2024

GitHub Paid Out Over $4 Million via Bug Bounty Program

GitHub Paid Out Over $4 Million via Bug Bounty Program 2024-06-12 at 15:16 By Eduard Kovacs The code hosting platform GitHub has paid out more than $4 million since the launch of its bug bounty program 10 years ago. The post GitHub Paid Out Over $4 Million via Bug Bounty Program appeared first on SecurityWeek. […]

GitHub Paid Out Over $4 Million via Bug Bounty Program Read More »

Lessons from the Ticketmaster-Snowflake Breach

Lessons from the Ticketmaster-Snowflake Breach 2024-06-12 at 14:46 By Last week, the notorious hacker gang, ShinyHunters, sent shockwaves across the globe by allegedly plundering 1.3 terabytes of data from 560 million Ticketmaster users. This colossal breach, with a price tag of $500,000, could expose the personal information of a massive swath of the live event

Lessons from the Ticketmaster-Snowflake Breach Read More »

Black Basta Ransomware May Have Exploited MS Windows Zero-Day Flaw

Black Basta Ransomware May Have Exploited MS Windows Zero-Day Flaw 2024-06-12 at 14:46 By Threat actors linked to the Black Basta ransomware may have exploited a recently disclosed privilege escalation flaw in the Microsoft Windows Error Reporting Service as zero-day, according to new findings from Symantec. The security flaw in question is CVE-2024-26169 (CVSS score:

Black Basta Ransomware May Have Exploited MS Windows Zero-Day Flaw Read More »

AMD’s DC chief happy to work with Intel and others to chip away at Nvidia’s AI empire

AMD’s DC chief happy to work with Intel and others to chip away at Nvidia’s AI empire 2024-06-12 at 14:31 By Tobias Mann ‘If everybody’s got their own little ecosystem, it’s very inefficient’ AMD and Intel have been rivals for decades, but there’s at least one thing they can agree on: they have a common

AMD’s DC chief happy to work with Intel and others to chip away at Nvidia’s AI empire Read More »

20,000 FortiGate appliances compromised by Chinese hackers

20,000 FortiGate appliances compromised by Chinese hackers 2024-06-12 at 14:16 By Zeljka Zorz Coathanger – a piece of malware specifically built to persist on Fortinet’s FortiGate appliances – may still be lurking on too many devices deployed worldwide. How Coathanger persists on FortiGate devices In February 2024, the Dutch Military Intelligence and Security Service (MIVD)

20,000 FortiGate appliances compromised by Chinese hackers Read More »

Chrome 126, Firefox 127 Patch High-Severity Vulnerabilities

Chrome 126, Firefox 127 Patch High-Severity Vulnerabilities 2024-06-12 at 13:31 By Ionut Arghire Google and Mozilla have released patches for 21 and 15 vulnerabilities in Chrome and Firefox, respectively. The post Chrome 126, Firefox 127 Patch High-Severity Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Chrome 126, Firefox 127 Patch High-Severity Vulnerabilities Read More »

Ransomware Attackers May Have Used Privilege Escalation Vulnerability as Zero-day

Ransomware Attackers May Have Used Privilege Escalation Vulnerability as Zero-day 2024-06-12 at 13:16 By Threat Hunter Team Some evidence to suggest that attackers linked to Black Basta compiled CVE-2024-26169 exploit prior to patching. This article is an excerpt from Broadcom Software Blogs View Original Source

Ransomware Attackers May Have Used Privilege Escalation Vulnerability as Zero-day Read More »

Ransomware Attackers May Have Used Privilege Escalation Vulnerability as Zero-day

Ransomware Attackers May Have Used Privilege Escalation Vulnerability as Zero-day 2024-06-12 at 13:16 By Threat Hunter Team Some evidence to suggest that attackers linked to Black Basta compiled CVE-2024-26169 exploit prior to patching. This article is an excerpt from Broadcom Software Blogs View Original Source

Ransomware Attackers May Have Used Privilege Escalation Vulnerability as Zero-day Read More »

Ransomware Attackers May Have Used Privilege Escalation Vulnerability as Zero-day

Ransomware Attackers May Have Used Privilege Escalation Vulnerability as Zero-day 2024-06-12 at 13:16 By Threat Hunter Team Some evidence to suggest that attackers linked to Black Basta compiled CVE-2024-26169 exploit prior to patching. This article is an excerpt from Broadcom Software Blogs View Original Source

Ransomware Attackers May Have Used Privilege Escalation Vulnerability as Zero-day Read More »

