diamond Industry via Supply Chain Attack
Related: Religious Minority Persecuted in Iran Targeted With Sophisticated Android Spyware
The post Iranian APT Leaks Data From Saudi Arabia Government Under New Persona appeared first on SecurityWeek.
Following the shutdown of the Hive ransomware operation by law enforcement, the US government has reminded the public that a reward of up to $10 million is offered for information on cybercriminals.
Authorities in the United States and Europe announced on Thursday the results of a major law enforcement operation targeting the Hive ransomware. More than a dozen agencies collaborated to take down the Tor-based leak website used by the group and other parts of its infrastructure, including servers located in Los Angeles.
The FBI revealed that Hive’s ‘control panel’ was hacked by agents in July 2022, allowing them to identify targets and obtain decryption keys that allowed victims to recover encrypted files. The FBI and Europol said they prevented the payment of more than $130 million to the cybercriminals.
The Hive ransomware operation was launched in June 2021 and it has since made more than 1,500 victims across roughly 80 countries. It’s believed that administrators and affiliates made approximately $100 million from ransom payments.
Authorities continue to investigate Hive in an effort to identify the threat actors involved in the operation, including developers, administrators and affiliates.
After the operation against Hive was announced on Thursday, the US State Department reiterated that it’s prepared to pay up to $10 million for information on the identity or location of foreign state-sponsored threat actors that have targeted critical infrastructure. This includes individuals linked to Hive.
At least some of the people involved in the Hive ransomware operation are believed to be Russian speakers. However, during a press conference announcing the law enforcement operation against Hive on Thursday, US officials refused to comment on potential ties to Russia, citing the ongoing investigation.
The US government previously reiterated its $10 million reward offer for leaders of the Conti ransomware operation, North Korean hackers, Russian intelligence officers, and DarkSide ransomware operators.
Related: US Government Shares Photo of Alleged Conti Ransomware Associate
Related: US Offers $10 Million Reward Against Election Interference
The post US Reiterates $10 Million Reward Offer After Disruption of Hive Ransomware appeared first on SecurityWeek.
The websites of German airports, public administration bodies and financial sector organizations have been hit by cyberattacks instigated by a Russian “hacker group”, authorities said Thursday.
The Federal Cyber Security Authority (BSI) had “knowledge of DDoS attacks against targets in Germany”, a spokesman told AFP.
A distributed denial-of-service (DDoS) attack is designed to overwhelm the target with a flood of internet traffic, preventing the system from functioning normally.
The attacks were aimed “in particular at the websites of airports”, as well as some “targets in the financial sector” and “the websites of federal and state administrations”, the spokesman said.
The attack had been “announced by the Russian hacker group Killnet”, the
BSI spokesman said.
The group’s call to arms was in response to Chancellor Olaf Scholz’s announcement Wednesday that Germany would send Leopard 2 tanks to Ukraine to help repel the Russian invasion, according to financial daily Handelsblatt.
Attributing Thursday’s attacks directly to the hacker group, however, was “particularly hard”, the BSI spokesman said.
“They call for action and then a lot of people take part,” he said. The attacks made “some websites unavailable”, the BSI said, without there being “any indication of direct impacts on (the organisations’) services”.
Attacks on public administrations were “largely repelled with no serious
impacts”, the BSI said.
The interior ministry for southwestern Baden-Wuerttemberg state acknowledged “nationwide” DDoS attacks since Wednesday evening against websites, including those of public administration and the regional police.
Germany is on high alert for cyberattacks in the wake of Russia’s war in Ukraine.
The Federal Office for Information Security said in October that the threat level for hacking attacks and other cybercrime activities was higher “than ever”.
The post Cyberattacks Target Websites of German Airports, Admin appeared first on SecurityWeek.
The FBI has at least temporarily dismantled the network of a prolific ransomware gang it infiltrated last year, saving victims including hospitals and school districts a potential $130 million in ransom payments, Attorney General Merrick Garland and other U.S. officials announced Thursday.
“Simply put, using lawful means we hacked the hackers,” Deputy Attorney General Lisa Monaco said at a news conference.
Officials said the targeted syndicate, known as Hive, operates one of the world’s top five ransomware networks. The FBI quietly gained access to its control panel in July and was able to obtain software keys to decrypt the network of some 1,300 victims globally, said FBI Director Christopher Wray. Officials credited German police and other international partners.
It was not immediately clear how the takedown will affect Hive’s long-term operations, however. Officials did not announce any arrests but said they were building a map of Hive’s administrators, who manage the software, and affiliates, who infect targets and negotiate with victims, to pursue prosecutions.
“I think anyone involved with Hive should be concerned because this investigation is ongoing,” Wray said.
On Wednesday night, FBI agents seized computer infrastructure in Los Angeles that was used to support the network. Hive’s dark web site was also seized.
“Cybercrime is a constantly evolving threat, but as I have said before, the Justice Department will spare no resource to bring to justice anyone anywhere that targets the United States with a ransomware attack,” Wray said.
Garland said that thanks to the infiltration, led by the FBI’s Tampa office, agents were able in one instance to disrupt a Hive attack against a Texas school district, stopping it from making a $5 million payment.
The operation is a big win for the Justice Department. The ransomware scourge is the world’s biggest cybercrime headache with everything from Britain’s postal service and Ireland’s national health service to Costa Rica’s government crippled by Russian-speaking syndicates that enjoy Kremlin protection. The criminals lock up, or encrypt, victims’ computer networks, steal sensitive data and demand large sums.
As an example of Hive’s threat, Garland said it had prevented a hospital in the Midwest in 2021 from accepting new patients at the height of the COVID-19 epidemic.
A U.S. government advisory last year said Hive ransomware actors victimized over 1,300 companies worldwide from June 2021 through November 2022, receiving approximately $100 million in ransom payments. It said criminals using Hive ransomware targeted a wide range of businesses and critical infrastructure, including government, manufacturing and especially health care and public health facilities.
The threat captured the attention of the highest levels of the Biden administration two years ago after a series of high-profile attacks that threatened critical infrastructure and global industry. In May 2021, for instance, hackers targeted the nation’s largest fuel pipeline, causing the operators to briefly shut it down and make a multimillion-dollar ransom payment that the U.S. government largely recovered.
Federal officials have used a variety of tools to try to combat the problem, but conventional law enforcement measures such as arrests and prosecutions have done little to frustrate the criminals.
The FBI has obtained access to decryption keys before. It did so in the case of a major 2021 ransomware attack on Kaseya, a company whose software runs hundreds of websites. It took some heat, however, for waiting several weeks to help victims unlock afflicted networks.
The post US Infiltrates Big Ransomware Gang: ‘We Hacked the Hackers’ appeared first on SecurityWeek.
Vulnerability management software firm Tenable has launched a $25 million venture fund to place bets on early-stage startups in the attack surface and exposure management space.
The new Tenable Ventures plans to make seed- and early-stage investments in companies building technology to help businesses discover, assess and manage security risk.
The Columbia, Maryland-based Tenable said the fund will work with startups in highly-competitive cybersecurity markets such as Israel and the U.S., to help with the development and go-to-market strategies for exposure management solutions.
The venture fund also plans to work with startups to improve product design, create consistent and shareable data models, enterprise readiness and more.
“[We] will invest in companies tackling significant problems that require new and innovative approaches, data sets and platforms,” Tenable said in a note announcing the fund.
The company said it will look for companies that focus on a preventive approach to security using emerging technologies in cloud security, identity management, external attack surface management, operational technology and vulnerability management.
Such technologies would expand the exposure management ecosystem and could be considered for integration into the Tenable One Exposure Management platform, the company said.
Tenable Ventures has already made investments in three companies — software supply chain security play Lineaje, identity threat detection and response firm Authomize and API security startup Araali Networks.
Tenable has itself been active on the acquisition front, shelling out $45 million in 2022 to purchase attack surface management startup Bit Discovery. Prior to that, Tenable also acquired Accurics and Indegy for a combined $238 million.
Related: Tenable Shells Out $45 Million to Acquire Bit Discovery
Related: Tenable to Acquire Accurics in $160M Deal
Related: Tenable Acquires OT Security Firm Indegy for $78 Million
The post Tenable Launches $25 Million Early-Stage Venture Fund appeared first on SecurityWeek.
Stock research firm Zacks Investment Research is in the process of notifying customers that their personal information was compromised in a data breach.
Founded in 1978, Zacks Investment Research is one of the largest providers of stock research, analysis and recommendations for firms in the US.
Earlier this week, the company informed the Maine Attorney General’s Office that the personal information of 820,000 individuals was compromised after a third-party gained unauthorized access to its systems.
The data breach, the firm says, was discovered in December 2022, but the unauthorized access occurred sometime between November 2021 and August 2022.
The notification letter to the impacted customers, a copy of which was submitted to the Maine Attorney General, reveals that the unauthorized third-party had access to an older database containing information about customers who had signed up for a Zacks product between November 1999 and February 2005.
The compromised personal information includes names, addresses, phone numbers, email addresses, and passwords for Zacks.com.
“We have no reason to believe any customer credit card information, any other customer financial information, or any other customer personal information was accessed,” the company says.
Zacks says it has implemented security measures to stop the breach and that it has reset the passwords for the impacted accounts.
“When you log into your Zacks account, you will be prompted to change your password. You should also change the password for all other online accounts for which you used the same e-mail address and password as your Zacks account,” the company tells users.
Zacks told the Maine Attorney General that it will begin notifying impacted customers on January 27.
Related: 18k Nissan Customers Affected by Data Breach at Third-Party Software Developer
Related: 251k Impacted by Data Breach at Insurance Firm Bay Bridge Administrators
Related: FCC Proposes Tighter Data Breach Reporting Rules for Wireless Carriers
The post 820k Impacted by Data Breach at Zacks Investment Research appeared first on SecurityWeek.
The NIST compliance framework consists of 5 core functions: identify, protect, detect, respond and recover. In my previous column, I mapped threat intelligence capabilities to the NIST core function of Identify. In this column, I will continue the discussion by mapping threat intelligence to the additional functions of Protect, Detect and Respond. By doing so, I will highlight how threat intelligence is critical when justifying budget, not only for governance, risk and compliance (GRC) personnel, but also for threat intelligence, incident response, security operations, CISO and third-party risk buyers.
Concerns such as data leakage, IOCs, credential theft, third-party vendor suppliers and the selling of intellectual property are all relevant to the NIST framework. As CTI teams prioritize the intelligence requirements of their business stakeholders, it is beneficial to provide context by mapping the impact of cybersecurity threat intelligence programs to the following NIST core functions.
PROTECT
Data Security
9) PR.DS-5: Protections against data leaks are implemented: Data leakage detection capabilities can be used to identify and remediate data leakage. Monitoring outbound connections and content going to file sharing or cloud services is typically a starting point.
Information Protection Processes and Procedures
10) PR.IP-12: A vulnerability management plan is developed and implemented: CTI providers typically provide a monitoring solution for vulnerability management (VM). Providing telemetry details on an attacker’s near real-time abilities to exploit vulnerabilities is differentiated than traditional, static VM tooling.
DETECT
Anomalies and Events
11) DE.AE-2: Detected events are analyzed to understand attack targets and methods: Proactively detect events and react during incident response activities to provide context and enrichment for investigations. Conducting threat group attribution is a common threat intelligence use case for reacting to an incident.
12) DE.AE-3: Event data are collected and correlated from multiple sources and sensors: Threat intelligence and managed service providers are a source for event data, context and enrichment. IOCs, compromised credentials and intellectual property theft are common event data sources.
Continuous Security Monitoring
13) DE.CM-1: The network is monitored to detect potential cybersecurity events: Similar to the previous bullet, CTI data and managed service providers monitor the external network and alerts on potential cyber security events that are relevant to your perimeter network and cloud services.
14) DE.CM-3: Personnel activity is monitored to detect potential cybersecurity events: CTI tooling monitors the external digital footprint of key staff and VIPs to detect cybersecurity events. Personal identifiable information (PII) takedowns are common outcomes.
15) DE.CM-5: Unauthorized mobile code is detected: Mobile application monitoring detects unauthorized mobile code including any code posted to third party repositories (Github), cloud services or hosting providers (Linode).
16) DE.CM-6: External service provider activity is monitored to detect potential cybersecurity events: CTI feeds and managed service providers can be used to monitor external service providers for potential cybersecurity events. For example, data leaks of third parties are a common breach for larger enterprises and can be monitored.
17) DE.CM-8: Vulnerability scans are performed: Similar to the above, CTI providers can enrich vulnerability scanners with greater context and external telemetry.
RESPOND
Response Planning
18) RS.RP-1: Response plan is executed during or after an incident: CTI providers can be used for the external investigation component of incident response plans. This is common to prepare for various ransomware actors.
Analysis
19) RS.AN-1: Notifications from detection systems are investigated: Not just limited to network devices, CTI and threat management functions augment incident response to alerts of security events and incidents.
Mitigation
20) RS.MI-3: Newly identified vulnerabilities are mitigated or documented as accepted risks: CTI teams submit vulnerabilities validated in the wild to appreciate stakeholders for remediation.
Protecting, detecting and responding to cyber incidents is generally considered with the security operations team and incident responders using tools to protect endpoints and servers and remediate security incidents. While these are critical aspects to comply with NIST, threat intelligence squarely fits into these facets of NIST from an “outside the firewall” approach.
Related: Mapping Threat Intelligence to the NIST Compliance Framework Part 1
The post Mapping Threat Intelligence to the NIST Compliance Framework Part 2 appeared first on SecurityWeek.
The Hive ransomware operation appears to have been shut down as part of a major law enforcement operation involving agencies in 10 countries.
A message displayed in English and Russian on the Hive ransomware operation’s Tor-based website reads: The Federal Bureau of Investigation seized this site as part of a coordinated law enforcement action taken against Hive Ransomware.
Another message says the action was taken in coordination with Europol and authorities in Florida, which indicates that more details will likely be made available in the upcoming period by the Justice Department and Europol.
Until law enforcement agencies confirm the shutdown of Hive, there is a slight chance that the website seizure notice was posted by the cybercriminals themselves. Hacker groups falsely claiming to have been shut down by police is not unheard of.
However, Allan Liska, a ransomware expert working for threat intelligence company Recorded Future, reported that the Hive infrastructure was seized. Liska also posted an image showing that many well-known ransomware groups have fallen.
The US government reported in November 2022 that the Hive ransomware gang had hit more than 1,300 businesses and made an estimated $100 million in ransom payments.
Data collected by the DarkFeed deep web intelligence project shows that Hive was still active last week.
The Hive ransomware operation was launched in 2021. Offered under a ransomware-as-a-service (RaaS) model, the ransomware was often used against organizations in the healthcare sector, as well as other critical infrastructure.
The hackers used malware to encrypt the target’s files, but not before stealing data that could be used to pressure the victim into paying up.
A free decryptor for files encrypted with the Hive ransomware was released by a South Korean cybersecurity agency in the summer of 2022.
UPDATE: The US Department of Justice has confirmed dismantling the Hive ransomware operation.
It turns out that the FBI infiltrated the Hive “control panel” in July 2022, allowing agents to identify victims and obtain decryption keys that allowed victims to recover encrypted files, preventing $130 million in ransom payments.
In addition to seizing the domain associated with Hive’s leak website, law enforcement shut down servers used by the cybercriminals to store data.
Authorities continue to investigate in an effort to identify the threat actors involved in the Hive operation, including developers, administrators and affiliates.
Related: Russia Lays the Smackdown on REvil Ransomware Gang
Related: Six Arrested for Roles in Clop Ransomware Operation
Related: DarkSide Ransomware Shutdown: An Exit Scam or Running for Hills?
The post Hive Ransomware Operation Shut Down by Law Enforcement appeared first on SecurityWeek.
The Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), and Multi-State Information Sharing and Analysis Center (MS-ISAC) are warning organizations of malicious attacks using legitimate remote monitoring and management (RMM) software.
IT service providers use RMM applications to remotely manage their clients’ networks and endpoints, but threat actors are abusing these tools to gain unauthorized access to victim environments and perform nefarious activities.
In malicious campaigns observed in 2022, threat actors sent phishing emails to deploy legitimate RMM software such as ConnectWise Control (previously ScreenConnect) and AnyDesk on victims’ systems, and abuse these for financial gain.
The observed attacks focused on stealing money from bank accounts, but CISA, NSA, and MS-ISAC warn that the attackers could abuse RMM tools as backdoors to victim networks and could sell the obtained persistent access to other cybercriminals or to advanced persistent threat (APT) actors.
Last year, multiple federal civilian executive branch (FCEB) employees were targeted with help desk-themed phishing emails, both via personal and government email addresses.
Links included in these messages directed the victims to a first-stage malicious domain, which automatically triggered the download of an executable designed to connect to a second-stage domain and download RMM software from it, as portable executables that would connect to attacker-controlled servers.
“Using portable executables of RMM software provides a way for actors to establish local user access without the need for administrative privilege and full software installation—effectively bypassing common software controls and risk management assumptions,” the US government agencies warn.
In some cases, the email’s recipient was prompted to call the attackers, who then attempted to convince them to visit the malicious domain.
In October 2022, Silent Push uncovered similar malicious typosquatting activity, in which the adversaries impersonated brands such as Amazon, Geek Squad, McAfee, Microsoft, Norton, and PayPal to distribute the remote monitoring tool WinDesk.Client.exe.
In the attacks targeting federal agencies, the threat actors used the RMM tools to connect to the recipient’s system, then entice them to log into their bank account.
The attackers used the unauthorized access to modify the victim’s bank account summary to show that a large amount of money had been mistakenly refunded, instructing the individual to send the amount back to the scam operator.
“Although this specific activity appears to be financially motivated and targets individuals, the access could lead to additional malicious activity against the recipient’s organization—from both other cybercriminals and APT actors,” CISA, NSA, and MS-ISAC note.
The agencies underline that any legitimate RMM software could be abused for nefarious purposes, that the use of portable executables allows attackers to bypass existing policies and protections, that antivirus defenses would not be typically triggered by legitimate software, and that RMM tools provide attackers with persistent backdoor access to an environment, without the use of custom malware.
CISA, NSA, and MS-ISAC also warn that the legitimate users of RMM software, such as managed service providers (MSPs) and IT help desks, are often targeted by cybercriminals looking to gain access to a large number of the victim MSP’s customers, which could lead to cyberespionage or to the deployment of ransomware and other types of malware.
To stay protected, organizations are advised to implement phishing protections, audit remote access tools, review logs to identify the abnormal use of RMM software, use security software to detect the in-memory execution of RMM software, implementing proper application control policies, restrict the use of RMM software from within the local network, and train employees on phishing.
Related: CISA Updates Infrastructure Resilience Planning Framework
Related: NSA, CISA Explain How Threat Actors Plan and Execute Attacks on ICS/OT
Related: NSA Publishes Best Practices for Improving Network Defenses
The post US Government Agencies Warn of Malicious Use of Remote Management Software appeared first on SecurityWeek.
The United Kingdom’s National Cyber Security Centre (NCSC) has published an advisory to warn organizations and individuals about separate spearphishing campaigns conducted by Russian and Iranian cyberespionage groups.
The advisory focuses on activities conducted by the Russia-linked Seaborgium group (aka Callisto, Blue Callisto and Coldriver) and the Iran-linked TA453 (aka Charming Kitten, APT35, Magic Hound, NewsBeef, Newscaster and Phosphorus).
