SecurityWeek

‘WallEscape’ Linux Vulnerability Leaks User Passwords

Security Week - Mon, 04/01/2024 - 12:06pm

A vulnerability in util-linux, a core utilities package in Linux systems, allows attackers to leak user passwords and modify the clipboard.

The post ‘WallEscape’ Linux Vulnerability Leaks User Passwords appeared first on SecurityWeek.

Categories: SecurityWeek

‘Vultur’ Android Malware Gets Extensive Device Interaction Capabilities

Security Week - Mon, 04/01/2024 - 11:52am

NCC Group researchers warn that the Android banking malware ‘Vultur’ has been updated with device interaction and file tampering capabilities.

The post ‘Vultur’ Android Malware Gets Extensive Device Interaction Capabilities appeared first on SecurityWeek.

Categories: SecurityWeek

AI Hallucinated Packages Fool Unsuspecting Developers

Security Week - Mon, 04/01/2024 - 10:26am

Software developers relying on AI chatbots for building applications may end up using hallucinated software packages.

The post AI Hallucinated Packages Fool Unsuspecting Developers appeared first on SecurityWeek.

Categories: SecurityWeek

Supply Chain Attack: Major Linux Distributions Impacted by XZ Utils Backdoor

Security Week - Mon, 04/01/2024 - 9:05am

Urgent security alerts issued as malicious code was found embedded in the XZ Utils data compression library used in many Linux distributions.

The post Supply Chain Attack: Major Linux Distributions Impacted by XZ Utils Backdoor appeared first on SecurityWeek.

Categories: SecurityWeek

AT&T Says Data on 73 Million Customers Leaked on Dark Web

Security Week - Sat, 03/30/2024 - 10:32pm

AT&T used the Easter holiday weekend to quietly share details on data that surfaced on the dark web roughly two weeks ago.

The post AT&T Says Data on 73 Million Customers Leaked on Dark Web appeared first on SecurityWeek.

Categories: SecurityWeek

SydeLabs Emerges From Stealth Mode With $2.5 Million in Funding

Security Week - Fri, 03/29/2024 - 10:13am

Generative-AI security startup SydeLabs emerges from stealth mode with $2.5 million in seed funding led by RTP Global.

The post SydeLabs Emerges From Stealth Mode With $2.5 Million in Funding appeared first on SecurityWeek.

Categories: SecurityWeek

In Other News: Airline Privacy Review, SEC’s SolarWinds Hack Probe, Apple MFA Bombing

Security Week - Fri, 03/29/2024 - 9:52am

Noteworthy stories that might have slipped under the radar: US government conducting airline privacy review, SEC’s overreaching SolarWinds hack probe, MFA bombing of Apple users.

The post In Other News: Airline Privacy Review, SEC’s SolarWinds Hack Probe, Apple MFA Bombing appeared first on SecurityWeek.

Categories: SecurityWeek

Pentagon Outlines Cybersecurity Strategy for Defense Industrial Base 

Security Week - Fri, 03/29/2024 - 8:43am

US Defense Department releases defense industrial base cybersecurity strategy with a focus on four key goals.

The post Pentagon Outlines Cybersecurity Strategy for Defense Industrial Base  appeared first on SecurityWeek.

Categories: SecurityWeek

The Complexity and Need to Manage Mental Well-Being in the Security Team

Security Week - Fri, 03/29/2024 - 8:12am

It is the CISO’s responsibility to build and maintain a high functioning team in a difficult environment – cybersecurity is a complex, continuous, and adversarial environment like none other outside of military conflict.

The post The Complexity and Need to Manage Mental Well-Being in the Security Team appeared first on SecurityWeek.

Categories: SecurityWeek

Energy Department Invests $15 Million in University Cybersecurity Centers 

Security Week - Fri, 03/29/2024 - 7:34am

The US Department of Energy announces $15 million funding for university-based electric power cybersecurity centers.

The post Energy Department Invests $15 Million in University Cybersecurity Centers  appeared first on SecurityWeek.

