FreshRSS

πŸ”’
❌ About FreshRSS
There are new available articles, click to refresh the page.
Before yesterdaySecurity

A Link to News Site Meduza Can (Technically) Land You in Russian Prison

By Andy Greenberg, Andrew Couts
Plus: Hive ransomware gang gets knocked offline, FBI confirms North Korea stole $100 million, and more.

Microsoft Urges Customers to Secure On-Premises Exchange Servers

By Ravie Lakshmanan
Microsoft is urging customers to keep their Exchange servers updated as well as take steps to bolster the environment, such as enablingΒ Windows Extended ProtectionΒ and configuringΒ certificate-based signingΒ of PowerShell serialization payloads. "Attackers looking to exploit unpatched Exchange servers are not going to go away," the tech giant's Exchange TeamΒ saidΒ in a post. "There are too many

Mon Dieu! Suspected French ShinyHunters gang member in the dock

Man seized in Morocco is now presumably sleepless in Seattle

A French citizen was scheduled to appear before a US court on Friday on a nine-count indictment related to his alleged involvement in the ShinyHunters cybercrime gang that trafficked in identity and corporate data theft and sometimes extortion.…

  • January 28th 2023 at 08:50

ISC Releases Security Patches for New BIND DNS Software Vulnerabilities

By Ravie Lakshmanan
The Internet Systems Consortium (ISC) has released patches to address multiple security vulnerabilities in the Berkeley Internet Name Domain (BIND) 9 Domain Name System (DNS) software suite that could lead to a denial-of-service (DoS) condition. "A remote attacker could exploit these vulnerabilities to potentially cause denial-of-service conditions and system failures," the U.S. Cybersecurity

Weekly Update 332

By Troy Hunt
Weekly Update 332

Breaches all over the place today! Well, this past week, and there's some debate as to whether one of them is a breach, a scrape or if the term just doesn't matter anyway. Plus, we've been kitchen shopping, I'm helping friends out with connected doorbells and other random but somehow related things this week. Enjoy 😊

Weekly Update 332
Weekly Update 332
Weekly Update 332
Weekly Update 332

References

  1. I'll be "at" GOTO Aarhus in May (there online, but definitely speaking at the show)
  2. Following all the awesome input, we decided to forego the teppanyaki plate on the Bora Professional 3.0 (there's a surprising amount of good culinary advice from my audience!)
  3. Zurich Japan was breached (big name, but small portion of people already in HIBP)
  4. Autotrader had a heap of data breacraped (breached? scraped? does it matter?)
  5. Speaking of which, when actually is a scrape a breach? (my more concerted thoughts on the matter all in one place)
  6. Norwegian adventure store KomplettFritid was also breached (apparently, they decided to not tell their customers)
  7. GoTo, the owner of LastPass, "shared more bad news" (I do have some historical views on this organisation...)
  8. Hey, it's my views on GoTo! (nearly 13 years old now, but this remains poor behaviour IMHO)
  9. Sponsored by: CrowdSec - Gain crowd-sourced protection against malicious IPs and benefit from the most accurate CTI in the world. Get started for free.

Ukraine Hit with New Golang-based 'SwiftSlicer' Wiper Malware in Latest Cyber Attack

By Ravie Lakshmanan
Ukraine has come under a fresh cyber onslaught from Russia that involved the deployment of a previously undocumented Golang-based data wiper dubbedΒ SwiftSlicer. ESET attributed the attack to Sandworm, a nation-state group linked to Military Unit 74455 of the Main Intelligence Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU). "Once executed it deletes shadow

Microsoft to enterprises: Patch your Exchange servers

If you want to keep the miscreants out, put the updates in, Redmond says

Microsoft is urging organizations to protect their Exchange servers from cyberattacks by keeping them updated and hardened, since online criminals are still going after valuable data in the email system.…

  • January 28th 2023 at 01:03

Uncle Sam slaps $10m bounty on Hive while Russia ban-hammers FBI, CIA

New meaning to sweetening the pot

Uncle Sam has put up a $10 million reward for intel on Hive ransomware criminals' identities and whereabouts, while Russia has blocked the FBI and CIA websites, along with the Rewards for Justice site offering the bounty.…

  • January 27th 2023 at 23:59

Eliminating SaaS Shadow IT is Now Available via a Self-Service Product, Free of Charge

By The Hacker News
The use of software as a service (SaaS) is experiencing rapid growth and shows no signs of slowing down. Its decentralized and easy-to-use nature is beneficial for increasing employee productivity, but it also poses many security and IT challenges. Keeping track of all the SaaS applications that have been granted access to an organization's data is a difficult task. Understanding the risks that

Enterprises Don't Know What to Buy for Responsible AI

By Dark Reading Staff, Dark Reading
Organizations are struggling to procure appropriate technical tools to address responsible AI, such as consistent bias detection in AI applications.

