News

Roundcube webmail XSS vulnerability exploited by attackers (CVE-2023-43770)

Roundcube webmail XSS vulnerability exploited by attackers (CVE-2023-43770) 2024-02-13 at 11:46 By Zeljka Zorz CVE-2023-43770, a vulnerability in the Roundcube webmail software that has been fixed in September 2023, is being exploited by attackers in the wild, CISA has warned by adding the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. About CVE-2023-43770 Roundcube is […]

Roundcube webmail XSS vulnerability exploited by attackers (CVE-2023-43770) Read More »

The future of cybersecurity: Anticipating changes with data analytics and automation

The future of cybersecurity: Anticipating changes with data analytics and automation 2024-02-13 at 08:01 By Mirko Zorz In this Help Net Security interview, Mick Baccio, Staff Security Strategist at Splunk SURGe, discusses the future of cybersecurity, emphasizing the importance of data analytics and automation in addressing evolving threats. He points out the changes in threat

The future of cybersecurity: Anticipating changes with data analytics and automation Read More »

Protecting against AI-enhanced email threats

Protecting against AI-enhanced email threats 2024-02-13 at 07:31 By Helga Labus Generative AI based on large language models (LLMs) has become a valuable tool for individuals and businesses, but also cybercriminals. Its ability to process large amounts of data and quickly generate results has contributed to its widespread adoption. AI in the hands of cybercriminals

Protecting against AI-enhanced email threats Read More »

Product showcase: SearchInform Risk Monitor – next-gen DLP based insider threat mitigation platform

Product showcase: SearchInform Risk Monitor – next-gen DLP based insider threat mitigation platform 2024-02-13 at 06:31 By Help Net Security Basically, DLP systems are aimed at prevention of data leaks, and in real-life mode they monitor and block (if required) transmitting of confidential data. However, the traditional approach to DLP system isn’t sufficient. That’s why

Product showcase: SearchInform Risk Monitor – next-gen DLP based insider threat mitigation platform Read More »

QR code attacks target organizations in ways they least expect

QR code attacks target organizations in ways they least expect 2024-02-13 at 06:01 By Help Net Security QR code attacks, or “quishing” attacks, have emerged as a popular tactic among cybercriminals, with no signs of slowing down, according to Abnormal Security. Although phishing emails have grown in sophistication over time, the end goal has stayed

QR code attacks target organizations in ways they least expect Read More »

Critical Fortinet FortiOS flaw exploited in the wild (CVE-2024-21762)

Critical Fortinet FortiOS flaw exploited in the wild (CVE-2024-21762) 2024-02-12 at 21:01 By Zeljka Zorz Fortinet has patched critical remote code execution vulnerabilities in FortiOS (CVE-2024-21762, CVE-2024-23313), one of which is “potentially” being exploited in the wild. The exploitation-in-the-wild has been confirmed by CISA, by adding it to its Known Exploited Vulnerabilities (KEV) catalog, though

Critical Fortinet FortiOS flaw exploited in the wild (CVE-2024-21762) Read More »

Decryptor for Rhysida ransomware is available!

Decryptor for Rhysida ransomware is available! 2024-02-12 at 13:46 By Zeljka Zorz Files encrypted by Rhysida ransomware can be successfully decrypted, due to a implementation vulnerability discovered by Korean researchers and leveraged to create a decryptor. About Rhysida Rhysida is a relatively new ransomware-as-a-service gang that engages in double extortion. First observed in May 2023,

Decryptor for Rhysida ransomware is available! Read More »

Integrating cybersecurity into vehicle design and manufacturing

Integrating cybersecurity into vehicle design and manufacturing 2024-02-12 at 08:01 By Mirko Zorz In this Help Net Security interview, Yaron Edan, CISO at REE Automotive, discusses the cybersecurity landscape of the automotive industry, mainly focusing on electric and connected vehicles. Edan highlights the challenges of technological advancements and outlines strategies for automakers to address cyber

Integrating cybersecurity into vehicle design and manufacturing Read More »

Ransomware tactics evolve, become scrappier

Ransomware tactics evolve, become scrappier 2024-02-12 at 07:02 By Help Net Security As we enter 2024, ransomware remains the most significant cyberthreat facing businesses, according to Malwarebytes. Malwarebytes reveals that the United States accounted for almost half of all ransomware attacks in 2023. “Small and medium-sized organizations face a deluge of cyber threats daily including

Ransomware tactics evolve, become scrappier Read More »

SiCat: Open-source exploit finder

SiCat: Open-source exploit finder 2024-02-12 at 06:31 By Mirko Zorz SiCat is an open-source tool for exploit research designed to source and compile information about exploits from open channels and internal databases. Its primary aim is to assist in cybersecurity, enabling users to search the internet for potential vulnerabilities and corresponding exploits. Akas Wisnu Aji,

