"POCs for Critical Arcserve UDP Vulnerabilities Released"

"POCs for Critical Arcserve UDP Vulnerabilities Released"

Tenable researchers have released proof-of-concepts (POCs) for now-patched critical security vulnerabilities in Arcserve's Unified Data Protection (UDP) solution. Arcserve UDP is a widely used enterprise data protection, backup, and disaster recovery solution that helps organizations improve resiliency against ransomware attacks. This article continues to discuss the potential exploitation and impact of the vulnerabilities affecting Arcserve UDP.

Submitted by Gregory Rigby on

"Japanese Space Agency JAXA Hacked in Summer Cyberattack"

"Japanese Space Agency JAXA Hacked in Summer Cyberattack"

The Japan Aerospace Exploration Agency (JAXA) was hacked in a cyberattack over the summer, which may have put sensitive space-related technology and data at risk.  The security breach was discovered this Fall when law enforcement authorities alerted Japan's space agency that its systems were compromised.  Chief Cabinet Secretary of Japan Hirokazu Matsuno revealed that attackers gained access to the agency's Active Directory (AD) server, a crucial component overseeing JAXA's network operations.

Submitted by Adam Ekwall on

"New BLUFFS Attack Lets Attackers Hijack Bluetooth Connections"

"New BLUFFS Attack Lets Attackers Hijack Bluetooth Connections"

Researchers at Eurecom have developed six new attacks collectively dubbed BLUFFS that can breach Bluetooth session confidentiality, enabling device impersonation and Man-in-the-Middle (MitM) attacks. BLUFFS exploits two previously unknown vulnerabilities in the Bluetooth standard related to how session keys are derived for decrypting data in exchange. These flaws are architectural rather than hardware or software configuration-specific, affecting Bluetooth at a fundamental level.

Submitted by Gregory Rigby on

"Critical Vulns Found in Ray Open-Source Framework for AI/ML Workloads"

"Critical Vulns Found in Ray Open-Source Framework for AI/ML Workloads"

Researchers from Bishop Fox have reported that organizations using Ray, an open-source framework for scaling Artificial Intelligence (AI) and Machine Learning (ML) workloads, could face attacks due to three unpatched vulnerabilities in the technology. The flaws allow attackers to gain operating system access to all nodes in a Ray cluster, enable Remote Code Execution (RCE), escalate privileges, and more. The Bishop Fox researchers discovered the flaws in August and reported them to Anyscale, which sells a fully managed version of the technology.

Submitted by Gregory Rigby on

"Okta Says Hackers Stole Data For All Customer Support Users in Cyber Breach"

"Okta Says Hackers Stole Data For All Customer Support Users in Cyber Breach"

Okta recently revealed that hackers stole information on all users of its customer support system in a network breach two months ago.  The company notified customers that it had determined hackers had downloaded a report containing data, including names and email addresses of all clients who use its customer support system.  Okta's shares slumped in October after the company said that the breach allowed some hackers to view files uploaded by certain clients.  Okta provides identity services such as single sign-on and multi-factor authentication.  
 

Submitted by Adam Ekwall on

"Google Patches Seventh Chrome Zero-Day of 2023"

"Google Patches Seventh Chrome Zero-Day of 2023"

Google recently announced a security update that addresses a zero-day vulnerability in the Chrome browser.  The high-severity issue tracked as CVE-2023-6345 is described as an integer overflow bug in Skia, the open-source 2D graphics library that serves as the graphics engine in Chrome, Firefox, and other browsers.  Google stated that it is aware that an exploit for CVE-2023-6345 exists in the wild.

Submitted by Adam Ekwall on

"AI Boosts Malware Detection Rates by 70%"

"AI Boosts Malware Detection Rates by 70%"

Threat intelligence-sharing platform VirusTotal has recently unveiled new research showing how cyber defenders can use AI to enhance malware analysis.  VirusTotal found that AI is extremely effective in analyzing malicious code, identifying 70% more malicious scripts than traditional techniques alone.  VirusTotal also observed that AI was up to 300% more accurate than traditional techniques at detecting attempts by malicious scripts to target a device with a common vulnerability or exploit.

Submitted by Adam Ekwall on
Subscribe to