Incident Response

Patch Tuesday: Code Execution Flaws in Adobe Commerce, Photoshop

Patch Tuesday: Code Execution Flaws in Adobe Commerce, Photoshop 10/10/2023 at 20:17 By Ryan Naraine Adobe Commerce customers exposed to code execution, privilege escalation, arbitrary file system read, and security feature bypass attacks. The post Patch Tuesday: Code Execution Flaws in Adobe Commerce, Photoshop appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

Patch Tuesday: Code Execution Flaws in Adobe Commerce, Photoshop Read More »

Nonprofit Service Provider Blackbaud Settles Data Breach Case for $49.5M With States

Nonprofit Service Provider Blackbaud Settles Data Breach Case for $49.5M With States 06/10/2023 at 15:03 By Associated Press The fundraising software company Blackbaud has agreed to pay $49.5 million to settle claims brought by the attorneys general of 49 states and Washington, D.C., related to a 2020 data breach. The post Nonprofit Service Provider Blackbaud […]

Nonprofit Service Provider Blackbaud Settles Data Breach Case for $49.5M With States Read More »

Cisco Plugs Gaping Hole in Emergency Responder Software

Cisco Plugs Gaping Hole in Emergency Responder Software 05/10/2023 at 21:31 By Ryan Naraine Cisco warns that unauthenticated, remote attackers can log into devices using root account, which has default, static credentials that cannot be changed or deleted. The post Cisco Plugs Gaping Hole in Emergency Responder Software appeared first on SecurityWeek. This article is […]

Cisco Plugs Gaping Hole in Emergency Responder Software Read More »

Live Exploitation Underscores Urgency to Patch Critical WS-FTP Server Flaw

Live Exploitation Underscores Urgency to Patch Critical WS-FTP Server Flaw 02/10/2023 at 20:17 By Ryan Naraine Rapid7 says attackers are targeting a critical pre-authentication flaw in Progress Software’s WS_FTP server just days after disclosure. The post Live Exploitation Underscores Urgency to Patch Critical WS-FTP Server Flaw appeared first on SecurityWeek. This article is an excerpt […]

Live Exploitation Underscores Urgency to Patch Critical WS-FTP Server Flaw Read More »

The hidden costs of neglecting cybersecurity for small businesses

The hidden costs of neglecting cybersecurity for small businesses 28/09/2023 at 07:31 By Mirko Zorz In this Help Net Security interview, Raffaele Mautone, CEO of Judy Security, talks about the cybersecurity problems that small businesses face and the need for prioritization to save businesses from potential fines and damage to their brand reputation. He also […]

The hidden costs of neglecting cybersecurity for small businesses Read More »

Gem Security Lands $23 Million Series A Funding

Gem Security Lands $23 Million Series A Funding 27/09/2023 at 17:17 By Ryan Naraine Israeli security startup Gem Security has raised a total of $34 million to tackle cloud threat detection and incident response. The post Gem Security Lands $23 Million Series A Funding appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

Gem Security Lands $23 Million Series A Funding Read More »

MITRE ATT&CK project leader on why the framework remains vital for cybersecurity pros

MITRE ATT&CK project leader on why the framework remains vital for cybersecurity pros 26/09/2023 at 07:32 By Mirko Zorz MITRE ATT&CK, a common language for cybersecurity professionals to communicate with each other and better understand real-world adversary behaviors, celebrates its 10th anniversary this fall. In this Help Net Security interview, project leader Adam Pennington discusses […]

MITRE ATT&CK project leader on why the framework remains vital for cybersecurity pros Read More »

Cybersecurity skills employers are desperate to find in 2023

Cybersecurity skills employers are desperate to find in 2023 26/09/2023 at 07:01 By Help Net Security The surge in digital economic growth and our increasing dependence on it make cybersecurity a critical profession. In this Help Net Security video, Aaron Rosenmund, Director of Security Research and Curriculum, Pluralsight, discusses the most sought-after cybersecurity skills in […]

Cybersecurity skills employers are desperate to find in 2023 Read More »

DHS Publishes New Recommendations on Cyber Incident Reporting

DHS Publishes New Recommendations on Cyber Incident Reporting 20/09/2023 at 16:47 By Ionut Arghire DHS has published a new set of recommendations to help federal agencies better report cyber incidents and protect critical infrastructure. The post DHS Publishes New Recommendations on Cyber Incident Reporting appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

DHS Publishes New Recommendations on Cyber Incident Reporting Read More »

Clorox Blames Damaging Cyberattack for Product Shortage

Clorox Blames Damaging Cyberattack for Product Shortage 19/09/2023 at 17:32 By Eduard Kovacs Clorox says the recent cyberattack has been contained, but production is still not fully restored and there is a short supply of products.  The post Clorox Blames Damaging Cyberattack for Product Shortage appeared first on SecurityWeek. This article is an excerpt from […]