SiCat: Open-source exploit finder Read More »

Week in review: 10 must-read cybersecurity books, AnyDesk hack, Patch Tuesday forecast

Week in review: 10 must-read cybersecurity books, AnyDesk hack, Patch Tuesday forecast 2024-02-11 at 11:06 By Help Net Security Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: How CISOs navigate policies and access across enterprises In this Help Net Security interview, Marco Eggerling, Global CISO at Check Point,

Week in review: 10 must-read cybersecurity books, AnyDesk hack, Patch Tuesday forecast Read More »

AI-generated voices in robocalls now illegal

AI-generated voices in robocalls now illegal 2024-02-09 at 14:32 By Help Net Security The FCC has revealed the unanimous adoption of a Declaratory Ruling that recognizes calls made with AI-generated voices are “artificial” under the Telephone Consumer Protection Act (TCPA). The ruling, which takes effect immediately, makes voice cloning technology used in common robocall scams

AI-generated voices in robocalls now illegal Read More »

February 2024 Patch Tuesday forecast: Zero days are back and a new server too

February 2024 Patch Tuesday forecast: Zero days are back and a new server too 2024-02-09 at 08:32 By Mirko Zorz January 2024 Patch Tuesday is behind us. A relatively light release from Microsoft with 39 CVEs addressed in Windows 10, 35 in Windows 11, and surprisingly no zero-day vulnerabilities from Microsoft to start the new

February 2024 Patch Tuesday forecast: Zero days are back and a new server too Read More »

Why we fall for fake news and how can we change that?

Why we fall for fake news and how can we change that? 2024-02-09 at 08:32 By Helga Labus Have you ever been swept away by an enticing headline and didn’t bother to probe the news in-depth? You might have shared an eye-catching news story or engaged with a compelling post, only to realize later that

Why we fall for fake news and how can we change that? Read More »

New infosec products of the week: February 9, 2024

New infosec products of the week: February 9, 2024 2024-02-09 at 08:01 By Help Net Security Here’s a look at the most interesting products from the past week, featuring releases from Cisco, Metomic, OPSWAT, Qualys, and Varonis. Varonis MDDR helps organizations prevent data breaches Varonis introduced Varonis Managed Data Detection and Response (MDDR), a managed

New infosec products of the week: February 9, 2024 Read More »

Key strategies for ISO 27001 compliance adoption

Key strategies for ISO 27001 compliance adoption 2024-02-09 at 07:32 By Mirko Zorz In this Help Net Security interview, Robin Long, founder of Kiowa Security, shares insights on how best to approach the implementation of the ISO/IEC 27001 information security standard. Long advises organizations to establish a detailed project roadmap and to book certification audits

Key strategies for ISO 27001 compliance adoption Read More »

Cybersecurity teams recognized as key enablers of business goals

Cybersecurity teams recognized as key enablers of business goals 2024-02-09 at 07:01 By Help Net Security 97% of office workers across the UK and US trust their cybersecurity team’s ability to prevent or minimize damage from cyberattacks, according to CybSafe. The study examining attitudes towards cybersecurity teams within organizations has uncovered that despite minor issues

Cybersecurity teams recognized as key enablers of business goals Read More »

How AI is revolutionizing identity fraud

How AI is revolutionizing identity fraud 2024-02-09 at 06:02 By Help Net Security Nearly half of businesses reported a growth in synthetic identity fraud, while biometric spoofs and counterfeit ID fraud attempts also increased, according to AuthenticID. Consumers and businesses alike are facing new challenges in today’s digital existence, from considering the ramifications of digital

How AI is revolutionizing identity fraud Read More »

LassPass is not LastPass: Fraudulent app on Apple App Store

LassPass is not LastPass: Fraudulent app on Apple App Store 2024-02-08 at 17:02 By Zeljka Zorz A fraudulent app named “LassPass Password Manager” that mimics the legitimate LastPass mobile app can currently be found on Apple’s App Store, the password manager maker is warning. The fraudulent app on Apple’s App Store “The app in question

LassPass is not LastPass: Fraudulent app on Apple App Store Read More »

Akira, LockBit actively searching for vulnerable Cisco ASA devices

Akira, LockBit actively searching for vulnerable Cisco ASA devices 2024-02-08 at 14:31 By Zeljka Zorz Akira and Lockbit ransomware groups are trying to breach Cisco ASA SSL VPN devices by exploiting several older vulnerabilities, security researcher Kevin Beaumont is warning. They are targeting vulnerabilities for which patches have been made available in 2020 and 2023.

Akira, LockBit actively searching for vulnerable Cisco ASA devices Read More »

Scroll to Top