Wednesday, May 11, 2022

Critical Gems Takeover Bug Reported in RubyGems Package Manager

The maintainers of the RubyGems package manager have addressed a critical security flaw that could have been abused to remove gems and replace them with rogue versions under specific circumstances. "Due to a bug in the yank action, it was possible for any RubyGems.org user to remove and replace certain gems even if that user was not authorized to do so," RubyGems said in a security advisory
https://thehackernews.com/2022/05/critical-gems-takeover-bug-reported-in.html?utm_source=dlvr.it&utm_medium=blogger

U.S. Proposes $1 Million Fine on Colonial Pipeline for Safety Violations After Cyberattack

The U.S. Department of Transportation's Pipeline and Hazardous Materials Safety Administration (PHMSA) has proposed a penalty of nearly $1 million to Colonial Pipeline for violating federal safety regulations, worsening the impact of the ransomware attack last year. The $986,400 penalty is the result of an inspection conducted by the regulator of the pipeline operator's control room management (
https://thehackernews.com/2022/05/us-proposes-1-million-fine-on-colonial.html?utm_source=dlvr.it&utm_medium=blogger

5 Benefits of Detection-as-Code

TL;DR:  Adopt a modern, test-driven methodology for securing your organization with Detection-as-Code. Over the past decade, threat detection has become business-critical and even more complicated. As businesses move to the cloud, manual threat detection processes are no longer able to keep up. How can teams automate security analysis at scale and address the challenges that threaten business
https://thehackernews.com/2022/05/5-benefits-of-detection-as-code.html?utm_source=dlvr.it&utm_medium=blogger

Experts Detail Saintstealer and Prynt Stealer Info-Stealing Malware Families

Cybersecurity researchers have dissected the inner workings of an information-stealing malware called Saintstealer that's designed to siphon credentials and system information. "After execution, the stealer extracts username, passwords, credit card details, etc.," Cyble researchers said in an analysis last week. "The stealer also steals data from various locations across the system and
https://thehackernews.com/2022/05/experts-detail-saintstealer-and-prynt.html?utm_source=dlvr.it&utm_medium=blogger

Another Set of Joker Trojan-Laced Android Apps Resurfaces on Google Play Store

A new set of trojanized apps spread via the Google Play Store has been observed distributing the notorious Joker malware on compromised Android devices. Joker, a repeat offender, refers to a class of harmful apps that are used for billing and SMS fraud, while also performing a number of actions of a malicious hacker's choice, such as stealing text messages, contact lists, and device information.
https://thehackernews.com/2022/05/another-set-of-joker-trojan-laced.html?utm_source=dlvr.it&utm_medium=blogger

Sunday, April 24, 2022

PTC and ITC Infotech expand partnership to accelerate customer digital transformation initiatives

This article has been indexed from Help Net Security PTC and ITC Infotech announced an agreement to accelerate customer digital transformation initiatives, focused on the adoption of PTC’s Windchill product lifecycle management (PLM) software as a service (SaaS). ITC Infotech… Read more → The post PTC and ITC Infotech expand partnership to accelerate customer digital transformation initiatives first appeared on IT Security News.
https://www.itsecuritynews.info/ptc-and-itc-infotech-expand-partnership-to-accelerate-customer-digital-transformation-initiatives/?utm_source=dlvr.it&utm_medium=blogger

Saturday, April 23, 2022

Dangerous malware is up 86%: Here’s how AI can help

This article has been indexed from Security – VentureBeat The need for AI-powered tools is only going to become more urgent as high-severity malware becomes more prevalent. Read the original article: Dangerous malware is up 86%: Here’s how AI can… Read more → The post Dangerous malware is up 86%: Here’s how AI can help first appeared on IT Security News.
https://www.itsecuritynews.info/dangerous-malware-is-up-86-heres-how-ai-can-help/?utm_source=dlvr.it&utm_medium=blogger

FBI Issues Warning as BlackCat Ransomware Targets More Than 60 Organizations Worldwide

This article has been indexed from CySecurity News – Latest Information Security and Hacking Incidents   An FBI flash alert released this week suggests that the law enforcement agency has identified at least 60 ransomware attacks worldwide by the BlackCat… Read more → The post FBI Issues Warning as BlackCat Ransomware Targets More Than 60 Organizations Worldwide first appeared on IT Security News.
https://www.itsecuritynews.info/fbi-issues-warning-as-blackcat-ransomware-targets-more-than-60-organizations-worldwide/?utm_source=dlvr.it&utm_medium=blogger

Stellar Repair for Exchange – Best Exchange Recovery Tool Admins Should Use in Vulnerability

Although you try to protect the Exchange Servers as much as possible, they still become a target of cyber attacks or ransomware attack. Such attacks can be mitigated by ensuring you have the right protection on your machine and the latest Exchange Server Cumulative Updates (CU) and patches are installed. When you get hit by […] The post Stellar Repair for Exchange – Best Exchange Recovery Tool Admins Should Use in Vulnerability appeared first on Cyber Security News.
https://cybersecuritynews.com/stellar-repair-for-exchange-best-exchange-recovery-tool-admins-should-use-in-vulnerability/?utm_source=dlvr.it&utm_medium=blogger

T-Mobile Admits Lapsus$ Hackers Gained Access to its Internal Tools and Source Code

This article has been indexed from The Hacker News Telecom company T-Mobile on Friday confirmed that it was the victim of a security breach in March after the LAPSUS$ mercenary gang managed to gain access to its networks. The acknowledgment… Read more → The post T-Mobile Admits Lapsus$ Hackers Gained Access to its Internal Tools and Source Code first appeared on IT Security News.
https://www.itsecuritynews.info/t-mobile-admits-lapsus-hackers-gained-access-to-its-internal-tools-and-source-code/?utm_source=dlvr.it&utm_medium=blogger