Security Week

Subscribe to Security Week feed Security Week
Latest cybersecurity news and expert insights from SecurityWeek's RSS feed
Updated: 16 min 22 sec ago

CrushFTP Patches Exploited Zero-Day Vulnerability

Mon, 04/22/2024 - 8:27am

CrushFTP patches a zero-day vulnerability allowing unauthenticated attackers to escape the VFS and retrieve system files.

The post CrushFTP Patches Exploited Zero-Day Vulnerability appeared first on SecurityWeek.

Categories: SecurityWeek

Thousands of Palo Alto Firewalls Potentially Impacted by Exploited Vulnerability 

Mon, 04/22/2024 - 7:55am

Shadowserver has identified roughly 6,000 internet-accessible Palo Alto Networks firewalls potentially vulnerable to CVE-2024-3400.

The post Thousands of Palo Alto Firewalls Potentially Impacted by Exploited Vulnerability  appeared first on SecurityWeek.

Categories: SecurityWeek

MITRE Hacked by State-Sponsored Group via Ivanti Zero-Days

Mon, 04/22/2024 - 5:42am

MITRE R&D network hacked in early January by a state-sponsored threat group that exploited an Ivanti zero-day vulnerability.

The post MITRE Hacked by State-Sponsored Group via Ivanti Zero-Days appeared first on SecurityWeek.

Categories: SecurityWeek

Cannes Hospital Cancels Medical Procedures Following Cyberattack

Mon, 04/22/2024 - 12:28am

Cannes Hospital Centre – Simone Veil cancels medical procedures after shutting down systems in response to a cyberattack.

The post Cannes Hospital Cancels Medical Procedures Following Cyberattack appeared first on SecurityWeek.

Categories: SecurityWeek

BreachRx Raises $6.5M to Revamp Incident Response Reporting Systems

Fri, 04/19/2024 - 1:14pm

Investors make an early-stage $6.5 million bet on BreachRx, a startup promising to shield cybersecurity executives from personal liability.

The post BreachRx Raises $6.5M to Revamp Incident Response Reporting Systems appeared first on SecurityWeek.

Categories: SecurityWeek

Threat-Intelligence Startup VulnCheck Closes $8M Seed Financing

Fri, 04/19/2024 - 10:36am

VulnCheck banks $8 million in early stage capital to build 'exploit intelligence' technologies and services.

The post Threat-Intelligence Startup VulnCheck Closes $8M Seed Financing appeared first on SecurityWeek.

Categories: SecurityWeek

In Other News: OSS Backdooring Attempts, Botnet Operator Charged, Automotive Firm Attack

Fri, 04/19/2024 - 9:24am

Noteworthy stories that might have slipped under the radar: OpenSSF and OpenJS incidents similar to XZ backdoor, Moldovan botnet operator charged, US automotive company targeted by FIN7.

The post In Other News: OSS Backdooring Attempts, Botnet Operator Charged, Automotive Firm Attack appeared first on SecurityWeek.

Categories: SecurityWeek

First Major Attempts to Regulate AI Face Headwinds From All Sides

Fri, 04/19/2024 - 8:52am

While over 400 AI-related bills are being debated this year in statehouses nationwide, most target one industry or just a piece of the technology — such as deepfakes used in elections.

The post First Major Attempts to Regulate AI Face Headwinds From All Sides appeared first on SecurityWeek.

Categories: SecurityWeek

US Government Releases Guidance on Securing Election Infrastructure

Fri, 04/19/2024 - 7:38am

New US guidance details foreign malign influence operations to help election infrastructure stakeholders increase resilience.

The post US Government Releases Guidance on Securing Election Infrastructure appeared first on SecurityWeek.

Categories: SecurityWeek

Akira Ransomware Made Over $42 Million in One Year: Agencies

Fri, 04/19/2024 - 7:25am

Akira ransomware has hit over 250 organizations worldwide and received over $42 million in ransom payments.

The post Akira Ransomware Made Over $42 Million in One Year: Agencies appeared first on SecurityWeek.

Categories: SecurityWeek

Frontier Communications Shuts Down Systems Following Cyberattack

Fri, 04/19/2024 - 7:12am

Telecom giant Frontier shuts down systems to contain a cyberattack that led to personal information compromise.

The post Frontier Communications Shuts Down Systems Following Cyberattack appeared first on SecurityWeek.

Categories: SecurityWeek

OpenMetadata Vulnerabilities Exploited to Abuse Kubernetes Clusters for Cryptomining  

Fri, 04/19/2024 - 4:59am

Microsoft warns that several OpenMetadata vulnerabilities are being exploited to deploy cryptomining malware to Kubernetes environments.

The post OpenMetadata Vulnerabilities Exploited to Abuse Kubernetes Clusters for Cryptomining   appeared first on SecurityWeek.

Categories: SecurityWeek

SAP Applications Increasingly in Attacker Crosshairs, Report Shows

Thu, 04/18/2024 - 12:06pm

Malicious hackers are targeting SAP applications at an alarming pace, according to warnings from Onapsis and Flashpoint.

The post SAP Applications Increasingly in Attacker Crosshairs, Report Shows appeared first on SecurityWeek.

Categories: SecurityWeek

Multi-Data Platform SIEM Anvilogic Raises $45 Million

Thu, 04/18/2024 - 10:55am

Silicon Valley startup Anvilogic has raised $45 million in a Series C funding round led by Evolution Equity Partners.

The post Multi-Data Platform SIEM Anvilogic Raises $45 Million appeared first on SecurityWeek.

Categories: SecurityWeek

United Nations Agency Investigating Ransomware Attack Involving Data Theft

Thu, 04/18/2024 - 10:21am

United Nations Development Programme (UNDP) investigating a ransomware attack in which hackers stole sensitive data.

The post United Nations Agency Investigating Ransomware Attack Involving Data Theft appeared first on SecurityWeek.

Categories: SecurityWeek

Five Eyes Agencies Release New AI Security Guidance

Thu, 04/18/2024 - 9:15am

Five Eyes cybersecurity agencies have released joint guidance on securely deploying and operating AI systems. 

The post Five Eyes Agencies Release New AI Security Guidance appeared first on SecurityWeek.

Categories: SecurityWeek

Cisco Says PoC Exploit Available for Newly Patched IMC Vulnerability

Thu, 04/18/2024 - 7:42am

Cisco patches a high-severity Integrated Management Controller vulnerability for which PoC exploit code is available.

The post Cisco Says PoC Exploit Available for Newly Patched IMC Vulnerability appeared first on SecurityWeek.

Categories: SecurityWeek

180k Impacted by Data Breach at Michigan Healthcare Organization

Thu, 04/18/2024 - 7:30am

Cherry Health says the personal information of over 180,000 individuals was stolen in a ransomware attack.

The post 180k Impacted by Data Breach at Michigan Healthcare Organization appeared first on SecurityWeek.

Categories: SecurityWeek

Phishing Platform LabHost Shut Down by Law Enforcement

Thu, 04/18/2024 - 6:44am

LabHost, a major phishing-as-a-service platform, has been shut down as part of a major law enforcement operation. 

The post Phishing Platform LabHost Shut Down by Law Enforcement appeared first on SecurityWeek.

Categories: SecurityWeek

Cisco Unveils AI-Native Enterprise Security Solution Hypershield

Thu, 04/18/2024 - 5:07am

Cisco announces Hypershield, an AI-native and cloud-native enterprise security solution with a wide range of capabilities.

The post Cisco Unveils AI-Native Enterprise Security Solution Hypershield appeared first on SecurityWeek.

Categories: SecurityWeek

Pages