Security News > 2024 > October

6 key elements for building a healthcare cybersecurity response plan
2024-10-30 04:30

Medical practices remain vulnerable to cyberattacks, with over a third unable to cite a cybersecurity incident response plan, according to Software Advice. This gap exposes healthcare providers to...

Uncle Sam outs a Russian accused of developing Redline infostealing malware
2024-10-29 23:30

Or: why using the same iCloud account for malware development and gaming is a bad idea The US government has named and charged a Russian national, Maxim Rudometov, with allegedly developing and...

Cast a hex on ChatGPT to trick the AI into writing exploit code
2024-10-29 22:30

'It was like watching a robot going rogue' says researcher OpenAI's language model GPT-4o can be tricked into writing exploit code by encoding the malicious instructions in hexadecimal, which...

New Windows Themes zero-day gets free, unofficial patches
2024-10-29 20:21

Free unofficial patches are now available for a new Windows Themes zero-day vulnerability that allows attackers to steal a target's NTLM credentials remotely. [...]

Massive PSAUX ransomware attack targets 22,000 CyberPanel instances
2024-10-29 19:15

Over 22,000 CyberPanel instances exposed online to a critical remote code execution (RCE) vulnerability were mass-targeted in a PSAUX ransomware attack that took almost all instances offline. [...]

QNAP fixes NAS backup software zero-day exploited at Pwn2Own
2024-10-29 17:35

QNAP has fixed a critical zero-day vulnerability exploited by security researchers on Thursday to hack a TS-464 NAS device during the Pwn2Own Ireland 2024 competition. [...]

Belgian cops cuff 2 suspected cybercrooks in Redline, Meta infostealer sting
2024-10-29 16:35

US also charges an alleged Redline dev, no mention of an arrest International law enforcement officials have arrested two individuals and charged another in connection with the use and...

US charges suspected Redline infostealer developer, admin
2024-10-29 16:14

The identity of a suspected developer and administrator of the Redline malware-as-a-service operation has been revealed: Russian national Maxim Rudometov. Infrastructure takedown As promised on...

The story behind the Health Infrastructure Security and Accountability Act
2024-10-29 16:00

Health care breaches lead to legislation Partner Content Breaches breed regulation; which hopefully in turn breeds meaningful change.…

Everything You Need to Know about the Malvertising Cybersecurity Threat
2024-10-29 16:00

Malvertising is a shortened mash-up of “malicious advertising.” In a nutshell, malvertising is a relatively new cyberattack method in which bad actors inject malicious code into digital ads. These...