Security News > 2023 > July

Key factors for effective security automation
2023-07-27 03:30

Harnessing the potential of automation in cybersecurity is key to maintaining a robust defense against ever-evolving threats. Still, this approach comes with its own unique challenges. In this...

CISOs gear up to combat the rising threat of B2B fraud
2023-07-27 03:00

The ongoing banking and economic turmoil has opened the floodgates to fraudsters. In this Help Net Security video, ex-British Intelligence officer Alex Beavan, Head of Ethics and Anti-Corruption...

UAC: Live response collection script for incident response
2023-07-27 02:30

Unix-like Artifacts Collector (UAC) is a live response collection script for incident response that makes use of native binaries and tools to automate the collection of AIX, Android, ESXi,...

Cryptojacking soars as cyberattacks increase, diversify
2023-07-27 02:00

Digital threat actors are adopting evolving tactical behaviors, opting for different types of malicious attacks compared to previous years, according to SonicWall. Overall intrusion attempts were...

Crooks pwned your servers? You've got four days to tell us, SEC tells public companies
2023-07-26 23:48

Cripes, they actually sound serious Public companies that suffer a computer crime likely to cause a "material" hit to an investor will soon face a four-day time limit to disclose the incident,...

Microsoft previews Defender for IoT firmware analysis service
2023-07-26 21:48

Microsoft announced the public preview of a new Defender for IoT feature that helps analyze the firmware of embedded Linux devices like routers for security vulnerabilities and common weaknesses. [...]

Russia throws founder of infosec biz Group-IB in the clink for treason
2023-07-26 20:31

Sachkov faces 14-year stretch after 'unreasonably rushed trial' A Russian court has sentenced Ilya Sachkov, the founder of security research house Group-IB, to 14 years in a maximum-security...

Lazarus hackers linked to $60 million Alphapo cryptocurrency heist
2023-07-26 20:19

Blockchain analysts blame the North Korean Lazarus hacking group for a recent attack on payment processing platform Alphapo where the attackers stole almost $60 million in crypto. [...]

Zenbleed: How the quest for CPU performance could put your passwords at risk
2023-07-26 19:01

In Ormandy's Zenbleed bug, now officially known as CVE-2023-20593, the problem arises when an AMD Zen 2 processor performs a special instruction that exists to set multiple so-called vector registers to zero at the same time. Vector registers are used to store data used by special high-performance numeric and data processing instructions, and in most modern Intel and AMD processors they are a chunky 256 bits wide, unlike the 64 bits of the CPU's general purpose registers used for traditional programming purposes.

Almost 40% of Ubuntu users vulnerable to new privilege elevation flaws
2023-07-26 18:51

Two Linux vulnerabilities introduced recently into the Ubuntu kernel create the potential for unprivileged local users to gain elevated privileges on a massive number of devices. [...]