-
"Spotify Fined $5 Million for Breaching EU Data Rules"Music streaming giant Spotify, was recently fined 58 million kronor ($5.4 million) for not properly informing users on how data it collected on them was being used, Swedish authorities said. Spotify said it planned to appeal the decision. The…
-
"SAP Patches High-Severity Vulnerabilities With June 2023 Security Updates"SAP on Tuesday announced the release of eight new security notes as part of its June 2023 Security Patch Day, including two notes that address high-severity vulnerabilities. Five other notes were updated. The most important of SAP’s new…
-
"Cyber Win: NSA Selects LSU to Build Cybersecurity Clinic to Support Small Businesses in Louisiana"The National Security Agency (NSA) has selected Louisiana State University (LSU) as the first university in the US to develop and pilot a cyber clinic to help protect small businesses, which are becoming increasingly frequent targets of cyberattacks. The…
-
"Hundreds of Thousands of eCommerce Sites Impacted by Critical Plugin Vulnerability"Security researchers at Patchstack discovered that hundreds of thousands of ecommerce websites could be exposed to attacks due to a critical vulnerability in the WooCommerce Stripe Payment Gateway plugin. Tracked as CVE-2023-34000, the issue is…
-
"US and International Partners Release Comprehensive Cyber Advisory on LockBit Ransomware""Understanding Ransomware Threat Actors: LockBit" is the title of a joint Cybersecurity Advisory (CSA) issued by the US Cybersecurity and Infrastructure Security Agency (CISA), FBI, Multi-State Information Sharing and Analysis Center (MS-ISAC), and the…
-
"DDoS Threats and Defense: How Certain Assumptions Can Lead to an Attack"There is a common misconception that a website with low traffic or that does not offer transaction-intensive online commerce does not need to prepare for Distributed Denial-of-Service (DDoS) attacks because it is not an attractive target. According to…
-
"Chrome 114 Update Patches Critical Vulnerability"Google recently announced a new Chrome 114 update that resolves five vulnerabilities, including four critical and high-severity bugs reported by external researchers. Google noted that the most important of these issues is CVE-2023-3214, a critical…
-
"E-Commerce Firms Are Top Targets for API, Web Apps Attacks"According to a new report by Akamai, hackers launched 14 billion attacks against the e-commerce industry in 15 months, placing it at the top of the list of targets for Application Programming Interface (API) and web application exploits. Researchers…
-
"Hackers Can Steal Cryptographic Keys by Video-Recording Power LEDs 60 Feet Away"Researchers have developed a novel attack that recovers the secret encryption keys in smart cards and smartphones by using iPhone cameras or commercial surveillance systems to video record the power LEDs that glow when the card reader or smartphone is on…
-
"LLM meets Malware: Starting the Era of Autonomous Threat"Researchers at B42 Labs have shared some findings from their exploratory research on the application of Large Language Models (LLMs) to malware automation, examining how a potential new type of autonomous threat may manifest in the near future. The…
-
"New Golang-based Skuld Malware Stealing Discord and Browser Data from Windows PCs"Skuld is a new Golang-based information stealer that has compromised Windows systems in Europe, Southeast Asia, and the US. According to Trellix researcher Ernesto Fernández Provecho, this new strain of malware attempts to steal sensitive information…
-
"Fake Zero-Day PoC Exploits on GitHub Push Windows, Linux Malware"Hackers are posing as cybersecurity researchers on Twitter and GitHub to publish fake proof-of-concept (PoC) exploits for zero-day vulnerabilities that infect Windows and Linux with malware. The alleged researchers advertise these malicious exploits…
News