July 2024

‘Error’ in Microsoft’s DDoS defenses amplified 8-hour Azure outage

‘Error’ in Microsoft’s DDoS defenses amplified 8-hour Azure outage 2024-07-31 at 16:07 By Richard Speed A playbook full of strategies and someone fumbles the implementation Do you have problems configuring Microsoft’s Defender? You might not be alone: Microsoft admitted that whatever it’s using for its defensive implementation exacerbated yesterday’s Azure instability.… This article is an

‘Error’ in Microsoft’s DDoS defenses amplified 8-hour Azure outage Read More »

Trustwave SpiderLabs: SYS01 and Rilide Linked to Same Actor

Trustwave SpiderLabs: SYS01 and Rilide Linked to Same Actor 2024-07-31 at 16:07 By Drawing on extensive proprietary research, Trustwave SpiderLabs believes the threat actors behind the Facebook malvertising infostealer SYS01 are the same group that developed the previously reported Rilide malware. This article is an excerpt from Trustwave Blog View Original Source

Trustwave SpiderLabs: SYS01 and Rilide Linked to Same Actor Read More »

SYS01 Infostealer and Rilide Malware Likely Developed by the Same Threat Actor

SYS01 Infostealer and Rilide Malware Likely Developed by the Same Threat Actor 2024-07-31 at 16:06 By Drawing on extensive proprietary research, Trustwave SpiderLabs believes the threat actors behind the Facebook malvertising infostealer SYS01 are the same group that developed the previously reported Rilide malware. This article is an excerpt from SpiderLabs Blog View Original Source

SYS01 Infostealer and Rilide Malware Likely Developed by the Same Threat Actor Read More »

City of Columbus Says Data Compromised in Ransomware Attack

City of Columbus Says Data Compromised in Ransomware Attack 2024-07-31 at 16:06 By Ionut Arghire The City of Columbus is investigating the scope of a data breach resulting from a thwarted ransomware attack. The post City of Columbus Says Data Compromised in Ransomware Attack appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

City of Columbus Says Data Compromised in Ransomware Attack Read More »

Chrome 127 Improves Cookie Protection on Windows

Chrome 127 Improves Cookie Protection on Windows 2024-07-31 at 16:06 By Ionut Arghire Google has improved the security of cookies in Chrome on Windows and rolled out a Chrome 127 update to address critical- and high-severity vulnerabilities. The post Chrome 127 Improves Cookie Protection on Windows appeared first on SecurityWeek. This article is an excerpt

Chrome 127 Improves Cookie Protection on Windows Read More »

Microsoft Says Azure Outage Caused by DDoS Attack Response

Microsoft Says Azure Outage Caused by DDoS Attack Response 2024-07-31 at 16:06 By Eduard Kovacs Microsoft’s response to a DDoS attack on Azure amplified the impact of the attack instead of mitigating it, causing outages. The post Microsoft Says Azure Outage Caused by DDoS Attack Response appeared first on SecurityWeek. This article is an excerpt

Microsoft Says Azure Outage Caused by DDoS Attack Response Read More »

The path to reducing software vulnerabilities leads to AI

The path to reducing software vulnerabilities leads to AI 2024-07-31 at 15:16 By Tool proliferation has created a data volume challenge, making it harder to secure the software development and deployment lifecycle. Fortunately, AI now offers a solution. This article is an excerpt from Subscribe to Security Magazine’s RSS Feed View Original Source

The path to reducing software vulnerabilities leads to AI Read More »

Chinese Hackers Target Japanese Firms with LODEINFO and NOOPDOOR Malware

Chinese Hackers Target Japanese Firms with LODEINFO and NOOPDOOR Malware 2024-07-31 at 14:31 By Japanese organizations are the target of a Chinese nation-state threat actor that leverages malware families like LODEINFO and NOOPDOOR to harvest sensitive information from compromised hosts while stealthily remaining under the radar in some cases for a time period ranging from

Chinese Hackers Target Japanese Firms with LODEINFO and NOOPDOOR Malware Read More »

How To Get the Most From Your Security Team’s Email Alert Budget

How To Get the Most From Your Security Team’s Email Alert Budget 2024-07-31 at 14:31 By We’ll TL;DR the FUDdy introduction: we all know that phishing attacks are on the rise in scale and complexity, that AI is enabling more sophisticated attacks that evade traditional defenses, and the never-ending cybersecurity talent gap means we’re all

How To Get the Most From Your Security Team’s Email Alert Budget Read More »