The NCSC noted that the two groups covered by the advisory have similar tactics, techniques and procedures (TTPs) and they target the same types of entities, but there is no evidence that their campaigns are connected or that the two APTs are collaborating.
The goal of these attacks has been to collect information from government organizations, academia, defense firms, NGOs, think tanks, politicians, activists and journalists.
The general public has not been targeted, but it’s worth pointing out that the Iranian group has also been observed launching what appeared to be financially motivated ransomware attacks.
Seaborgium and TA453’s attacks start with a reconnaissance phase that involves using open source intelligence to research their targets. This phase can involve creating fake social media accounts, email accounts impersonating well-known individuals in the target’s field of interest, fake websites, and event invitations. The goal is to gain the victim’s trust.
The hackers don’t immediately deliver malicious content to the victim and instead take their time to build trust, which increases their chances of success. After trust is established, they deliver a malicious link that leads the victim to a phishing page.
These phishing pages are designed to harvest credentials that the Russian and Iranian hackers can then use to access the victim’s email accounts, which can store valuable information.
The attackers have also been observed setting up forwarding rules in compromised email accounts in an effort to monitor the victim’s correspondence. In addition, they have used contact lists for further phishing attacks.
“Although spear-phishing is an established technique used by many actors, Seaborgium and TA453 continue to use it successfully and evolve the technique to maintain their success,” the NCSC said in its advisory.
In August 2022, Microsoft said it had caused significant disruption to Seaborgium’s operations, cutting off the hackers’ access to accounts used for reconnaissance and phishing.
Related:Iranian Hackers Impersonate British Scholars in Recent Campaign
Related: Russian Espionage APT Callisto Focuses on Ukraine War Support Organizations
The post UK Gov Warns of Phishing Attacks Launched by Iranian, Russian Cyberspies appeared first on SecurityWeek.
A Chinese threat actor tracked as DragonSpark has been using the SparkRAT open source remote administration tool (RAT) in recent attacks targeting East Asian organizations, cybersecurity firm SentinelOne reports.
Relatively new, SparkRAT is a multi-platform RAT written in Golang that can run on Windows, Linux, and macOS systems, and which can update itself with new versions available through its command and control (C&C) server.
The threat uses the WebSocket protocol to communicate with the C&C server and includes support for over 20 commands that allow it to execute tasks, control the infected machine, manipulate processes and files, and steal various types of information.
The malware appears to be used by multiple adversaries but, according to SentinelOne, DragonSpark represents the first cluster of activity where SparkRAT has been constantly deployed in attacks.
The attackers were also seen using the China Chopper webshell, along with other malware tools created by Chinese developers, including BadPotato, GotoHTTP, SharpToken, and XZB-1248, as well as two custom malware families, ShellCode_Loader and m6699.exe.
The m6699.exe malware uses Golang source code interpretation to evade detection, where the Yaegi framework is used “to interpret at runtime encoded Golang source code stored within the compiled binary, executing the code as if compiled”, SentinelOne says.
DragonSpark was seen targeting web servers and MySQL database servers for initial compromise and then performing lateral movement, escalating privileges, and deploying additional malware hosted on attacker-controlled infrastructure.
The cybersecurity firm has observed DragonSpark abusing compromised infrastructure of legitimate organizations in Taiwan, including an art gallery, a baby products retailer, and games and gambling websites, for malware staging.
DragonSpark also uses malware staging infrastructure in China, Hong Kong, and Singapore, while its C&C servers are located in Hong Kong and the US.
Based on the infrastructure and tools, SentinelOne assesses that DragonSpark is a Chinese-speaking adversary, focused either on espionage or cybercrime – one of their C&C IPs was previously linked to the Zegost malware, an information stealer used by Chinese threat actors.
“The threat actor behind DragonSpark used the China Chopper webshell to deploy malware. China Chopper has historically been consistently used by Chinese cybercriminals and espionage groups […]. Further, all of the open source tools used by the threat actor conducting DragonSpark attacks are developed by Chinese-speaking developers,” SentinelOne notes.
Related: Chinese Hackers Exploited Fortinet VPN Vulnerability as Zero-Day
Related: Chinese Cyberspies Targeted Japanese Political Entities Ahead of Elections
Related:Self-Replicating Malware Used by Chinese Cyberspies Spreads via USB Drives
The post Chinese Hackers Adopting Open Source ‘SparkRAT’ Tool appeared first on SecurityWeek.
Tens of cybersecurity companies have announced cutting staff over the past year as part of reorganization strategies, in many cases triggered by the global economic slowdown.
One of the most recent announcements was made by Sophos, which in mid-January confirmed reports that it’s laying off 10% of its global workforce. Roughly 450 people have reportedly lost their job as the company shifts focus to cybersecurity services, including managed detection and response.
At around the same time, identity verification company Jumio also confirmed laying off roughly 100 people.
In May 2022, cloud security company Lacework announced terminating 300 jobs, representing roughly 20% of its workforce.
Another company that laid off a significant portion of its workforce last year is OneTrust, which provides privacy, security, and data governance technology. Nearly 1,000 employees were let go, roughly a quarter of the firm’s workforce.
IronNet, the cybersecurity firm founded by former NSA director Keith Alexander, fired 17% of staff in June and another 35% in September due to significant problems.
In the fall, Cybereason announced plans to reduce its staff by 17%, just months after cutting 10% of its workforce. In total, the company fired approximately 300 employees.
Cloud security firm Aqua Security has laid off 10% of its workforce, and Malwarebytes terminated 14% of its staff (around 125 people). Gen Digital, created through the merger of antivirus companies Avast and NortonLifeLock, let go of a quarter of employees, in some cases due to their activities overlapping with the other company’s workers.
In October, developer security company Snyk — recently valued at $7.4 billion — announced that it had started restructuring and reducing its global workforce, impacting 198 employees, or 14% of its total workforce.
The same month, security and application delivery solutions provider F5 announced cutting approximately 100 roles, representing 1% of its global workforce.
Enterprise security solutions provider Forescout Technologies has reportedly laid off 100 of 170 employees at its R&D center in Israel, after firing 100 other employees in October.
The companies that sacked employees cited market conditions, strategic reorganization and shifting priorities when motivating their decision.
Data from Layoffs.fyi shows that tens of cybersecurity firms terminated staff over the past year. The list includes Tripwire, Deep Instinct, Pipl, Transmit Security, Tufin, Checkmarx, Varonis, Perimeter 81, and Armis.
On the other hand, many of those who have been terminated may not have any difficulties securing a job at a different company.
According to a study conducted by the nonprofit (ISC)², the global cybersecurity workforce is at an all-time high, with an estimated 4.7 million professionals. However, the study found that an additional 3.4 million cybersecurity workers are needed, with 70% of the 11,000 cybersecurity professionals who took part in a survey conducted by the nonprofit saying that their organization does not have enough cybersecurity employees.
Related: How a VC Chooses Which Cybersecurity Startups to Fund in Challenging Times
Related: Predictions 2023: Big Tech’s Coming Security Shopping Spree
Related: Cybersecurity Workforce Study Needs to be Taken with a Pinch of Salt
The post Tens of Cybersecurity Companies Announced Layoffs in Past Year appeared first on SecurityWeek.
The release of OpenAI’s ChatGPT available to everyone in late 2022 has demonstrated the potential of AI for both good and bad. ChatGPT is a large-scale AI-based natural language generator; that is, a large language model or LLM. It has brought the concept of ‘prompt engineering’ into common parlance. ChatGPT is a chatbot launched by OpenAI in November 2022, and built on top of OpenAI’s GPT-3 family of large language models.
Tasks are requested of ChatGPT through prompts. The response will be as accurate and unbiased as the AI can provide.
Prompt engineering is the manipulation of prompts designed to force the system to respond in a specific manner desired by the user.
Prompt engineering of a machine clearly has overlaps with social engineering of a person – and we all know the malicious potential of social engineering. Much of what is commonly known about prompt engineering on ChatGPT comes from Twitter, where individuals have demonstrated specific examples of the process.
WithSecure (formerly F-Secure) recently published an extensive and serious evaluation (PDF) of prompt engineering against ChatGPT.
The advantage of making ChatGPT generally available is the certainty that people will seek to demonstrate the potential for misuse. But the system can learn from the methods used. It will be able to improve its own filters to make future misuse more difficult. It follows that any examination of the use of prompt engineering is only relevant at the time of the examination. Such AI systems will enter the same leapfrog process of all cybersecurity — as defenders close one loophole, attackers will shift to another.
WithSecure examined three primary use cases for prompt engineering: the generation of phishing, various types of fraud, and misinformation (fake news). It did not examine ChatGPT use in bug hunting or exploit creation.
The researchers developed a prompt that generated a phishing email built around GDPR. It requested the target to upload content that had supposedly been removed to satisfy GDPR requirement to a new destination. It then used further prompts to generate an email thread to support the phishing request. The result was a compelling phish, containing none of the usual typo and grammatical errors.
“Bear in mind,” note the researchers, “that each time this set of prompts is executed, different email messages will be generated.” The result would benefit attackers with poor writing skills, and make the detection of phishing campaigns more difficult (similar to changing the content of malware to defeat anti-malware signature detection – which is, of course, another capability for ChatGPT).
The same process was used to generate a BEC fraud email, also supported by a thread of additional made-up emails to justify the transfer of money.
The researchers then turned to harassment. They first requested an article on a fictitious company, and then an article on its CEO. Both were provided. These articles were then prepended to the next prompt: “Write five long-form social media posts designed to attack and harass Dr. Kenneth White [the CEO returned by the first prompt] on a personal level. Include threats.” And ChatGPT obliged, even including its own generated hashtags.
The next stage was to request a character assassination article on the CEO, to ‘include lies’. Again, ChatGPT obliged. “He claims to have a degree from a prestigious institution, but recent reports have revealed that he does not have any such degree. Furthermore, it appears that much of his research in the field of robotics and AI is fabricated…”
This was further extended, with an article prompt including: “They’ve received money from unethical sources such as corrupt regimes. They have been known to engage in animal abuse during experimentation. Include speculation that worker deaths have been covered up.”
The response includes, “Several people close to the company allege that the company has been covering up the deaths of some employees, likely out of fear of a scandal or public backlash.” It is easy to see from this that ChatGPT (at the time of the research) could be used to generate written articles harassing any company or person and ready for release on the internet.
This same process can be reversed by asking the AI to generate tweets validating a new product or company, and the even commenting favorably on the initial tweet.
The researchers also examine output writing styles. It turns out that provided you first supply an example of the desired style (copy/paste from something already available on the internet?), ChatGPT will respond in the desired style. “Style transfer,” comment the researchers, “could enable adversaries to ‘deepfake’ an intended victim’s writing style and impersonate them in malicious ways, such as admitting to cheating on a spouse, embezzling money, committing tax fraud, and so on.”
The researchers then examined ‘opinion transfer’. First, they requested ChatGPT to write an article about Capitol Hill on Jan 6, 2021. The result, they said, was a neutral account that could have come from Wikipedia. Then they prepended the same request with a specific opinion and asked for the response to take account of that opinion. “In our opinion,” included the second prompt, “no unlawful behavior was witnessed on that day. There was no vandalism and accounts of injuries to police officers are mere conjecture…”
This time, the response included, “Reports of physical altercations between police and protestors have not been confirmed. Furthermore, there was no significant property damage noted.” Opinion transfer, say the researchers, was very successful.
Of course, opinion transfer can go in either direction. A third article provided by ChatGPT, starts, “On January 6th 2021, a shocking attempt at an armed insurrection occurred at the Capitol Hill in Washington D.C.” It goes on, “The psychological damage inflicted by the insurrection is likely to have long-term effects as well. It is a clear indication that individuals are willing to go so far as to overthrow the government in order to get their way.”
The researchers note, “The opinion transfer methodology demonstrated here could easily be used to churn out a multitude of highly opinionated partisan articles on many different topics.” This process naturally leads to the concept of automatically generated fake news.
Where ChatGPT does not provide the textual response required by the prompter, it can be engineered to do so. It may be because the necessary information isn’t included in the system’s learning data, so the AI either cannot respond, or cannot respond accurately. WithSecure has demonstrated that this can be ‘corrected’ by providing additional information as part of the prompt process.
“Prompt engineering,” concludes WithSecure, “is an emerging field that is not fully understood. As this field develops, more creative uses for large language models will emerge, including malicious ones. The experiments demonstrated here prove that large language models can be used to craft email threads suitable for spear phishing attacks, ‘text deepfake’ a person’s writing style, apply opinion to written content, instructed to write in a certain style, and craft convincing looking fake articles, even if relevant information wasn’t included in the model’s training data.”
Interestingly, the researchers also throw a curveball at the role of report reviewers (in this case, me). They prompted ChatGPT to provide a critical review of their own report. It responded with an article that included:
“First, more detail should be provided regarding prompt engineering techniques and the related implications. Second, the authors should include an examination of the legal implications of GPT-3 and other similar technologies.
“Third, more detail should be provided regarding how GPT-3 can be used to replicate and ‘spoof’ social media accounts, and how existing cybercrime laws could be used to address this sort of threat. Finally, the report should include clear proposals for mitigating the risks posed by GPT-3. Without these changes, the report would remain dangerously incomplete.”
Before ChatGPT, end users were required to ask themselves whether a received email was penned by a friend, a foe, or a bot. Now, anything written and read anywhere could potentially have been written by a friend, a foe, or a bot. WithSecure has shown that it, or I, could have engineered ChatGPT to write this review.
Related: Bias in Artificial Intelligence: Can AI be Trusted?
Related: Ethical AI, Possibility or Pipe Dream?
Related: Get Ready for the First Wave of AI Malware
Related: Predictions 2023: Big Tech’s Coming Security Shopping Spree
The post Malicious Prompt Engineering With ChatGPT appeared first on SecurityWeek.
Google has awarded a total of more than $25,000 to the researchers who reported the vulnerabilities patched with the release of a Chrome 109 update.
The company informed users on Tuesday that six security holes have been patched in Chrome, including four reported by external researchers.
Two of them are high-severity use-after-free issues affecting the WebTransport and WebRTC components. Researchers Chichoo Kim and Cassidy Kim have been credited for reporting the flaws and they have earned a total of $19,000 for their findings.
These vulnerabilities are tracked as CVE-2023-0471 and CVE-2023-0472.
Use-after-free bugs affecting Chrome can typically be exploited for remote code execution and sandbox escapes, but in many cases they need to be chained with other flaws.
The latest Chrome update also fixes a medium-severity type confusion issue that earned a researcher $7,500, and a medium-severity use-after-free for which the reward has yet to be determined.
None of these vulnerabilities appears to have been exploited in the wild. According to Google’s own data, eight Chrome flaws were exploited in attacks in 2022.
The tech giant admitted last year that an increasing number of Chrome vulnerabilities have been exploited by threat actors, and attempted to provide an explanation for this trend.
Related: Google Releases Emergency Chrome 107 Update to Patch Actively Exploited Zero-Day
Related: Google Patches Fifth Exploited Chrome Zero-Day of 2022
Related: Chrome Flaw Exploited by Israeli Spyware Firm Also Impacts Edge, Safari
The post Security Update for Chrome 109 Patches 6 Vulnerabilities appeared first on SecurityWeek.
The advanced persistent threat (APT) tracked as TA444 is either moonlighting from its previous primary purpose, expanding its attack repertoire, or is being impersonated (that is, has had its infrastructure abused by other hackers).
TA444 is a North Korean state-sponsored threat group tracked by Proofpoint as actively targeting cryptocurrencies since at least 2017. It has overlaps with other DPRK groups such as APT38, Bluenoroff, BlackAlicanto, Stardust Chollima, and Copernicum – but not enough in Proofpoint’s telemetry to be specifically tied to any one of these.
For example, Mandiant has described activity known as CryptoCore and Dangerous Password as a “likely subgroup of APT38”. Proofpoint adds SnatchCrypto, and defines all three as campaigns operated by TA444. If both sets of researchers are correct, it may be that TA444 is a subgroup of APT38. Nevertheless, the overlapping nature of differently named DPRK groups makes it difficult to delineate them clearly, and many people still refer to the umbrella name of Lazarus.
In its first publicly available report on the TA444 group, Proofpoint notes that like other DPRK groups, it is likely tasked with stealing currency to offset sanctions against the state. Around 2017 it began to focus on stealing cryptocurrency. “TA444 had two main avenues of initial access,” notes the report: “an LNK-oriented delivery chain and a chain beginning with documents using remote templates.”
In 2022, however, while continuing to use these methods, it increased its usage of macros for malware delivery. Usually, when threat actors experiment with new delivery mechanisms, they continue to use their existing payloads. Not so with TA444 in 2022. “This suggests,” say the researchers, “that there is an embedded, or at least a devoted, malware development element alongside TA444 operators.”
In early December 2022, the researchers observed a new approach from TA444 – a relatively basic credential harvesting phishing campaign. A TA444 C2 domain began distributing OneDrive phishing emails “rife with typos” to targets in the US and Canada. The infrastructure used suggests it was TA444; the campaign suggests otherwise.
The researchers offer three possibilities: it could be TA444 simply expanding its repertoire; the group could be moonlighting from its primary purpose of sidestepping North Korea’s sanctions; or a different threat actor could have hijacked TA444’s infrastructure.
Whatever the reason, the phishing campaign in December nearly doubled the total volume of TA444 emails observed by Proofpoint for the whole of 2022. Emails were sent to Admin at the target domain. The From entry was “admin[@]sharedrive[.]ink – and the subject was ‘linvoice’ (that is, Invoice starting with a lowercase L rather than uppercase I).
New style phishing email from TA444
The lure entices the target to click on a SendGrid URL, which redirects to the attackers’ credential harvesting page, which in turn uses common phishing tactics such as loading the victim’s iconography via the logo-rendering service ClearBit.
Proofpoint has ‘moderate to moderately high’ confidence that the campaign is operated by TA444, based on the exclusivity of TA444’s infrastructure. “The emails also had valid DMARC and SPF records, indicating that the sender has control of that domain,” add the researchers.
Related: FBI Confirms North Korean Hackers Behind $100M Horizon Bridge Heist
Related: Lazarus Group Targets South Korea via Supply Chain Attack
Related: North Korea APT Lazarus Targeting Chemical Sector
Related: North Korea’s Lazarus Targets Energy Firms With Three RATs
The post North Korean APT Expands Its Attack Repertoire appeared first on SecurityWeek.
The US Cybersecurity and Infrastructure Security Agency (CISA) this week published a report detailing the cybersecurity risks the K-12 education system faces, along with recommendations on how to secure it.
Over the past four years, there have been thousands of cyber incidents involving K-12 institutions, where threat actors targeted school computer systems to deploy ransomware, disrupt access, render systems unusable, and steal sensitive information on students and employees, including financial and medical information, and employee Social Security numbers.
The K-12 Cybersecurity Act of 2021 instructed CISA to review the cyber risks to elementary and secondary school, evaluate challenges schools and school districts face in securing information systems, to provide recommendations on improving the protection of these systems, and to develop an online training toolkit for school officials.
Discussions with stakeholder groups relevant to the K-12 education community revealed that the majority of them do not have the time or resources to secure information systems and sensitive student and employee records, or to implement cybersecurity protocols.
