Category: Uncategorized
-
Tor Code Audit Finds 17 Vulnerabilities Eduard Kovacs
Over a dozen vulnerabilities discovered in Tor audit, including a high-risk flaw that can be exploited to inject arbitrary bridges. The post Tor Code Audit Finds 17 Vulnerabilities appeared first on SecurityWeek. Read More
-
Leaked GitHub Token Exposed Mercedes Source Code Ionut Arghire
A leaked token provided unrestricted access to the entire source code on Mercedes-Benz’s GitHub Enterprise server. The post Leaked GitHub Token Exposed Mercedes Source Code appeared first on SecurityWeek. Read More
-

Telegram Marketplaces Fuel Phishing Attacks with Easy-to-Use Kits and Malware [email protected] (The Hacker News)
Cybersecurity researchers are calling attention to the “democratization” of the phishing ecosystem owing to the emergence of Telegram as an epicenter for cybercrime, enabling threat actors to mount a mass attack for as little as $230. “This messaging app has transformed into a bustling hub where seasoned cybercriminals and newcomers alike exchange illicit tools and…
-
Two More Individuals Charged for DraftKings Hacking Ionut Arghire
Nathan Austad and Kamerin Stokes have been charged for hacking user accounts at fantasy sports and betting website DraftKings. The post Two More Individuals Charged for DraftKings Hacking appeared first on SecurityWeek. Read More
-
How to Align Your Incident Response Practices With the New SEC Disclosure Rules Torsten George
By turning incident response simulation into a continuous process and employing innovative tools, you can address the stringent requirements of the new SEC incident disclosure rules. The post How to Align Your Incident Response Practices With the New SEC Disclosure Rules appeared first on SecurityWeek. Read More
-
Aim Security Raises $10M to Tackle Shadow AI Ryan Naraine
A new Israeli startup called Aim Security has raised $10 million in seed financing to help with the secure deployment of generative-AI technologies. The post Aim Security Raises $10M to Tackle Shadow AI appeared first on SecurityWeek. Read More
-
US Sanctions Two ISIS-Affiliated ‘Cybersecurity Experts’ Eduard Kovacs
US Treasury Department announces sanctions against two Egyptian nationals accused of running an ISIS cyber platform. The post US Sanctions Two ISIS-Affiliated ‘Cybersecurity Experts’ appeared first on SecurityWeek. Read More
-

Italian Businesses Hit by Weaponized USBs Spreading Cryptojacking Malware [email protected] (The Hacker News)
A financially motivated threat actor known as UNC4990 is leveraging weaponized USB devices as an initial infection vector to target organizations in Italy. Google-owned Mandiant said the attacks single out multiple industries, including health, transportation, construction, and logistics. “UNC4990 operations generally involve widespread USB infection followed by the deployment of theRead More
-

The SEC Won’t Let CISOs Be: Understanding New SaaS Cybersecurity Rules [email protected] (The Hacker News)
The SEC isn’t giving SaaS a free pass. Applicable public companies, known as “registrants,” are now subject to cyber incident disclosure and cybersecurity readiness requirements for data stored in SaaS systems, along with the 3rd and 4th party apps connected to them. The new cybersecurity mandates make no distinction between data exposed in a breach that…
-
45,000 Exposed Jenkins Instances Found Amid Reports of In-the-Wild Exploitation Eduard Kovacs
Shadowserver Foundation has seen 45,000 Jenkins instances affected by CVE-2024-23897, which may already be exploited in attacks. The post 45,000 Exposed Jenkins Instances Found Amid Reports of In-the-Wild Exploitation appeared first on SecurityWeek. Read More