  • January 27th 2023 at 22:30

Enterprises Need to Do More to Assure Consumers About Privacy

By Edge Editors, Dark Reading
Organizations care about data privacy, but their priorities appear to be different from what their customers think are important.

  • January 27th 2023 at 22:00

Why Most Companies Still Don’t Know What’s on Their Network

By Terry Sweeney, Contributing Editor
Chris Kirsch, CEO of runZero, sits down with Dark Reading’sTerry Sweeney for a Fast Chat on the importance of asset discovery.

  • January 27th 2023 at 21:00

On Data Privacy Day, Organizations Fail Data Privacy Expectations

By Maxine Holt, Research Director, Omdia
Data Privacy Day rolls around year after year, and data privacy breaches likewise. Two-thirds of data breaches result in data exposure.

  • January 27th 2023 at 20:00

Are you in control of your personal data? – Week in security with Tony Anscombe

By Editor

Data Privacy Week is a reminder to protect your data – all year round. Here are three privacy-boosting habits you can start today.

The post Are you in control of your personal data? – Week in security with Tony Anscombe appeared first on WeLiveSecurity

  • January 27th 2023 at 18:15

Critical RCE Lexmark Printer Bug Has Public Exploit

By Dark Reading Staff, Dark Reading
A nasty SSRF bug in Web Services plagues a laundry list of enterprise printers.

  • January 27th 2023 at 18:02

Hive ransomware servers shut down at last, says FBI

By Naked Security writer
Unfortunately, you've probably already heard the cliche that "cybercrime abhors a vacuum"...

SwiftSlicer: New destructive wiper malware strikes Ukraine

By Editor

Sandworm continues to conduct attacks against carefully chosen targets in the war-torn country

The post SwiftSlicer: New destructive wiper malware strikes Ukraine appeared first on WeLiveSecurity

Google: Influence Operator Dragonbridge Floods Social Media in Sprawling Cyber Campaign

By Nathan Eddy, Contributing Writer, Dark Reading
Google has mounted a massive takedown, but Dragonbridge's extensive capabilities for generating and distributing vast amounts of largely spammy content calls into question the motivation behind the group.

  • January 27th 2023 at 16:11

How Noob Website Hackers Can Become Persistent Threats

By Jai Vijayan, Contributing Writer, Dark Reading
An academic analysis of website defacement behavior by 241 new hackers shows there are four clear trajectories they can take in the future, researchers say.

  • January 27th 2023 at 15:49

3 Ways ChatGPT Will Change Infosec in 2023

By Matt Georgy, Chief Technology Officer, Redacted
OpenAI's chatbot has the promise to revolutionize how security practitioners work.

  • January 27th 2023 at 15:00

Experts Uncover the Identity of Mastermind Behind Golden Chickens Malware Service

By Ravie Lakshmanan
Cybersecurity researchers have discovered the real-world identity of the threat actor behindΒ Golden ChickensΒ malware-as-a-service, who goes by the online persona "badbullzvenom." eSentire's Threat Response Unit (TRU), in an exhaustive report published following a 16-month-long investigation,Β saidΒ it "found multiple mentions of the badbullzvenom account being shared between two people." The

The Nominees for the 2023 Cybersecurity Defender of the Year Award in EMEA

By Cristina Errico

Cybersecurity professionals are often perceived as sole practitioners, plying their craft in dimly lit rooms. Nothing could be further from the truth, as one of the keys to being a successful cybersecurity professional is the ability to collaborate and, more importantly, to share knowledge as far and wide as possible.

At Cisco, we have formed the Cisco Insider Advocacy program, which consists of a global community of professionals passionate about working and spreading their knowledge with others. We celebrate these individuals’ efforts with annual awards in various disciplines and locales. In 2023, Cisco will recognize top advocates by region for the Global Advocate Awards. Our first event – highlighting Cisco customers from across the EMEA region – is around the corner. It all happens at Cisco Live in Amsterdam, in a live ceremony on February 8!

