Category: Uncategorized
-
Hacker Conversations: Alex Ionescu Kevin Townsend
SecurityWeek talks to Alex Ionescu, a world-renowned cybersecurity expert who has combined a career as a business executive with that of a security researcher. The post Hacker Conversations: Alex Ionescu appeared first on SecurityWeek. Read More
-
Chrome 116 Update Patches High-Severity Vulnerabilities Ionut Arghire
Google has released another weekly Chrome update, to address four high-severity vulnerabilities reported by external researchers. The post Chrome 116 Update Patches High-Severity Vulnerabilities appeared first on SecurityWeek. Read More
-

9 Alarming Vulnerabilities Uncovered in SEL’s Power Management Products [email protected] (The Hacker News)
Nine security flaws have been disclosed in electric power management products made by Schweitzer Engineering Laboratories (SEL). “The most severe of those nine vulnerabilities would allow a threat actor to facilitate remote code execution (RCE) on an engineering workstation,” Nozomi Networks said in a report published last week. The issues, tracked as CVE-2023-34392 and from CVE-2023-31168Read More
-
AtlasVPN to Patch IP Leak Vulnerability After Public Disclosure Eduard Kovacs
AtlasVPN developers are working on a patch for an IP leak vulnerability after a researcher publicly disclosed the flaw due to being ignored. The post AtlasVPN to Patch IP Leak Vulnerability After Public Disclosure appeared first on SecurityWeek. Read More
-

W3LL Store: How a Secret Phishing Syndicate Targets 8,000+ Microsoft 365 Accounts [email protected] (The Hacker News)
A previously undocumented “phishing empire” has been linked to cyber attacks aimed at compromising Microsoft 365 business email accounts over the past six years. “The threat actor created a hidden underground market, named W3LL Store, that served a closed community of at least 500 threat actors who could purchase a custom phishing kit called W3LL…
-

Ukraine’s CERT Thwarts APT28’s Cyberattack on Critical Energy Infrastructure [email protected] (The Hacker News)
The Computer Emergency Response Team of Ukraine (CERT-UA) on Tuesday said it thwarted a cyber attack against an unnamed critical energy infrastructure facility in the country. The intrusion, per the agency, started with a phishing email containing a link to a malicious ZIP archive that activates the infection chain. “Visiting the link will download a…
-
United Airlines Says the Outage That Held Up Departing Flights Was Not a Cybersecurity Issue Associated Press
United Airlines flights were halted nationwide on Sept. 5, because of an “equipment outage,” according to the FAA. The post United Airlines Says the Outage That Held Up Departing Flights Was Not a Cybersecurity Issue appeared first on SecurityWeek. Read More
-
CISA Hires ‘Mudge’ to Work on Security-by-Design Principles Ryan Naraine
Peiter ‘Mudge’ Zatko joins the US government’s cybersecurity agency to preach the gospel of security-by-design and secure-by-default development principles. The post CISA Hires ‘Mudge’ to Work on Security-by-Design Principles appeared first on SecurityWeek. Read More
-
MITRE and CISA Release Open Source Tool for OT Attack Emulation Ionut Arghire
MITRE and CISA introduce Caldera for OT, a new extension to help security teams emulate attacks targeting operational technology systems. The post MITRE and CISA Release Open Source Tool for OT Attack Emulation appeared first on SecurityWeek. Read More
-

New BLISTER Malware Update Fuelling Stealthy Network Infiltration [email protected] (The Hacker News)
An updated version of a malware loader known as BLISTER is being used as part of SocGholish infection chains to distribute an open-source command-and-control (C2) framework called Mythic. “New BLISTER update includes keying feature that allows for precise targeting of victim networks and lowers exposure within VM/sandbox environments,” Elastic Security Labs researchers Salim Bitam and DanielRead…
