Category: Uncategorized
-
Hackers Stole ‘Sensitive’ Data From Taiwan Telecom Giant: Ministry AFP
Hackers stole “sensitive information” including military and government documents from telecom giant Chunghwa Telecom and sold it on the dark web, the island’s ministry of national defense said. The post Hackers Stole ‘Sensitive’ Data From Taiwan Telecom Giant: Ministry appeared first on SecurityWeek. Read More
-

4 Instructive Postmortems on Data Downtime and Loss [email protected] (The Hacker News)
More than a decade ago, the concept of the ‘blameless’ postmortem changed how tech companies recognize failures at scale. John Allspaw, who coined the term during his tenure at Etsy, argued postmortems were all about controlling our natural reaction to an incident, which is to point fingers: “One option is to assume the single cause is incompetence…
-
Industry Reactions to NIST Cybersecurity Framework 2.0: Feedback Friday Eduard Kovacs
Industry professionals comment on the official release of the NIST Cybersecurity Framework 2.0. The post Industry Reactions to NIST Cybersecurity Framework 2.0: Feedback Friday appeared first on SecurityWeek. Read More
-

New BIFROSE Linux Malware Variant Using Deceptive VMware Domain for Evasion [email protected] (The Hacker News)
Cybersecurity researchers have discovered a new Linux variant of a remote access trojan (RAT) called BIFROSE (aka Bifrost) that uses a deceptive domain mimicking VMware. “This latest version of Bifrost aims to bypass security measures and compromise targeted systems,” Palo Alto Networks Unit 42 researchers Anmol Maurya and Siddharth Sharma said. BIFROSE is one of the long-standingRead…
-

Five Eyes Agencies Warn of Active Exploitation of Ivanti Gateway Vulnerabilities [email protected] (The Hacker News)
The Five Eyes (FVEY) intelligence alliance has issued a new cybersecurity advisory warning of cyber threat actors exploiting known security flaws in Ivanti Connect Secure and Ivanti Policy Secure gateways, noting that the Integrity Checker Tool (ICT) can be deceived to provide a false sense of security. “Ivanti ICT is not sufficient to detect compromise…
-

GitHub Rolls Out Default Secret Scanning Push Protection for Public Repositories [email protected] (The Hacker News)
GitHub on Thursday announced that it’s enabling secret scanning push protection by default for all pushes to public repositories. “This means that when a supported secret is detected in any push to a public repository, you will have the option to remove the secret from your commits or, if you deem the secret safe, bypass…
-
Biden Administration Will Investigate National Security Risks Posed by Chinese-Made ‘Smart Cars’ Associated Press
Government probe could lead to new regulations aimed at preventing China from using sophisticated technology in connected vehicles to track drivers and their personal information. The post Biden Administration Will Investigate National Security Risks Posed by Chinese-Made ‘Smart Cars’ appeared first on SecurityWeek. Read More
-
German Steelmaker Thyssenkrupp Confirms Ransomware Attack SecurityWeek News
German steelmaking conglomerate Thyssenkrupp confirms one of its automotive units was disrupted by a ransomware attack. The post German Steelmaker Thyssenkrupp Confirms Ransomware Attack appeared first on SecurityWeek. Read More
-

New Silver SAML Attack Evades Golden SAML Defenses in Identity Systems [email protected] (The Hacker News)
Cybersecurity researchers have disclosed a new attack technique called Silver SAML that can be successful even in cases where mitigations have been applied against Golden SAML attacks. Silver SAML “enables the exploitation of SAML to launch attacks from an identity provider like Entra ID against applications configured to use it for authentication, such as Salesforce,” SemperisRead More
-
Discount Retail Giant Pepco Loses €15 Million to Cybercriminals Eduard Kovacs
European discount retailer Pepco has lost €15.5 million as a result of what it described as a phishing attack. The post Discount Retail Giant Pepco Loses €15 Million to Cybercriminals appeared first on SecurityWeek. Read More
