The UK Cyber Security Councilv has launched the first phase of its certification mapping tool. It has been created to map all available cyber security certifications onto the 16 specialisms identified by the Council, with the first phase now available.…
Read more →
The post UK Cyber Security Council launches certification mapping tool first appeared on IT Security News.
https://www.itsecuritynews.info/uk-cyber-security-council-launches-certification-mapping-tool/?utm_source=dlvr.it&utm_medium=blogger
Sunday, April 30, 2023
Saturday, April 29, 2023
Tonto Team Uses Anti-Malware File to Launch Attacks on South Korean Institutions
South Korean education, construction, diplomatic, and political institutions are at the receiving end of new attacks perpetrated by a China-aligned threat actor known as the Tonto Team.
"Recent cases have revealed that the group is using a file related to anti-malware products to ultimately execute their malicious attacks," the AhnLab Security Emergency Response Center (ASEC) said in a report
https://thehackernews.com/2023/04/tonto-team-uses-anti-malware-file-to.html?utm_source=dlvr.it&utm_medium=blogger
https://thehackernews.com/2023/04/tonto-team-uses-anti-malware-file-to.html?utm_source=dlvr.it&utm_medium=blogger
Friday, April 28, 2023
RTM Locker's First Linux Ransomware Strain Targeting NAS and ESXi Hosts
The threat actors behind RTM Locker have developed a ransomware strain that's capable of targeting Linux machines, marking the group's first foray into the open source operating system.
"Its locker ransomware infects Linux, NAS, and ESXi hosts and appears to be inspired by Babuk ransomware's leaked source code," Uptycs said in a new report published Wednesday. "It uses a combination of ECDH on
https://thehackernews.com/2023/04/rtm-lockers-first-linux-ransomware.html?utm_source=dlvr.it&utm_medium=blogger
https://thehackernews.com/2023/04/rtm-lockers-first-linux-ransomware.html?utm_source=dlvr.it&utm_medium=blogger
Microsoft Confirms PaperCut Servers Used to Deliver LockBit and Cl0p Ransomware
Microsoft has confirmed that the active exploitation of PaperCut servers is linked to attacks that are designed to deliver Cl0p and LockBit ransomware families.
The tech giant's threat intelligence team is attributing a subset of the intrusions to a financially motivated actor it tracks under the name Lace Tempest (formerly DEV-0950), which overlaps with other hacking groups like FIN11, TA505,
https://thehackernews.com/2023/04/microsoft-confirms-papercut-servers.html?utm_source=dlvr.it&utm_medium=blogger
https://thehackernews.com/2023/04/microsoft-confirms-papercut-servers.html?utm_source=dlvr.it&utm_medium=blogger
Thursday, April 27, 2023
VMware Releases Critical Patches for Workstation and Fusion Software
VMware has released updates to resolve multiple security flaws impacting its Workstation and Fusion software, the most critical of which could allow a local attacker to achieve code execution.
The vulnerability, tracked as CVE-2023-20869 (CVSS score: 9.3), is described as a stack-based buffer-overflow vulnerability that resides in the functionality for sharing host Bluetooth devices with the
https://thehackernews.com/2023/04/vmware-releases-critical-patches-for.html?utm_source=dlvr.it&utm_medium=blogger
https://thehackernews.com/2023/04/vmware-releases-critical-patches-for.html?utm_source=dlvr.it&utm_medium=blogger
Wednesday, April 26, 2023
Google Cloud Introduces Security AI Workbench for Faster Threat Detection and Analysis
Google's cloud division is following in the footsteps of Microsoft with the launch of Security AI Workbench that leverages generative AI models to gain better visibility into the threat landscape.
Powering the cybersecurity suite is Sec-PaLM, a specialized large language model (LLM) that's "fine-tuned for security use cases."
The idea is to take advantage of the latest advances in AI to augment
https://thehackernews.com/2023/04/google-cloud-introduces-security-ai.html?utm_source=dlvr.it&utm_medium=blogger
https://thehackernews.com/2023/04/google-cloud-introduces-security-ai.html?utm_source=dlvr.it&utm_medium=blogger
Tuesday, April 25, 2023
Hackers Exploit Outdated WordPress Plugin to Backdoor Thousands of WordPress Sites
Threat actors have been observed leveraging a legitimate but outdated WordPress plugin to surreptitiously backdoor websites as part of an ongoing campaign, Sucuri revealed in a report published last week.
The plugin in question is Eval PHP, released by a developer named flashpixx. It allows users to insert PHP code pages and posts of WordPress sites that's then executed every time the posts are
https://thehackernews.com/2023/04/hackers-exploit-outdated-wordpress.html?utm_source=dlvr.it&utm_medium=blogger
https://thehackernews.com/2023/04/hackers-exploit-outdated-wordpress.html?utm_source=dlvr.it&utm_medium=blogger
Monday, April 24, 2023
Russian Hackers Suspected in Ongoing Exploitation of Unpatched PaperCut Servers
Print management software provider PaperCut said that it has "evidence to suggest that unpatched servers are being exploited in the wild," citing two vulnerability reports from cybersecurity company Trend Micro.
"PaperCut has conducted analysis on all customer reports, and the earliest signature of suspicious activity on a customer server potentially linked to this vulnerability is 14th April 01
https://thehackernews.com/2023/04/russian-hackers-suspected-in-ongoing.html?utm_source=dlvr.it&utm_medium=blogger
https://thehackernews.com/2023/04/russian-hackers-suspected-in-ongoing.html?utm_source=dlvr.it&utm_medium=blogger
Sunday, April 23, 2023
IT Security News Daily Summary 2023-04-22
The Current State of Wireless (In)security, by Bastille CTO ChatGPT Can be Tricked To Write Malware When You Act as a Developer Mode CISA adds MinIO, PaperCut, and Chrome bugs to its Known Exploited Vulnerabilities catalog DNS Malware Toolkit Discovered…
Read more →
The post IT Security News Daily Summary 2023-04-22 first appeared on IT Security News.
https://www.itsecuritynews.info/it-security-news-daily-summary-2023-04-22/?utm_source=dlvr.it&utm_medium=blogger
https://www.itsecuritynews.info/it-security-news-daily-summary-2023-04-22/?utm_source=dlvr.it&utm_medium=blogger
The Current State of Wireless (In)security, by Bastille CTO
Guest Editorial by Brett T. Walkenhorst, Ph.D., CTO, Bastille From cell phones and Wi-Fi to wearables, peripherals, and IoT, the modern world is swimming in wireless devices, and their wireless data is constantly racing through the air all around us.…
Read more →
The post The Current State of Wireless (In)security, by Bastille CTO first appeared on IT Security News.
https://www.itsecuritynews.info/the-current-state-of-wireless-insecurity-by-bastille-cto/?utm_source=dlvr.it&utm_medium=blogger
https://www.itsecuritynews.info/the-current-state-of-wireless-insecurity-by-bastille-cto/?utm_source=dlvr.it&utm_medium=blogger
Subscribe to:
Posts (Atom)




.jpg)