Categories: SecurityWeek

Massachusetts Health Insurer Data Breach Impacts 2.8 Million

Security Week - Fri, 03/29/2024 - 7:01am

Harvard Pilgrim Health Care says the personal information of over 2.8 million individuals was stolen in a year-old ransomware attack.

The post Massachusetts Health Insurer Data Breach Impacts 2.8 Million appeared first on SecurityWeek.

Categories: SecurityWeek

26 Security Issues Patched in TeamCity

Security Week - Fri, 03/29/2024 - 6:45am

JetBrains patches 26 security issues in TeamCity and takes steps to avoid malicious exploitation of vulnerabilities.

The post 26 Security Issues Patched in TeamCity appeared first on SecurityWeek.

Categories: SecurityWeek

VP Harris Says US Agencies Must Show Their AI Tools Aren’t Harming People’s Safety or Rights

Security Week - Thu, 03/28/2024 - 8:21pm

U.S. federal agencies must show that their artificial intelligence tools aren’t harming the public, or stop using them, under new rules unveiled by the White House on Thursday. “When government agencies use AI tools, we will now require them to verify that those tools do not endanger the rights and safety of the American people,” […]

The post VP Harris Says US Agencies Must Show Their AI Tools Aren’t Harming People’s Safety or Rights appeared first on SecurityWeek.

Categories: SecurityWeek

Malware Upload Attack Hits PyPI Repository

Security Week - Thu, 03/28/2024 - 1:45pm

Maintainers of the Python Package Index (PyPI) repository were forced to suspend new project creation and new user registration to mitigate a malware upload campaign.

The post Malware Upload Attack Hits PyPI Repository appeared first on SecurityWeek.

Categories: SecurityWeek

Splunk Patches Vulnerabilities in Enterprise Product

Security Week - Thu, 03/28/2024 - 11:21am

Splunk patches high-severity vulnerabilities in Enterprise, including an authentication token exposure issue.

The post Splunk Patches Vulnerabilities in Enterprise Product appeared first on SecurityWeek.

Categories: SecurityWeek

Cybersecurity Mesh: Overcoming Data Security Overload

Security Week - Thu, 03/28/2024 - 11:07am

A significant cybersecurity challenge arises from managing the immense volume of data generated by numerous IT security tools, leading organizations into a reactive rather than proactive approach.

The post Cybersecurity Mesh: Overcoming Data Security Overload appeared first on SecurityWeek.

Categories: SecurityWeek

Cyberespionage Campaign Targets Government, Energy Entities in India

Security Week - Thu, 03/28/2024 - 10:37am

Threat intelligence firm EclecticIQ documents the delivery of malware phishing lures to government and private energy organizations in India.

The post Cyberespionage Campaign Targets Government, Energy Entities in India appeared first on SecurityWeek.

Categories: SecurityWeek

Coro Raises $100 Million for All-in-One Security Platform

Security Week - Thu, 03/28/2024 - 9:15am

Coro has raised $100 million in Series D funding for its enterprise-grade platform tailored for the small- and mid-sized market.

The post Coro Raises $100 Million for All-in-One Security Platform appeared first on SecurityWeek.

Categories: SecurityWeek

Cisco Patches DoS Vulnerabilities in Networking Products

Security Week - Thu, 03/28/2024 - 9:08am

Cisco has released patches for multiple IOS and IOS XE software vulnerabilities leading to denial-of-service (DoS).

The post Cisco Patches DoS Vulnerabilities in Networking Products appeared first on SecurityWeek.

Categories: SecurityWeek

Zafran Emerges From Stealth With Risk and Mitigation Platform, $30M in Funding

Security Week - Thu, 03/28/2024 - 8:53am

Zafran has emerged from stealth mode with a risk and mitigation platform and $30 million in funding from Sequoia Capital and Cyberstarts.

The post Zafran Emerges From Stealth With Risk and Mitigation Platform, $30M in Funding appeared first on SecurityWeek.

Categories: SecurityWeek

Pages