Information security

[ follow ]
critical-infrastructure
CyberScoop
3 days ago
Information security

Pro-Russia hacktivists attacking vital tech in water and other sectors, agencies say

Pro-Russia hacktivists target critical infrastructure sectors in North America and Europe, exploiting cybersecurity weaknesses and causing physical threats. [ more ]
euronews
1 day ago
Information security

'Cyberwarriors' prepare against attacks during Paris Olympics

France anticipates increased cyber threats during the upcoming Paris Olympic Games, particularly from Russian actors. [ more ]
CyberScoop
3 days ago
Information security

CISA's incident reporting requirements go too far, trade groups and lawmakers say

The draft rule for cyber incident reporting may be too burdensome for critical infrastructure entities and for the agency itself. [ more ]
morecritical-infrastructure
ITPro
1 day ago
Information security

Security agencies warn of heightened threat to critical national infrastructure

Hacktivists target ICS in North America and Europe with potential physical threats, utilizing unsophisticated techniques initially. [ more ]
gitlab
Developer Tech News
2 days ago
Information security

CISA sounds alarm on critical GitLab flaw under active exploit

Organizations should promptly apply security updates in response to active exploitation attempts. [ more ]
ComputerWeekly.com
1 day ago
Information security

Patch GitLab vuln without delay, users warned | Computer Weekly

Prompt patching of CVE-2023-7028 vulnerability in GitLab is essential to prevent account takeover and potential cyber threats. [ more ]
moregitlab
The Verge
1 day ago
Information security

Microsoft overhaul treats security as "top priority" after a series of failures

Microsoft is prioritizing security by tying it to compensation for senior leadership. [ more ]
TechRepublic
1 day ago
Information security

U.K. and U.S. Warn of Pro-Russia Hacktivist Attacks on Operational Technology Systems

Pro-Russia hacktivists are targeting providers of operational technology like smart water meters and dam monitoring systems in North America and Europe. [ more ]
Theregister
2 days ago
Information security

Federal frenzy to patch gaping security hole in GitLab

CISA mandates federal agencies to patch critical GitLab vulnerability under active exploitation. [ more ]
Ars Technica
2 days ago
Information security

0-click GitLab hijacking flaw under active exploit, with thousands still unpatched

A maximum severity vulnerability in GitLab allows account hijacking without user interaction. [ more ]
CyberScoop
3 days ago
Information security

How to fine-tune the White House's new critical infrastructure directive

Biden administration updated federal infrastructure protection policy via NSM-22, linking it to modern cyber threat landscape, but fell short by not including space and cloud industries. [ more ]
ITPro
1 day ago
Information security

Hackers are exploiting critical GitLab password reset vulnerability - here's what you need to know

CISA warns of actively exploited GitLab vulnerability CVE-2023-7028, urging swift remediation to prevent potential account hijacking. [ more ]
ComputerWeekly.com
2 days ago
Information security

NCSC updates warning over hacktivist threat to CNI | Computer Weekly

Russia-backed hacktivist groups targeting critical infrastructure with unsophisticated attacks.
NCSC and CISA warning about evolving threats from hacktivist groups not officially backed by the Kremlin. [ more ]
Nextgov.com
2 days ago
Information security

House cyber chairman tries again to undo SEC cyber disclosure rules

Rep. Andrew Garbarino aims to dissolve SEC cybersecurity incident disclosure rule, favoring Cybersecurity and Infrastructure Security Agency for handling such disclosures. [ more ]
Engadget
2 days ago
Information security

Microsoft's latest Windows security updates might break your VPN

Windows April security updates may cause VPN issues, prompting users to uninstall updates as a temporary workaround. [ more ]
CyberScoop
2 days ago
Information security

Iranian hackers impersonate journalists in social engineering campaign

Iranian hackers linked to Revolutionary Guard impersonated journalists and human rights groups for phishing attacks. [ more ]
Ars Technica
1 day ago
Information security

Microsoft ties executive pay to security following multiple failures and breaches

Microsoft faced major security breaches resulting in data exposure and criticism. The company is taking steps to improve its security practices and prioritize security as the top concern. [ more ]
ComputerWeekly.com
1 day ago
Information security

EU calls out Fancy Bear over attacks on Czech, German governments | Computer Weekly

The EU and member states condemn Russian cyber attacks by Fancy Bear. [ more ]
CyberScoop
3 days ago
Information security

Data stolen in Change Healthcare attack likely included U.S. service members, executive says

