Category: Uncategorized
-
Multiple Security Issues Identified in Peloton Fitness Equipment Ionut Arghire
Internet-connected Peloton workout equipment is impacted by multiple security risks, such as having USB debugging enabled. The post Multiple Security Issues Identified in Peloton Fitness Equipment appeared first on SecurityWeek. Read More
-
The Good, the Bad and the Ugly of Generative AI Marc Solomon
Thinking through the good, the bad, and the ugly now is a process that affords us “the negative focus to survive, but a positive one to thrive.” The post The Good, the Bad and the Ugly of Generative AI appeared first on SecurityWeek. Read More
-

GameOver(lay): Two Severe Linux Vulnerabilities Impact 40% of Ubuntu Users [email protected] (The Hacker News)
Cybersecurity researchers have disclosed two high-severity security flaws in the Ubuntu kernel that could pave the way for local privilege escalation attacks. Cloud security firm Wiz, in a report shared with The Hacker News, said the easy-to-exploit shortcomings have the potential to impact 40% of Ubuntu users. “The impacted Ubuntu versions are prevalent in the cloud as…
-

New Malvertising Campaign Distributing Trojanized IT Tools via Google and Bing Search Ads [email protected] (The Hacker News)
A new malvertising campaign has been observed leveraging ads on Google Search and Bing to target users seeking IT tools like AnyDesk, Cisco AnyConnect VPN, and WinSCP, and trick them into downloading trojanized installers with an aim to breach enterprise networks and likely carry out future ransomware attacks. Dubbed Nitrogen, the “opportunistic” activity is designed to…
-
Two New Vulnerabilities Could affect 40% of Ubuntu Cloud Workloads Kevin Townsend
Researchers discovered two vulnerabilities in the Ubuntu OverlayFS module: CVE-2023-2640 and CVE-2023-32629 (together dubbed ‘GameOver(lay)’). The post Two New Vulnerabilities Could affect 40% of Ubuntu Cloud Workloads appeared first on SecurityWeek. Read More
-
CardioComm Takes Systems Offline Following Cyberattack Ionut Arghire
Canadian medical software provider CardioComm has taken systems offline to contain a cyberattack. The post CardioComm Takes Systems Offline Following Cyberattack appeared first on SecurityWeek. Read More
-
Axis Door Controller Vulnerability Exposes Facilities to Physical, Cyber Threats Eduard Kovacs
An Axis network door controller vulnerability can be exploited to target facilities, exposing them to both physical and cyber threats. The post Axis Door Controller Vulnerability Exposes Facilities to Physical, Cyber Threats appeared first on SecurityWeek. Read More
-

The 4 Keys to Building Cloud Security Programs That Can Actually Shift Left [email protected] (The Hacker News)
As cloud applications are built, tested and updated, they wind their way through an ever-complex series of different tools and teams. Across hundreds or even thousands of technologies that make up the patchwork quilt of development and cloud environments, security processes are all too often applied in only the final phases of software development. Placing…
-

Hackers Target Apache Tomcat Servers for Mirai Botnet and Crypto Mining [email protected] (The Hacker News)
Misconfigured and poorly secured Apache Tomcat servers are being targeted as part of a new campaign designed to deliver the Mirai botnet malware and cryptocurrency miners. The findings come courtesy of Aqua, which detected more than 800 attacks against its Tomcat server honeypots over a two-year time period, with 96% of the attacks linked to the Mirai…
-

Group-IB Co-Founder Sentenced to 14 Years in Russian Prison for Alleged High Treason [email protected] (The Hacker News)
A city court in Moscow on Wednesday convicted Group-IB co-founder and CEO Ilya Sachkov of “high treason” and jailed him for 14 years in a “strict regime colony” over accusations of passing information to foreign spies. “The court found Sachkov guilty under Article 275 of the Russian Criminal Code (high treason) sentencing him to 14…
