Featured

Exploitation of Ivanti Sentry Zero-Day Confirmed

Exploitation of Ivanti Sentry Zero-Day Confirmed 23/08/2023 at 12:17 By Eduard Kovacs While initially it was unclear if the Ivanti Sentry vulnerability CVE-2023-38035 has been exploited, the vendor and CISA have now confirmed it. The post Exploitation of Ivanti Sentry Zero-Day Confirmed appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed […]

Exploitation of Ivanti Sentry Zero-Day Confirmed Read More »

CISA Warns of Another Exploited Adobe ColdFusion Vulnerability

CISA Warns of Another Exploited Adobe ColdFusion Vulnerability 22/08/2023 at 13:47 By Eduard Kovacs CISA warns that CVE-2023-26359, an Adobe ColdFusion vulnerability patched in March, has been exploited in the wild. The post CISA Warns of Another Exploited Adobe ColdFusion Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View

CISA Warns of Another Exploited Adobe ColdFusion Vulnerability Read More »

Exploitation of Citrix ShareFile Vulnerability Spikes as CISA Issues Warning 

Exploitation of Citrix ShareFile Vulnerability Spikes as CISA Issues Warning  17/08/2023 at 12:18 By Eduard Kovacs Exploitation of a Citrix ShareFile vulnerability tracked as CVE-2023-24489 has spiked as CISA added it to its ‘must patch’ catalog. The post Exploitation of Citrix ShareFile Vulnerability Spikes as CISA Issues Warning  appeared first on SecurityWeek. This article is

Exploitation of Citrix ShareFile Vulnerability Spikes as CISA Issues Warning  Read More »

CISO Conversations: CISOs in Cloud-based Services Discuss the Process of Leadership

CISO Conversations: CISOs in Cloud-based Services Discuss the Process of Leadership 15/08/2023 at 16:31 By Kevin Townsend SecurityWeek talks to Billy Spears, CISO at Teradata (a multi-cloud analytics provider), and Lea Kissner, CISO at cloud security firm Lacework. The post CISO Conversations: CISOs in Cloud-based Services Discuss the Process of Leadership appeared first on SecurityWeek.

CISO Conversations: CISOs in Cloud-based Services Discuss the Process of Leadership Read More »

Iagona ScrutisWeb Vulnerabilities Could Expose ATMs to Remote Hacking

Iagona ScrutisWeb Vulnerabilities Could Expose ATMs to Remote Hacking 14/08/2023 at 13:46 By Eduard Kovacs Several vulnerabilities discovered in Iagona ScrutisWeb ATM fleet monitoring software could be exploited to remotely hack ATMs. The post Iagona ScrutisWeb Vulnerabilities Could Expose ATMs to Remote Hacking appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS

Iagona ScrutisWeb Vulnerabilities Could Expose ATMs to Remote Hacking Read More »

CISA Warns Organizations of Exploited Vulnerability Affecting .NET, Visual Studio 

CISA Warns Organizations of Exploited Vulnerability Affecting .NET, Visual Studio  10/08/2023 at 12:33 By Eduard Kovacs CISA has added CVE-2023-38180, a zero-day vulnerability affecting .NET and Visual Studio, to its Known Exploited Vulnerabilities Catalog. The post CISA Warns Organizations of Exploited Vulnerability Affecting .NET, Visual Studio  appeared first on SecurityWeek. This article is an excerpt

CISA Warns Organizations of Exploited Vulnerability Affecting .NET, Visual Studio  Read More »

Downfall: New Intel CPU Attack Exposing Sensitive Information

Downfall: New Intel CPU Attack Exposing Sensitive Information 09/08/2023 at 09:32 By Eduard Kovacs Google researcher discloses the details of an Intel CPU attack method named Downfall that may be remotely exploitable. The post Downfall: New Intel CPU Attack Exposing Sensitive Information appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed

Downfall: New Intel CPU Attack Exposing Sensitive Information Read More »

North Korean Hackers Targeted Russian Missile Developer

North Korean Hackers Targeted Russian Missile Developer 07/08/2023 at 20:01 By Eduard Kovacs A sanctioned Russian missile maker appears to have been targeted by two important North Korean hacking groups. The post North Korean Hackers Targeted Russian Missile Developer appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

North Korean Hackers Targeted Russian Missile Developer Read More »

Five Eyes Agencies Call Attention to Most Frequently Exploited Vulnerabilities

Five Eyes Agencies Call Attention to Most Frequently Exploited Vulnerabilities 04/08/2023 at 12:31 By Ionut Arghire Five Eyes government agencies have published a list of the software vulnerabilities that were most frequently exploited in malicious attacks in 2022. The post Five Eyes Agencies Call Attention to Most Frequently Exploited Vulnerabilities appeared first on SecurityWeek. This

Five Eyes Agencies Call Attention to Most Frequently Exploited Vulnerabilities Read More »

