Security News > 2023 > July

Turla's New DeliveryCheck Backdoor Breaches Ukrainian Defense Sector
2023-07-20 09:40

The defense sector in Ukraine and Eastern Europe has been targeted by a novel. NET-based backdoor called DeliveryCheck that's capable of delivering next-stage payloads.

Ukraine busts bot farm spreading Russian infowar propaganda and fraud
2023-07-20 07:30

Ukrainian cops have disrupted a massive bot farm with more than 100 operators allegedly spreading fake news about the Russian invasion, leaking personal information belonging to Ukrainian citizens, and instigating fraud schemes. "The Cyber Police established that the attackers used special equipment and software to register thousands of bot accounts in various social networks and subsequently launch advertisements that violated the norms and legislation of Ukraine," according to machine translation of the news alert issued by the police.

New P2PInfect Worm Targeting Redis Servers on Linux and Windows Systems
2023-07-20 06:12

Cybersecurity researchers have uncovered a new cloud targeting, peer-to-peer worm called P2PInfect that targets vulnerable Redis instances for follow-on exploitation. "P2PInfect exploits Redis servers running on both Linux and Windows Operating Systems making it more scalable and potent than other worms," Palo Alto Networks Unit 42 researchers William Gamazo and Nathaniel Quist said.

Microsoft Expands Cloud Logging to Counter Rising Nation-State Cyber Threats
2023-07-20 05:06

Microsoft on Wednesday announced that it's expanding cloud logging capabilities to help organizations investigate cybersecurity incidents and gain more visibility after facing criticism in the wake of a recent espionage attack campaign aimed at its email infrastructure. "Over the coming months, we will include access to wider cloud security logs for our worldwide customers at no additional cost," Vasu Jakkal, corporate vice president of security, compliance, identity, and management at Microsoft, said.

Why data travel is healthcare’s next big cybersecurity challenge
2023-07-20 05:00

Here's why data travel is the next big cybersecurity challenge - and what healthcare organizations can do to keep their data safe. Data travel is the journey your data takes once it leaves the direct control of your organization.

LLMs and AI positioned to dominate the AppSec world
2023-07-20 04:30

A new research report explores emerging trends that software organizations need to consider as part of their security strategy, and risks associated with the use of existing open source software in application development. In particular, as modern software development increasingly adopts distributed architectures and microservices alongside third party and open source components, the report tracks the astonishing popularity of ChatGPT's API, how current large language model-based AI platforms are unable to accurately classify malware risk in most cases, and how almost half of all applications make no calls at all to security-sensitive APIs in their code base.

A fresh look at the current state of financial fraud
2023-07-20 04:00

In this Help Net Security video, Greg Woolf, CEO at FiVerity, discusses how the emergence of sophisticated fraud tools powered by AI and recent upheavals in the banking sector have forged an ideal environment for financial fraud. This complex scenario presents considerable obstacles for financial establishments to defend themselves efficiently.

Adobe Rolls Out New Patches for Actively Exploited ColdFusion Vulnerability
2023-07-20 03:31

Adobe has released a fresh round of updates to address an incomplete fix for a recently disclosed ColdFusion flaw that has come under active exploitation in the wild. The critical shortcoming, tracked as CVE-2023-38205, has been described as an instance of improper access control that could result in a security bypass.

67% of daily security alerts overwhelm SOC analysts
2023-07-20 03:30

Manual alert triage costs organizations $3.3 billion annually in the US alone, and security analysts are tasked with the massive undertaking of detecting, investigating and responding to threats as quickly and efficiently as possible while being challenged by an expanding attack surface and thousands of daily security alerts. On average, SOC teams receive 4,484 alerts daily and spend nearly three hours a day manually triaging alerts.

Exploring the macro shifts in enterprise security
2023-07-20 03:00

"The shift to the cloud has been a long journey and attackers are taking advantage now that employees regularly log into multiple cloud services, often from outside the traditional enterprise network perimeter," said Ariel Tseitlin, Partner at Scale Venture Partners and an avid investor in the cloud and security industries. As AI/ML models become more commonplace within organizations, 49% of security leaders worried about threat actors poisoning those AI/ML models to bypass security protections.