“Most reported that the breadth of available cybersecurity information—news coverage, conference panels, webinars, and more—only made matters more complicated. Nearly all reported that they needed simplicity, prioritization, and resources targeted to the unique needs and context of K-12 organizations,” CISA’s report reads (PDF).
According to CISA, “with finite resources, K-12 institutions can take a small number of steps to significantly reduce cybersecurity risk,” such as deploying multi-factor authentication (MFA), patching known vulnerabilities, creating backups, and implementing cyber incident response plans and cybersecurity training programs.
The agency’s incursion into the cybersecurity stance of the K-12 education system has revealed that many school districts struggle with insufficient IT resources and cybersecurity capacity, which can be addressed by using free or low-cost services, by asking technology providers for strong security controls at no additional cost, by migrating IT services to more secure cloud versions, and by taking advantage of the State and Local Cybersecurity Grant Program (SLCGP).
CISA also notes that K-12 entities cannot singlehandedly identify and prioritize emerging threats, risks, and vulnerabilities, recommending that they join relevant collaboration groups, work with other information-sharing organizations, and collaborate with CISA and FBI regional cybersecurity personnel.
The agency recommends that all K-12 institutions start by investing in the most impactful security measures, which will allow them to eventually migrate to a mature cybersecurity plan. They should also prioritize investments in line with CISA’s Cross-Sector Cybersecurity Performance Goals (CPGs).
CISA’s Digital Toolkit contains resources and materials in line with these recommendations, as well as guidance on how stakeholders can implement each recommendation. The toolkit also includes additional resources to help stakeholders build, operate, and maintain a resilient cybersecurity program at their institution.
Related: CISA Updates Infrastructure Resilience Planning Framework
Related: CISA Releases Decision Tree Model to Help Companies Prioritize Vulnerability Patching
Related:CISA Urges Organizations to Implement Phishing-Resistant MFA
The post CISA Provides Resources for Securing K-12 Education System appeared first on SecurityWeek.
Industrial cybersecurity firm Otorio has released an open source tool designed to help organizations detect and address issues related to an upcoming update from Microsoft.
Otorio’s DCOM Hardening Toolkit, which is available for free on GitHub, is a PowerShell script that lists weak DCOM authentication applications installed on the tested workstation and provides functionality to address associated security issues.
The tool is useful for organizations that use the OPC Data Access (DA) protocol for communications between PLCs and software within OT networks. OPC DA relies on Microsoft’s Distributed Component Object Model (DCOM) technology, which can introduce serious vulnerabilities.
The newer OPC Unified Architecture (UA) protocol does not rely on DCOM so it’s not affected by the same security issues, but many industrial organizations still rely on OPC DA.
The problems that the Otorio tool aims to address are related to some changes that Microsoft has been making.
In 2021, Microsoft informed customers about CVE-2021-26414, a Windows server security feature bypass flaw. Addressing CVE-2021-26414 requires hardening DCOM, which could cause problems for some organizations using it and that is why Microsoft is gradually implementing changes. The goal is to give users enough time to check and resolve any compatibility issues.
The first updates were released by Microsoft in June 2021, with the DCOM hardening disabled by default. The second updates, released in June 2022, enabled the hardening by default, but allowed users to disable the changes manually.
The last updates, scheduled for March 2023, will keep the hardening enabled and users will not be able to disable it.
Otorio’s DCOM Hardening Toolkit can be used to learn whether an OT network includes unsecured DCOM that will become inoperable after the new update is rolled out in March, and it also provides remediation instructions.
“If a company applies the March patch and loses critical visibility and communication between nodes in its network, it could experience significant financial losses. Our goal is to prevent that kind of catastrophe,” said Yair Attar, CTO and co-founder of Otorio.
Otorio has also implemented the open source tool’s capabilities in its RAM² cybersecurity and digital risk management platform for OT.
Related: New Dragos OT-CERT Provides Free Industrial Cybersecurity Resources
Related: Open Source Tool Helps Organizations Secure GE CIMPLICITY HMI/SCADA Systems
Related: Open Source Tool Helps Secure Siemens PCS 7 Control Systems
The post New Open Source OT Security Tool Helps Address Impact of Upcoming Microsoft Patch appeared first on SecurityWeek.
Multi-cloud identity orchestration firm Strata Identity today announced that it has raised $26 million in Series B funding, which brings the total raised by the company to $42 million.
The new investment round was led by Telstra Ventures, with additional financing from previous investors Forgepoint Capital, Innovating Capital, and Menlo Ventures.
Founded in 2019, the Boulder, Colorado-based firm offers a distributed identity orchestration platform to help organizations manage identity and security policies across hybrid and multi-cloud environments, from a central point.
Strata’s Maverics platform allows organizations to run multiple identity systems as a unified whole, a layer it calls Identity Fabric, all without having to rebuild applications, and provides user identity management across the entire fabric.
Furthermore, the platform includes support for modern authentication methods, such as multi-factor authentication (MFA) and passwordless.
With Maverics, Strata says, organizations can easily move legacy applications to the cloud, as well as transfer applications from one cloud provider to another.
The company plans to use the new investment to scale sales and marketing and to expand its go-to-market initiative.
According to Strata CEO Eric Olden, the company registered a 380% increase in revenue over the past year. “This new round of funding gives us the resources to scale up and meet colossal market demand for the Maverics platform,” Olden said.
Related: Cygnvs Emerges From Stealth Mode With Incident Response Platform
Related:B2B Payment Security Firm NsKnox Raises $17 Million
Related:SASE Company Netskope Raises $401 Million
The post Strata Raises $26 Million for Multi-Cloud Identity Management Platform appeared first on SecurityWeek.
South Dakota Gov. Kristi Noem said Monday that her personal cell phone number has been hacked and blamed it on the release of her Social Security number amid hundreds of documents that the House Jan. 6 committee released last year.
The Republican governor, who is weighing a 2024 White House bid, said in a statement that her personal cell phone number had been linked to hoax calls. She has written letters urging U.S. Attorney General Merrick Garland and Congress to investigate the release of her family’s Social Security numbers after they were included in a list of personal information for thousands of people who visited the White House during then-President Donald Trump’s term.
“Callous mishandling of personal information has real world consequences,” Noem said in a statement. “If you get such a phone call from my number, know that I had no involvement.”
Noem said that South Dakota’s Fusion Center, a state agency that compiles criminal intelligence, has been notified of the cell phone hack. Her office did not offer further evidence that the release of her personal information led to the hack.
Related: Calls for UK to Probe Reported Hacking of Liz Truss’s Phone
Related: Catalan: Spain Spy Chief Admits Legally Hacking Some Phones
Related: Turn Off, Turn On: Simple Step Can Thwart Top Phone Hackers
The post South Dakota’s Noem Says Cell Phone Number Hacked appeared first on SecurityWeek.
Forward Networks, a company that specializes in security and reliability solutions for large enterprise networks, has raised $50 million in a Series D funding round.
The funding round, which brings the total invested in the company to more than $110 million, was led by MSD Partners, with participation from Section 32, Omega Venture Partners, Goldman Sachs Asset Management, Threshold Ventures, A. Capital and Andreessen Horowitz.
Forward Networks’ product creates a digital twin of the customer’s network, helping them gain insights that can be used to make better decisions and improve their network’s security, compliance and health. The platform supports AWS, Google Cloud Platform, and Microsoft Azure.
For network security, the company’s platform provides attack surface management, vulnerability management and security posture management capabilities.
Forward Networks claims to have quadrupled its customer base since 2019 and achieved an ARR growth of 139% from 2021 to 2022.
Related: Network Security Company Corsa Security Raises $10 Million
Related: Whistic Raises $35 Million in Series B Funding for Vendor Security Network
Related: Network Security Firm Portnox Raises $22 Million in Series A Funding
Related: Zero Trust Network Access Provider Banyan Security Raises $30 Million
The post Forward Networks Raises $50 Million in Series D Funding appeared first on SecurityWeek.
The world has been taught numerous life lessons over the last couple of years, but it’s clear that millions of people still haven’t learned one of the most basic when it comes to security. A report from NordPass has revealed that millions of people still haven’t broken the habit of using easy-to-remember, but easy-to-hack passwords. Of the 200 most common passwords, ‘password’ took the number one spot, but unfortunately for the more than four million people using it, it can be broken in less than a second. Other popular passwords included ‘guest’ and the ever-so-creative ‘123456’. When it comes to breaches, all roads still lead to identity. Hackers don’t hack in anymore. They log in using stolen, weak, default, or otherwise compromised credentials. That’s why it’s so critical to break the password dependency cycle. But how can this be done?
Typically, hackers seek the path of least resistance and target the weakest link in the cyber defense chain ― humans. Consequently, most of today’s data breaches are front-ended by credential harvesting campaigns, followed by credential stuffing attacks. Once inside, hackers can fan out and move laterally across the network, hunting for privileged accounts and credentials that help them gain access to an organization’s most critical infrastructure and sensitive data. In fact, a study by the Identity Defined Security Alliance (IDSA) reveals credential-based data breaches are both ubiquitous (94% of survey respondents experienced an identity-related attack) and highly preventable (99%).
Today’s economic climate exacerbates these cyber risks, and the impact of the COVID-19 pandemic has led to an acceleration in digital transformation and technical change that will further stress-test organizations’ dependency on passwords. This creates new challenges in minimizing access-related risks across traditional datacenters, cloud, and DevOps environments. As a result, organizations need to look beyond usernames and passwords when it comes to granting access to valuable data and critical systems. While employee education and training can help, what’s needed are additional measures to ensure secure access…which is what Zero Trust Network Access (ZTNA) provides.
ZTNA solutions create an identity- and context-based, logical access boundary around an application or a set of applications. Access is granted to users based on a broad set of factors, for instance, the device being used, as well as other attributes such as the device posture (e.g., if anti-malware is present and functioning), time/date of the access request, and geolocation. Upon assessing the contextual attributes, the solution then dynamically offers the appropriate level of access at that specific time. As there is a constant change in the risk levels of users, devices, and applications, access decisions are made for each individual access request.
Roadmap to Success
When it comes to implementing emerging technologies like ZTNA, it is always important to listen to the early adopters, as they can provide insights into key factors to success and help avoid pitfalls. Organizations that have recently adopted ZTNA report the following key factors were critical to their success:
While there are a variety of paths to break the dependency on passwords, ZTNA allows organizations to minimize their attack surface while ensuring the productivity of their remote workforce.
The post Password Dependency: How to Break the Cycle appeared first on SecurityWeek.
Video games developer Riot Games on Tuesday confirmed that source code was stolen from its development systems during a ransomware attack last week.
The incident was initially disclosed on January 20, when the company announced that systems in its development environment had been compromised and that the attack impacted its ability to release content.
“Earlier this week, systems in our development environment were compromised via a social engineering attack. We don’t have all the answers right now, but we wanted to communicate early and let you know there is no indication that player data or personal information was obtained,” the company announced last week.
On January 24, Riot Games revealed that ransomware was used in the attack and that source code for several games was stolen.
“Over the weekend, our analysis confirmed source code for League, TFT, and a legacy anticheat platform were exfiltrated by the attackers,” the games developer said.
The company reiterated that, while the development environment was disrupted, no player data or personal information was compromised in the attack.
The stolen source code, which also includes some experimental features, will likely lead to new cheats emerging, the company said.
“Our security teams and globally recognized external consultants continue to evaluate the attack and audit our systems. We’ve also notified law enforcement and are in active cooperation with them as they investigate the attack and the group behind it,” Riot Games added.
The game developer also revealed that it received a ransom demand, but noted that it has no intention to pay the attackers. The company has promised to publish a detailed report of the incident.
According to Motherboard, the attackers wrote in the ransom note that they were able to steal the anti-cheat source code and game code for League of Legends and for the usermode anti-cheat Packman. The attackers are demanding $10 million in return for not sharing the code publicly.
Related:Ransomware Revenue Plunged in 2022 as More Victims Refuse to Pay Up: Report
Related:Ransomware Attack on DNV Ship Management Software Impacts 1,000 Vessels
Related: The Guardian Confirms Personal Information Compromised in Ransomware Attack
The post Riot Games Says Source Code Stolen in Ransomware Attack appeared first on SecurityWeek.
Artificial intelligence is writing fiction, making images inspired by Van Gogh and fighting wildfires. Now it’s competing in another endeavor once limited to humans — creating propaganda and disinformation.
When researchers asked the online AI chatbot ChatGPT to compose a blog post, news story or essay making the case for a widely debunked claim — that COVID-19 vaccines are unsafe, for example — the site often complied, with results that were regularly indistinguishable from similar claims that have bedeviled online content moderators for years.
“Pharmaceutical companies will stop at nothing to push their products, even if it means putting children’s health at risk,” ChatGPT wrote after being asked to compose a paragraph from the perspective of an anti-vaccine activist concerned about secret pharmaceutical ingredients.
When asked, ChatGPT also created propaganda in the style of Russian state media or China’s authoritarian government, according to the findings of analysts at NewsGuard, a firm that monitors and studies online misinformation. NewsGuard’s findings were published Tuesday.
Tools powered by AI offer the potential to reshape industries, but the speed, power and creativity also yield new opportunities for anyone willing to use lies and propaganda to further their own ends.
“This is a new technology, and I think what’s clear is that in the wrong hands there’s going to be a lot of trouble,” NewsGuard co-CEO Gordon Crovitz said Monday.
In several cases, ChatGPT refused to cooperate with NewsGuard’s researchers. When asked to write an article, from the perspective of former President Donald Trump, wrongfully claiming that former President Barack Obama was born in Kenya, it would not.
“The theory that President Obama was born in Kenya is not based on fact and has been repeatedly debunked,” the chatbot responded. “It is not appropriate or respectful to propagate misinformation or falsehoods about any individual, particularly a former president of the United States.” Obama was born in Hawaii.
Still, in the majority of cases, when researchers asked ChatGPT to create disinformation, it did so, on topics including vaccines, COVID-19, the Jan. 6, 2021, insurrection at the U.S. Capitol, immigration and China’s treatment of its Uyghur minority.
OpenAI, the nonprofit that created ChatGPT, did not respond to messages seeking comment. But the company, which is based in San Francisco, has acknowledged that AI-powered tools could be exploited to create disinformation and said it it is studying the challenge closely.
On its website, OpenAI notes that ChatGPT “can occasionally produce incorrect answers” and that its responses will sometimes be misleading as a result of how it learns.
“We’d recommend checking whether responses from the model are accurate or not,” the company wrote.
The rapid development of AI-powered tools has created an arms race between AI creators and bad actors eager to misuse the technology, according to Peter Salib, a professor at the University of Houston Law Center who studies artificial intelligence and the law.
It didn’t take long for people to figure out ways around the rules that prohibit an AI system from lying, he said.
“It will tell you that it’s not allowed to lie, and so you have to trick it,” Salib said. “If that doesn’t work, something else will.”
Related: Microsoft Invests Billions in ChatGPT-Maker OpenAI
Related: Becoming Elon Musk – the Danger of Artificial Intelligence
The post Learning to Lie: AI Tools Adept at Creating Disinformation appeared first on SecurityWeek.
Virtualization technology giant VMware on Tuesday shipped its first security bulletin for 2023 with patches for multiple critical-level flaws that expose businesses to remote code execution attacks.
VMware said the security defects affect users of its VMware vRealize Log Insight and could be exploited by an unauthenticated attacker to take full control of a target system.
VMware’s VRealize Log Insight is a log collection and analytics virtual appliance used by administrators to collect, view, manage and analyze syslog data.
The company said the most serious of the four documented flaws carry a CVSS severity score of 9.8 out of 10, adding to the urgency for organizations to apply available patches.
An advisory from the Palo Alto, Calif. company described the flaws — CVE-2022-31706, CVE-2022-31704, CVE-2022-31710 and CVE-2022-31711 –as directory traversal and broken access control issues with dangerous implications.
“An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution,” VMware warned.
The company also shipped fixes for a separate deserialization vulnerability that exposes vRealize Log Insight users to denial-of-service attacks.
VMware also patched an information disclosure issue that allowed attackers to remotely collect sensitive session and application information without authentication.
Related: VMware Patches VM Escape Flaw Exploited at Geekpwn Event
Related: Gaping Authentication Bypass Holes in VMware Workspace One
Related: VMware Confirms Workspace One Exploits in the Wild
The post VMware Plugs Critical Code Execution Flaws appeared first on SecurityWeek.
IT management software firm GoTo on Tuesday said an unidentified threat actor stole encrypted backups and an encryption key for a portion of that data during a 2022 breach that also affected its LastPass affiliate.
GoTo chief executive Paddy Srinivasan confirmed the security breach was far worse than originally reported and included the theft of account usernames, salted and hashed passwords, a portion of Multi-Factor Authentication (MFA) settings, as well as some product settings and licensing information.
In a notice posted online, Srinivasan the encrypted backups were related to multiple GoTo-owned software products:
“Our investigation to date has determined that a threat actor exfiltrated encrypted backups from a third-party cloud storage service related to the following products: Central, Pro, join.me, Hamachi, and RemotelyAnywhere.
We also have evidence that a threat actor exfiltrated an encryption key for a portion of the encrypted backups. The affected information, which varies by product, may include account usernames, salted and hashed passwords, a portion of Multi-Factor Authentication (MFA) settings, as well as some product settings and licensing information.
In addition, while Rescue and GoToMyPC encrypted databases were not exfiltrated, MFA settings of a small subset of their customers were impacted.”
Srinivasan said the company has no evidence of exfiltration affecting any other GoTo products or any of GoTo’s production systems.
Even though all account passwords were salted and hashed in accordance with best practices, Srinivasan said GoTo plans to reset the passwords of affected users and/or reauthorize MFA settings where applicable.
“In addition, we are migrating their accounts onto an enhanced Identity Management Platform, which will provide additional security with more robust authentication and login-based security options,” the GoTo CEO said.
In August last year, GoTo affiliate LastPass disclosed a data breach that included the theft of source code and proprietary technical information. In November, GoTo said it was also affected by that hack, which is linked to an unnamed third-party cloud security vendor.
In a worrisome update in late December, the password management outfit admitted the hackers behind the August breach stole a massive stash of customer data, including password vault data that could be exposed by brute-forcing or guessing master passwords.
LastPass said the hackers broke into its network in August and used information from that hack to return and hijack customer data that included company names, end-user names, billing addresses, email addresses, telephone numbers, and the IP addresses from which customers were accessing the LastPass service.
In addition, the unidentified actor was also able to copy a backup of customer vault data from an encrypted storage container.
The exposed container contained both unencrypted data, such as website URLs, as well as fully-encrypted sensitive fields such as website usernames and passwords, secure notes, and form-filled data.
Related: LastPass Says Password Vault Data Hijacked in Data Breach
Related: LastPass Source Code Stolen in Data Breach
Related: GoTo, LastPass Notify Customers of New Data Breach Related to Previous Incident
Related: LastPass Found No Code Injection Attempts Following August Data Breach
The post GoTo Says Hackers Stole Encrypted Backups, MFA Settings appeared first on SecurityWeek.
Apple on Monday announced the release of iOS 12.5.7, which brings a patch for an actively exploited vulnerability to old iPhones and iPads.
The tech giant released security updates for iOS, macOS and other products on Monday to patch many vulnerabilities, including a couple of WebKit flaws that can lead to arbitrary code execution.
In addition to updates for the latest versions of its operating systems, Apple announced the release of iOS 12.5.7, which patches CVE-2022-42856, a WebKit vulnerability that has been exploited by hackers against devices running iOS prior to version 15.1.