Salesforce Email Service Zero-Day Exploited in Phishing Campaign

Salesforce Email Service Zero-Day Exploited in Phishing Campaign 03/08/2023 at 12:47 By Eduard Kovacs Threat actors have exploited a Salesforce email service zero-day vulnerability and abused Meta features in a sophisticated phishing campaign. The post Salesforce Email Service Zero-Day Exploited in Phishing Campaign appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS

Salesforce Email Service Zero-Day Exploited in Phishing Campaign Read More »

Microsoft Catches Russian Government Hackers Phishing with Teams Chat App

Microsoft Catches Russian Government Hackers Phishing with Teams Chat App 03/08/2023 at 01:01 By Ryan Naraine Microsoft says a Russian government-linked hacking group is using its Microsoft Teams chat app to phish for credentials at targeted organizations. The post Microsoft Catches Russian Government Hackers Phishing with Teams Chat App appeared first on SecurityWeek. This article

Microsoft Catches Russian Government Hackers Phishing with Teams Chat App Read More »

Nearly All Modern CPUs Leak Data to New Collide+Power Side-Channel Attack

Nearly All Modern CPUs Leak Data to New Collide+Power Side-Channel Attack 01/08/2023 at 20:15 By Eduard Kovacs A new power side-channel attack named Collide+Power can allow an attacker to obtain sensitive information and it works against nearly any modern CPU. The post Nearly All Modern CPUs Leak Data to New Collide+Power Side-Channel Attack appeared first

Nearly All Modern CPUs Leak Data to New Collide+Power Side-Channel Attack Read More »

Ransomware Attacks on Industrial Organizations Doubled in Past Year: Report

Ransomware Attacks on Industrial Organizations Doubled in Past Year: Report 01/08/2023 at 14:03 By Eduard Kovacs The number of ransomware attacks targeting industrial organizations and infrastructure has doubled since the second quarter of 2022, according to Dragos. The post Ransomware Attacks on Industrial Organizations Doubled in Past Year: Report appeared first on SecurityWeek. This article

Ransomware Attacks on Industrial Organizations Doubled in Past Year: Report Read More »

Second Ivanti EPMM Zero-Day Vulnerability Exploited in Targeted Attacks

Second Ivanti EPMM Zero-Day Vulnerability Exploited in Targeted Attacks 31/07/2023 at 13:31 By Eduard Kovacs Ivanti EPMM customers have been warned of CVE-2023-35081, a second zero-day vulnerability that has been exploited in targeted attacks. The post Second Ivanti EPMM Zero-Day Vulnerability Exploited in Targeted Attacks appeared first on SecurityWeek. This article is an excerpt from

Second Ivanti EPMM Zero-Day Vulnerability Exploited in Targeted Attacks Read More »

Two New Vulnerabilities Could affect 40% of Ubuntu Cloud Workloads

Two New Vulnerabilities Could affect 40% of Ubuntu Cloud Workloads 27/07/2023 at 17:20 By Kevin Townsend Researchers discovered two vulnerabilities in the Ubuntu OverlayFS module: CVE-2023-2640 and CVE-2023-32629 (together dubbed ‘GameOver(lay)’). The post Two New Vulnerabilities Could affect 40% of Ubuntu Cloud Workloads appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS

Two New Vulnerabilities Could affect 40% of Ubuntu Cloud Workloads Read More »

Ivanti Zero-Day Vulnerability Exploited in Attack on Norwegian Government

Ivanti Zero-Day Vulnerability Exploited in Attack on Norwegian Government 25/07/2023 at 13:04 By Eduard Kovacs An Ivanti EPMM product zero-day vulnerability tracked as CVE-2023-35078 has been exploited in an attack aimed at the Norwegian government. The post Ivanti Zero-Day Vulnerability Exploited in Attack on Norwegian Government appeared first on SecurityWeek. This article is an excerpt

Ivanti Zero-Day Vulnerability Exploited in Attack on Norwegian Government Read More »

Microsoft Cloud Hack Exposed More than Exchange, Outlook Emails

Microsoft Cloud Hack Exposed More than Exchange, Outlook Emails 21/07/2023 at 20:19 By Ryan Naraine Cloud security researcher warns that stolen Microsoft signing key was more powerful and not limited to Outlook.com and Exchange Online. The post Microsoft Cloud Hack Exposed More than Exchange, Outlook Emails appeared first on SecurityWeek. This article is an excerpt

Microsoft Cloud Hack Exposed More than Exchange, Outlook Emails Read More »

Citrix Zero-Day Exploited Against Critical Infrastructure Organization

Citrix Zero-Day Exploited Against Critical Infrastructure Organization 21/07/2023 at 13:33 By Eduard Kovacs CISA says the new Citrix zero day vulnerability tracked as CVE-2023-3519 has been exploited against a critical infrastructure organization. The post Citrix Zero-Day Exploited Against Critical Infrastructure Organization appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View

Citrix Zero-Day Exploited Against Critical Infrastructure Organization Read More »

Scroll to Top