UnitedHealth Group CEO revealed data breach involving U.S. military personnel.
Delay in notifying affected individuals poses challenges for health data protection. [ more ]
ComputerWeekly.com
2 days ago
Information security

Dropbox Sign user information accessed in data breach | Computer Weekly

Dropbox Sign (formerly HelloSign) faced a data breach leading to unauthorized access to customer data, prompting security measures and notifications to impacted users. [ more ]
ITPro
2 days ago
Information security

The Dropbox data breach is a classic case of "breach by acquisition"

Breaches through acquisitions can expose organizations to unknown vulnerabilities. [ more ]
Theregister
3 days ago
Information security

Dropbox warns of attack that leaked customers' personal info

Dropbox faced a major cyber attack on its Dropbox Sign service resulting in unauthorized access to personal information including email addresses, usernames, phone numbers, hashed passwords, and authentication information. [ more ]
TechCrunch
3 days ago
Information security

United HealthCare CEO says 'maybe a third' of U.S. citizens were affected by recent hack | TechCrunch

The cyberattack on Change Healthcare systems impacted a substantial number of Americans, with uncertainty about the exact extent of the breach. [ more ]
The Verge
3 days ago
Information security

UnitedHealth CEO admits it paid $22 million ransom to BlackCat

CEO Andrew Witty confirmed paying a $22 million ransom to hackers for data breach, facing criticism and calls for better cybersecurity measures. [ more ]
www.aljazeera.com
1 day ago
Information security

Germany accuses Russia of intolerable' cyberattack, warns of consequences

Germany attributes cyberattack on SPD to Russia's APT28, military intelligence service. [ more ]
Coindesk
1 day ago
Information security

Exploiter Steals $68M Worth of Crypto Through Address Poisoning

A user lost $68 million worth of wrapped bitcoin due to address poisoning. [ more ]
WIRED
14 hours ago
Information security

A New Surveillance Tool Invades Border Towns

Yahoo Boys operate openly on social platforms engaging in various criminal activities. [ more ]
Theregister
2 days ago
Information security

Four critical bugs in ArubaOS lead to remote code execution

Network admins should patch critical vulnerabilities in ArubaOS immediately to avoid remote code execution by privilege escalation. [ more ]
Theregister
1 day ago
Information security

Software supply chain security still in early days, says CEO

Software supply chain vulnerabilities are increasing due to reliance on untrusted sources, requiring better management and vetting processes. [ more ]
Theregister
2 days ago
Information security

More than two dozen Android vulnerabilities fixed

Oversecured identified over two dozen vulnerabilities in Xiaomi and Google's Android Open Source Project over the past years. [ more ]
Nextgov.com
2 days ago
Information security

US warns of North Korean hackers using email security flaws for phishing attacks

North Korean hacking group Kimsuky exploits email security flaws for phishing attacks on organizations.
Proper configuration of email security protocols, such as DMARC, is crucial in preventing phishing attempts and spoofing. [ more ]
DevOps.com
2 days ago
Information security

LayerX Security Raises $24M for its Browser Security Platform, Enabling Employees to Work Securely from Any Browser, Anywhere - DevOps.com

LayerX secures users with innovative browser security solution for enterprises. [ more ]
TechCrunch
1 day ago
Information security

UnitedHealth data breach should be a wakeup call for the UK and NHS | TechCrunch

Ransomware attack on UnitedHealth Group highlights the risk of entrusting sensitive data to companies with irresponsible data protection practices. [ more ]
ITPro
1 day ago
Information security

Three million Docker Hub repositories are being used to spread malware

Three million Docker Hub repositories impacted by malware campaigns since 2021. [ more ]
CyberScoop
1 day ago
Information security

Microsoft organizational changes seek to address security failures

Microsoft ties executive compensation to security targets and prioritizes security over new features to address recent breaches. [ more ]
Engadget
2 days ago
Information security

You can finally use passkeys to sign into your Microsoft account

Microsoft has introduced consumer passkey support for Microsoft accounts, following Apple and Google, making sign-ins easier and more secure. [ more ]
Theregister
1 day ago
Information security

Chinese government website security has big problems

Chinese researchers found vulnerabilities in Chinese government websites, including DNS configuration lapses and a notable dependence on a few DNS service providers. [ more ]
ITPro
1 day ago
Information security

Nearly half of EMEA data breaches were due to internal blunders in 2023

Almost half of EMEA data breaches are internal. Human error is a significant factor. Zero-day vulnerabilities are increasing, with ransomware exploiting them. [ more ]
TechRepublic
2 days ago
Information security

