Security News > 2024 > November

Winos4.0 abuses gaming apps to infect, control Windows machines
2024-11-08 02:30

'Multiple' malware samples likely targeting education orgs Criminals are using game-related applications to infect Windows systems with a malicious software framework called Winos4.0 that gives...

Don't open that 'copyright infringement' email attachment – it's an infostealer
2024-11-07 22:18

Curiosity gives crims access to wallets and passwords Organizations should be on the lookout for bogus copyright infringement emails as they might be the latest ploy by cybercriminals to steal their data.…

North Korean hackers use new macOS malware against crypto firms
2024-11-07 22:15

North Korean threat actor BlueNoroff has been targeting crypto-related businesses with a new multi-stage malware for macOS systems. [...]

CISA warns of critical Palo Alto Networks bug exploited in attacks
2024-11-07 19:03

Today, CISA warned that attackers are exploiting a critical missing authentication vulnerability in Palo Alto Networks Expedition, a migration tool that can help convert firewall configuration...

Nokia says hackers leaked third-party app source code
2024-11-07 18:24

Nokia's investigation of recent claims of a data breach found that the source code leaked on a hacker forum belongs to a third party and company and customer data has not been impacted. [...]

Canada orders TikTok to shut down over national risk concerns
2024-11-07 16:23

The Canadian government has ordered the dissolution of TikTok Technology Canada following a multi-step review that provided information and evidence of the social media company posing a national...

Prompt Injection Defenses Against LLM Cyberattacks
2024-11-07 16:13

Interesting research: “Hacking Back the AI-Hacker: Prompt Injection as a Defense Against LLM-driven Cyberattacks“: Large language models (LLMs) are increasingly being harnessed to automate...

Cyber Insurance Policy
2024-11-07 16:00

As the digital landscape becomes more interconnected, it brings with it the growing threat of cyberattacks. The purpose of this policy, written by Maria Carrisa Sanchez for TechRepublic Premium,...

HPE warns of critical RCE flaws in Aruba Networking access points
2024-11-07 15:47

Hewlett Packard Enterprise (HPE) released updates for Instant AOS-8 and AOS-10 software to address two critical vulnerabilities in Aruba Networking Access Points. [...]

Industrial companies in Europe targeted with GuLoader
2024-11-07 13:39

A recent spear-phishing campaign targeting industrial and engineering companies in Europe was aimed at saddling victims with the popular GuLoader downloader and, ultimately, a remote access trojan...