Major cybersecurity upgrades announced to safeguard American healthcare

Major cybersecurity upgrades announced to safeguard American healthcare 2024-06-12 at 13:01 By Help Net Security Recent cyberattacks targeting the nation’s healthcare system have demonstrated the vulnerability of hospitals and payment systems. Providers across the health system had to scramble for funding after one attack on a key payment system. And some hospitals had to redirect

Major cybersecurity upgrades announced to safeguard American healthcare Read More »

Microsoft launches cybersecurity program to tackle attacks, protect rural hospitals

Microsoft launches cybersecurity program to tackle attacks, protect rural hospitals 2024-06-12 at 13:01 By Help Net Security Microsoft has unveiled a new cybersecurity program to support hospitals serving more than 60 million people living in rural America. In 2023, the healthcare sector reported more ransomware attacks than any other critical infrastructure sector and attacks involving

Microsoft launches cybersecurity program to tackle attacks, protect rural hospitals Read More »

Ransomware Group Exploits PHP Vulnerability Days After Disclosure

Ransomware Group Exploits PHP Vulnerability Days After Disclosure 2024-06-12 at 12:16 By Ionut Arghire The TellYouThePass ransomware gang started exploiting a recent code execution flaw in PHP days after public disclosure. The post Ransomware Group Exploits PHP Vulnerability Days After Disclosure appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View

Ransomware Group Exploits PHP Vulnerability Days After Disclosure Read More »

ICS Patch Tuesday: Advisories Published by Siemens, Schneider Electric, Aveva, CISA

ICS Patch Tuesday: Advisories Published by Siemens, Schneider Electric, Aveva, CISA 2024-06-12 at 12:16 By Eduard Kovacs Several ICS vendors released advisories on Tuesday to inform customers about vulnerabilities found in their industrial and OT products.  The post ICS Patch Tuesday: Advisories Published by Siemens, Schneider Electric, Aveva, CISA appeared first on SecurityWeek. This article

ICS Patch Tuesday: Advisories Published by Siemens, Schneider Electric, Aveva, CISA Read More »

New Phishing Campaign Deploys WARMCOOKIE Backdoor Targeting Job Seekers

New Phishing Campaign Deploys WARMCOOKIE Backdoor Targeting Job Seekers 2024-06-12 at 12:16 By Cybersecurity researchers have disclosed details of an ongoing phishing campaign that leverages recruiting- and job-themed lures to deliver a Windows-based backdoor named WARMCOOKIE. “WARMCOOKIE appears to be an initial backdoor tool used to scout out victim networks and deploy additional payloads,” Elastic

New Phishing Campaign Deploys WARMCOOKIE Backdoor Targeting Job Seekers Read More »

China-Backed Hackers Exploit Fortinet Flaw, Infecting 20,000 Systems Globally

China-Backed Hackers Exploit Fortinet Flaw, Infecting 20,000 Systems Globally 2024-06-12 at 12:16 By State-sponsored threat actors backed by China gained access to 20,000 Fortinet FortiGate systems worldwide by exploiting a known critical security flaw between 2022 and 2023, indicating that the operation had a broader impact than previously known. “The state actor behind this campaign

China-Backed Hackers Exploit Fortinet Flaw, Infecting 20,000 Systems Globally Read More »

AuthenticID introduces deep fake and generative AI detection solution

AuthenticID introduces deep fake and generative AI detection solution 2024-06-12 at 12:01 By Industry News AuthenticID released a new solution to detect deep fake and generative AI injection attacks. This new enhancement to their identity verification technology, developed by AuthenticID’s Product and Applied Research team, uses proprietary algorithms to prevent the majority of digital injection

AuthenticID introduces deep fake and generative AI detection solution Read More »

Kyndryl and Apollo Global linked to bid for DXC Technology

Kyndryl and Apollo Global linked to bid for DXC Technology 2024-06-12 at 11:46 By Paul Kunert Creating economies of scale by merging ever-shrinking infrastructure services businesses DXC Technology, the beleaguered tech services provider that emerged from the alliance between HPE Enterprise Services and CSC then lost billions in revenue, is again reportedly the subject of

Kyndryl and Apollo Global linked to bid for DXC Technology Read More »

Lacework’s visibility enhancements give businesses real time insight into resource inventory

Lacework’s visibility enhancements give businesses real time insight into resource inventory 2024-06-12 at 11:46 By Industry News Lacework announced a range of visibility updates to its platform headlined by Continuous Threat Exposure Management (CTEM). These advancements provide customers with continuous visibility, real-time threat detection, and streamlined vulnerability management for cloud-native applications. Continuous Threat Exposure Management

Lacework’s visibility enhancements give businesses real time insight into resource inventory Read More »

Scroll to Top