Category: Uncategorized
-
Chipmaker Patch Tuesday: AMD and Intel Patch Over 100 Vulnerabilities Ionut Arghire
AMD and Intel patch dozens of vulnerabilities on February 2024 Patch Tuesday, including multiple high-severity bugs. The post Chipmaker Patch Tuesday: AMD and Intel Patch Over 100 Vulnerabilities appeared first on SecurityWeek. Read More
-
KeyTrap DNS Attack Could Disable Large Parts of Internet: Researchers Eduard Kovacs
Patches released for a new DNSSEC vulnerability named KeyTrap, described as the worst DNS attack ever discovered. The post KeyTrap DNS Attack Could Disable Large Parts of Internet: Researchers appeared first on SecurityWeek. Read More
-
Beyond the Hype: Questioning FUD in Cybersecurity Marketing Kevin Townsend
Could cybersecurity professionals benefit from FUD awareness training in the same way that users benefit from phishing awareness training? The post Beyond the Hype: Questioning FUD in Cybersecurity Marketing appeared first on SecurityWeek. Read More
-

Cybersecurity Tactics FinServ Institutions Can Bank On in 2024 [email protected] (The Hacker News)
The landscape of cybersecurity in financial services is undergoing a rapid transformation. Cybercriminals are exploiting advanced technologies and methodologies, making traditional security measures obsolete. The challenges are compounded for community banks that must safeguard sensitive financial data against the same level of sophisticated threats as larger institutions, but often with moreRead More
-

Bumblebee Malware Returns with New Tricks, Targeting U.S. Businesses [email protected] (The Hacker News)
The infamous malware loader and initial access broker known as Bumblebee has resurfaced after a four-month absence as part of a new phishing campaign observed in February 2024. Enterprise security firm Proofpoint said the activity targets organizations in the U.S. with voicemail-themed lures containing links to OneDrive URLs. “The URLs led to a Word file with names…
-
Windows Zero-Day Exploited in Attacks on Financial Market Traders Eduard Kovacs
CVE-2024-21412, one of the security bypass zero-days fixed by Microsoft with Patch Tuesday updates, exploited by Water Hydra (DarkCasino). The post Windows Zero-Day Exploited in Attacks on Financial Market Traders appeared first on SecurityWeek. Read More
-
Albanian Authorities Accuse Iranian-Backed Hackers of Cyberattack on Institute of Statistics Associated Press
Albania’s cybersecurity authorities have accused a hacker group “sponsored” by the Iranian government of attacking the country’s Institute of Statistics earlier this month. The post Albanian Authorities Accuse Iranian-Backed Hackers of Cyberattack on Institute of Statistics appeared first on SecurityWeek. Read More
-
SAP Patches Critical Vulnerability Exposing User, Business Data Ionut Arghire
SAP patches a critical code-injection vulnerability in the SAP ABA (Application Basis) cross-application component. The post SAP Patches Critical Vulnerability Exposing User, Business Data appeared first on SecurityWeek. Read More
-

DarkMe Malware Targets Traders Using Microsoft SmartScreen Zero-Day Vulnerability [email protected] (The Hacker News)
A newly disclosed security flaw in the Microsoft Defender SmartScreen has been exploited as a zero-day by an advanced persistent threat actor called Water Hydra (aka DarkCasino) targeting financial market traders. Trend Micro, which began tracking the campaign in late December 2023, said it entails the exploitation of CVE-2024-21412, a security bypass vulnerability related to InternetRead More
-

Microsoft Rolls Out Patches for 73 Flaws, Including 2 Windows Zero-Days [email protected] (The Hacker News)
Microsoft has released patches to address 73 security flaws spanning its software lineup as part of its Patch Tuesday updates for February 2024, including two zero-days that have come under active exploitation. Of the 73 vulnerabilities, 5 are rated Critical, 65 are rated Important, and three and rated Moderate in severity. This is in addition to 24 flaws that…