4 IoT Trends U.K. Businesses Should Watch in 2024

Compliance with the PSTI Act is crucial for IoT security and innovation in the U.K. [ more ]
Ars Technica
2 days ago
Information security

April updates for Windows 10 and 11 break some VPN software, Microsoft says

Microsoft is investigating a bug in recent Windows updates affecting VPN software. [ more ]
www.independent.co.uk
1 day ago
Information security

French cyberwarriors ready to test their defense against hackers and malware during the Olympics

Cybersecurity preparations for the Paris Olympics are in full swing, focusing on defending against a wide range of potential attackers and scenarios. [ more ]
InfoQ
2 days ago
Information security

Understanding Email Threats with Cloudflare Radar

Cloudflare launched Email Security section on Cloudflare Radar, offering insights into email security trends and real-time visibility into threats. [ more ]
TechCrunch
2 days ago
Information security

Google brings passkey support to its Advanced Protection Program ahead of the US presidential election | TechCrunch

Google is introducing passkey support for its Advanced Protection Program, offering an additional security option for high-risk users like campaign workers and journalists. [ more ]
Read Satya Nadella’s Microsoft memo on putting security first.

Security is now Microsoft’s “top priority.” https://t.co/k8EbSfLGWQ
The Verge
1 day ago
Information security

Read Satya Nadella's Microsoft memo on putting security first

Prioritize security above all else for the company's success, with a focus on the Secure Future Initiative (SFI) principles. [ more ]
The Verge
1 day ago
Information security

Read Satya Nadella's Microsoft memo on putting security first

Prioritize security above all else for the company's success, with a focus on the Secure Future Initiative (SFI) principles. [ more ]
The Verge
2 days ago
Information security

Microsoft launches passkey support for all consumer accounts

Microsoft introduces passkey support for all consumer accounts, enabling easier login without passwords across devices. [ more ]
Graham Cluley
3 days ago
Information security

Smashing Security podcast #370: The closed loop conundrum, default passwords, and Baby Reindeer

The 'Smashing Security' podcast episode covers cybersecurity, online privacy, IoT weaknesses, identity theft, and scams. [ more ]
Ars Technica
1 day ago
Information security

Microsoft plans to lock down Windows DNS like never before. Here's how.

ZTDNS aims to address security risks in DNS by encrypting connections and allowing strict control over resolved domains within Windows networks. [ more ]
ITPro
2 days ago
Information security

Preventing deepfake attacks: How businesses can stay protected

Deepfake technology is increasingly used in fraudulent activities, posing a significant threat to businesses. [ more ]
Theregister
2 days ago
Information security

Microsoft, Google do a victory lap around passkeys

Microsoft introduces passkey support for consumer accounts as a step towards a password-free world. [ more ]
ITPro
1 day ago
Information security

April rundown: Ransomware revenants and 'open source' AI

April highlighted AWS legal issues, a ransomware attack on Change Healthcare, and advancements in AI like Llama 3. [ more ]
Los Angeles Times
2 days ago
Information security

Panda Express is the latest to be hacked. What to do when your personal data are exposed

Companies collecting even mundane information can be targeted by hackers, leading to data breaches and potential misuse of personal data. [ more ]
ReadWrite
1 day ago
Information security

Microsoft to make signing in easier with passkeys - here's how it works

Microsoft is introducing Passkeys to replace passwords for consumer accounts. [ more ]
TechRepublic
3 days ago
Information security

10 Ways to Build an Effective Online Presence for Your Business | TechRepublic

Leverage social media strategically for effective online presence. [ more ]
TechRepublic
1 day ago
Information security

Top 5 Global Cyber Security Trends of 2023, According to Google Report

It is taking less time for organisations to detect attackers in their environment, a report by Mandiant Consulting, a part of Google Cloud, has found.
ComputerWeekly.com
1 day ago
Information security

Optimising application connections, improving security posture top SD-WAN priorities | Computer Weekly

80% of businesses evolve SD-WAN offerings every two years due to complexity, risk, and pace of innovation. [ more ]
Theregister
1 day ago
Information security

Microsoft won't be fixing Windows Recovery Environment error

Microsoft will not provide an automatic resolution for a Windows 10 issue related to a BitLocker security vulnerability patch, requiring manual steps for affected users. [ more ]
ComputerWeekly.com
2 days ago
Information security

Palo Alto Networks claims to raise bar on SASE | Computer Weekly

Enhanced Prisma SASE 3.0 version aims to future-proof workforce by delivering zero-trust capability, AI-powered data security, and 5x faster application performance. [ more ]
www.npr.org
1 day ago
Information security

