News
-
"University Admission Platform Exposed Student Passports"The popular university admissions platform called Leverage EDU leaked nearly 240,000 sensitive files, including passports, financial documents, certificates, and exam results. The Cybernews research team discovered that Leverage EDU's misconfiguration of…
-
"Chrome 113 Security Update Patches Critical Vulnerability"Google recently announced the release of a Chrome 113 security update that resolves a total of 12 vulnerabilities, including one rated "critical." Six of the flaws were reported by external researchers. The "critical" vulnerability, tracked…
-
"Want to Keep AI From Sharing Secrets? Train It Yourself"Artificial Intelligence (AI) is subject to the same privacy regulations as other technologies. In March 2023, there was a security incident in which ChatGPT users were able to view the chat histories of other users, prompting Italy to temporarily ban…
-
"Apple Blocked 1.7 Million Applications From App Store in 2022"Apple recently announced that it blocked 1.7 million applications from being published in the App Store in 2022. The rejected apps did not meet the required privacy, security, and content standards. The App Store has more than 650 million…
-
"Threat Group UNC3944 Abusing Azure Serial Console for Total VM Takeover"Mandiant has observed a financially-motivated cyber actor abusing Microsoft Azure Serial Console on Virtual Machines (VMs) in order to install third-party remote management tools in compromised environments. The activity was attributed to a threat group…
-
"FBI Warns Organizations of the New BianLian Ransomware Tactics"A joint Cybersecurity Advisory (CSA) issued by US and Australia government agencies and published by the US Homeland Security Department's Cybersecurity and Infrastructure Security Agency (CISA) warns organizations of the most recent tactics, techniques…
-
"TP-Link Routers Implanted With Malicious Firmware in State-Sponsored Attacks"According to Check Point researchers, a Chinese state-sponsored Advanced Persistent Threat (APT) group implanted malicious firmware into TP-Link routers as part of attack campaigns targeting European foreign affairs entities. The malicious firmware was…
-
"Unpatched Wemo Smart Plug Bug Opens Countless Networks to Cyberattacks"The Wemo Mini Smart Plug V2, which enables users to remotely control anything connected to it via a mobile app, contains a security flaw that cyberattackers can exploit to trigger a variety of undesirable outcomes. These include the ability to turn…
-
"Herman's Study Furthering Cybersecurity Curriculum Assessment Earns Best Paper Award"Geoffrey Herman is a Professor in the Department of Computer Science at the University of Illinois at Urbana-Champaign, whose most recent work came through a multi-institutional research project that resulted in a Best Paper Award from the 2023 Technical…
-
"Illinois Tech's CARNATIONS Receives $10M Federal Grant as New Tier 1 Transportation Center to Bolster Cybersecurity in Navigation Systems"The US Department of Transportation has designated the Center for Assured and Resilient Navigation in Advanced Transportation Systems (CARNATIONS) at the Illinois Institute of Technology (Illinois Tech) as a Tier 1 University Transportation Center (UTC…
-
"Infiltration of Qilin Reveals Customizable Nature of RaaS Marketplace"The Russia-aligned Ransomware-as-a-Service (RaaS) group Qilin offers its affiliates sophisticated, user-friendly tools to trap their victims, as well as a significant portion of the proceeds they steal. Qilin, also known as Agenda ransomware, was first…
-
"Is the New .zip Top-Level Domain a Cyber Security Risk?"According to security experts, the new '.zip' top-level domain (TLD) could drive an increase in the spread of malware and undermine legitimate sources. TLDs are the letters that follow the final period in a URL, such as '.com.' At the beginning of May,…