Security
Headlines
HeadlinesLatestCVEs

Source

DARKReading

China's 'Volt Typhoon' APT Turns to Zoho ManageEngine for Fresh Cyberattacks

A recent campaign shows that the politically motivated threat actor has more tricks up its sleeve than previously known, targeting an old RCE flaw and wiping logs to cover their tracks.

DARKReading
#vulnerability#web#windows#microsoft#apache#git#java#rce
ITDR Combines and Refines Familiar Cybersecurity Approaches

Identity threat detection and response adds user entity behavioral analytics to fraud detection, creating a powerful tool for real-time protection.

Silobreaker Unveils Geopolitical Threat Intelligence Capabilities With RANE at Infosecurity Europe 2023

Integration provides threat intel teams with an early warning system for geopolitical events that could trigger cyberattacks.

NSA: BlackLotus BootKit Patching Won't Prevent Compromise

It's unclear why the NSA issued in-depth mitigation guidance for the software boot threat now, but orgs should take steps to harden their environments.

Suspicious Smartwatches Mailed to US Army Personnel

Unknown senders have been shipping smartwatches to service members, leading to questions regarding what kind of ulterior motive is at play, malware or otherwise.

Microsoft Teams Attack Skips the Phish to Deliver Malware Directly

Exploiting a flaw in how the app handles communication with external tenants gives threat actors an easy way to send malicious files from a trusted source to an organization's employees, but no patch is imminent.

Why Legacy System Users Prioritize Uptime Over Security

For line-of-business execs, the fear of grinding mission-critical systems to a halt overrides the fear of ransomware. How can CISOs overcome this?

Black Hat Asia 2023: Cybersecurity Maturity and Concern in Asia

Black Hat Asia 2023 showed that cybersecurity is nascent among organizations in Asia with opportunities for improvement.

How Government Contractors & Agencies Should Navigate New Cyber Rules

The impending regulations highlight the increasing importance of enhanced network security and regulatory compliance across the government sector.

Millions of Repos on GitHub Are Potentially Vulnerable to Hijacking

Many organizations are unwittingly exposing users of their code repositories to repojacking when renaming projects, a new study shows.