I am joined on the Advocate Awards judges’ panel by my colleagues, Cindy Valladares, Director of Brand Strategy and Customer Advocacy at Cisco Secure, Caroline Surujpaul, EMEA and European Marketing Director at Cisco Secure and Sarah Stephens, Senior Security Marketing Leader for EMEA at Cisco Secure. We are pleased to introduce the nominees for the Cybersecurity Defender of the Year Award in EMEA.

We have five distinguished nominees, and while we have yet to select a winner, you will see how each of their contributions to Cisco’s cybersecurity community raised our attention.

Nominees for 2023 EMEA Cybersecurity Defender of the Year

Alessandro BragaΒ  – CDO, Talent Garden

Alessandro was featured in a recent successful case study about the Future of Work with Umbrella, as well as an earlier piece about simplified security using Cisco Meraki in Talent Garden.

Alessandro also authored a book about digital transformation long before it was a common buzzword. That is typical of Alessandro’s foresight, the ability to be proactive to changes before they are commonplace. He is indeed on the cutting edge.

Alessandro considers his involvement in the Advocacy community as β€œa very easy goal for me. First, because I’m very passionate about cybersecurity, and second because here I can find very valuable peers and professionals to share information with.” Alessandro’s abilities are borne from passion, drive, and adherence to a personal code of excellence; he learned security in a strictly hands-on style. He is also a member of Cisco’s β€œLeague of Cybersecurity Heroes.”

Christoffer Vargtass Hallstensen – Head of SOC, Norwegian University of Science and Technology

Christoffer, the newest Cisco Insider Advocacy community member, has gotten off to a brisk involvement with the group. He was recently featured in the case study β€œNTNU Supports a Diverse Academic and Research Community with Proactive Security,” which detailed how the Norwegian University of Science and Technology tackled the management of a dizzying 110,000 endpoints connecting to the university’s VPN.

Christoffer fully embraces the ideology of collaboration, mentioning that when he was seeking a security solution, β€œWe didn’t want a vendor. We didn’t want a product. We wanted a partner to help us attack this large problem of cybersecurity.”  He also demonstrates a fervent dedication to sharing by authoring half a dozen works in the cybersecurity realm, ranging from scientific to academic articles. His involvement in the Insider Advocacy community has earned him a spot in Cisco’s β€œLeague of Cybersecurity Heroes.”

Mark Healey – Senior Cyber Security Engineer, South Yorkshire Police

Mark is one of the most erudite cybersecurity professionals one could meet. He has extensive educational credentials and enjoys sharing his knowledge, making him one of the Top 10 most engaged advocates of the Cybersecurity Channel within the Cisco Insider Advocates community.

Mark’s professional involvement extends beyond his local precinct, offering his knowledge of security best practices across the UK Policing community. In completing his most recent university degree, he authored a dissertation that β€œhas led to an initiative to improve the security posture of my workplace.” Mark’s support to other Cisco customers has also led to his election as Vice-Chair of the Internet Society Cybersecurity Special Interest Group. He is also a member of Cisco’s β€œLeague of Cybersecurity Heroes.”

Luigi Vassallo – COO & CTO, Sara Assicurazioni

Luigi is a valuable member of the Insider Advocacy group and was recently featured in a video and written success story about Zero Trust and XDR.

Luigi is an agent of change who embraces the collaborative spirit of a true cybersecurity expert, as exemplified in his entire professional approach: β€œSince the infrastructure is now cloud-based, we had to change our mindset regarding cybersecurity as well. It was important to have the people, the process, the organisation, and the technology under the same security umbrella.”

When not working to ensure the security of the Sara Assicurazioni environment, Luigi has dedicated time to speaking at events, such as the β€œExperts Learning from Experts” global virtual session, a special virtual roundtable dedicated to Zero Trust and, last but not least, his presentation at Cisco Live Emea in Amsterdam about XDR and Zero Trust. His contributions to the Insider Advocacy platform reflect a tireless commitment to the cybersecurity community. Luigi is also a member of Cisco’s β€œLeague of Cybersecurity Heroes.”

Diego Zengin – Global CTO, Grupo Cosentino

Last year, Diego participated as speaker at the Tech Forum: Convergencia entre redes y seguridad. He will also be featured in a future ThreatWise TV – Cisco episode

Diego recognised early on that remote work would place his organisation outside the scope of their security and took proactive measures to meet the challenge. Part of his proactive approach is to freely communicate his ideas, leading to his involvement in the Insider Advocacy community. This has also earned him a place within Cisco’s β€œLeague of Cybersecurity Heroes.”

