Security News > 2024 > November

2,000 Palo Alto Networks devices compromised in latest attacks
2024-11-21 11:20

Attackers have compromised around 2,000 Palo Alto Networks firewalls by leveraging the two recently patched zero-days (CVE-2024-0012 and CVE-2024-9474), Shadowserver Foundation’s internet-wide...

Over 145,000 Industrial Control Systems Across 175 Countries Found Exposed Online
2024-11-21 11:00

New research has uncovered more than 145,000 internet-exposed Industrial Control Systems (ICS) across 175 countries, with the U.S. alone accounting for over one-third of the total exposures. The...

Now Online Safety Act is law, UK has 'priorities' – but still won't explain 'spy clause'
2024-11-21 10:38

Draft doc struggles to describe how theoretically encryption-busting powers might be used The UK government has set out plans detailing how it will use the new law it has created to control online...

Now BlueSky hit with crypto scams as it crosses 20 million users
2024-11-21 10:28

As users are flocking to BlueSky from social media platforms like X/Twitter, so are threat actors. BleepingComputer has spotted cryptocurrency scams popping up on BlueSky just as the decentralized...

Researchers unearth two previously unknown Linux backdoors
2024-11-21 09:59

ESET researchers have identified multiple samples of two previously unknown Linux backdoors: WolfsBane and FireWood. The goal of the backdoors and tools discovered is cyberespionage that targets...

5 Scattered Spider Gang Members Indicted in Multi-Million Dollar Cybercrime Scheme
2024-11-21 09:16

Five alleged members of the infamous Scattered Spider cybercrime crew have been indicted in the U.S. for targeting employees of companies across the country using social engineering techniques to...

Ukrainian cyberwar experience becomes blueprint for TRYZUB cyber training service
2024-11-21 08:55

The Computer Emergency Response Team of Ukraine (CERT-UA), part of the State Service of Special Communications and Information Protection (SSSCIP), has joined forces with the simulation training...

Google's AI-Powered OSS-Fuzz Tool Finds 26 Vulnerabilities in Open-Source Projects
2024-11-21 07:13

Google has revealed that its AI-powered fuzzing tool, OSS-Fuzz, has been used to help identify 26 vulnerabilities in various open-source code repositories, including a medium-severity flaw in the...

NodeStealer Malware Targets Facebook Ad Accounts, Harvesting Credit Card Data
2024-11-21 06:34

Threat hunters are warning about an updated version of the Python-based NodeStealer that's now equipped to extract more information from victims' Facebook Ads Manager accounts and harvest credit...

AxoSyslog: Open-source scalable security data processor
2024-11-21 06:30

AxoSyslog is a syslog-ng fork, created and maintained by the original creator of syslog-ng, Balazs Scheidler, and his team. “We first started by making syslog-ng more cloud-ready: we packaged...