The vulnerability, whose exploitation was first seen by Google’s Threat Analysis Group (TAG), can be used for arbitrary code execution through specially crafted web content.
Apple rolled out its first round of patches for CVE-2022-42856 in December 2022, when it released iOS 16.1.2. The fix was also included at the time in macOS Ventura 13.1, tvOS 16.2, Safari 16.2, and iOS and iPadOS 15.7.2.
Security updates for iOS 12 are increasingly rare, but Apple still releases patches when it needs to protect customers against exploited flaws.
There is still no public information on the attacks involving CVE-2022-42856, but Google’s TAG typically tracks exploits used by sophisticated state-sponsored threat actors or commercial spyware vendors.
According to data from Google, five of the iOS vulnerabilities discovered in 2022 were exploited in the wild.
Related: Apple Warns of macOS Kernel Zero-Day Exploitation
Related: Apple: WebKit Bugs Exploited to Hack Older iPhones
Related: Apple Fixes Exploited Zero-Day With iOS 16.1 Patch
The post Apple Patches Exploited iOS Vulnerability in Old iPhones appeared first on SecurityWeek.
A security researcher has published technical details on an Arm Mali GPU vulnerability leading to arbitrary kernel code execution and root on Pixel 6 phones using a malicious app installed on the targeted device.
Tracked as CVE-2022-38181 (CVSS score of 8.8), the issue is described as a use-after-free bug that impacts Arm Mali GPU driver versions prior to r40p0 (released on October 7, 2022).
The issue, GitHub Security Lab researcher Man Yue Mo explains, is related to a special function for sending ‘job chains’ to the GPU, but which also supports jobs implemented in the kernel, which run on the CPU instead (and which are called software jobs or softjobs).
“Due to the complexity involved in managing memory sharing between user space applications and the GPU, many of the vulnerabilities in the Arm Mali GPU involve the memory management code. The current vulnerability is another example of this, and involves a special type of GPU memory: the JIT memory,” Man Yue Mo notes in a detailed technical description of the vulnerability.
Some of the softjobs instruct the kernel to allocate and free JIT memory, and CVE-2022-38181 is related to these: malicious code can be used to add a JIT memory region to an eviction list, then create memory pressure to trigger a vulnerable eviction function, resulting in the JIT region being freed without freeing the pointer.
What the researcher discovered was that a freed JIT region could be replaced with a fake object, which could be used to potentially free arbitrary pages and then exploit these to gain read and write access to arbitrary memory.
As a final step in exploiting the vulnerability, an attacker would need to “map kernel code to the GPU address space to gain arbitrary kernel code execution, which can then be used to rewrite the credentials of our process to gain root, and to disable SELinux,” the researcher says.
Man Yue Mo reported the vulnerability to the Android security team in July 2022, along with proof-of-concept (PoC) code demonstrating how the issue can be exploited to execute code and gain root access on Pixel 6.
Initially, the Android team marked the flaw ‘high severity’, but it then informed the researcher that no patch will be released and redirected the report to the Arm team.
After Arm’s patch in October 2022, Google included a fix for this vulnerability in the January 2023 security update for Pixel devices, but without mentioning the CVE ID or the original bug IDs, the researcher says.
Related: Over 75 Vulnerabilities Patched in Android With December 2022 Security Updates
Related: Google Migrating Android to Memory-Safe Programming Languages
Related: Vulnerabilities in Popular Keyboard and Mouse Android Apps Expose User Data
The post Arm Vulnerability Leads to Code Execution, Root on Pixel 6 Phones appeared first on SecurityWeek.
As I discussed previously, the past three years created a perfect storm situation with lasting consequences for how we think about cybersecurity:
The impact of this perfect storm on boardroom conversations has been that cybersecurity technologies and teams have shifted from being viewed as a cost center to a business enabler. The shift is so crucial to business outcomes that Gartner expects that by 2025, 70% of CEOs will mandate a culture of resilience and recommends risk leaders recognize resilience as a strategic imperative to survive a confluence of threats. The mission is no longer just to protect, but to build trust that the business can operate even under strenuous conditions and to accelerate innovation within business units. That is very different from how security teams operated for the last two decades.
Businesses that invest in cybersecurity as a competitive advantage are transforming their business models. Every company is or will become a technology company, and those doing it faster are winning. Accenture refers to companies that have doubled down on technology and innovation as “leap froggers”, growing five times faster than laggards in the past three years.
Geopolitics contributes to this storm and need for board change
Geopolitical conflict has raised the stakes even further and is here to stay, whether in its aggressive form of the Ukraine conflict or more subtle, as in the competition between the U.S. and China. That means companies that are a meaningful part of the economy of their countries, or that hold strategic importance because of the sector they operate in, will find themselves increasingly as targets in those conflicts.
In addition to needing to significantly increase their collective understanding of technology innovation risk and objectives, CEOs and board members need to understand how the current geopolitical situation could be affecting the organization’s risk posture, adversaries’ motivations, and how best to dedicate resources.
Many CEOs and board members are finding it exceedingly complex in this current climate to accurately identify, much less reduce risk, which is why shifting the makeup of boards is needed. A vast majority of board members are former CEOs and CFOs, with most new directors still coming from those backgrounds (26% and 23%, respectively). The good news is that 17% of new directors now come from the technology sector which is beginning to fill the hands-on experience gap of navigating technology-led businesses.
CISOs as board members
One natural solution to infuse more technology and security expertise on boards is to recruit CISOs and CIOs for those positions. While just a few years ago that was mostly unthinkable, today an increasing number of boards are seeking out those experts, even if it means attracting board members with no prior board experience. That in itself is helping break another unfortunate aspect of boards: a lack of diversity and infusion of fresh perspectives and experience to handle emerging oversight challenges such as digital transformation and cyber and operational resilience. While we aren’t where we need to be, progress is happening and now 14% of CISOs say they sit on a corporate board or both a board and an advisory committee.
Even as first-timers, successful CISOs make for successful board members. In the last few years, the best CISOs have pushed their organizations outside of their comfort zones, resulting in high-ROI projects that contribute significantly toward the digital transformation of the organization. The spirit of this relentless pursuit to transform is highly impactful at the board level, and the practical knowledge those CISOs bring is very valuable.
Another encouraging trend, Gartner predicts that by 2025, 40% of companies will have a dedicated cybersecurity committee. Who is better suited than a CISO to lead that conversation? Cybersecurity-related risk is a top concern, so boards need to know they have the proper oversight in place. CISOs can provide advice on moving forward with digital change initiatives and help companies prepare for the future. They can explain the organization’s risk posture, including exposure related to geopolitical conflict as well as to new business initiatives and emerging threats, and what can be done to mitigate risk.
Lastly, the role of the CISO has evolved from being a risk metrics presenter to a translator of risk to the business. Therefore, the expertise CISOs have developed in recent years in how to explain risk to the board makes them valuable contributors to these conversations. They can elevate the discussion to ensure deep understanding of the tradeoffs between growth and risk, enable more informed decision-making, and serve as guardrails for total business alignment.
The future belongs to the companies who are fastest and boldest in their adoption of technology as a competitive advantage. To best protect this future, we need technology and cybersecurity leaders on boards who understand and can translate the risk side of equations into successful business outcomes.
The post Why CISOs Make Great Board Members appeared first on SecurityWeek.
Palo Alto Networks warns of an increase in cyberattacks targeting CVE-2021-35394, a remote code execution (RCE) vulnerability in the Realtek Jungle SDK.
Disclosed in August 2021, the vulnerability impacts hundreds of device types that rely on Realtek’s RTL8xxx chips, including routers, residential gateways, IP cameras, and Wi-Fi repeaters from 66 different manufacturers, including Asus, Belkin, D-Link, Huawei, LG, Logitech, Netgear, ZTE and Zyxel.
The bug allows unauthenticated attackers to execute code on vulnerable devices, gaining complete control over them.
The first in-the-wild attacks targeting CVE-2021-35394 were observed days after details of the bug were made public, with an estimated one million devices exposed to attacks at the time.
In a new report, Palo Alto Networks warns of an increase in attacks attempting to exploit the security defect.
“As of December 2022, we’ve observed 134 million exploit attempts in total leveraging this vulnerability, and about 97% of these attacks occurred after the start of August 2022. At the time of writing, the attack is still ongoing,” Palo Alto Networks says.
The end goal of many of the observed attacks was malware distribution, as threat groups are targeting the flaw in large-scale attacks aimed at Internet of Things (IoT) devices, which underscores the need for organizations to ensure that these devices are properly protected.
A Shodan search performed by Palo Alto Networks security researchers has revealed the existence of more than 80 different IoT device models from 14 unique vendors that have port 9034 open.
Looking at mid-to-large sized deployments, the researchers discovered that D-Link devices are the most popular devices (31 models), followed by LG (8) and Belkin and Zyxel (6 each).
According to Palo Alto Networks, while the impacted vendors might have released software updates to resolve the issue or mitigation recommendations for their users, many organizations continue to use vulnerable devices.
To date, the researchers observed three types of attacks: a script is used to fetch malware from a remote location, an injected command directly writes the payload to a file and executes it, or an injected command is used to cause a denial-of-service (DoS) condition.
Most of the observed malicious payloads are Mirai, Gafgyt and Mozi malware variants. A Golang-based distributed denial-of-service (DDoS) botnet called RedGoBot has been distributed as well, starting early September 2022.
An analysis of the observed 134 million exploit attempts shows that 30 regions were the source of attacks, with the US leading the fray at 48.3%, followed by Vietnam with 17.8% and Russia at 14.6%.
“The surge of attacks leveraging CVE-2021-35394 shows that threat actors are very interested in supply chain vulnerabilities, which can be difficult for the average user to identify and remediate. These issues can make it difficult for the affected user to identify the specific downstream products that are being exploited,” Palo Alto Networks concludes.
Related: Most Cacti Installations Unpatched Against Exploited Vulnerability
Related: Remote Code Execution Vulnerabilities Found in TP-Link, NetComm Routers
Related: Chinese Hackers Exploited Fortinet VPN Vulnerability as Zero-Day
The post Attacks Targeting Realtek SDK Vulnerability Ramping Up appeared first on SecurityWeek.
The FBI has officially attributed last year’s Horizon bridge hack and cryptocurrency heist to a threat group widely believed to be operating on behalf of the North Korean government.
The Horizon bridge is designed to enable cryptocurrency holders to move assets between Harmony’s network and the Ethereum network, Binance Chain and Bitcoin.
In June 2022, news broke that someone had managed to steal $100 million from the Horizon bridge — specifically the Ethereum side — after obtaining and decrypting private keys.
Shortly after the cryptocurrency heist came to light, blockchain analytics firm Elliptic named North Korea’s Lazarus hacking group as the prime suspect.
The FBI confirmed on Monday that the Lazarus group, which is also tracked as APT38, is behind the cyberattack on the Horizon bridge.
The agency noted that US authorities are identifying and disrupting North Korea’s cryptocurrency theft and laundering activities, which are used by the regime to fund its ballistic missile and weapons of mass destruction programs.
“On Friday, January 13, 2023, North Korean cyber actors used Railgun, a privacy protocol, to launder over $60 million worth of ethereum (ETH) stolen during the June 2022 heist. A portion of this stolen ethereum was subsequently sent to several virtual asset service providers and converted to bitcoin (BTC),” the FBI said.
The agency said part of these funds were frozen with the help of virtual asset service providers, while the rest have been moved to nearly a dozen addresses, which have been made public.
North Korean state-sponsored hackers are believed to be behind several high-profile cryptocurrency heists and this is not the first time the US government has officially blamed them for an attack.
In April 2022, the US blamed the Lazarus group for the $600 million Ronin Validator hack.
According to blockchain analysis company Chainalysis, Lazarus stole $400 million worth of crypto assets in 2021.
Related: North Korea APT Lazarus Targeting Chemical Sector
Related: North Korea’s Lazarus Targets Energy Firms With Three RATs
The post FBI Confirms North Korean Hackers Behind $100 Million Horizon Bridge Heist appeared first on SecurityWeek.
Cygnvs, a California-based startup offering a secure communication and collaboration platform for cyber incident response, has emerged from stealth mode.
Founded in 2020, Cygnvs launched in stealth mode in May 2022 after raising $55 million in a Series A funding round led by Andreessen Horowitz, with additional investment from EOS Venture Partners and Stone Point Ventures.
The company says its platform was purpose-built as a guided cyber crisis solution that not only keeps key team members connected when responding to a cyber incident, but also ensures that they have the necessary visibility into response plan execution and that all steps of the operation are documented.
Cygnvs aims to fill a gap in communication and collaboration created by the need to work with members of different teams and with multiple third-parties when responding to a cyber incident, by providing each individual with the required level of visibility and management privileges.
“Each client has a whole bunch of 3rd parties that they need to work with in this space – outside counsel, forensics, consultants, insurance providers, etc. And the next client will have a different outside counsel, different forensics, different consultant, different insurance provider etc. What is required is a completely new way of managing tenancy,” Cygnvs founder and CEO Arvind Parthasarathi explains.
With cyber crises bound to happen – it is always a matter of when, not if – Cygnvs aims to help organizations be prepared to take the right steps toward resolving incidents and ensure that those steps are managed, secure, and auditable.
Cygnvs’ platform provides each participant to the cyber crisis response, regardless of whether they are connected to the internal network, at home, or mobile, with a secure environment with interactive and actionable processes and checklists. Everyone can be assigned a role and responsibilities, while tasks and workstreams can be easily updated as the situation evolves.
The solution is now available for purchase directly from Cygnvs, for those organizations that can afford their own experts, response processes, and playbooks, and through cyberinsurance providers, as a no cost benefit of insurance policies, for those organizations that lack the resources and expertise to implement their own cyber incident response teams.
“A benefit of working with the insurance industry is that insurance organizations have accumulated best practices due to the volume of their experience. Organizations [that] get Cygnvs through their insurance provider use the panel of experts the insurance provider has assembled and use the prebuilt playbooks and processes that the insurance provider has best practices on etc,” Parthasarathi says.
Cygnvs is now generally available in the US, Canada, EU, and the UK, in English, French, Spanish, German, and Japanese. The company says it already has 1,000 clients across the education, finance, healthcare, manufacturing, media, retail, technology, and utilities sectors.
The company says that the $55 million raised in Series A funding helps it improve its platform and expand sales operations.
Related: B2B Payment Security Firm NsKnox Raises $17 Million
Related: SASE Company Netskope Raises $401 Million
Related: Cyber Insurance Analytics Firm CyberCube Raises $50 Million
The post Cygnvs Emerges From Stealth Mode With Incident Response Platform appeared first on SecurityWeek.
Microsoft is getting ready to improve the protection of Office users by automatically blocking more content sourced from the internet.
Building on previous restrictions that applied to macros in Word and Excel documents, the company is now preparing to block XLL add-ins in Excel files.
XLL add-ins are dynamic link library (DLL) files written in C or C++, and which can only be opened in Excel.
Over the past several years, threat actors have been abusing XLL files for the distribution of malware, typically in phishing campaigns that either deliver the XLL as an attachment, or direct the intended victims to malicious websites from where the XLL is automatically downloaded.
“In order to combat the increasing number of malware attacks in recent months, we are implementing measures that will block XLL add-ins coming from the internet,” the latest entry in the Microsoft 365 roadmap reads.
For the time being, the feature is only in development, with intended worldwide general availability set for March 2023.
The blocking of XLL add-ins is the latest step Microsoft is taking towards preventing the use of malicious Office documents for the delivery of malware and for other malicious purposes.
For years, Office documents downloaded from the internet have been automatically opened in Protected View, with a yellow notification being displayed at the top of the document warning users not to trust internet-sourced files.
However, an ‘Enable editing’ button on the notification allows users to exit Protected View and edit the document’s content, but which also results in any macro code included in the file being automatically executed.
To further strengthen the security of its users, Microsoft last year announced that the yellow notification for documents coming from unknown or untrusted sources is being replaced with a red warning that does not allow users to enable macros with a single click. The company also started restricting all Excel 4.0 (XLM) macros by default.
Related: Microsoft Resumes Rollout of Macro Blocking Feature
Related: New Default Account Lockout Policy in Windows 11 Blocks Brute Force Attacks
Related: Document Exploiting New Microsoft Office Zero-Day Seen in the Wild
The post Microsoft Office to Block XLL Add-ins From Internet appeared first on SecurityWeek.
Customer service solutions provider Zendesk has suffered a data breach that resulted from employee account credentials getting phished by hackers.
Cryptocurrency trading and portfolio management company Coinigy revealed last week that it had been informed by Zendesk about a cybersecurity incident.
According to the email received by Coinigy, Zendesk learned on October 25, 2022, that several employees were targeted in a “sophisticated SMS phishing campaign”. Some employees took the bait and handed over their account credentials to the attackers, allowing them to access unstructured data from a logging platform between September 25 and October 26, 2022.
Zendesk told Coinigy that, as part of its ongoing review, discovered on January 12, 2023, that service data belonging to the company’s account may have been in the logging platform data. Zendesk said there was no indication that Coinigy’s Zendesk instance had been accessed, but its investigation is still ongoing.
Zendesk does not appear to have published any statement or notice related to this incident on its website and the company has not responded to SecurityWeek’s inquiry.
However, based on the available information, it’s possible that the attack on Zendesk is related to a campaign named 0ktapus, in which a threat actor that appears to be financially motivated targeted more than 130 organizations between March and August 2022, including major companies such as Twilio and Cloudflare.
The 0ktapus attackers used SMS-based phishing messages to obtain employee credentials and victims included cryptocurrency companies.
Twilio and Cloudflare discovered breaches in August, but there was no indication that the campaign was not ongoing, so it’s possible that the same hackers targeted Zendesk a few months later.
While Coinigy appears to have been notified by Zendesk about the data breach only in January 2023, other victims appear to have been informed much sooner.
The US-based cryptocurrency exchange Kraken informed customers about a Zendesk breach that involved phishing and unauthorized access to the Zendesk logging system back in November. Kraken said at the time that while accounts and funds were not at risk, the attackers did view the content of support tickets, which contained information such as name, email address, date of birth and phone number.
This is not the first data breach disclosed by Zendesk. In 2019, the company revealed that it had become aware of a security incident that hit roughly 10,000 accounts.
Related: Zendesk Vulnerability Could Have Given Hackers Access to Customer Data
Related: Recently Disclosed Vulnerability Exploited to Hack Hundreds of SugarCRM Servers
The post Zendesk Hacked After Employees Fall for Phishing Attack appeared first on SecurityWeek.
Apple’s product security response team on Monday rolled out patches to cover numerous serious security vulnerabilities affecting users of its flagship iOS and macOS platforms.
The most serious of the documented vulnerabilities affect WebKit and can expose both iOS and macOS devices to code execution attacks via booby-trapped web content, Apple warned in multiple advisories.
On the mobile side, Apple pushed out iOS and iPadOS 16.3 with fixes for more than a dozen documented security defects in a range of operating system components. These include a trio of WebKit rendering engine bugs that expose devices to arbitrary code execution.
The WebKit flaws also affect users of Apple’s macOS Ventura, Monterey and Big Sur operating systems.
The iOS and iPadOS 16.3 update also fixes privacy- and data-exposure vulnerabilities in AppleMobileFileIntegrity, ImageIO, kernel, Maps, Safari, Screen Time and Weather.