Diego’s view of working with Cisco’s products is summed up in a catchy phrase: β€œIf it’s connected, it’s protected.” His involvement within the Insider Advocacy community makes us echo that sentiment by stating that he is connected, helping to keep everyone protected.

Supporting Diversity, Equity, and Inclusion

One point of note is the absence of women from the list of nominees. This was not the result of bias, as Cisco has a history of substantial diversity, equity, and inclusion. Β As you can see from the activities of the current nominees, the selection was based strictly on contributions to the community. We would love to see more engagement and membership in the Insider Advocacy program, not only from women but from a broader geographic area. This would increase the choices of possible nominees and add an even wider palette of inclusion to the entire nomination process.

We know that there is an entire population of cybersecurity professionals who seek more connection with like-minded individuals, and we welcome you to join this cohesive community.

Join Cisco’s most strategic, forward-thinking customer and partner advocates so
we can feature your story of passion and commitment on our next nomination list!

Cisco Insider Advocacy

Β 


We’d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with Cisco Secure on social!

Cisco Secure Social Channels

Instagram
Facebook
Twitter
LinkedIn

ADS-B Exchange, the Flight Tracker That Powered @ElonJet, Sold to Jetnet

By Justin Ling
ADS-B Exchange, beloved for resisting censorship, was sold to a company owned by private equityβ€”and now even its biggest fans are bailing.

Researchers Discover New PlugX Malware Variant Spreading via Removable USB Devices

By Ravie Lakshmanan
Cybersecurity researchers have uncovered a PlugX sample that employs sneaky methods to infect attached removable USB media devices in order to propagate the malware to additional systems. "This PlugX variant is wormable and infects USB devices in such a way that it conceals itself from the Windows operating file system," Palo Alto Networks Unit 42 researchers Mike Harbison and Jen Miller-OsbornΒ 

3 Lifehacks While Analyzing Orcus RAT in a Malware Sandbox

By The Hacker News
OrcusΒ is a Remote Access Trojan with some distinctive characteristics. The RAT allows attackers to create plugins and offers a robust core feature set that makes it quite a dangerous malicious program in its class. RAT is quite a stable type that always makes it to the top. ANY.RUN’s top malware types in 2022 That's why you'll definitely come across this type in your practice, and the Orcus

British Cyber Agency Warns of Russian and Iranian Hackers Targeting Key Industries

By Ravie Lakshmanan
The U.K. National Cyber Security Centre (NCSC) on Thursday warned of spear-phishing attacks mounted by Russian and Iranian state-sponsored actors for information-gathering operations. "The attacks are not aimed at the general public but targets in specified sectors, including academia, defense, government organizations, NGOs, think tanks, as well as politicians, journalists, and activists," the

Savvy cybersecurity pros benefit from host of free resources to step up fight against hackers and cyber threats

Sign up to SANS Institute to keep up to speed with all aspects of the fast-evolving infosec sector

Sponsored Post They say there's no such thing as a free lunch, but in fact there's a veritable feast of valuable resources online for infosec professionals which won't cost you anything.…

  • January 27th 2023 at 08:57

UK Cyber Security Centre's scary new story: One phish, two phish, Russia phish, Iran phish

Nice people on LinkedIn want to harvest logins from politicians, boffins, and defense types

The UK's National Cyber Security Centre (NCSC) has warned of two similar spear-phishing campaigns, one originating from Russia, the other from Iran.…

  • January 27th 2023 at 05:32

Riot Games Latest Video-Game Maker to Suffer Breach

By Robert Lemos, Contributing Writer, Dark Reading
Highlighting continued attacks on game developers, attackers stole source code from and issued a ransom demand to the maker of League of Legends.

  • January 26th 2023 at 22:25

A Child's Garden of Cybersecurity

By Karen Spiegelman, Features Editor
Whether you dream of your child becoming a CISO or just want them to improve their security hygiene, consider this roundup of literary geekery.

  • January 26th 2023 at 22:02

FBI smokes ransomware Hive after secretly buzzing around gang's network for months

Uncle Sam doles out decryption keys to 300+ victims amid sting op

The FBI said it has shut down the Hive's ransomware network, seizing control of the notorious gang's servers and websites, and thwarting the pesky criminals' ability to sting future victims.…

  • January 26th 2023 at 20:30

Federal Agencies Infested by Cyberattackers via Legit Remote Management Systems

By Nate Nelson, Contributing Writer, Dark Reading
Hackers don't need a key to get past your defenses if they can essentially teleport using RMMs, warns CISA and the NSA.

