Security News > 2023 > June

Now Apple takes a bite out of encryption-bypassing 'spy clause' in UK internet law
2023-06-29 06:40

Apple has joined the rapidly growing chorus of tech organizations calling on British lawmakers to revise the nation's Online Safety Bill - which for now is in the hands of the House of Lords - so that it safeguards strong end-to-end encryption. "It also helps everyday citizens defend themselves from surveillance, identity theft, fraud, and data breaches. The Online Safety Bill poses a serious threat to this protection, and could put UK citizens at greater risk."

Newly Uncovered ThirdEye Windows-Based Malware Steals Sensitive Data
2023-06-29 04:48

A previously undocumented Windows-based information stealer called ThirdEye has been discovered in the wild with capabilities to harvest sensitive data from infected hosts. The arrival vector for the malware is presently unknown, although the nature of the lure points to it being used in a phishing campaign.

Popular generative AI projects pose serious security threat
2023-06-29 04:30

Many popular generative AI projects are an increased security threat and open-source projects that utilize insecure generative AI and LLMs also have poor security posture, resulting in an environment with substantial risk for organizations, according to Rezilion. "On top of their inherent security issues, individuals and organizations provide these AI models with excessive access and authorization without proper security guardrails. Through our research, we aimed to convey that the open-source projects that utilize insecure generative AI and LLMs have poor security posture as well. These factors result in an environment with significant risk for organizations."

Micropatches: What they are and how they work
2023-06-29 04:00

In this Help Net Security video, Mitja Kolsek, CEO at Acros Security, discusses micropatches, a solution to a huge security problem. With micropatches, there are no reboots or downtime when patching and no fear that an official update will break production.

Global rise in DDoS attacks threatens digital infrastructure
2023-06-29 03:30

In 2022, the total number of DDoS attacks worldwide increased by 115.1% over the amount observed in 2021, according to Nexusguard. While the overall number of DDoS attacks did more than double, the maximum size of 361.9 gigabits per second represented a 48.2% decrease over those measured in 2021.

Businesses count the cost of network downtime
2023-06-29 03:00

Fewer than one in ten CIOs can claim that they have avoided a network outage, according to Opengear. The scale and frequency of network outages is revealed by 91% of CIOs stating that they experience downtime at least once a quarter.

Guide: Attack Surface Management (ASM)
2023-06-29 02:30

Attack surface expansion is a byproduct of doing business today, especially for enterprises that rely on the cloud. This can result in attack surface exposures, both known and unknown, giving malicious actors many pathways to gain entry to networks.

Network security guy in extradition tug of war between US and Russia
2023-06-29 00:58

A Russian network security specialist and former editor of Hacker magazine who is wanted by the US and Russia on cybercrime charges has been detained in Kazakhstan as the two governments seek his extradition. Maybe the second part wasn't such a good idea after all - an update to the statement notes that Kislitsin is also wanted by Russia.

Microsoft Sysmon now detects when executables files are created
2023-06-28 21:28

Microsoft has released Sysmon 15, converting it into a protected process and adding the new 'FileExecutableDetected' option to log when executable files are created. Users can find the complete list of directives in the Sysmon schema, which can be viewed by running the sysmon -s command at the command line.

Exploit released for new Arcserve UDP auth bypass vulnerability
2023-06-28 20:50

Data protection vendor Arcserve has addressed a high-severity security flaw in its Unified Data Protection backup software that can let attackers bypass authentication and gain admin privileges.According to the company, Arcserve UDP is a data and ransomware protection solution designed to help customers thwart ransomware attacks, restore compromised data, and enable effective disaster recovery to ensure business continuity.