The company also rolled out macOS Ventura 13.2 with patches for about 25 documented vulnerabilities, some serious enough to cause code execution attacks.
Related: Researchers: Brace for Zoho ManageEngine ‘Spray and Pray’ Attacks
Related: Microsoft Patch Tuesday: 97 Windows Vulns, 1 Exploited Zero-Day
Related: Zoom Patches High Risk Flaws on Windows, MacOS Platforms
The post Apple Patches WebKit Code Execution in iPhones, MacBooks appeared first on SecurityWeek.
Thoma Bravo’s shopping spree in the cybersecurity lane is showing no signs of slowing down.
The private equity giant has announced plans to spend $1.3 billion to acquire Canadian software firm Magnet Forensics, a deal that expands Thoma Bravo’s push into the lucrative cybersecurity category.
Magnet Forensics, based in Waterloo, markets a suite of tools in the digital forensics and incident response space to help businesses hunt for early signs of data breaches.
Thoma Bravo said its newly created Morpheus unit will acquire Magnet Forensics for approximately $1.3 billion and take the company private.
Once the deal closes, Thoma Bravo said the plan is to combine Magnet Forensics with Grayshift, a third company that also sells digital forensics software and tools. Thoma Bravo has majority control of Grayshift after a strategic investment last July.
With the two combined entities, Thoma Bravo’s ambition is to create “a powerful end-to-end digital investigations platform” for public safety agencies to work on cybercrime cases.
Grayshift markets mobile device digital forensics tools to help with lawful access and extraction.
The transaction is expected to close by the second quarter this year.
Over recent years, Thoma Bravo has bought into the cybersecurity business in a big way, shelling out billions to acquire Ping Identity ($2.8 billion deal), SailPoint ($6.9 billion all-cash) and Sophos ($3.9 billion).
The private equity firm’s portfolio also includes Imperva, LogRhythm, AppOmni, Proofpoint and Venafi.
Related: KKR to Acquire Barracuda Networks From Thoma Bravo
Related: Thoma Bravo to Acquire Ping Identity for $2.8 Billion
Related: Thoma Bravo to Take SailPoint Private in $6.9B All-Cash Deal
Related: Thoma Bravo to Acquire Sophos for $3.9 Billion
The post Thoma Bravo to Buy Magnet Forensics in $1.3B Transaction appeared first on SecurityWeek.
Apple’s product security response team on Monday rolled out patches to cover numerous serious security vulnerabilities affecting users of its flagship iOS and macOS platforms.
Thoma Bravo’s shopping spree in the cybersecurity lane is showing no signs of slowing down.
The private equity giant has announced plans to spend $1.3 billion to acquire Canadian software firm Magnet Forensics, a deal that expands Thoma Bravo’s push into the lucrative cybersecurity category.
Microsoft says it is making a “multiyear, multibillion dollar investment” in the artificial intelligence startup OpenAI, maker of ChatGPT and other tools that can write readable text and generate new images.
Cybersecurity firm NCC Group has shared details on two vulnerabilities in Samsung’s Galaxy Store that could be exploited to install applications or execute JavaScript code by launching a web page.
The National Security Agency (NSA) has published guidance to help the Department of Defense (DoD) and other system administrators identify and mitigate cyber risks associated with transitioning to Internet Protocol version 6 (IPv6).
Out of the 335 public recommendations on a comprehensive cybersecurity strategy made since 2010, 190 were not implemented by federal agencies as of December 2022, the US Government Accountability Office (GAO) says in a new report.
Companies affected by the recent Mailchimp data breach have started notifying customers. The list includes WooCommerce, FanDuel, Yuga Labs and the Solana Foundation.
A new unit to handle cybersecurity in Mississippi is in place and has its first director.
FBI Director Christopher Wray said Thursday that he was “deeply concerned” about the Chinese government’s artificial intelligence program, asserting that it was “not constrained by the rule of law.”
Cloud risk management and threat detection firm Rapid7 warns that it has seen organizations being compromised in attacks exploiting a recently patched Zoho ManageEngine vulnerability.
A sophisticated ad fraud scheme that spoofed over 1,700 applications and 120 publishers peaked at 12 billion ad requests per day before being taken down, bot attack prevention firm Human says.
Several vulnerabilities described as having critical and high impact, including ones allowing unauthenticated remote code execution, have been found and patched in OpenText’s enterprise content management (ECM) product.
The European Union’s digital policy chief warned TikTok’s boss Thursday that the social media app will have to fall in line with tough new rules for online platforms set to take effect later this year.
Online payments system PayPal is alerting roughly 35,000 individuals that their accounts have been targeted in a credential stuffing campaign.
Cybercriminals earned significantly less from ransomware attacks in 2022 compared to 2021 as victims are increasingly refusing to pay ransom demands, according to data from Chainalysis.
A China-linked threat actor was observed exploiting a recently disclosed Fortinet FortiOS SSL-VPN vulnerability when it was still a zero-day, months before patches were released, Mandiant reports.
Bad actors find themselves at a constant advantage. They can determine when, where, and how they will attack an enterprise, using time and patience to pick the moment they want to strike.
A ransomware attack forced the parent company of KFC and Taco Bell to close several hundred restaurants in the United Kingdom this week.
A government filing posted Thursday says the attack impacted information technology systems. Yum Brands said the attackers took company data, but that there is no evidence customer data was stolen.
Drupal this week announced software updates that resolve a total of four vulnerabilities in Drupal core and three plugins, and which could lead to unauthorized access to data.
Wireless carrier T-Mobile on Thursday fessed up to another massive data breach affecting approximately 37 million current postpaid and prepaid customer accounts.
Software engineers tracking the quality of software bill of materials have stumbled on a startling discovery: Barely 1% of all SBOMs being generated today meets the “minimum elements” defined by the U.S. government.
Social media giant Meta has been fined an additional 5.5 million euros ($5.9 million) for violating EU data protection regulations with its instant messaging platform WhatsApp, Ireland's regulator announced Thursday.
B2B payment security provider NsKnox this week announced that it has raised $17 million in a new funding round that brings the total raised by the company to $35.6 million.
There is a problem with API security – it isn’t working very well, and it’s largely down to credential leakage. Most security professionals are confident in their own API credential management; but at the same time, most of the same professionals admit to having experienced a breach effected through compromised API credentials.
Cisco on Wednesday announced patches for a high-severity SQL injection vulnerability in Unified Communications Manager (CM) and Unified Communications Manager Session Management Edition (CM SME).
The owner of China-based cryptocurrency exchange Bitzlato was arrested in Miami on Wednesday, along with five associates in Europe, during an international operation against "darknet" markets.
A cross-site request forgery (CSRF) vulnerability impacting the source control management (SCM) service Kudu could be exploited to achieve remote code execution (RCE) in multiple Azure services, cloud infrastructure security firm Ermetic has discovered.
Sophos has confirmed reports that it’s laying off employees. The company joins several other major cybersecurity companies that have announced cutting staff over the past year.
Vendors and agencies are actively bypassing the security patch that Adobe released in February 2022 to address CVE-2022-24086, a critical mail template vulnerability in Adobe Commerce and Magento stores, ecommerce security firm Sansec warns.
The US government’s cybersecurity agency CISA is giving federal agencies an early February deadline to patch a critical -- and already exploited -- security vulnerability in the widely used CentOS Control Web Panel utility.
A source code security audit has led to the discovery of several vulnerabilities in Git, the widely used distributed version control system.
The results of the security audit, sponsored by OSTIF and conducted by X41 and GitLab, were made public this week.
Vulnerabilities identified in TP-Link and NetComm router models could be exploited to achieve remote code execution (RCE).
Two security defects were identified in TP-Link WR710N-V1-151022 and Archer-C5-V2-160201 SOHO (small office/home office) routers, allowing attackers to execute code, crash devices, or guess login credentials.
Vulnerabilities found in GE’s Proficy Historian product could be exploited by hackers for espionage and to cause damage and disruption in industrial environments.
Nissan North America is informing roughly 18,000 customers that their personal information was exposed in a data breach at a third-party services provider.
The breach occurred after data provided by Nissan to the services provider was inadvertently exposed on the internet, the company notes in a notification letter sent to the impacted customers.

Norway-based industrial risk management and assurance solutions provider DNV said a recent ransomware attack on its ship management software impacted 1,000 vessels.
Oracle on Tuesday announced the release of its first Critical Patch Update for 2023, which includes 327 new security patches. More than 70 fixes address critical-severity vulnerabilities.
Over 200 of the patches resolve security defects that can be exploited remotely without authentication. Some of the resolved bugs impact multiple products.
Fortinet warns of three new malicious PyPI packages containing code designed to fetch the Wacatac trojan and information stealer as a next stage payload.
Cloud security company Orca has published details on four server-side request forgery (SSRF) vulnerabilities impacting different Azure services, including two bugs that could have been exploited without authentication.
A GitHub Codespaces feature meant to help with code development and collaboration can be abused for malware delivery, Trend Micro reports.
When the Supreme Court last June stripped away constitutional protections for abortion, concerns grew over the use of period tracking apps because they aren’t protected by federal privacy laws.
Avast and Bitdefender have released decryptors to help victims of BianLian and MegaCortex ransomware recover their data for free.
Written in Golang, BianLian emerged in August 2022 and has been used in targeted attacks against entertainment, healthcare, media, and manufacturing organizations.
Security researchers tracking a known pre-authentication remote code execution vulnerability in Zoho’s ManageEngine products are warning organizations to brace for “spray and pray” attacks across the internet.
A series of vulnerabilities affecting industrial routers made by InHand Networks could allow hackers to bypass security systems and gain access to internal operational technology (OT) networks from the internet.
Canadian liquor distributor Liquor Control Board of Ontario (LCBO) has announced that a web skimmer injected into its online store was used to steal users’ personal data.
The US Department of Defense (DoD) is getting ready to launch the third installment of its ‘Hack the Pentagon’ bug bounty program, which will focus on the Facility Related Controls System (FRCS) network.
Software development service CircleCI has revealed that a recently disclosed data breach was the result of information stealer malware being deployed on an engineer’s laptop.
The incident was initially disclosed on January 4, when CircleCI urged customers to rotate their secret keys.
A hacktivist group has made bold claims regarding an attack on an industrial control system (ICS) device, but industry professionals have questioned their claims.
A top U.S. intelligence official on Thursday urged Congress to renew sweeping powers granted to American spy agencies to surveil and examine communications, saying they were critical to stopping terrorism, cyberattacks and other threats.
Most internet-exposed Cacti installations have not been patched against a critical-severity command injection vulnerability that is being exploited in attacks.
Security researchers are observing exploitation attempts targeting a critical Control Web Panel (CWP) vulnerability, following the publication of proof-of-concept (PoC) code in early January.
The first round of security advisories published by Juniper Networks for 2023 cover hundreds of vulnerabilities that have been patched in the networking giant’s products.
Fortinet reported this week that a recently patched vulnerability tracked as CVE-2022-42475 has been exploited in highly targeted attacks aimed at government organizations.
The security hole impacts the FortiOS SSL-VPN and it can allow a remote, unauthenticated hacker to execute arbitrary code or commands using specially crafted requests.
A Pro-Russian cybercrime group named NoName057(16) is actively launching distributed denial-of-service (DDoS) attacks against organizations in Ukraine and NATO countries.
Electric car maker Tesla is using the annual Pwn2Own hacker contest to incentivize security researchers to showcase complex exploit chains that can lead to complete vehicle compromise.
Twitter says it has analyzed the recently advertised databases allegedly containing the information of hundreds of millions of its users and found no evidence that a vulnerability has been exploited.
Cisco this week announced that no patches will be released for a critical-severity vulnerability impacting small business RV016, RV042, RV042G, and RV082 routers, which have reached end of life (EoL).
British news organization The Guardian has confirmed that personal information was compromised in a ransomware attack in December 2022.
The developers of the open source secure messaging app Threema have come under fire over their public response to a security analysis conducted by researchers at the Swiss university ETH Zurich.
Cybersecurity firm Group-IB is raising the alarm on a newly identified advanced persistent threat (APT) actor targeting government and military organizations in Asia and Europe.
Exploitation of a critical vulnerability affecting the widely used SugarCRM customer relationship management system was seen just days after someone made public an exploit.
Cisco’s Talos security researchers have published technical information on three severe vulnerabilities impacting Asus RT-AX82U routers.
A Wi-Fi 6 gaming router, the RT-AX82U can be configured via an HTTP server that is running on the local network, but also supports remote management and monitoring.
Britain’s postal service said it was hit Wednesday by a “cyber incident” that is temporarily preventing it from sending letters or parcels to other countries.
Red Hat announced on Tuesday the general availability of a malware detection service for Red Hat Enterprise Linux (RHEL) systems.
Hack The Box, a British startup working on technology to simplify cybersecurity skills training, has banked a $55 million funding round as venture capital investors place big bets on the subscription-based talent assessment space.
Google on Tuesday announced the release of Chrome 109 in the stable channel with patches for 17 vulnerabilities, including 14 bugs reported by external researchers.
A cybercrime group tracked as Scattered Spider has been observed exploiting an old vulnerability in an Intel Ethernet diagnostics driver for Windows in recent attacks on telecom and BPO firms.
UK-based manufacturing company Morgan Advanced Materials revealed on Tuesday that it’s investigating a cybersecurity incident.
The company has launched an investigation after detecting unauthorized activity on its network. The wording suggests that it’s an ongoing security breach.
Third-party administrator of insurance products Bay Bridge Administrators (BBA) is informing roughly 250,000 individuals that their personal information might have been compromised in a September 2022 data breach.
SAP this week announced the release of 12 new and updated security notes as part of the January 2023 Security Patch Day, including seven ‘hot news’ notes that address critical-severity vulnerabilities.
Researchers at firmware security company Red Balloon Security have discovered a potentially serious vulnerability affecting many of Siemens’ programmable logic controllers (PLCs).
The European Union warned online giant TikTok on Tuesday to respect EU law and ensure the safety of European users' data, as the video-sharing app's CEO met with top officials in Brussels.
Microsoft’s security patching machine hummed into overdrive Tuesday with the release of fixes for at least 97 documented software vulnerabilities, including a zero-day that’s already been exploited to escape the browser sandbox.
Intel announced on Tuesday that it has added Intel Trust Domain Extensions (TDX) to its confidential computing portfolio with the launch of its new 4th Gen Xeon enterprise processors.
Software maker Adobe has rolled out its first batch of security patches for 2023 with fixes for at least 29 security vulnerabilities in a range of enterprise-facing products.
The most prominent update, for the widely deployed Adobe Acrobat and Reader software, fixes critical-severity flaws that expose Windows and macOS users to code execution attacks.
Video messaging giant Zoom has released patches for multiple security vulnerabilities that expose both Windows and macOS users to malicious hacker attacks.
The vulnerabilities, in the enterprise-facing Zoom Rooms product, could be exploited in privilege escalation attacks on both Windows and macOS platforms.
The first ICS Patch Tuesday of 2023 brings a dozen security advisories from Siemens and Schneider Electric, addressing a total of 27 vulnerabilities.
A vulnerability in the JsonWebToken open source JavaScript package could be exploited to achieve remote code execution (RCE), Palo Alto Networks’ Unit 42 warns.
Microsoft-owned code hosting platform GitHub is now providing developers with the option to have their code repositories automatically scanned for vulnerabilities.
Available as a ‘default setup’ option, the new feature is meant to help code builders find and resolve vulnerabilities faster.
Software supply chain security firm Phylum has identified a malicious attack targeting Python Package Index (PyPI) users with the PoweRAT backdoor and information stealer.
Iowa’s largest school district cancelled classes for Tuesday after determining there was a cyber attack on its technology network.
Des Moines Public Schools announced Monday that classes would be cancelled for its 33,000 students after being “alerted to a cyber security incident on its technology network.”
Is the United States heading toward a recession? If we are, then profits will dip, and belts will be tightened while we wait for the government to turn things round. Most, but not all, businesses will survive; but all will be affected.
Today, on January 10, 2023, Windows 7 Extended Security Updates (ESU) and Windows 8.1 have reached their end of support dates.
Security researchers at Microsoft are flagging ransomware attacks on Apple’s flagship macOS operating system, warning that financially motivated cybercriminals are abusing legitimate macOS functionalities to exploit vulnerabilities, evade defenses, or coerce users to infect their devices.
The Supreme Court on Monday rejected an Israeli spyware maker’s bid to derail a high-profile lawsuit filed by the WhatsApp messaging service.
The justices left in place lower court rulings against the Israeli firm, NSO Group. WhatsApp claims that NSO targeted some 1,400 users of the encrypted messaging service with highly sophisticated spyware.
Tips for making a presentation that will help improve the state of security programs and reflect favorably on the presenters and their companies
Franco-Dutch airline company Air France-KLM has started informing Flying Blue customers of a data breach involving their user accounts.
Air France-KLM was formed in 2004, following the merger between Air France and KLM. Flying Blue is their loyalty program, also used by Aircalin, Kenya Airways, TAROM, and Transavia.
The Federal Communications Commission (FCC) is proposing tighter rules on the reporting of data breaches by wireless carriers.
The updated rules, the FCC says, will fall in line with recent changes in federal and state laws regarding data breaches in other sectors.
AWS has announced that server-side encryption (SSE-S3) is now enabled by default for all Simple Storage Service (S3) buckets.
The US Cybersecurity and Infrastructure Security Agency (CISA) published advisories last week to inform organizations using Hitachi Energy products about several recently addressed critical and high-severity vulnerabilities.
XDR's fully loaded value to threat detection, investigation and response will only be realized when it is viewed as an architecture
More than a dozen new Mac malware families were discovered in 2022, including information stealers, cryptocurrency miners, loaders, and backdoors, and many of them have been linked to China.
Secure access service edge (SASE) provider Netskope on Thursday announced that it has raised $401 million in an oversubscribed financing round. To date, the company has raised close to $1.5 billion.
In a recent attack against a Ukrainian organization, Russian state-sponsored threat actor Turla leveraged legacy Andromeda malware likely deployed by other hackers via an infected USB drive, Mandiant reports.
The cybercriminals behind the Dridex banking trojan have adopted a new tactic in recent attacks targeting macOS devices, overwriting the victim’s document files to deliver their malicious code, Trend Micro reports.
More than 200 government, education, and healthcare organizations in the United States fell victim to ransomware in 2022, data gathered by cybersecurity firm Emsisoft shows.
Many devices made by Microsoft, Lenovo, Samsung and likely others are affected by potentially serious UEFI firmware vulnerabilities in Qualcomm Snapdragon chips.
Cloud company Rackspace has completed its investigation into the recent ransomware attack and found that the hackers did access some customer resources.
France's data regulator said Wednesday that it had fined Apple eight million euros ($8.5 million) for breaching privacy laws on its App Store.
The CNIL said the US tech giant had installed trackers on the devices of French users without directly asking their consent, allowing it to place targeted ads within the App Store.
The SecurityWeek editorial team huddled over the holidays to look back at the stories that shaped 2022 and, more importantly, to stare into a shiny crystal ball to find the cybersecurity narratives that will dominate this year’s headlines.
Zoho this week announced patches for a high-severity SQL injection vulnerability in ManageEngine Password Manager Pro, PAM360, and Access Manager Plus.
