Security News > 2023 > November

Okta data breach exposed personal information of employees
2023-11-02 14:09

Okta is warning nearly 5,000 current and former employees that their personal information was exposed after a third-party vendor was breached. The data breach notification warns of a security incident that impacted Rightway Healthcare, which provides healthcare coverage for Okta employees and their families.

G7 Countries Establish Voluntary AI Code of Conduct
2023-11-02 14:09

The code of conduct provides guidelines for AI regulation across G7 countries and includes cybersecurity considerations and international standards. The Group of Seven countries have created a voluntary AI code of conduct, released on October 30, regarding the use of advanced artificial intelligence.

#AI
Your end-users are reusing passwords – that’s a big problem
2023-11-02 14:01

A Microsoft study found that 44 million Microsoft users were reusing passwords over a 3-month period, while a more recent LastPass survey estimates 62% of knowledge workers reuse the same password or a close variation. There is no way to know which users are reusing passwords, but there are ways to reduce the potential impact if a reused password is compromised.

Mysterious Kill Switch Disrupts Mozi IoT Botnet Operations
2023-11-02 13:45

The unexpected drop in malicious activity connected with the Mozi botnet in August 2023 was due to a kill switch that was distributed to the bots. "First, the drop manifested in India on August...

Spyware in India
2023-11-02 11:07

Multiple top leaders of India's opposition parties and several journalists have received a notification from Apple, saying that "Apple believes you are being targeted by state-sponsored attackers who are trying to remotely compromise the iPhone associated with your Apple ID.". For India to uphold fundamental rights, authorities must initiate an immediate independent inquiry, implement a ban on the use of rights-abusing commercial spyware, and make a commitment to reform the country's surveillance laws.

SaaS Security is Now Accessible and Affordable to All
2023-11-02 09:24

This new product offers SaaS discovery and risk assessment coupled with a free user access review in a unique “freemium” model Securing employees' SaaS usage is becoming increasingly crucial for...

Iran's MuddyWater Targets Israel in New Spear-Phishing Cyber Campaign
2023-11-02 09:21

The Iranian nation-state actor known as MuddyWater has been linked to a new spear-phishing campaign targeting two Israeli entities to ultimately deploy a legitimate remote administration tool from...

Protect Your Data With the MonoDefense Security Suite for $130
2023-11-02 09:05

Get VPN, Firewall and SmartDNS protection in one package! Combining five top-rated security apps, the MonoDefense Security Suite offers complete protection - and lifetime subscriptions are now 62% off. It usually involves investing in multiple different security tools and installing those apps across all your devices.

Researchers Find 34 Windows Drivers Vulnerable to Full Device Takeover
2023-11-02 08:59

As many as 34 unique vulnerable Windows Driver Model (WDM) and Windows Driver Frameworks (WDF) drivers could be exploited by non-privileged threat actors to gain full control of the devices and...

FIRST Announces CVSS 4.0 - New Vulnerability Scoring System
2023-11-02 05:19

The Forum of Incident Response and Security Teams (FIRST) has officially announced CVSS v4.0, the next generation of the Common Vulnerability Scoring System standard, more than eight years after...