Biden tries get tougher on border security without alienating immigrant communities

The White House is shoring up defenses on one of its most sensitive issues: immigration.
Biden is trying to balance border security while protecting vulnerable undocumented immigrants in the U.S.
The Verge
2 days ago
Information security

Over 400 million Google accounts have used passkeys but our passwordless future remains elusive

Google introduced passkeys as a more secure alternative for user authentication, simplifying the login process and proving faster than traditional passwords. [ more ]
Theregister
2 days ago
Information security

NTLM auth traffic spikes after Windows Server patch

Microsoft's April 2024 security update caused a significant increase in NTLM authentication traffic on Windows Server. [ more ]
Engadget
2 days ago
Information security

Google says its secure entry passkeys have been used a billion times

Passkeys are faster and more secure than passwords, used by over one billion times by 400 million Google accounts. [ more ]
ITPro
2 days ago
Information security

C-suite to cyber pros: Try and tone down the technical jargon

Lack of understanding and communication between executives, boards, and security professionals leaves security vulnerable. [ more ]
TechCrunch
2 days ago
Information security

Digital fraud detection startup BioCatch hits $1.3B valuation as Permira buys majority stake | TechCrunch

BioCatch's new majority shareholder Permira acquires shares, valuing the company at $1.3 billion. Existing shareholders like Sapphire Ventures also increase their stake.
The cybersecurity industry sees significant private equity deals, such as Thoma Bravo acquiring Darktrace. Permira plans to bring growth and expand BioCatch across Europe. [ more ]
Coindesk
2 days ago
Information security

Rabotnik, Affiliate of Ransomware Group REvil, Sentenced to 13 Years in Jail

Rabotnik, a member of the REvil ransomware group, sentenced to 13 years and seven months in jail. [ more ]
The Verge
2 days ago
Information security

Microsoft investigating VPN issues with latest Windows 11 update

Microsoft says it's investigating VPN connection errors related to the April 2024 security patch for Windows 11.
It comes nearly a year after a similar bug.
Ars Technica
3 days ago
Information security

Hacker free-for-all fights for control of home and office routers everywhere

Financially motivated hackers and state-sponsored cyber actors share and coexist in compromised routers for covert attacks. [ more ]
South China Morning Post
2 days ago
Information security

Hong Kong watchdog suffered cyberattack due to lack of security measures: report

Chung mainly attributed the cyberattack to a failure to introduce a multi-step authentication system for the remote access of data.
ITPro
2 days ago
Information security

UK councils are paying out a fortune in data breach claims

(Image credit: Getty Images)
UK Councils are forking out tens of thousands of pounds in data breach claims, freedom of information requests have revealed.
Nextgov.com
3 days ago
Information security

NASA doesn't know if its spacecraft have adequate cyber defenses, GAO warns

NASA needs mandatory cybersecurity guidelines for spacecraft acquisition policies. [ more ]
Theregister
2 days ago
Information security

REvil ransomware perp sentenced to almost 14 years jail

A Ukrainian man has been sentenced to almost 14 years in prison and ordered to pay more than $16 million in restitution for his role in infecting thousands of victims with REvil ransomware.
Mail Online
3 days ago
Information security

Android users warned fake Chrome update could drain your bank account

Brokewell is a new banking malware targeting Android users, posing as Google Chrome and other popular applications, capable of spying on users and stealing sensitive information. [ more ]
The Verge
3 days ago
Information security

AI security bill aims to prevent safety breaches of AI models

A new bill, the Secure Artificial Intelligence Act, aims to establish a database to track AI system breaches and focus on counter-AI techniques. [ more ]
Nextgov.com
3 days ago
Information security

UnitedHealth CEO grilled over 'clear national security threat' from Change Healthcare hack

Senators questioned UnitedHealth CEO on recent ransomware cyberattack. [ more ]
ComputerWeekly.com
3 days ago
Information security

EMEA CISOs must address human factors behind cyber incidents | Computer Weekly

Organizations in EMEA need to address human factors in data breaches, with 87% attributed to human errors, system intrusion, and social engineering. [ more ]
CyberScoop
3 days ago
Information security

Exploitation of vulnerabilities almost tripled as a source of data breaches last year

Attacks exploiting vulnerabilities increased by 180% driven by MOVEit hack. [ more ]
CyberScoop
4 days ago
Information security

Easterly appeals to Congress on CISA funding, citing Chinese threats to critical infrastructure

More funding is crucial for CISA to enhance cybersecurity defense, particularly against Chinese hackers in critical infrastructure. [ more ]
[ Load more ]