News
-
"Unsecured APIs Could Be Costing Firms $75bn Per Year"Security researchers at Imperva discovered that global businesses could be exposing themselves to billions in annual losses because they aren't properly securing their APIs. Imperva teamed up with the Marsh McLennan Cyber Risk Analytics Center to analyze…
-
"$100 Million Worth of Crypto Has Been Stolen in Another Major Hack"It has recently been discovered that hackers have stolen $100 million in cryptocurrency from Horizon, a so-called blockchain bridge, in the latest major heist in the world of decentralized finance. Details of the attack are still slim, but Harmony…
-
"Avos Ransomware Threat Actor Updates Its Attack Arsenal"A new Cisco Talos Intelligence Group report reveals new tools used in Avos ransomware attacks. Avos is a ransomware group that has been active since July 2021. The group follows the Ransomware-as-a-Service (RaaS) business model, meaning they provide…
-
"Apple, Android Phones Targeted By Italian Spyware: Google"According to Google's threat analysis team, hacking tools developed in Italy were used to spy on Apple and Android smartphones in Italy and Kazakhstan, shedding light on a thriving spyware industry. Spyware developed by RCS Lab targeted the phones using…
-
"CISA: Log4Shell Exploits Still Being Used to Hack VMware Servers"The US Homeland Security Department's Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning pertaining to threat actors, including state-backed hacking groups, using the Log4Shell Remote Code Execution (RCE) vulnerability to hack…
-
"Pair of Brand-New Cybersecurity Bills Become Law"The Biden administration continued its efforts to fortify US cyber defenses by signing two bills into law, both with the goal of facilitating the free flow of cybersecurity expertise and resources between federal agencies and down to municipalities in…
-
"Over 40 Organizations Breached by Conti Ransomware Attacks in a Month"The Conti cybercrime group has become highly organized, running one of the most aggressive ransomware operations. As a result, affiliates were able to breach over 40 firms in a month. Security researchers dubbed the hacking operation ARMattack and…
-
"Cyber Threats Targeting Agriculture Focus of New Cybersecurity Testbed"A cybersecurity professor at the University of Nebraska at Omaha (UNO) is leading research aimed at protecting against hackers and cyber criminals who may target Nebraska's agricultural industry and beyond, from farmers in the fields to large-scale…
-
"Access Management Issues May Create Security Holes"According to a study by the security vendor strongDM that polled 600 IT, security, and DevOps workers, access restrictions meant to secure corporate systems may have the adverse effect of causing employees to find workarounds and share credentials with…
-
"Amazon’s Plan For Alexa to Mimic Anyone’s Voice Raises Fears it Will be Used For Deepfakes And Scams"Amazon is developing new technology for its voice assistant Alexa, which will be able to mimic any human's voice, dead or alive, using less than a minute of recorded audio. At a conference in Las Vegas, Amazon's senior vice president and head…
-
"Researchers Uncover Ways to Break the Encryption of 'MEGA' Cloud Storage Service"Researchers at ETH Zurich found a number of critical security vulnerabilities in the MEGA cloud storage service that could allow malicious actors to break the confidentiality and integrity of user data. The researchers explain how MEGA's system does not…
-
"Google Patches 14 Vulnerabilities With Release of Chrome 103"Google recently released Chrome 103 to the stable channel with patches for 14 vulnerabilities, including nine reported by external researchers. The most severe vulnerability is CVE-2022-2156, which is described as a critical-severity use-after-free…