Clutch Security launches to transform management of NHIs

Clutch Security launches to transform management of NHIs 2024-07-31 at 14:01 By Industry News Clutch Security emerged from stealth and unveiled its Universal Non-Human Identity (NHI) Security Platform. The company also announced a $8.5 million funding round led by Lightspeed Venture Partners, with participation from Merlin Ventures, and notable angel investors. Clutch’s mission is to

Clutch Security launches to transform management of NHIs Read More »

Microsoft: DDoS defense error amplified attack on Azure, leading to outage

Microsoft: DDoS defense error amplified attack on Azure, leading to outage 2024-07-31 at 13:46 By Zeljka Zorz A DDoS attack that started on Tuesday has made a number of Microsoft Azure and Microsoft 365 services temporarily inaccessible, the company has confirmed. Microsoft’s mitigation statement on the Azure status history page Microsoft Azure, 365 outage triggered

Microsoft: DDoS defense error amplified attack on Azure, leading to outage Read More »

DigiCert Revoking Many Certificates Due to Verification Issue

DigiCert Revoking Many Certificates Due to Verification Issue 2024-07-31 at 13:46 By Eduard Kovacs DigiCert is immediately revoking many certificates due to a domain validation issue, which could cause disruption to sites, apps and services. The post DigiCert Revoking Many Certificates Due to Verification Issue appeared first on SecurityWeek. This article is an excerpt from

DigiCert Revoking Many Certificates Due to Verification Issue Read More »

Senate Passes Bill to Protect Kids Online and Make Tech Companies Accountable for Harmful Content

Senate Passes Bill to Protect Kids Online and Make Tech Companies Accountable for Harmful Content 2024-07-31 at 13:46 By Associated Press The US Senate has passed a bill to protect kids online and make tech companies accountable for harmful content. The post Senate Passes Bill to Protect Kids Online and Make Tech Companies Accountable for

Senate Passes Bill to Protect Kids Online and Make Tech Companies Accountable for Harmful Content Read More »

Company Paid Record-Breaking $75 Million to Ransomware Group: Report

Company Paid Record-Breaking $75 Million to Ransomware Group: Report 2024-07-31 at 13:46 By Eduard Kovacs Zscaler is aware of a company that paid a record-breaking $75 million ransom to the Dark Angels ransomware group. The post Company Paid Record-Breaking $75 Million to Ransomware Group: Report appeared first on SecurityWeek. This article is an excerpt from

Company Paid Record-Breaking $75 Million to Ransomware Group: Report Read More »

OpenTofu hits version 1.8 with more crowd-pleasing features

OpenTofu hits version 1.8 with more crowd-pleasing features 2024-07-31 at 13:32 By Richard Speed Open source TerraForm rival introduces a new file extension so users can ‘keep older code around for compatibility’ Terraform alternative OpenTofu has reached version 1.8 amid further signs of fragmentation.… This article is an excerpt from The Register View Original Source

OpenTofu hits version 1.8 with more crowd-pleasing features Read More »

Cybercriminals Deploy 100K+ Malware Android Apps to Steal OTP Codes

Cybercriminals Deploy 100K+ Malware Android Apps to Steal OTP Codes 2024-07-31 at 13:16 By A new malicious campaign has been observed making use of malicious Android apps to steal users’ SMS messages since at least February 2022 as part of a large-scale campaign. The malicious apps, spanning over 107,000 unique samples, are designed to intercept

Cybercriminals Deploy 100K+ Malware Android Apps to Steal OTP Codes Read More »

Cyber Espionage Group XDSpy Targets Companies in Russia and Moldova

Cyber Espionage Group XDSpy Targets Companies in Russia and Moldova 2024-07-31 at 13:16 By Companies in Russia and Moldova have been the target of a phishing campaign orchestrated by a little-known cyber espionage group known as XDSpy. The findings come from cybersecurity firm F.A.C.C.T., which said the infection chains lead to the deployment of a

Cyber Espionage Group XDSpy Targets Companies in Russia and Moldova Read More »

Fortanix expands Key Insight to enhance cryptographic security across hybrid environments

Fortanix expands Key Insight to enhance cryptographic security across hybrid environments 2024-07-31 at 13:01 By Industry News Fortanix announced a major expansion to the Key Insight solution, allowing organizations to discover, assess, and remediate their fragmented cryptographic security risks proactively. Key Insight can now scan on-premises services such as databases, storage, etc., making it the

Fortanix expands Key Insight to enhance cryptographic security across hybrid environments Read More »

Scroll to Top