Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest Cybersecurity News

The Municipal Water Authority of Aliquippa was just one of multiple organizations breached in the U.S. by Iran-linked “Cyber Av3ngers” hackers

Members of Congress asked the U.S. Justice Department to investigate how foreign hackers breached a water authority near Pittsburgh, prompting CISA to warn other water and sewage-treatment utilities that they may be vulnerable.

Office supply retail giant confirms security incident disrupted online orders, communications channels and customer service lines.

Noteworthy stories that might have slipped under the radar: Utilities in US and Europe targeted in attacks, aerospace hacks, and Killnet leader unmasked.

New Turtle macOS ransomware is not sophisticated but shows that cybercriminals continue to target Apple devices.

The US has announced sanctions against North Korean cyberespionage group Kimsuky over its intelligence gathering activities. 

Researchers found that a ‘silly’ attack method could have been used to trick ChatGPT into handing over training data.

Apple’s security response team warns that flaws CVE-2023-42916 and CVE-2023-42917 were already exploited against versions of iOS before iOS 16.7.1.

Zyxel patches at least 15 security flaws that expose users to authentication bypass, command injection and denial-of-service attacks.

Meta removed three foreign influence operations from the Facebook platform during Q3, 2023. Two were Chinese in origin, and one was Russian, the company says. 

Qlik Sense vulnerabilities CVE-2023-41266, CVE-2023-41265 and CVE-2023-48365 exploited for initial access in Cactus ransomware attacks. 

The Black Basta ransomware group has infected over 300 victims and received more than $100 million in ransom payments.

US Treasury sanctions Sinbad, saying the cryptocurrency mixer is laundering funds for North Korean hacking group Lazarus.

Palo Alto Networks has launched a new rugged firewall for industrial environments and announced several OT security improvements.

ZeroedIn says personal information of 2 million individuals was compromised in an August 2023 data breach that impacts customers such as Dollar Tree.

Cyber Av3ngers hackers Cyber Av3ngers hackers

The Municipal Water Authority of Aliquippa was just one of multiple organizations breached in the U.S. by Iran-linked “Cyber Av3ngers” hackers

Unitronics PLC hacked Unitronics PLC hacked

Members of Congress asked the U.S. Justice Department to investigate how foreign hackers breached a water authority near Pittsburgh, prompting CISA to warn other water and sewage-treatment utilities that they may be vulnerable.

North Korea Kimsuky sanctioned North Korea Kimsuky sanctioned

The US has announced sanctions against North Korean cyberespionage group Kimsuky over its intelligence gathering activities. 

Top Cybersecurity Headlines

The Municipal Water Authority of Aliquippa was just one of multiple organizations breached in the U.S. by Iran-linked “Cyber Av3ngers” hackers

Members of Congress asked the U.S. Justice Department to investigate how foreign hackers breached a water authority near Pittsburgh, prompting CISA to warn other…

Office supply retail giant confirms security incident disrupted online orders, communications channels and customer service lines.

Noteworthy stories that might have slipped under the radar: Utilities in US and Europe targeted in attacks, aerospace hacks, and Killnet leader unmasked.

SecurityWeek Industry Experts

More Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join us as we delve into the transformative potential of AI, predictive ChatGPT-like tools and automation to detect and defend against cyberattacks.

Register

Join Microsoft and Finite State for a webinar that will introduce a new strategy for securing the software supply chain.

Watch Now

Upcoming Virtual Events

CISOs and risk management leaders must understand clearly the role of cyber insurance in a robust security program, ongoing changes to premiums and policy pricing, the errors that could deny coverage and how it all fits into global incident response planning.

Learn More
Cyber AI & Automation Summit

SecurityWeek’s inaugural Cyber AI & Automation Summit pushes the boundaries of security discussions by exploring the implications and applications of predictive AI, machine learning, and automation in modern cybersecurity programs.

Learn More

Designed for senior level cybersecurity leaders to discuss, share and learn innovative information security and risk management strategies, SecurityWeek’s CISO Forum, will take place in 2023 as a virtual event. (June 13-14, 2023)

Learn More

As CISOs and corporate defenders grapple with the intricacies of securing sensitive data passing through multi-cloud deployments and APIs, the importance of frameworks, tools, controls and design models have surfaced to the front burner. (July 19, 2023)

Learn More

Vulnerabilities

Cybercrime

SAN FRANCISCO – RSA CONFERENCE 2012 – Organizations with large and disparate IT systems are often challenged in dealing with vulnerability management initiatives and determining what order vulnerabilities should be addressed in order to more effectively improve their risk posture.

According to the results of a study released today by Websense, the Bring-Your-Own-Device phenomenon is growing, and with the trend, employees are often circumventing corporate security policies. The results showed that seventy-seven percent of the 4,000 people interviewed said that mobile devices are mission critical when it comes to getting work done, but within that same group 76-percent believe that their mission critical devices place the organization at risk.

SAN FRANCISCO -- RSA CONFERENCE 2012 -- Tufin Technologies, a company that offers solutions for automated security policy management and risk mitigation, released the results of a quick survey this week, after speaking to 100 network managers on the topic of recently announced updates to the EU’s Data Protection legislation.

SAN FRANCISCO – RSA CONFERENCE 2012 – EMC today announced the availability of five new security and risk management advisory services designed to help organizations improve levels of trust and control for next-generation IT infrastructures such as cloud, virtualization, and mobile.

SAN FRANCISCO - RSA Conference 2012 – FireEye announced the release of a new appliance that will detect and remove malware introduced to the network through Web mail, FTP, personal storage, and other means.Called File Malware Protection System (MPS), the new offering complements FireEye’s existing MPS line, which includes Email MPS and Web MPS.

SAN FRANCISCO – RSA CONFERENCE 2012 - Bit9, the company best known for its application whitelisting technology, today announced a platform that the company says will help protect all enterprise endpoints, servers and private clouds from cyber-attacks that often make their way past other anti-virus and behavioral security solutions.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

Aikido Security has raised €5 million (~$5.4 million) in seed funding for an all-in-one application security platform.

Cloud Security