Category: Uncategorized
-
In Other News: Data Breach Cost Rises, Russia Targets Diplomats, Tracker Alerts in Android SecurityWeek News
Weekly cybersecurity news roundup that provides a summary of noteworthy stories that might have slipped under the radar for the week of July 24, 2023. The post In Other News: Data Breach Cost Rises, Russia Targets Diplomats, Tracker Alerts in Android appeared first on SecurityWeek. Read More
-
Exploitation of Recent Citrix ShareFile RCE Vulnerability Begins Ionut Arghire
The first attempts to exploit CVE-2023-24489, a recent critical Citrix ShareFile remote code execution vulnerability, have been observed. The post Exploitation of Recent Citrix ShareFile RCE Vulnerability Begins appeared first on SecurityWeek. Read More
-

IcedID Malware Adapts and Expands Threat with Updated BackConnect Module [email protected] (The Hacker News)
The threat actors linked to the malware loader known as IcedID have made updates to the BackConnect (BC) module that’s used for post-compromise activity on hacked systems, new findings from Team Cymru reveal. IcedID, also called BokBot, is a strain of malware similar to Emotet and QakBot that started off as a banking trojan in 2017, before switching to…
-
Industry Reactions to New SEC Cyber Incident Disclosure Rules: Feedback Friday Eduard Kovacs
Several industry professionals comment on the SEC’s new cybersecurity incident disclosure rules and their implications. The post Industry Reactions to New SEC Cyber Incident Disclosure Rules: Feedback Friday appeared first on SecurityWeek. Read More
-

STARK#MULE Targets Koreans with U.S. Military-themed Document Lures [email protected] (The Hacker News)
An ongoing cyber attack campaign has set its sights on Korean-speaking individuals by employing U.S. Military-themed document lures to trick them into running malware on compromised systems. Cybersecurity firm Securonix is tracking the activity under the name STARK#MULE. “Based on the source and likely targets, these types of attacks are on par with past attacks stemming…
-
Intersection of generative AI, cybersecurity and digital trust
Post ContentRead More
-

A Data Exfiltration Attack Scenario: The Porsche Experience [email protected] (The Hacker News)
As part of Checkmarx’s mission to help organizations develop and deploy secure software, the Security Research team started looking at the security posture of major car manufacturers. Porsche has a well-established Vulnerability Reporting Policy (Disclosure Policy)[1], it was considered in scope for our research, so we decided to start there, and see what we could find. What…
-

Hackers Abusing Windows Search Feature to Install Remote Access Trojans [email protected] (The Hacker News)
A legitimate Windows search feature is being exploited by malicious actors to download arbitrary payloads from remote servers and compromise targeted systems with remote access trojans such as AsyncRAT and Remcos RAT. The novel attack technique, per Trellix, takes advantage of the “search-ms:” URI protocol handler, which offers the ability for applications and HTML links…
-
Zimbra Patches Exploited Zero-Day Vulnerability Ionut Arghire
Zimbra has released patches for a cross-site scripting (XSS) vulnerability that has been exploited in malicious attacks. The post Zimbra Patches Exploited Zero-Day Vulnerability appeared first on SecurityWeek. Read More
-
CoinsPaid Blames North Korean Hackers for $37 Million Cryptocurrency Heist Ionut Arghire
CoinsPaid says North Korean hacking group Lazarus is likely responsible for the recent theft of $37 million in cryptocurrency. The post CoinsPaid Blames North Korean Hackers for $37 Million Cryptocurrency Heist appeared first on SecurityWeek. Read More
