Category: Uncategorized
-
Hackers Earn Over $1 Million at Pwn2Own Toronto 2023 Ionut Arghire
Hackers have demonstrated 58 zero-days and earned more than $1 million in rewards at Pwn2Own Toronto 2023. The post Hackers Earn Over $1 Million at Pwn2Own Toronto 2023 appeared first on SecurityWeek. Read More
-

New Webinar: 5 Must-Know Trends Impacting AppSec [email protected] (The Hacker News)
Modern web app development relies on cloud infrastructure and containerization. These technologies scale on demand, handling millions of daily file transfers – it’s almost impossible to imagine a world without them. However, they also introduce multiple attack vectors that exploit file uploads when working with public clouds, vulnerabilities in containers hosting web applications, and many…
-

ServiceNow Data Exposure: A Wake-Up Call for Companies [email protected] (The Hacker News)
Earlier this week, ServiceNow announced on its support site that misconfigurations within the platform could result in “unintended access” to sensitive data. For organizations that use ServiceNow, this security exposure is a critical concern that could have resulted in major data leakage of sensitive corporate data. ServiceNow has since taken steps to fix this issue. This article fully…
-
Whistleblowers: Should CISOs Consider Them a Friend or Foe? Kevin Townsend
Are whistleblowers traitors to the company, a danger to corporate brand image, and a form of insider threat? Or are they an early warning safety valve that can be used to strengthen cybersecurity and compliance? The post Whistleblowers: Should CISOs Consider Them a Friend or Foe? appeared first on SecurityWeek. Read More
-

EleKtra-Leak Cryptojacking Attacks Exploit AWS IAM Credentials Exposed on GitHub [email protected] (The Hacker News)
A new ongoing campaign dubbed EleKtra-Leak has set its eyes on exposed Amazon Web Service (AWS) identity and access management (IAM) credentials within public GitHub repositories to facilitate cryptojacking activities. “As a result of this, the threat actor associated with the campaign was able to create multiple AWS Elastic Compute (EC2) instances that they used for wide-ranging…
-
Biden Wants to Move Fast on AI Safeguards and Will Sign an Executive Order to Address His Concerns Associated Press
President Joe Biden on Monday will sign a sweeping executive order to guide the development of artificial intelligence — requiring industry to develop safety and security standards, and introducing new consumer protections. The post Biden Wants to Move Fast on AI Safeguards and Will Sign an Executive Order to Address His Concerns appeared first on…
-

Urgent: New Security Flaws Discovered in NGINX Ingress Controller for Kubernetes [email protected] (The Hacker News)
Three unpatched high-severity security flaws have been disclosed in the NGINX Ingress controller for Kubernetes that could be weaponized by a threat actor to steal secret credentials from the cluster. The vulnerabilities are as follows – CVE-2022-4886 (CVSS score: 8.8) – Ingress-nginx path sanitization can be bypassed to obtain the credentials of the ingress-nginx controller CVE-2023-5043 (Read More
-

Hackers Using MSIX App Packages to Infect Windows PCs with GHOSTPULSE Maware [email protected] (The Hacker News)
A new cyber attack campaign has been observed using spurious MSIX Windows app package files for popular software such as Google Chrome, Microsoft Edge, Brave, Grammarly, and Cisco Webex to distribute a novel malware loader dubbed GHOSTPULSE. “MSIX is a Windows app package format that developers can leverage to package, distribute, and install their applications to Windows users,”…
-

Researchers Uncover Wiretapping of XMPP-Based Instant Messaging Service [email protected] (The Hacker News)
New findings have shed light on what’s said to be a lawful attempt to covertly intercept traffic originating from jabber[.]ru (aka xmpp[.]ru), an XMPP-based instant messaging service, via servers hosted on Hetzner and Linode (a subsidiary of Akamai) in Germany. “The attacker has issued several new TLS certificates using Let’s Encrypt service which were used to…
-

N. Korean Lazarus Group Targets Software Vendor Using Known Flaws [email protected] (The Hacker News)
The North Korea-aligned Lazarus Group has been attributed as behind a new campaign in which an unnamed software vendor was compromised through the exploitation of known security flaws in another high-profile software. The attack sequences, according to Kaspersky, culminated in the deployment of malware families such as SIGNBT and LPEClient, a known hacking tool used by the threat…
