Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

The cybercriminals behind the ransomware known as Maze claim to have breached the systems of LG Electronics and obtained highly sensitive information.The operators of the Maze ransomware are known for targeting major organizations and not only encrypting their files, but also stealing files and threatening to make them public unless a ransom is paid.

Morocco said Wednesday it is investigating a journalist for receiving "foreign funding" for "intelligence services" days after rights group Amnesty alleged the government had used Israeli spyware to bug his phone.

Apple has acquired Fleetsmith, a San Francisco-based company that specializes in solutions designed to help organizations manage the Apple devices used by their employees.Fleetsmith’s enterprise device management solution automates setup, patching, intelligence and security for Macs, iPhones, iPads and Apple TV devices.

Akamai on Thursday revealed that it mitigated a second record-setting distributed denial-of-service (DDoS) attack since the beginning of June, one that peaked at 809 MPPS (million packets per second).

WikiLeaks founder Julian Assange sought to recruit hackers at conferences in Europe and Asia who could provide his anti-secrecy website with classified information, and conspired with members of hacking organizations, according to a new Justice Department indictment announced Wednesday.

Google is tweaking its privacy settings to keep less data on new users by default.The search giant said that starting Wednesday, it will automatically and continuously delete web and app activity and location history for new users after 18 months.

The threat actor behind the Sodinokibi ransomware was observed scanning the victim networks for credit card or point of sale (POS) software.Sodinokibi, Symantec’s security researchers reveal, was found on the networks of three organizations that had been previously infected with the Cobalt Strike commodity malware.

Cyber security is described as a form of asymmetric warfare. One side, the defenders, have limited numbers -- just the security team. The other side includes every blackhat hacker in the world -- that is, many, many thousands. The blackhats only need to succeed once; the defenders need to succeed many times every day. Bugcrowd seeks to reverse this impossible mathematics.

The need for improved access control is proven by empirical observation -- it keeps failing. But improving access control beyond passwords suffers from a fundamental contradiction: while 98% of companies believe strong authentication is necessary for secure cloud adoption, 41% believe the username/password combination is one of the most effective access management tools, and 58% allow their employees to log on to corporate resources via social media credentials.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.

Cloud Security

Cloud Security

A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities.

ICS/OT

ICS/OT

The attack caused real-world operational disruption and raised concerns about the resilience of Britain’s distributed energy infrastructure and the potential for repeatable attacks.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.