News
-
"Security Flaws in Court Record Systems Used in Five US States Exposed Sensitive Legal Documents"The sensitive legal court filings discovered by security researcher Jason Parker to be exposed to the open Internet for anyone to access, include witness lists, mental health evaluations, detailed allegations of abuse, corporate trade secrets, and more
-
"Boosting Faith in the Authenticity of Open Source Software"A team of researchers developed a new system called Speranza to reassure software consumers that the product they are receiving has not been tampered with and is coming directly from a trusted source.
-
"XDSpy Hackers Attack Military-Industrial Companies in Russia"New research reveals that a cyber espionage group called XDSpy recently targeted Russian military-industrial organizations.
-
"Critical Zoom Room Bug Allowed to Gain Access to Zoom Tenants"AppOms researchers discovered a vulnerability in Zoom Room while participating in the HackerOne live hacking event H1-4420.
-
"Cyber Risk to the UK's Water Network, NCSC Warns"The UK's National Cyber Security Centre (NCSC) has warned about the active exploitation of Unitronics Programmable Logic Controllers (PLCs) widely used in the water sector.
-
"US And Allies Sanction Kimsuky Actors"The US government, together with foreign partners, sanctioned alleged members of Kimsuky, the North Korean state-sponsored hacking group suspected of conducting numerous campaigns against entities in the US, South Korea, Russia, Japan, and many Europea
-
"Qakbot Takedown Aftermath: Mitigations and Protecting Against Future Threats"The FBI and the US Department of Justice (DOJ) recently collaborated to take down the Qakbot malware and botnet in a multinational operation. Although the operation successfully disrupted this threat, Qakbot may still pose a threat in a reduced form.
-
"Apple Patches Actively Exploited iOS Zero-Days"Apple has been forced to patch yet another pair of zero-day vulnerabilities, bringing the total for the year to 20. The tech giant stated that the two bugs in its WebKit browser engine were being actively exploited in the wild.
-
"LogoFAIL Attack Can Install UEFI Bootkits Through Bootup Logos"A collection of security vulnerabilities named LogoFAIL affects image-parsing components in the Unified Extensible Firmware Interface (UEFI) code from different vendors.
-
"Organizations Can't Ignore the Surge in Malicious Web Links"According to Hornetsecurity, even though there has been an increase in the adoption of collaboration and instant messaging software, email remains a significant concern regarding cyberattacks.
-
"New Turtle macOS Ransomware Analyzed"Patrick Wardle, a cybersecurity researcher specializing in Apple products, has analyzed a new macOS ransomware named Turtle.
-
"Simple Hacking Technique Can Extract ChatGPT Training Data"According to a team of researchers from Google DeepMind, Cornell University, and four other universities who tested ChatGPT's vulnerability to leaking data when prompted in a certain way, getting it to repeat the same word can cause it to regurgitate l