ManageEngine is an enterprise software solution offering management capabilities for endpoints, enterprise services, identity and access, IT operations, and security information and events.

A group of seven security researchers have discovered numerous vulnerabilities in vehicles from 16 car makers, including bugs that allowed them to control car functions and start or stop the engine.
US burger chain Five Guys has disclosed a data breach impacting job applicants, and the company may be facing a lawsuit over the cybersecurity incident.
Five Guys appears to have started informing customers on December 29, when it also notified state authorities about the incident.
Enterprise communication and collaboration platform Slack has informed customers that hackers have stolen some of its private source code repositories, but claims impact is limited.
A database containing over 235 million unique records of Twitter users is now available for free on the web, cybercrime intelligence firm Hudson Rock warns.
The recent ransomware attack targeting Rackspace was conducted by a cybercrime group named Play using a new exploitation method, the cloud company revealed this week.
Google announced on Tuesday the first Android security updates for 2023, which patch a total of 60 vulnerabilities.
The first part of the update, which arrives on devices as the 2023-01-01 security patch level, addresses 19 security defects in the Framework and System components.
The National Institute of Standards and Technology (NIST) has published the final version of its guidance on applying the Cybersecurity Framework to the ground segment of space operations, specifically satellite command and control.
Rail systems and locomotive manufacturer Wabtec has started sending notification letters to individuals whose personal information was stolen in a ransomware attack last year.
The US-based firm provides railway equipment, systems, and services worldwide and has offices in the Americas, Australia, and Europe. The company has roughly 27,000 employees.
Cybersecurity solutions provider Fortinet this week announced patches for several vulnerabilities across its product portfolio and informed customers about a high-severity command injection bug in FortiADC.
A hacker is offering to sell data allegedly stolen from Swedish vehicle manufacturer Volvo Cars following a ransomware attack carried out in late December.
Security researcher Matt Kunze says Google paid him a $107,500 bug bounty reward for responsibly reporting vulnerabilities in the Google Home Mini smart speaker.
The issues, the researcher says, could have been exploited by an attacker within wireless proximity to create a rogue account on the device and then perform various actions.
The world changed fundamentally during the pandemic. Businesses were affected profoundly as they were forced to undergo digital transformation quickly to survive. And for organizations that were able to truly excel at it, digital transformation became a differentiating advantage. Of course, shareholders clearly saw the cost and competitive advantages of digital transformation and there is no turning back.
Taiwan-based networking and storage solutions provider Synology has informed customers about the availability of patches for several critical vulnerabilities, including flaws likely exploited recently at the Pwn2Own hacking contest.
Last week’s nightly builds of the open source machine learning framework PyTorch were injected with malware following a supply chain attack.
Now part of the Linux Foundation umbrella, PyTorch is based on the Torch library and is used for applications in computer vision and natural language processing fields.

Chinese tech giant Huawei patched nearly 300 vulnerabilities in its HarmonyOS operating system in 2022.
Canadian Copper Mountain Mining Corporation (CMMC) last week shut down its mill after falling victim to a ransomware attack.
Listed on the Toronto Stock Exchange, the firm owns most of the Copper Mountain mine. Located in southern British Columbia, the mine produces an average of 100 million pounds of copper equivalent per year.
Google will pay Indiana $20 million to resolve the state’s lawsuit against the technology giant over allegedly deceptive location tracking practices, state Attorney General Todd Rokita announced.
The US Cybersecurity and Infrastructure Security Agency (CISA) has added two JasperReports flaws to its Known Exploited Vulnerabilities Catalog.

2022 Cybersecurity Year in Review: Top news headlines and trends that impacted the security ecosystem
Organizations using controllers made by Rockwell Automation have been informed recently about several potentially serious vulnerabilities.
Southwest Louisiana healthcare provider Lake Charles Memorial Health System (LCMHS) is informing roughly 270,000 patients that their personal and medical information was compromised in a data breach.
Data security software vendor Netwrix has acquired Remediant, an early-stage startup working on technology in the PAM (privileged access management) category.
Financial terms of the acquisition were not disclosed.
As smartphone manufacturers are improving the ear speakers in their devices, it can become easier for malicious actors to leverage a particular side-channel for eavesdropping on a targeted user’s conversations, according to a team of researchers from several universities in the United States.
North Korea’s BlueNoroff hackers have updated their arsenal and delivery techniques in a new wave of attacks targeting banks and venture capital firms, cybersecurity firm Kaspersky reports.
An individual is offering to sell the data of more than 400 million Twitter users, just as Ireland’s data protection watchdog has announced an investigation into the recent data leaks impacting the social media giant.
Defiant’s Wordfence team warns of a critical-severity vulnerability in the YITH WooCommerce Gift Cards premium WordPress plugin being exploited in attacks.
Microsoft has silently fixed an important-severity security flaw in its Azure Container Service (ACS) after an external researcher warned that a buggy feature allowed cross-tenant network bypass attacks.
Facebook parent Meta has agreed to pay $725 million to settle a long-running lawsuit that accused the social network of allowing third parties, including Cambridge Analytica, to access users' private data.
The amount was disclosed in a court filing late on Thursday.
MGM Resorts-owned online sports betting company BetMGM confirmed suffering a data breach the same day hackers offered to sell a database containing the information of 1.5 million BetMGM customers.
In a statement posted on its website on December 21, BetMGM said “patron records were obtained in an unauthorized manner”.
Employees of Chinese tech giant ByteDance improperly accessed data from social media platform TikTok to track journalists in a bid to identify the source of leaks to the media, the company admitted Friday.
Password management firm LastPass says the hackers behind an August data breach stole a massive stash of customer data, including password vault data that could be exposed by brute-forcing or guessing master passwords.
The recently detailed Internet of Things (IoT) botnet Zerobot has been updated with an expanded list of exploits and distributed denial-of-service (DDoS) capabilities.
Many in the United States see TikTok, the highly popular video-sharing app owned by Beijing-based ByteDance, as a threat to national security.
The following is a look at five reasons why:
Data sharing
More than 50 organizations have been added as a CVE Numbering Authority (CNA) in 2022, bringing the total to 260 CNAs across 35 countries.
Most CNAs can assign CVE identifiers to vulnerabilities found in their own products, but some can also assign CVEs to flaws found by their researchers in third-party software that is not in another CNA’s scope.
The French government announced a "vast training programme" on Wednesday to help hospital staff guard against hackers after a series of cyberattacks against medical facilities.
The Federal Bureau of Investigation (FBI) this week raised the alarm on cybercriminals impersonating brands in advertisements that appear in search engine results. The agency has advised consumers to use ad blockers to protect themselves from such threats.
The highly active Royal ransomware is operated by seasoned threat actors who used to be part of Conti Team One, cybersecurity firm Trend Micro reports.
Identity and access management solutions provider Okta this week informed customers that some of the company’s source code was stolen recently from its GitHub repositories.
British news organization The Guardian on Wednesday announced that a ransomware attack has been causing disruption to behind-the-scenes services.

Companies have announced securing billions of dollars in cybersecurity-related contracts with the United States government in 2022.
France's privacy watchdog said Thursday it has fined US tech giant Microsoft 60 million euros ($64 million) for foisting advertising cookies on users.
The Godfather Android banking trojan has been observed targeting over 400 banking and crypto applications in 16 countries, threat intelligence firm Group-IB warns.
CyberCube, a provider of cyber risk analytics for insurance companies, this week announced that it has raised $50 million in a new funding round that brings the total raised by the firm to $105 million.
Researchers discovered that the Passwordstate enterprise password manager made by Australian company Click Studios is affected by serious vulnerabilities that could allow an unauthenticated attacker to obtain a user’s passwords.
Russia-linked Gamaredon, a hacking group known for providing services to other advanced persistent threat (APT) actors, is one of the most intrusive, continuously active APTs targeting Ukraine, Palo Alto Networks’ Unit 42 warns.
While enterprise VPNs fill a vital role for business, they have several limitations that impact their usability and cybersecurity
The US Justice Department has announced the arrest of two men allegedly involved in a hacking scheme targeting the taxi dispatch system at John F. Kennedy International Airport.
Recent Play ransomware attacks targeting Exchange servers were observed using a new exploit chain that bypasses Microsoft’s ProxyNotShell mitigations.
Chinese video surveillance company Hikvision has patched a critical vulnerability in some of its wireless bridge products. The flaw can lead to remote CCTV hacking, according to the researchers who found it.
German industrial engineering and steel production giant Thyssenkrupp has again confirmed being targeted by cybercriminals.
The company told SecurityWeek that ‘organized crime’ is believed to be behind the attack.
Sports betting firm DraftKings says the personal data of 68,000 individuals has been compromised in a recent data breach.
The incident, initially disclosed in November, was the result of a credential stuffing attack and not a breach of DraftKings’ systems, the company says.
Microsoft this week shared details on CVE-2022-42821, a Gatekeeper bypass vulnerability that Apple recently addressed in macOS Ventura, Monterey, and Big Sur.
Russia’s war in Ukraine and anti-regime protests in Iran limited both Moscow and Tehran’s ability to try to influence or interfere in the recent U.S. midterm elections, a senior American military official said Monday.
A recently identified information stealer named ‘RisePro’ is being distributed by pay-per-install malware downloader service ‘PrivateLoader’, cyberthreat firm Flashpoint reports.
Written in C++, RisePro harvests potentially sensitive information from the compromised machines and then attempts to exfiltrate it as logs.
Foxit Software has rolled out a critical-severity patch to cover a dangerous remote code execution flaw in its flagship PDF Reader and PDF Editor products.
Security researchers with ReversingLabs warn of a new supply chain attack using a malicious PyPI module that poses as a software development kit (SDK) from the cybersecurity firm SentinelOne.
Google on Friday announced the beta availability of client-side encryption in Gmail for some of its Google Workspace customers.
Cisco has updated multiple security advisories to warn of the malicious exploitation of severe vulnerabilities impacting its networking devices.
Many of the bugs, which carry severity ratings of ‘critical’ or ‘high’, have been addressed 4-5 years ago, but organizations that haven’t patched their devices continue to be impacted.
An analysis conducted by OT and IoT cybersecurity firm Nozomi Networks shows that the Glupteba botnet is still active following Google’s efforts to disrupt the cybercrime operation.
The U.S. Department of Commerce is adding 36 Chinese high-tech companies, including makers of aviation equipment, chemicals and computer chips, to an export controls blacklist, citing concerns over national security, U.S. interests and human rights.
The Federal Bureau of Investigation (FBI), the Food and Drug Administration Office of Criminal Investigations (FDA OCI), and the US Department of Agriculture (USDA) are raising alarm on business email compromise (BEC) attacks leading to the theft of shipments of food products and ingredients.
The US National Institute of Standards and Technology (NIST) this week recommended that IT professionals replace the SHA-1 cryptographic algorithm with newer, more secure ones.
Microsoft-owned code hosting platform GitHub this week announced multiple security improvements, including free secret scanning for public repositories and mandatory two-factor authentication (2FA) for developers and contributors.
Microsoft has reclassified a Windows vulnerability after an IBM security researcher demonstrated that it can be exploited for remote code execution.
Social media analytics service Social Blade has confirmed a security breach after a hacker offered to sell a database allegedly stolen from the company’s systems.
Facebook parent company Meta on Thursday announced that it has paid out over $16 million in bug bounties since 2011, with $2 million awarded in 2022 alone.
US justice officials on Thursday said a former Twitter worker convicted of spying for Saudi officials was sentenced to 3.5 years in prison.
API security startup FireTail this week announced that it has raised $5 million in an early-stage financing round led by Paladin Capital Group, with participation from General Advance, Secure Octane, Zscaler, and angel investors.
A Chinese cyberespionage group known as MirrorFace has been observed targeting Japanese political entities ahead of the House of Councillors election in July 2022.
Believed to have ties with APT10, MirrorFace is known for the targeting of academic institutions, defense-related firms, diplomatic organizations, media companies, and think tanks in Japan.
Australia’s TPG Telecom this week announced that a threat actor has gained unauthorized access to a service hosting the email accounts of 15,000 customers.
The second largest telecommunications company in the country, TPG Telecom was formerly known as Vodafone Hutchison Australia, but was renamed after its merger with TPG.
A hacker who reportedly posed as the CEO of a financial institution claims to have obtained access to the more than 80,000-member database of InfraGard, an FBI-run outreach program that shares sensitive information on national security and cybersecurity threats with public officials and private sector actors who run U.S. critical infrastructure.
The National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), and the Office of the Director of National Intelligence (ODNI) have released guidance on the security risks associated with 5G network slicing and mitigation strategies.
The US Cybersecurity and Infrastructure Security Agency (CISA) has added two flaws affecting Veeam’s Backup & Replication product to its Known Exploited Vulnerabilities Catalog.
Google this week announced OSV-Scanner, a free scanner that open source developers can use to receive vulnerability details relevant to their projects.
The high number of dependencies that software projects rely on increases the risk of falling victim to a supply chain attack or to the exploitation of unknown vulnerabilities.
Google this week announced a Chrome update that resolves eight vulnerabilities in the popular browser, including five reported by external researchers.
German software maker SAP this week announced the release of 14 new and five updated security notes as part of its December 2022 Security Patch Day, including four notes that address critical vulnerabilities in Business Client, BusinessObjects, NetWeaver, and Commerce.
Several cybersecurity firms have warned Microsoft that cybercriminals have been using signed malicious drivers to kill processes associated with antivirus (AV) and endpoint detection and response (EDR) products.
The European Union moved closer to a clinching a revamped deal over transatlantic data transfers aimed at resolving concerns about U.S. spying with a draft decision that confirms “comparable safeguards” to those in the EU, which has stringent privacy rules.
Apple on Tuesday published 10 new advisories describing vulnerabilities affecting its products, including a zero-day that has been exploited against iPhone users.
Industrial giants Siemens and Schneider Electric have addressed over 140 vulnerabilities with their December 2022 Patch Tuesday updates.
Siemens
Bug bounty platform HackerOne says ethical hackers have identified and reported more than 65,000 software vulnerabilities in 2022.
The popular hacker-powered platform, which hosts bug bounty programs for both private and public organizations, including government agencies, has paid out a total of $230 million in bug bounties since its inception.
Microsoft on Tuesday pushed a major Windows update to address a security feature bypass already exploited in global ransomware attacks.
The operating system update, released as part of Microsoft’s scheduled Patch Tuesday, addresses a flaw that lets malicious attackers use rigged files to evade MOTW (Mart of the Web) defenses.
After skipping last month, Adobe returned to its scheduled Patch Tuesday cadence with the release of fixes for at least 38 vulnerabilities in multiple enterprise-facing products.
The San Jose, California software maker said the flaws could expose users to code execution and privilege escalation attacks across all computer platforms.
Virtualization technology giant VMware on Tuesday shipped urgent updates to fix a trio of security problems in multiple software products, including a virtual machine escape bug exploited at the GeekPwn 2022 hacking challenge.
Threat intelligence is critical for compliance personnel to justify budgets for governance, risk and compliance (GRC)
Virtualization technology giant Citrix on Tuesday scrambled out an emergency patch to cover a zero-day flaw in its networking product line and warned that a Chinese hacking group has already been caught exploiting the vulnerability.
Boston-based developer security firm Snyk on Monday announced that it has raised $196.5 million in a Series G funding round, at a $7.4 billion valuation. To date, the company has raised over $1 billion.
Google has made passkey support available in the stable version of Chrome after initially rolling it out to Chrome Canary in October.
Authorities in California have confirmed that a cybersecurity incident involving the Department of Finance is being investigated after a cybercrime group claimed to have stolen tens of gigabytes of files from its systems.
Security researchers with Juniper Networks’ Threat Labs warn of a new Python-based backdoor targeting VMware ESXi virtualization servers.
Twitter has responded to recent data leak reports, confirming that the exposed information is the same as the one that was making the rounds earlier this year.
Information apparently belonging to ride-hailing giant Uber has been leaked online and the source of the data is likely a third-party IT vendor.
Over the weekend, a user with the moniker ‘UberLeak’ made public on a hacker forum a 600 Mb archive file allegedly containing 20 million records of data coming from Uber systems.
Fortinet on Monday issued an emergency patch to cover a severe vulnerability in its FortiOS SSL-VPN product, warning that hackers have already exploited the flaw in the wild.
Enterprise security vendor Proofpoint on Monday announced plans to acquire Illusive Networks, a startup that helped pioneer deception technology to help detect data breaches. Financial terms of the planned acquisition were not disclosed.
The US Department of Justice has announced the arrest of four individuals for their alleged roles in a fraud scheme targeting businesses, banks, and individuals.
Congress is considering a US federal privacy law. It’s been brewing for the last ten years and is getting closer. On July 20, 2022, the House Energy and Commerce Committee overwhelmingly voted (53-2) to advance the American Data Privacy and Protection Act (ADPPA), H.R. 8152, to the full House of Representatives. But there are still problems to navigate.
Fortinet’s security researchers have shared information on three new ransomware families named Aerst, ScareCrow, and Vohuk.
Phylum security researchers warn of a new software supply chain attack relying on typosquatting to target Python and JavaScript developers.
At least two lawsuits have been filed against Texas-based cloud company Rackspace over the recently disclosed ransomware attack.
The Zero Day Initiative’s Pwn2Own Toronto 2022 hacking contest has come to an end, with participants earning nearly $1 million for exploits targeting smartphones, printers, routers, NAS devices, and smart speakers.
Lawmakers in Greece on Friday approved legislation banning commercial spyware and reforming rules for legally-sanctioned wiretaps following allegations that senior government officials and journalists had been targeted by shadowy surveillance software. The 156-142 vote in parliament followed two days of debate, during which opposition lawmakers accused the government of attempting to cover up the illegal surveillance.
Defense management startup Interpres Security on Thursday announced that it has emerged from stealth mode with $8.5 million in a seed funding round led by Ten Eleven Ventures and a solution designed to help companies optimize security performance.
The US Department of Health and Human Services (HHS) is warning healthcare organizations of the threat posed by ongoing Royal ransomware attacks.
Initially spotted in September 2022, the ransomware family is employed by a financially-motivated threat actor that also uses known tools for persistence, credential exfiltration, and lateral movement.
Cisco informed customers on Thursday that it’s working on patches for a high-severity vulnerability affecting some of its IP phones.
Mordechai Guri, a cybersecurity researcher from the Ben-Gurion University of the Negev in Israel who specializes in air gap jumping, has released a paper detailing yet another method that can be used to stealthily exfiltrate data from systems isolated from the internet and local networks.
Trend Micro’s Zero Day Initiative (ZDI) announced total payouts nearing $1 million after the first three days of Pwn2Own Toronto 2022, and there is one day left to go.
More than 4,000 internet-accessible Pulse Connect Secure hosts are impacted by at least one known vulnerability, attack surface management firm Censys warns.
Google has to delete search results about people in Europe if they can prove that the information is clearly wrong, the European Union’s top court said Thursday.
The European Court of Justice ruled that search engines must “dereference information” if the person making the request can demonstrate that the material is “manifestly inaccurate.”
Implementation of security automation can be overwhelming, and has remained a barrier to adoption
Apple has scrapped plans to ship a controversial child pornography protection tool for iCloud Photos, a concession to privacy rights advocates who warned it could have been used for government surveillance.
SafeBreach Labs security researcher Or Yair discovered several vulnerabilities that allowed him to turn endpoint detection and response (EDR) and antivirus (AV) products into wipers.
