Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

An alert the U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) published this week reiterates previously issued recommendations on how organizations should properly secure Microsoft Office 365 deployments.

A memorandum sent by the United States Cybersecurity and Infrastructure Security Agency (CISA) to Chief Information Officers (CIOs) at federal agencies reminds them to use EINSTEIN 3 Accelerated (E3A)’s Domain Name System (DNS) sinkholing capability for DNS resolution.

Individuals and criminal organizations have taken immediate advantage of the COVID-19 pandemic to find new ways of making money, the European Union’s law enforcement agency said Thursday, citing a spike in counterfeiting and cybercrime.

Google said Thursday its task force devoted to fighting "bad" ads hawking bogus coronavirus cures, illegitimate unemployment benefits and overpriced medical supplies had blocked tens of millions of messages.

American education technology company Chegg this week sent notifications to its employees to inform them of a data breach that occurred earlier this month.Based in Santa Clara, California, Chegg offers various student services, including digital and physical textbook rentals and online tutoring, and has more than three million subscribers.

YARA 4.0.0 was released on Wednesday with some important new features and performance improvements.YARA is a highly popular open source tool designed to help researchers identify and classify malware samples. It has been described as “the pattern-matching swiss knife for malware researchers.”

Ransomware Capabilities Added to 'Lucy' Android MalwareA piece of Android ransomware uses a scareware tactic to extort money from victims: it asks them to provide their credit card information to pay a “fine,” Check Point reveals.

Google this week announced a new set of rules for its Chrome Web Store, meant to ensure that developers don’t spam users with extensions that have similar functionality.The Chrome Web Store has been available since 2011, offering a total of more than 200.000 browser extensions that allow users to easily customize their browsing experience in Chrome.

The Salt community has been aware of a critical vulnerability in Salt Master versions since late last week. It was informed that the vulnerability has a CVSS rating of 10.0, that Salt Masters should not be exposed to the internet, and that fixes would be released this week.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.

Cloud Security

Cloud Security

A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities.

ICS/OT

ICS/OT

The attack caused real-world operational disruption and raised concerns about the resilience of Britain’s distributed energy infrastructure and the potential for repeatable attacks.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.