News
-
"Energy Department Offering $9M in Cybersecurity Competition for Small Electric Utilities"The US Department of Energy recently announced a competition that can help smaller electric utilities obtain funding and technical assistance for improving their cybersecurity posture. The competition, named the Advanced Cybersecurity Technology (…
-
"500k Impacted by Data Breach at Fashion Retailer Forever 21"Fashion retailer Forever 21 has recently started informing more than 500,000 individuals that their personal information was compromised in a data breach earlier this year. The fashion retailer revealed that, on March 20, 2023, it identified a…
-
"Splunk Patches High-Severity Flaws in Enterprise, IT Service Intelligence"Splunk recently announced patches for multiple high-severity vulnerabilities in Splunk Enterprise and IT Service Intelligence, including flaws in third-party packages. The most severe of the bugs resolved in Splunk Enterprise this month is CVE-2023…
-
"Innovative Approach: Detecting Malware Through Hardware-integrated Protection"Dr. Marcus Botacin, a visiting assistant professor in the computer science and engineering department at Texas A&M University, was recently awarded a grant by the National Science Foundation (NSF) for efforts aimed at moving malware detection from…
-
"Tech Companies Mull Strategies to Block Threat Groups From Abusing Platforms"As threat groups increasingly use cloud storage, email, and messaging platforms in cyberattacks, technology providers seek new ways to bolster their defense strategies. Threat groups have used legitimate services for command-and-control (C2)…
-
"Checkmarx Warns of Unknown Threat Actor Targeting Developers Through NPM Packages"Researchers at Checkmarx have uncovered a previously unknown threat actor using NPM packages to steal source code and secrets from developers. The threat actor, suspected to have been active since 2021, has published malicious NPM packages designed to…
-
"Credentials of NASA, Tesla, DOJ, Verizon, and 2K Others Leaked by Workplace Safety Organization"The National Safety Council (NSC) is a US nonprofit organization that provides workplace and driving safety training. On its digital platform, NSC offers online resources to its nearly 55,000 members, representing various businesses, agencies, and…
-
"Earth Estries Cyberespionage Group Targets Government, Tech Sectors"A cyberespionage group possibly linked to China has recently targeted government-related organizations and technology companies in various parts of the world. Security researchers at Trend Micro, which tracks it as Earth Estries, say the group has…
-
"UK Cyber Agency Warns of Potentially Fundamental Flaw in AI Technology"Britain's National Cyber Security Centre (NCSC) has issued a warning about a fundamental security vulnerability impacting Large Language Models (LLMs), the type of Artificial Intelligence (AI) used by ChatGPT to perform human-like conversations. Since…
-
"China-Linked BadBazaar Android Spyware Targeting Signal and Telegram Users"Researchers have found malicious Android apps for Signal and Telegram being distributed through the Google Play Store and Samsung Galaxy Store. They are designed to deliver the BadBazaar spyware on infected devices. ESET researchers attributed the…
-
"DreamBus Malware Exploits RocketMQ Flaw to Infect Servers"A new version of the DreamBus botnet malware infects devices by exploiting a critical Remote Code Execution (RCE) flaw in RocketMQ servers. The exploited vulnerability, tracked as CVE-2023-33246, is a permission verification flaw that affects RocketMQ…
-
"Rising Cyber Incidents Challenge Healthcare Organizations"According to Claroty, healthcare organizations face multiple cybersecurity challenges, calling for them to increasingly prioritize cybersecurity and compliance. In addition to focusing on Information Technology (IT) systems, threat actors have shifted…