Security News > 2023 > June

MITRE Unveils Top 25 Most Dangerous Software Weaknesses of 2023: Are You at Risk?
2023-06-30 05:44

MITRE has released its annual list of the Top 25 "Most dangerous software weaknesses" for the year 2023. "These weaknesses lead to serious vulnerabilities in software," the U.S. Cybersecurity and Infrastructure Security Agency said.

Unlocking internet’s secrets via monitoring, data collection, and analysis
2023-06-30 02:00

In this Help Net Security interview, Ryan Woodley, CEO of Netcraft, discusses the importance of monitoring, collecting, and analyzing internet data to gain a profound understanding of the internet. The aim is to generate a vast, rich pool of data, which is processed using advanced algorithms and data enrichment techniques.

Fujitsu admits it fluffed the fix for Japan’s flaky ID card scheme
2023-06-30 01:47

Fujitsu Japan is in the spotlight again for all the wrong reasons, after fumbling its attempt to fix the nation's troubled ID card scheme. One use of the cards is to arrange for administrative documents to be printed at convenience stores or government offices.

Businesses are ignoring third-party security risks
2023-06-30 01:45

In the dynamic business landscape where third-party relationships assume a critical role, organizations confront various risks that can profoundly affect their security and compliance requirements, according to Panorays. 84% of organizations prioritize third-party security risk management, indicating a growing awareness of the potential threats posed by third-party relationships.

Employees worry less about cybersecurity best practices in the summer
2023-06-30 01:15

IT teams are struggling to monitor and enforce BYOD policies during summer months when more employees are often traveling or working remotely, according to ThreatX. With more endpoints and applications in use, and often personal rather than corporate issued, the risk to corporate data may increase. 55% of employees admit to relying solely on their mobile devices while working from vacation and holiday destinations in the summer.

Crook who stole $23m+ in YouTube song royalties gets five years behind bars
2023-06-29 23:38

One of the two men who admitted stealing more than $23 million in royalty payments for songs played on YouTube has been sentenced to nearly six years behind bars for his role in what prosecutors called "One of the largest music-royalty frauds ever." Teran pleaded guilty to conspiracy, wire fraud, and money laundering in January, following a November 2021 indictment in which a federal grand jury charged him and Batista with 30 felony counts.

Different Methods to Secure Your Microsoft Word Documents
2023-06-29 23:31

Microsoft offers different Word document security solutions. Microsoft Word offers several ways to secure a document so that other people can't view or edit it.

8Base Ransomware Attacks Show Spike in Activity
2023-06-29 21:08

Ransomware attacks from the 8Base group claimed the second largest number of victims over the past 30 days, says VMware. Analyzing ransomware attacks in June 2023, VMware found 8Base hit almost 80 victims over the past 30 days, second only to the LockBit 3 gang, which compromised almost 100 organizations.

It's 2023 and memory overwrite bugs are not just a thing, they're still number one
2023-06-29 20:24

Number two on MITRE's list is the less complex but still annoying cross-site scripting bug, which was key in four CVEs in the known exploited vulnerabilities catalog maintained by Uncle Sam's CISA. This bug type is a fancy form of a failure to sanitize user input. Number three - SQL injection flaws - account for four known exploited bugs in the CISA catalog.

Kaspersky’s New Report Reveals the Top Cyber Threats for SMBs in 2023
2023-06-29 19:40

A new report from Kaspersky reveals the top cyber threats for SMBs in 2023. The biggest cybersecurity threat to SMBs is the use of exploits by attackers; there were 483,980 detections in the five first months of 2023.