Security News > 2023 > October

Fresh curl tomorrow will patch 'worst' security flaw in ages
2023-10-10 14:30

Start your patch engines - a new version of curl is due tomorrow that addresses a pair of flaws, one of which lead developer Daniel Stenberg describes as "Probably the worst curl security flaw in a long time." Curl 8.4.0 will hit at around 0600 UTC on October 11 and deal with CVE-2023-38545, which affects both libcurl and the curl tool, and CVE-2023-38546, which only affects libcurl.

New 'HTTP/2 Rapid Reset' zero-day attack breaks DDoS records
2023-10-10 14:12

A new DDoS technique named 'HTTP/2 Rapid Reset' has been actively exploited as a zero-day since August, breaking all previous records in magnitude.Since late August, Cloudflare has detected and mitigated over a thousand 'HTTP/2 Rapid Reset' DDoS attacks that surpassed 10 million rps, with 184 breaking the previous 71 million rps record.

A Primer on Cyber Risk Acceptance and What it Means to Your Business
2023-10-10 14:02

This article provides a guide to cyber risk acceptance and outlines the valuable role of continuous penetration testing in making informed risk acceptance decisions. The risk hasn't disappeared here; instead, another business takes on the task of mitigating the risk.

Dangerous vulnerability can be exploited to carry out massive DDoS attacks (CVE-2023-44487)
2023-10-10 13:18

Cloudflare, Google, and Amazon AWS revealed that a zero-day vulnerability in the HTTP/2 protocol has been used to mount massive, high-volume DDoS attacks, which they dubbed HTTP/2 Rapid Reset. Based on Cloudflare's data, several attacks leveraging Rapid Reset were nearly three times larger than the largest DDoS attack in Internet history.

Google Adopts Passkeys as Default Sign-in Method for All Users
2023-10-10 12:50

Google on Tuesday announced the ability for all users to set up passkeys by default, five months after it rolled out support for the FIDO Alliance-backed passwordless standard for Google Accounts...

Google makes passkeys the default sign-in for personal accounts
2023-10-10 12:00

Google announced today that passkeys are now the default sign-in option across all personal Google Accounts across its services and platforms. "We've received really positive feedback from our users, so today we're making passkeys even more accessible by offering them as the default option across personal Google Accounts," said Google product managers Christiaan Brand and Sriram Karra.

GNOME users at risk of RCE attack (CVE-2023-43641)
2023-10-10 11:30

If you're running GNOME on you Linux system(s), you are probably open to remote code execution attacks via a booby-trapped file, thanks to a memory corruption vulnerability in the libcue library. Discovered by GitHub security researcher Kevin Backhouse, CVE-2023-43641 affects the libcue library, which is used for parsing cue sheets that contain the layout of tracks on a CD. Libcue is also used by an application called tracker-miners, which indexes files in users' home directory.

Model Extraction Attack on Neural Networks
2023-10-10 11:09

Abstract: Billions of dollars and countless GPU hours are currently spent on training Deep Neural Networks for a variety of tasks. Thus, it is essential to determine the difficulty of extracting all the parameters of such neural networks when given access to their black-box implementations.

New Report: Child Sexual Abuse Content and Online Risks to Children on the Rise
2023-10-10 10:28

Certain online risks to children are on the rise, according to a recent report from Thorn, a technology nonprofit whose mission is to build technology to defend children from sexual abuse....

Researchers Uncover Grayling APT's Ongoing Attack Campaign Across Industries
2023-10-10 10:25

A previously undocumented threat actor of unknown provenance has been linked to a number of attacks targeting organizations in the manufacturing, IT, and biomedical sectors in Taiwan. The Symantec...