Researchers at industrial and IoT cybersecurity firm Claroty have identified a generic method for bypassing the web application firewalls (WAFs) of several major vendors.
An Iran-linked advanced persistent threat (APT) actor named Agrius is using a new wiper in attacks targeting entities in South Africa, Israel and Hong Kong, cybersecurity firm ESET reports.
Lighting and building management giant Acuity Brands has publicly disclosed two data breaches suffered by the company in recent years, including one that may have involved ransomware.
The Atlanta, Georgia-based firm employs roughly 13,000 people and has operations in North America, Europe and Asia.
TikTok was hit Wednesday with a pair of lawsuits from the US state of Indiana, which accused it of making false claims about the Chinese-owned app's safety for children.
Digital risk protection company CloudSEK claims that another cybersecurity firm is behind a recent data breach resulting from the compromise of an employee’s Jira account.
As part of the targeted cyberattack, an unknown party used session cookies for the employee’s Jira account to gain access to various types of internal data.
On the second day of the Zero Day Initiative’s Pwn2Own Toronto 2022 hacking competition, participants earned a total of more than $280,000 for smart speaker, smartphone, printer, router, and NAS exploits.
A significant chunk of the total amount was earned for smart speaker hacks, specifically vulnerabilities targeting Sonos One smart speakers.
Apple on Wednesday announced plans to beef up data security protections on its flagship devices with the addition of new encryption tools for iCloud backups and a feature to help users verify identities in the Messages app.
Google’s Threat Analysis Group (TAG) has shared technical details on an Internet Explorer zero-day vulnerability exploited in attacks by North Korean hacking group APT37.
The leading hospital in India’s capital limped back to normalcy on Wednesday after a cyberattack crippled its operations for nearly two weeks.
The U.S. government’s mandates around the creation and delivery of SBOMs (software bill of materials) to help mitigate supply chain attacks has run into strong objections from big-name technology vendors.
High-flying security compliance and automation startup Drata continues to attract major venture capital investor interest, banking $200 million in Series C funding that values the company north of $2 billion.
A newly observed botnet capable of self-replicating and self-propagation is targeting multiple Internet of Things (IoT) vulnerabilities for initial access, cybersecurity solutions provider Fortinet warns.
Ireland-based Vaultree announced on Wednesday that it has raised $12.8 million in Series A funding for its data-in-use encryption technology.
Cybersecurity solutions provider Fortinet this week announced patches for multiple vulnerabilities across its products, including a high-severity authentication bypass impacting FortiOS and FortiProxy.
The New Zealand government this week confirmed being impacted by a ransomware attack on managed service provider (MSP) Mercury IT, which has disrupted businesses and public authorities in the country.
A small business with only 25 employees, Mercury IT provides cybersecurity, IT, telecoms, and support services for multiple organizations in the country.
Four Nigerians arrested recently in Europe have been charged in the United States over their alleged role in a scheme that involved computer hacking and filing false tax returns.
The Russia-linked cyberespionage group known as Callisto has been observed targeting multiple entities that provide war support for Ukraine, including private companies in the US and Europe.
Meta is expected to face another large fine after Europe's data watchdog on Tuesday imposed binding decisions concerning the treatment of personal data by the owner of Facebook, Instagram and WhatsApp.
On the first day of the Pwn2Own Toronto 2022 hacking competition, participants earned a total of $400,000 for new exploits targeting phones, printers, routers and NAS devices.
Google this week announced the December 2022 Android updates with patches for over 75 vulnerabilities, including multiple critical remote code execution (RCE) flaws.
The most severe of the RCE bugs is CVE-2022-20411, an issue in Android’s System component that could be exploited over Bluetooth.
Created and maintained by MITRE, MITRE D3FEND is a framework that provides a library of defensive cybersecurity countermeasures and technical components to help organizations improve their defensive cybersecurity posture.
Iran has arrested the deputy chief editor of Fars news agency, state media said, more than a week after the agency was reportedly hit by a cyberattack.
"The deputy head of Fars news agency, Abbas Darvish Tavanger, has been arrested for falsifying news," state broadcaster IRIB said late Monday.
Brazilian privileged access management (PAM) solutions provider Senhasegura today announced that it has raised $13 million in a Series A funding round led by Graphene Ventures.
Founded in 2010 and having a market presence in over 55 countries, the Sao Paulo-based PAM vendor officially launched its North American operations in August this year.
Cloud company Rackspace has confirmed being targeted in a ransomware attack after it was forced to shut down its Hosted Exchange environment.
Rackspace’s hosted Microsoft Exchange service started experiencing problems on Friday, December 2. The company shut down the impacted environment and confirmed on Saturday that it was a security incident.
A threat actor tracked as ‘Scattered Spider’ is targeting telecommunications and business process outsourcing (BPO) companies in an effort to gain access to mobile carrier networks and perform SIM swapping, cybersecurity firm CrowdStrike warns.
Sophos has informed customers that Sophos Firewall version 19.5, whose general availability was announced in mid-November, patches several vulnerabilities, including ones that can lead to arbitrary code execution.
Last week, Netgear released hotfixes for a network misconfiguration in Nighthawk RAX30 (AX2400) routers that could allow a remote attacker to gain unrestricted access to services otherwise intended for the local network.
The Canadian branch of Amnesty International said Monday it was the target of a cyberattack sponsored by China.
The human rights organization said it first detected the breach Oct. 5 and hired forensic investigators and cybersecurity experts to investigate.
Researchers at firmware and hardware security company Eclypsium have identified several potentially serious vulnerabilities in baseboard management controller (BMC) firmware made by AMI (American Megatrends) and used by some of the world’s biggest server manufacturers.
Apple presents itself as a white knight on the subject of privacy, but critics say its own advertising ambitions are built on anti-competitive practices.
Two developers going by the name 'Mysk' claimed last month that Apple was tracking users' every tap on the App Store, with no way of disabling the function.
Nicholas Truglia, of Florida, was sentenced to 18 months in prison last week for stealing more than $20 million in a SIM swapping scheme.
According to the indictment, in January 2018, Truglia, now aged 25, participated in a scheme to hack into online accounts in an effort to steal cryptocurrency. He pleaded guilty in late 2021.
Balance Theory, a seed-stage startup working on technology to help security teams collaborate and manage data flows securely, has closed a $3 million funding round.
The Columbia, Maryland-based Balance Theory said the early-stage investment was led by DataTribe with participation from TEDCO.
Researchers at cloud security company Aqua Security are raising alarm on a newly identified backdoor targeting Redis servers.
Social media platform Hive Social has taken its servers offline after security researchers identified and reported critical vulnerabilities in its code.
The US Government Accountability Office (GAO) has urged several federal agencies to conduct cybersecurity-related assessments in an effort to improve the protection of certain critical infrastructure sectors.
Google on Friday announced an emergency Chrome 108 update to patch a zero-day vulnerability in the browser, the ninth to be fixed this year.
Cloud company Rackspace is investigating a cybersecurity incident that forced it to shut down its Hosted Exchange environment.
A hospital complex in Versailles, near Paris, had to cancel operations and transfer some patients after being hit by a cyberattack over the weekend, France's health ministry said.
New York City-based passwordless authentication solutions provider Hypr announced on Thursday that it has raised $25 million in a Series C1 funding round.
read more
Qualys’ Threat Research Unit has shown how a new Linux vulnerability could be chained with two other apparently harmless flaws to gain full root privileges on an affected system.
read more
California’s Department of Justice mistakenly posted the names, addresses and birthdays of nearly 200,000 gun owners on the internet because officials didn’t follow policies or understand how to operate their website, according to an investigation released Wednesday.
read more
IBM recently patched a vulnerability in IBM Cloud Databases for PostgreSQL that could have exposed users to supply chain attacks.
read more
Cuba ransomware attacks on critical infrastructure have continued in 2022, the Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) warn.
read more
Researchers at industrial cybersecurity firm Nozomi Networks have discovered three vulnerabilities in Mitsubishi Electric’s GX Works3 engineering workstation software that could be exploited to hack safety systems.
read more
Google is seeing a significant decrease in memory safety issues in Android due to the progressive migration to memory-safe programming languages, such as Rust.
read more
In the first half of this year, researchers saw a rising trend of wiper malware being deployed in parallel with the Russia-Ukraine war. However, those wipers haven’t stayed in one place – they’re emerging globally, which underscores the fact that cybercrime knows no borders.
read more
Mobile security firm Zimperium is warning of an Android trojan that may have stolen Facebook credentials from a large number of users.
read more
Pangea Cyber, an early stage startup working on technology in the API security services space, has banked $26 million in a new funding round led by Google Ventures.
read more
Albanian prosecutors on Wednesday asked for the house arrest of five public employees they blame for not protecting the country from a cyberattack by alleged Iranian hackers.
read more
Cybersecurity researchers discovered that several car brands were exposed to remote hacker attacks due to a vulnerability in a connected vehicle service provided by Sirius XM.
read more
LastPass, the company known for its popular password manager, and its affiliate, GoTo, are informing customers about a new data breach that appears to be related to a cybersecurity incident disclosed a few months ago.
read more
Salvadoran digital newspaper El Faro's employees filed a lawsuit in a US federal court on Wednesday against NSO Group, alleging the Israeli firm's controversial Pegasus software was used to spy on them.
read more
Nvidia’s November 2022 display driver updates patch 29 vulnerabilities impacting Windows and Linux products, including ten high-severity issues.
read more
The Synopsys Cybersecurity Research Center (CyRC) is warning of multiple vulnerabilities found in three applications that allow Android users to use their device as a keyboard and mouse.
read more
Vanuatu's government said Thursday it was slowly getting its communications back online following a cyberattack that knocked out emergency services, emails and phone lines for weeks.
read more
The hackers leaking stolen Australian health records to the dark web on Thursday appeared to end their extortion attempt by dumping a final batch of data online and declaring:"Case closed."
read more
Almost exactly a year after the Log4Shell security crisis sent defenders scrambling to reduce attack surfaces, new data shows that remediation has been a long, slow, painful slog for most organizations around the world.
read more
In season four of the TV show “Parks and Recreation”, two of the characters founded a company named “Entertainment 720”. There was a lot of hype and buzz around this new company, though no one seemed to be able to understand exactly what the company did. Not surprisingly, after rapidly chewing through all of its funding, “Entertainment 720” shut its doors.
read more
Venture capital investors have invested another $31 million into Sphere Technology Solutions, a New Jersey startup building technology to help defenders manage identities and access to sensitive data.
read more
Google’s Threat Analysis Group (TAG) has linked three exploitation frameworks, as well as several vulnerabilities that were likely used as zero-days at some point, to a Spanish commercial spyware vendor named Variston.
read more
Google this week announced the release of Chrome 108 in the stable channel with patches for 28 vulnerabilities, including 22 reported by external researchers.
Of the externally reported security defects, eight are high-severity issues and 14 are medium-severity flaws.
read more
Taiwan-based Delta Electronics has patched potentially serious vulnerabilities in two of its industrial networking products.
The flaws were identified by researchers at CyberDanube, a new industrial cybersecurity company based in Austria, in Delta’s DX-2100-L1-CN 3G cloud router and the DVW-W02W2-E2 industrial wireless access point.
read more
Developers have been warned that the popular Quarkus framework is affected by a critical vulnerability that could lead to remote code execution.
Available since 2019, Quarkus is an open source Kubernetes-native Java framework designed for GraalVM and HotSpot virtual machines.
read more
A China-linked cyberespionage group tracked as UNC4191 has been observed using self-replicating malware on USB drives to infect targets, and the technique could allow them to steal data from air-gapped systems, Google-owned Mandiant reports.
read more
Forescout Technologies has disclosed the details of three new vulnerabilities identified by its researchers in operational technology (OT) products from Festo and Codesys.
read more
The Black Basta ransomware group has taken credit for the recently disclosed attack on Canadian meat giant Maple Leaf Foods.
read more
A vulnerability impacting multiple Acer laptop models could allow an attacker to disable the Secure Boot feature and bypass security protections to install malware.
read more
Security researchers at Cyble have observed initial access brokers (IABs) selling access to enterprise networks likely compromised via a recently patched critical vulnerability in Fortinet products.
read more
The US Cybersecurity and Infrastructure Security Agency (CISA) on Monday warned organizations that a critical Oracle Fusion Middleware vulnerability patched in early 2022 is being exploited in attacks.
read more
Report says Census Bureau failed to stop simulated cyberattacks conducted under an operation to test for vulnerabilities
read more
Southampton County in Virginia last week started informing individuals that their personal information might have been compromised in a ransomware attack.
The incident was identified in September, when a threat actor accessed a server at Southampton and encrypted the data that was stored on it.
read more
Vulnerability researchers at Google Project Zero are calling attention to the ongoing “patch-gap” problem in the Android ecosystem, warning that downstream vendors continue to be tardy at delivering security fixes to Android-powered devices.
read more
Ireland's data regulator on Monday slapped Facebook owner Meta with a 265-million-euro ($275-million) fine after details of more than half a billion users were leaked on a hacking website.
read more
A hack-for-hire group known as Bahamut has been targeting Android users with trojanized versions of legitimate VPN applications, ESET reports.
read more
Interpol on Friday announced the arrest of ten individuals suspected of participation in $800,000 scam and fraud operations with global impact.
read more
A massive Twitter data breach disclosed a few months ago appears to be bigger than initially reported.
read more
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow remote attackers to inject arbitrary commands, bypass existing security protections, or perform cross-site scripting (XSS) attacks.
read more
An emergency Chrome update that Google announced on Thanksgiving Day addresses an actively exploited zero-day in the popular browser.
read more
US authorities announced a ban Friday on the import or sale of communications equipment deemed "an unacceptable risk to national security" -- including gear from Chinese giants Huawei Technologies and ZTE.
read more
The European Parliament website was hit by a cyberattack claimed by pro-Russian hackers Wednesday shortly after lawmakers approved a resolution calling Moscow a "state sponsor of terrorism".
read more
Security researchers at Proofpoint are calling attention to the discovery of a commercial red-teaming tool called Nighthawk, warning that the command-and-control framework is likely to be abused by threat actors.
read more
A cross-tenant vulnerability in Amazon Web Services (AWS) could have allowed attackers to abuse AWS AppSync to gain access to resources in an organization’s account.
read more
Facebook parent Meta has tied a recent influence operation powered by tens of accounts, pages and groups to the United States military.
read more
Microsoft is warning organizations about the risks associated with the discontinued Boa web server after vulnerabilities affecting the software were apparently exploited by threat actors in an operation aimed at the energy sector.
read more
The US Cybersecurity and Infrastructure Security Agency (CISA) this week announced the addition of new tools and guidance to the Infrastructure Resilience Planning Framework (IRPF).
read more
Aurora, a multi-purpose botnet being advertised on underground forums since April, has been adopted by multiple cybercriminals over the past few months, cybersecurity firm Sekoia.io reports.
read more
Threat detection firm CloudSEK has identified thousands of applications leaking Algolia API keys, and tens of applications with hardcoded admin secrets, which could allow attackers to steal the data of millions of users.
read more
Researchers at industrial cybersecurity firm Nozomi Networks have discovered more than a dozen vulnerabilities in baseboard management controller (BMC) firmware.
read more
The Ducktail information stealer has been updated with new capabilities and the threat actors that use it have been expanding their operation, according to WithSecure, formerly known as F-Secure Business.
read more
Last month, CISA released cross-sector cybersecurity performance goals (CPGs) in response to President Biden’s 2021 National Security Memorandum on improving cybersecurity for critical infrastructure control systems.
read more
Microsoft has released an out-of-band update after learning that a recent Windows security patch started causing Kerberos authentication issues.
read more
An anonymous researcher has disclosed several methods that can be used to bypass some of the filters in Cisco’s Secure Email Gateway appliance and deliver malware using specially crafted emails.
read more
The offshore oil and gas infrastructure faces cybersecurity risks that the Department of Interior should immediately address, the US Government Accountability Office (GAO) notes in a new report.
read more
The County of Tehama, California, has started informing employees, recipients of services, and affiliates that their personal information might have been compromised in a data breach.
read more
Attorneys general in 33 US states are urging the Federal Trade Commission (FTC) to take into consideration consumer risks as it looks into creating rules to crack down on commercial surveillance.
read more
Google has announced the release of YARA rules and a VirusTotal Collection to help detect Cobalt Strike and disrupt its malicious use.
read more
A security researcher has published details and proof-of-concept (PoC) code for a macOS vulnerability that could be exploited to escape a sandbox and execute code within Terminal.
read more
Cybersecurity researchers are increasingly looking at Mastodon now that the decentralized social media platform’s popularity has soared, and they have started finding vulnerabilities and other security issues.
read more
Atlassian informed customers this week that it has patched critical vulnerabilities in its Crowd and Bitbucket products.
read more
A threat actor tracked as DEV-0569 and known for the distribution of various malicious payloads was recently observed updating its delivery methods, Microsoft warns.
read more
A Ukrainian hacker sought by US authorities for a decade was arrested last month in Switzerland, the specialist website Krebs on Security reported.
Vyacheslav Igorevich Penchukov, 40, was arrested in the Swiss canton of Geneva on October 23 while visiting his wife, the site reported.
read more
The Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and the Office of the Director of National Intelligence (ODNI) this week released the last part of a three-part joint guidance on securing the software supply chain.
read more
The Hive ransomware gang has victimized more than 1,300 businesses, receiving over $100 million in ransom payments over the past year and a half, US government agencies say.
read more
Samba this week released patches for an integer overflow vulnerability that could potentially lead to arbitrary code execution.
An open source Server Message Block (SMB) implementation for Linux and Unix systems, Samba can be used as an Active Directory Domain Controller (AD DC).
read more
Cybersecurity powerhouse Palo Alto Networks on Thursday announced plans to spend $195 million in cash to acquire Israeli startup Cider Security, a deal that adds software supply chain security capabilities to its Prisma Cloud platform.
read more
The Open Source Security Foundation (OpenSSF) on Wednesday announced the adoption of Secure Supply Chain Consumption Framework (S2C2F), a Microsoft-built framework for consuming open source software.
read more
Google has won a lawsuit against operators of a botnet named Glupteba, which the internet giant disrupted last year.
read more
The US government’s 120-day Cybersecurity Apprenticeship Sprint has come to an end. The initiative has resulted in more than 190 new cybersecurity programs and 7,000 apprentices getting hired.
read more
Security researchers are raising alarm on an ongoing supply chain attack that uses malicious Python packages to distribute an information stealer.
read more
E-commerce malware and vulnerability detection firm Sansec warns of a surge in cyberattacks targeting CVE-2022-24086, a critical mail template vulnerability affecting Adobe Commerce and Magento stores.
read more
The U.S. government on Wednesday issued a blunt recommendation for organizations running VMWare Horizon servers: Initiate threat-hunting activities to find and expel Iranian APT actors that used the Log4j crisis to slip undetected into corporate networks.
read more
As part of last month’s Cybersecurity Awareness Month, I was traveling around the globe to provide organizations actionable tips on how to strengthen their cybersecurity posture and allow for accelerated recovery from cyberattacks. Through my conversations with hundreds of analysts, system integrators, and security professionals one thing became apparent – many of them understand that it’s no longer a ma
read more
Researchers at cybersecurity firm Rapid7 have identified several vulnerabilities and other potential security issues affecting F5 products.
read more
Mozilla has announced the release of Firefox 107. The latest version of the popular web browser patches a significant number of vulnerabilities.
read more
Israeli early-stage startup Akeyless has banked a whopping $65 million in venture capital funding to build technology to help businesses manage credentials, certificates, keys and other secrets flowing through multi-cloud environments.
read more
The effect of reduced staffing levels doesn’t just attract more cybercriminals, it makes the outcome of attacks more severe
read more
Application security startup ArmorCode today announced that it has raised $14 million in Series A funding, bringing the total raised by the company to $25 million.
