News
-
"Exclusive: CISA Sounds the Alarm on UEFI Security"The Cybersecurity and Infrastructure Security Agency (CISA) is calling for improved security for Unified Extensible Firmware Interface (UEFI) update mechanisms in the wake of the debacle that has been mitigating the BlackLotus bootkit. CISA urges the…
-
"Researcher Explores Effect of Hospital Mergers on Data Breaches"According to research conducted by a University of Texas at Dallas doctoral student, patient data is especially vulnerable during and after hospital mergers and acquisitions, when the likelihood of a cybersecurity breach more than doubles. Nan Clement, a…
-
"Researchers Strengthen Defenses Against Common Cyberattack"Scientists have developed a method that improves the detection of a common Internet attack by 90 percent compared to current methods. The new technique developed by computer scientists at the Pacific Northwest National Laboratory (PNNL) of the US…
-
"Satellites Easier to Hack Than a Windows Device"According to a new paper by a team of researchers from Ruhr University Bochum and the CISPA Helmholtz Center for Information Security in Saarbrücken, satellites are vulnerable to cyberattacks and do not even use basic cryptography. The research team…
-
"Microsoft Teams Targeted in Midnight Blizzard Phishing Attacks"Microsoft Threat Intelligence has recently announced that it detected a series of highly targeted social engineering attacks employing credential theft phishing lures delivered as Microsoft Teams chats. Microsoft stated that these attacks have been…
-
"Google Awards Over $60,000 for V8 Vulnerabilities Patched With Chrome 115 Update"Google recently announced a Chrome 115 update that patches 17 vulnerabilities, including 11 flaws reported by external researchers. Google noted that the browser update resolves three high-severity type confusion bugs in the V8 JavaScript and…
-
"U.S. and International Cybersecurity Partners Warn Organizations of Routinely Exploited Vulnerabilities"The Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), the Federal Bureau of Investigation (FBI), and international cybersecurity partners have published an advisory on the Common Vulnerabilities and Exposures (…
-
"Python Versions of Stealer Malware Discovered Targeting Facebook Business Accounts"Researchers have discovered a previously unknown phishing campaign that targets Facebook business accounts and distributes two variants of a Python-written infostealer. Palo Alto Networks Unit 42 reported finding Python variants of the NodeStealer…
-
"Salesforce Email Service Zero-Day Exploited in Phishing Campaign"According to security researchers at Guardio, threat actors have exploited a Salesforce zero-day vulnerability and abused Meta features in a sophisticated phishing campaign. Attackers sent out legitimate-looking emails designed to lure targeted…
-
"OWASP Top 10 for LLM (Large Language Model) Applications"The Open Worldwide Application Security Project (OWASP) has released the "OWASP Top 10 for Large Language Model (LLM) Applications" list, which highlights the most critical vulnerabilities impacting LLM applications. The project aims to educate…
-
"Humans Unable to Reliably Detect Deepfake Speech"Researchers from the University College London (UCL) have discovered that humans cannot detect deepfake speech 27% of the time. During the study, the researchers presented 529 individuals with genuine and deepfake audio samples and asked them to…
-
"NSA Releases Guide to Harden Cisco Next Generation Firewalls"The National Security Agency (NSA) has issued a new Cybersecurity Technical Report (CTR) titled "Cisco Firepower Hardening Guide" to help network and system administrators configure these next generation firewalls (NGFWs). The CTR covers properly…