Clorox Blames Damaging Cyberattack for Product Shortage Read More »

Caesars Confirms Ransomware Hack, Stolen Loyalty Program Database

Caesars Confirms Ransomware Hack, Stolen Loyalty Program Database 14/09/2023 at 21:06 By Ryan Naraine The hijacked data includes driver’s license numbers and/or social security numbers from a Caesars Entertainment loyalty database. The post Caesars Confirms Ransomware Hack, Stolen Loyalty Program Database appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View […]

Caesars Confirms Ransomware Hack, Stolen Loyalty Program Database Read More »

DFIR Company Binalyze Raises $19 Million in Series A Funding

DFIR Company Binalyze Raises $19 Million in Series A Funding 12/09/2023 at 14:46 By Eduard Kovacs Estonian DFIR company Binalyze has raised $19 million in a Series A funding round to grow and improve its product.  The post DFIR Company Binalyze Raises $19 Million in Series A Funding appeared first on SecurityWeek. This article is […]

DFIR Company Binalyze Raises $19 Million in Series A Funding Read More »

Best practices for implementing a proper backup strategy

Best practices for implementing a proper backup strategy 08/09/2023 at 07:01 By Help Net Security Implementing a robust backup strategy for safeguarding crucial business data is more essential than ever. Without such a plan, organizations risk paying ransoms and incurring expenses related to investigations and lost productivity. In this Help Net Security video, David Boland, […]

Best practices for implementing a proper backup strategy Read More »

Shifting left and right, innovating product security

Shifting left and right, innovating product security 07/09/2023 at 07:03 By Mirko Zorz In this Help Net Security interview, Slava Bronfman, CEO at Cybellum, discusses approaches for achieving product security throughout a device’s entire lifecycle, fostering collaboration across business units and product lines, ensuring transparency and security in the supply chain, and meeting regulatory requirements […]

Shifting left and right, innovating product security Read More »

United Airlines Says the Outage That Held Up Departing Flights Was Not a Cybersecurity Issue

United Airlines Says the Outage That Held Up Departing Flights Was Not a Cybersecurity Issue 06/09/2023 at 07:16 By Associated Press United Airlines flights were halted nationwide on Sept. 5, because of an “equipment outage,” according to the FAA. The post United Airlines Says the Outage That Held Up Departing Flights Was Not a Cybersecurity […]

United Airlines Says the Outage That Held Up Departing Flights Was Not a Cybersecurity Issue Read More »

Velociraptor: Open-source digital forensics and incident response

Velociraptor: Open-source digital forensics and incident response 30/08/2023 at 06:32 By Help Net Security Velociraptor is a sophisticated digital forensics and incident response tool designed to improve your insight into endpoint activities. Velociraptor enables you to conduct precise and rapid collection of digital forensic data across multiple endpoints simultaneously. Persistently gather events from endpoints, including […]

Velociraptor: Open-source digital forensics and incident response Read More »

Experts demand clarity as they struggle with cloud security prioritization

Experts demand clarity as they struggle with cloud security prioritization 28/08/2023 at 06:32 By Help Net Security Cloud Native Application Protection Platforms (CNAPPs) have emerged as a critical category of security tooling in recent years due to the complexity of comprehensively securing multi-cloud environments, according to Cloud Security Alliance. Secure cloud computing environment Much of […]

Experts demand clarity as they struggle with cloud security prioritization Read More »

Ransomware dwell time hits new low

Ransomware dwell time hits new low 25/08/2023 at 06:34 By Help Net Security Median attacker dwell time—the time from when an attack starts to when it’s detected—shrunk from 10 to eight days for all attacks, and to five days for ransomware attacks during the first half of 2023, according to Sophos. In 2022, the median […]

Ransomware dwell time hits new low Read More »

UAC: Live response collection script for incident response

UAC: Live response collection script for incident response 27/07/2023 at 05:33 By Help Net Security Unix-like Artifacts Collector (UAC) is a live response collection script for incident response that makes use of native binaries and tools to automate the collection of AIX, Android, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD, and Solaris systems artifacts. It […]

UAC: Live response collection script for incident response Read More »

Citrix ADC zero-day exploitatation: CISA releases details about attack on CI organization (CVE-2023-3519)

Citrix ADC zero-day exploitatation: CISA releases details about attack on CI organization (CVE-2023-3519) 21/07/2023 at 14:19 By Zeljka Zorz The exploitation of the Citrix NetScaler ADC zero-day vulnerability (CVE-2023-3519) was first spotted by a critical infrastructure organization, who reported it to the Cybersecurity and Infrastructure Security Agency (CISA). “In June 2023, threat actors exploited this […]

Citrix ADC zero-day exploitatation: CISA releases details about attack on CI organization (CVE-2023-3519) Read More »

Scroll to Top