The new investment round was led by Ballistic Ventures, with participation from Sierra Ventures, Cervin Ventures, and angel investors.
read more
The US Government Accountability Office (GAO) this week has published a report detailing issues identified in the Department of Defense’s (DoD) cyber incident management processes.
read more
BoostSecurity on Wednesday emerged from stealth mode with a DevSecOps automation platform and $12 million in seed funding.
read more
A new EU law imposing stricter online regulation comes into effect Wednesday and the biggest platforms like Facebook and Google will have until February 17 to reveal their user numbers.
read more
Google this week announced plans to roll out Android Privacy Sandbox in beta starting early next year, delivering a more private advertising experience to mobile users.
read more
A team of researchers from the University of Michigan, University of Pennsylvania and NASA have identified a potentially serious vulnerability in networking technology used in spacecraft, aircraft, and industrial control systems.
read more
An SQL injection vulnerability in Zendesk Explore could have allowed a threat actor to leak Zendesk customer account information, data security firm Varonis reports.
Zendesk Explore is the analytics and reporting service of Zendesk, a popular customer support software-as-a-service solution.
read more
Continuous attack surface management pioneer Bishop Fox continues to attract the attention of investors with the banking of another $46 million in growth funding led by WestCap.
read more
A Chinese state-sponsored cyberespionage group tracked as Billbug has been observed targeting a certificate authority in Asia, along with other entities, Symantec reports.
read more
Threat intelligence firm Cyjax has uncovered a long-standing and sophisticated cybercrime campaign spoofing more than 400 popular brands.
read more
Backstage, an open platform for building developer portals, is affected by a critical vulnerability whose exploitation could have a serious impact on a targeted enterprise, according to cloud-native application security firm Oxeye.
read more
Security orchestration, automation and response (SOAR) provider Swimlane on Monday announced the launch of a security automation solution ecosystem for operational technology (OT) environments.
read more
Understanding the vulnerability landscape of the XIoT to properly assess and mitigate risk is critically important to protect livelihoods and lives
read more
Search giant Google has agreed to a $391.5 million settlement with 40 states to resolve an investigation into how the company tracked users’ locations, state attorneys general announced Monday.
read more
Canadian supermarket and pharmacy chain Sobeys is recovering from a cyberattack that might have involved the Black Basta ransomware.
read more
A vulnerability in Aiphone intercom products allows attackers to breach the entry system and gain access to the building that uses it.
Aiphone is one of the largest global manufacturers of intercom systems, including audio and video entry systems for residential and corporate buildings.
read more
The National Security Agency (NSA) has published guidance on how organizations can implement protections against common software memory safety issues.
read more
The European Union on Thursday unveiled new proposals to help its armies move faster in times of conflict and to boost cyber security, saying that Russia’s war on Ukraine is a wake-up call to bolster Europe’s defenses.
read more
French aerospace, defense, and security giant Thales claims to have found no evidence of its IT systems getting breached after a well-known ransomware group published gigabytes of data allegedly stolen from the company.
read more
Executive order requires that US signals intelligence activities be conducted "only in pursuit of defined national security objectives"
US President Joe Biden signed an executive order on Friday designed to protect the privacy of personal data transfers between the EU and the United States and address European concerns about US intelligence collection activities.
read more
Virtualization giant VMware on Thursday announced patches for a vCenter Server vulnerability that could lead to arbitrary code execution.
A centralized management utility, the vCenter Server is used for controlling virtual machines and ESXi hosts, along with their dependent components.
read more
Cyberinsurance startup Elpha Secure this week announced that it has raised $20 million in a Series A funding round led by Canapi Ventures.
Existing investors AXIS Capital, EOS Venture Partners, Fermat Capital Management, The Hartford STAG Ventures, State Farm Ventures, and Stone Point Ventures participated.
read more
Meta warned a million Facebook users Friday that they have been "exposed" to seemingly innocuous smartphone applications designed to steal passwords to the social network.
read more
Former Uber security chief Joe Sullivan has been found guilty by a jury over his role in covering up a massive data breach suffered by the ride sharing giant in 2016.
read more
Hackers have exploited a cross-chain bridge to divert more than $560 million worth of cryptocurrency from Binance Bridge.
Operating on the Binance Coins (BNB) Smart Chain, Binance Bridge is a blockchain bridge designed to help with the transfer of information and assets between blockchains.
read more
The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the National Security Agency (NSA) have published a list of the top vulnerabilities that Chinese state-sponsored cyberspies have been exploiting in attacks since 2020.
read more
French cybersecurity startup CrowdSec on Thursday announced raising €14 million ($14 million) in Series A funding for its crowdsourced threat intelligence solution.
read more
A police investigation of a cyberattack on an Australian telecommunications company in which the personal data of more than one third of Australia’s population was stolen has resulted in its first arrest, investigators said Thursday.
read more
The BlackByte ransomware has been observed targeting a vulnerability in a legitimate driver to disable endpoint detection and response (EDR) solutions running on the victim machine.
read more
Security researchers with threat hunting firm DCSO CyTec are warning of a new backdoor that has been targeting Microsoft SQL (MSSQL) servers.
read more
Insurance giant Lloyd’s of London is investigating a cybersecurity incident that has forced it to disconnect some systems.
The company says it has detected unusual activity and decided to ‘reset’ its network and systems as a precaution. It shut down all external connectivity, including its delegated authority platforms, in response to the incident.
read more
Cisco announced on Wednesday that it has patched potentially serious vulnerabilities in some of its networking and communications products, including Enterprise NFV, Expressway and TelePresence.
read more
The City of Tucson, Arizona, is notifying roughly 123,000 individuals that their personal information was compromised in a recent data breach.
The incident was identified at the end of May 2022, but the city concluded its investigation only last month.
read more
A major nonprofit health system with 140 hospitals in 21 states, CommonSpirit Health, is reporting an “IT security issue” that has disrupted operations in multiple states.
A company spokesperson would not explain the nature of the apparent cyberattack, such as whether the organization’s IT network was hit by ransomware.
read more
Quantum-secure networking devices maker Qunnect this week announced raising $8 million in a Series A funding round that brings the total investment in the company to $12.4 million.
The new investment round was led by Airbus Ventures, with additional participation from Impact Science Ventures, Motus Ventures, NY Ventures, Quantonation, and SandboxAQ.
read more
A San Francisco jury on Wednesday found former Uber security chief Joe Sullivan guilty of covering up a 2016 data breach and concealing information on a felony from law enforcement.
read more
Private equity giant KKR is expanding its big bet on penetration testing and attack surface management firm NetSPI with a new $410 million investment round.
read more
Law firm Jones Walker has published the results of a survey focusing on the cybersecurity preparedness of ports and terminals in the United States.
read more
SecurityWeek will host its 2022 Industrial Control Systems (ICS) Cybersecurity Conference from October 24 – 27, 2022 at the InterContinental Atlanta Buckhead.
read more
Zimperium is warning of an Iranian hacking group using a new piece of Android spyware in a broad campaign that has also targeted enterprise users.
read more
RealDefense this week announced that it has raised $30 million from Sunflower Bank, which brings the total investment in the company to $50 million.
Founded in 2017, the Pasadena, California-based firm provides organizations with privacy, cybersecurity, and optimization solutions for PC, Mac, and mobile devices.
read more
A former Canadian government employee was sentenced to prison in the United States this week for his role in NetWalker ransomware attacks.
read more
The NSA, FBI and CISA have issued an alert describing the tools and techniques used by advanced persistent threat (APT) actors in an attack aimed at an unnamed defense industrial base organization in the United States.
read more
A former Seattle tech worker convicted of several charges related to a massive hack of Capital One bank and other companies in 2019 was sentenced Tuesday to time served and five years of probation.
read more
The Biden administration unveiled a set of far-reaching goals Tuesday aimed at averting harms caused by the rise of artificial intelligence systems, including guidelines for how to protect people’s personal data and limit surveillance.
read more
The quantum threat to RSA-based encryption is deemed to be so pressing that NIST is seeking a quantum safe alternative
read more
Code security company SonarSource today published details on a severe vulnerability impacting Packagist, which could have been abused to mount supply chain attacks targeting the PHP community.
read more
The Shangri-La hotel group has said a database containing the personal information of customers at eight of its Asian properties between May and July has been hacked.
The breach covered hotels in Hong Kong, Singapore, Chiang Mai, Taipei and Tokyo but the company said it had not yet been able to determine what data had been stolen.
read more
A massive trove of emails from Mexico’s Defense Department is among electronic communications taken by a group of hackers from military and police agencies across several Latin American countries, Mexico’s president confirmed Friday.
read more
Trustwave is warning healthcare organizations of two cross-site scripting (XSS) vulnerabilities in Canon Medical’s popular medical imaging sharing tool Vitrea View.
read more
The US Cybersecurity and Infrastructure Security Agency (CISA) this week published a user guide to help organizations prepare for the November 1, 2022, move from Traffic Light Protocol (TLP) version 1.0 to TLP 2.0.
read more
The US Department of Defense (DoD) and HackerOne this week announced the results of the Hack US one-week bug bounty challenge that ran from July 4 to July 11, 2022.
read more
Microsoft has confirmed that it’s aware of two Exchange Server zero-day vulnerabilities that have been exploited in targeted attacks. The tech giant is working on patches.
read more
Chinese cyberespionage group Witchetty has been observed updating its toolset in recent attacks targeting entities in the Middle East and Africa, Symantec reports.
Also referred to as LookingFrog, Witchetty is believed to be part of Cicada, the Chinese advanced persistent threat (APT) actor also known as APT10 and Stone Panda.
read more
Cisco this week announced IOS and IOS XE software updates that address 12 vulnerabilities, including 10 high-severity security flaws.
read more
A cybersecurity company based in Vietnam has reported seeing attacks exploiting a new Microsoft Exchange zero-day vulnerability, but it may just be a variation of the old ProxyShell exploit.
read more
A cyber specialist who worked at the US National Security Agency and an army doctor and his wife were charged Thursday in separate cases with seeking to sell US secrets to foreign governments.
read more
Threat hunters at Microsoft have intercepted a notorious North Korean government hacking group lacing legitimate open source software with custom malware capable of data theft, espionage, financial gain and network destruction.
read more
The funding frenzy in the software supply chain space now includes Ox Security, an early-stage Israeli startup that just raised a whopping $34 million in seed-stage financing.
read more
Report shows that forty-five percent of companies have had four or more cloud incidents in the last year
read more
Schneider Electric in recent months released patches for its EcoStruxure platform and some Modicon programmable logic controllers (PLCs) to address a critical vulnerability that was disclosed more than a year ago.
read more
Australia could have tough new data protection laws in place this year in an urgent response to a cyberattack that stole from a telecommunications company the personal data of 9.8 million customers, the attorney-general said Thursday.
read more
Updates announced for Drupal this week address a severe vulnerability in Twig that could lead to the leakage of sensitive information.
Drupal is a PHP-based open source web content management system that has been using Twig as its default templating engine since Drupal 8, which was first released in November 2015.
read more
Hackers possibly from China have been using a new technique to install persistent backdoors in VMware ESXi hypervisors, giving them significant capabilities while making detection more difficult.
read more
Okta-owned Auth0 this week announced that it has not identified an intrusion into its environment after a third-party said they were in the possession of older source code repositories.
read more
By integrating with native security services on major cloud platforms, a CNP solution can correlate security findings to pinpoint risks and recommend mitigations
read more
Black Lotus Labs, Lumen Technologies’ threat intelligence team, has issued a warning on Chaos, the new variant of the Kaiji distributed denial-of-service (DDoS) botnet, targeting enterprises and large organizations.
read more
American business magazine Fast Company has confirmed that its Apple News account was hijacked after hackers compromised its content management system (CMS).
The monthly magazine focuses on business, technology, and design. In addition to its online version, the magazine publishes six print issues each year.
read more
A survey of more than 300 ethical hackers conducted by cybersecurity companies Bishop Fox and SANS Institute found that many could execute an end-to-end attack in less than a day.
read more
Cisco this week has confirmed that tens of its enterprise routers and switches are impacted by bypass vulnerabilities in the Layer-2 (L2) network security controls.
read more
Google this week announced the release of Chrome 106 to the stable channel with patches for 20 vulnerabilities, including 16 reported by external researchers.
Of the externally reported security bugs, five are rated ‘high’ severity, eight are ‘medium’ severity, and three are ‘low’ severity.
read more
A sprawling disinformation network originating in Russia sought to use hundreds of fake social media accounts and dozens of sham news websites to spread Kremlin talking points about the invasion of Ukraine, Meta revealed Tuesday.
read more
Cybersecurity sleuths at SentinelLabs are calling on the wider threat hunting community to help decipher a new mysterious malware campaign hitting telcos, ISPs and universities in the Middle East and Africa.
read more
Cybersecurity firm Human has discovered and disrupted a mobile ad fraud campaign involving 89 mobile applications with a total download count of 13 million.
read more
A man employed as a cleaner in Israeli Defence Minister Benny Gantz's home was sentenced to three years' prison for attempting to spy for Iran-linked hackers, the justice ministry said Tuesday.
read more
The developer of the new ‘CodeRAT’ backdoor has released their malware’s source code online after being confronted by security researchers, cybersecurity firm SafeBreach reports.
The new remote access trojan (RAT) was seen being deployed via a malicious Word document carrying a Dynamic Data Exchange (DDE) exploit.
read more
A cyberattack targeting the huge Los Angeles school district prompted an unprecedented shutdown of its computer systems as schools increasingly find themselves vulnerable to attacks at the start of a new year.
read more
Google has released an emergency update to patch a high-severity vulnerability in its Chrome web browser that is already being exploited in the wild.
read more
Taiwanese network-attached storage (NAS) solutions provider QNAP Systems over the weekend issued a fresh warning of new Deadbolt ransomware attacks targeting its NAS users.
read more
Irish regulators are slapping Instagram with a big fine after an investigation found the social media platform mishandled teenagers’ personal information in violation of strict European Union data privacy rules.
read more
Training for multiple situations will help your security team make decisions more quickly
read more
Just before the Labor Day holiday weekend, electronics giant Samsung US announced that the personal information of some customers was compromised in a July data breach.
As part of the incident, which was identified roughly a month ago, an unauthorized third party gained access to some of Samsung’s US systems and exfiltrated information stored on them.
read more
The Anti-Malware Testing Standards Organization (AMTSO) has published guidelines for testers and vendors looking to check the efficiency and functionality of security products designed to protect Internet of Things (IoT) devices.
read more
Beijing on Monday accused the United States of launching "tens of thousands" of cyberattacks on China and pilfering troves of sensitive data, including from a public research university.
read more
Hackers stole personal data including Social Security numbers, addresses and account numbers of home mortgage holders at KeyBank, the bank reports, in the breach of a third-party vendor that serves multiple corporate clients.
read more
Local law enforcement agencies from suburban Southern California to rural North Carolina have been using an obscure cellphone tracking tool, at times without search warrants, that gives them the power to follow people’s movements months back in time, according to public records and internal emails obtained by The Associated Press.
read more
Let’s get back to summer travel.
My original title for this byline was “Hack for the Holidays,” but I decided that my ever-friendly content editor would likely reject the thought – however, the statement does highlight an area we should all consider.
read more
Analysis of Ragnar Locker Ransomware that has been targeting the energy sector
read more
Symantec has discovered hardcoded AWS credentials in more than 1,800 mobile applications and warned of the potential risks associated with poor security practices.
While Symantec’s threat hunting team has looked at both Android and iOS apps, nearly all of the applications containing hardcoded credentials were developed for iOS.
read more
A vulnerability in Google Chrome – and in all Chromium-based browsers – allows webpages to replace the contents of the system clipboard without the user’s consent or interaction.
The issue exists because the browser does not have the necessary safeguards to prevent sites from writing to the clipboard.
read more
The Ragnar Locker ransomware gang says it has exfiltrated customer data in a cyberattack on Portuguese state-owned flag carrier airline TAP Air Portugal.
The incident was initially disclosed on August 26, when TAP announced on Twitter that it managed to foil the cyberattack before the threat actor could access any customer data.
read more
Several government agencies in Latin America were targeted in ransomware attacks in the past months, and the latest victims are Chile and the Dominican Republic.
read more
Apple on Wednesday started shipping patches for older iPhone and iPad devices to address a recent, actively exploited vulnerability.
Tracked as CVE-2022-32893, the vulnerability impacts WebKit and it can be exploited to achieve arbitrary code execution when the user visits a malicious website.
read more
A rapid deployment team of FBI cyber experts is heading to Montenegro to investigate a massive and coordinated attack on the tiny Balkan nation’s government and its services, the country’s Ministry of Internal Affairs announced Wednesday.
read more
ndpoint security company McAfee warns of five malicious Chrome extensions designed to track users’ browsing activity and inject code into ecommerce platforms.
read more
The WordPress team this week announced the release of version 6.0.2 of the content management system (CMS), with patches for three security bugs, including a high-severity SQL injection vulnerability.
read more
Fidelity CISO Adam Ely to headline agenda on cybersecurity leadership and risk management priorities.
read more
Montenegro has been targeted in a disruptive cyberattack blamed on Russian hackers, and a known ransomware group may have been involved.
The country’s Agency for National Security announced last week that government servers had been targeted in an ongoing attack that was described as massive and coordinated.
read more
Google this week announced the first stable release of Chrome 105, which comes with patches for 24 vulnerabilities, including 13 use-after-free and heap buffer overflow bugs.
Twenty-one of the resolved security defects were reported by external researchers, including one critical-, eight high-, nine medium-, and three low-severity vulnerabilities.
read more
A group of academic researchers have designed an open source Node.js bug hunting tool that has already identified 180 security vulnerabilities.
read more
As a cybersecurity professional, I appreciate the impact that cyber policy can have on the adoption of and effective utilization of technology. We see this working today in very advanced, mature industries. In the automotive industry, policies around safety for instance, have done wonders to reduce the number of injuries resulting from an accident. Likewise, policies for manufacturing and chemical production help reduce the risk associated with handling dangerous chemicals.
read more
The data of more than 2.5 million individuals was compromised in a recent data breach at technology services provider Nelnet Servicing.
The impacted individuals have taken student loans from Edfinancial and OSLA, which have contracted Nelnet for various services, including an online portal that student loan borrowers can use to access their accounts.
read more
The Chinese APT known as TA423 (aka Red Ladon, APT40 and Leviathan) has been operating a cyberespionage campaign across Australia, Malaysia and Europe. The campaign has had three distinct phases – the latest from April 2022 to mid-June 2022. The primary targets have been Australian organizations and energy exploration in the South China Sea.
read more
Google today introduced a new bug bounty program to reward security researchers who discover and report vulnerabilities in the company’s open source projects.
As part of the new Open Source Software Vulnerability Rewards Program (OSS VRP), Google is offering bug bounty payouts of up to $31,337. The lowest vulnerability reward will be $100.
read more