  • January 26th 2023 at 20:13

SaaS Rootkit Exploits Hidden Rules in Microsoft 365

A vulnerability within Microsoft's OAuth application registration allows an attacker to create hidden forwarding rules that act as a malicious SaaS rootkit.

  • January 26th 2023 at 20:00

Dutchman Detained for Dealing Details of Tens of Millions of People

By Dark Reading Staff, Dark Reading
The accused sold an enormous data set stolen from the Austrian radio and television licensing authority β€” to an undercover cop.

  • January 26th 2023 at 20:00

Hive Ransomware Gang Loses Its Honeycomb, Thanks to DoJ

By Tara Seals, Managing Editor, News, Dark Reading
The US Department of Justice hacked into Hive's infrastructure, made off with hundreds of decryptors, and seized the gang's operations.

  • January 26th 2023 at 19:40

German Government, Airports, Banks Hit With Killnet DDoS Attacks

By Dark Reading Staff, Dark Reading
After Berlin pledged tanks for Ukraine, some German websites were knocked offline temporarily by Killnet DDoS attacks.

  • January 26th 2023 at 19:26

7 Insights From a Ransomware Negotiator

By Ericka Chickowski, Contributing Writer, Dark Reading
The rapid maturation and rebranding of ransomware groups calls for relentless preparation and flexibility in response, according to one view from the trenches.

  • January 26th 2023 at 18:18

Companies Struggle With Zero Trust as Attackers Adapt to Get Around It

By Robert Lemos, Contributing Writer, Dark Reading
Only one in 10 enterprises will create a robust zero-trust foundation in the next three years, while more than half of attacks won't even be prevented by it, according to Gartner.

  • January 26th 2023 at 17:36

Center for Cyber Safety and Education Opens 2023 Cybersecurity Scholarship Applications

Program provides financial assistance to aspiring information security professionals, enabling students toward long-term career success.
  • January 26th 2023 at 16:12

Cybellum Releases Enhanced SBOM Management and Compliance Oversight for Manufacturers with New Release of its Product Security Platform

Advanced workflow, approval process, and management dashboard enhance control, distribution, and supervision, while reducing errors and streamlining the entire SBOM management process.
  • January 26th 2023 at 15:58

NIST Risk Management Framework Aims to Improve Trustworthiness of Artificial Intelligence

New guidance seeks to cultivate trust in AI technologies and promote AI innovation while mitigating risk
  • January 26th 2023 at 15:43

Organizations Must Brace for Privacy Impacts This Year

By J. Trevor Hughes, President & CEO, IAPP
Expect more regulatory and enforcement action in the US and around the world.

  • January 26th 2023 at 15:00

Snyk Gets Nod of Approval With ServiceNow Strategic Investment

By Jeffrey Schwartz, Contributing Writer, Dark Reading
One of the most closely watched security startups continues to build bank because its platform appeals to both developers and security pros.

  • January 26th 2023 at 00:34

KORE Delivers IoT SAFE Solution for Massive IoT Use Cases with AWS

Delivering secure, global IoT device connectivity, deployment, and management at scale.
  • January 25th 2023 at 22:39

Microsoft Azure-Based Kerberos Attacks Crack Open Cloud Accounts

By Robert Lemos, Contributing Writer, Dark Reading
Two common attacks against on-premises Kerberos authentication servers β€” known as Pass the Ticket and Silver Ticket β€” can be used against Microsoft's Azure AD Kerberos, a security firms says.

  • January 25th 2023 at 22:17

Zacks Investment Research Hack Exposes Data for 820K Customers

By Dark Reading Staff, Dark Reading
Zacks Elite sign-ups for the period 1999–2005 were accessed, including name, address, email address, phone number, and the password associated with Zacks.com.

  • January 25th 2023 at 21:43

Google Pushes Privacy to the Limit in Updated Terms of Service

By Stephen Lawton, Contributing Writer
In the Play Store's ToS, a paragraph says Google may remove "harmful" applications from users' devices. Is that a step too far?

  • January 25th 2023 at 21:42

Despite Slowing Economy, Demand for Cybersecurity Workers Remains Strong

New Cyberseekβ„’ data shows US is short nearly 530,000 skilled cybersecurity staff.
  • January 25th 2023 at 21:25
❌