Security News

DeltaNet International Phishing Simulator strengthens phishing attacks awareness training
2021-06-30 02:15

DeltaNet International announced the availability of its Phishing Simulator, to help organizations strengthen their cybersecurity awareness training against phishing attacks. The phishing simulation tool can be used simply to test the susceptibility of an organization from falling victim to a phishing attack, but when combined with follow-up training to close knowledge and risk gaps, users can experience true added value.

Microsoft Translation Bugs Open Edge Browser to Trivial UXSS Attacks
2021-06-29 16:34

Microsoft patched two bugs in its Chromium-based Edge browser last week, one of which could be used by an attacker to bypass security and to remotely inject and execute arbitrary code on any website just by sending a message. The flaw stems from a universal cross-site scripting issue that's triggered when automatically translating web pages using the Edge browser's built-in Microsoft Translator feature: a feature through which the browser automatically prompts users to translate a webpage when the page is in a language other than those listed under the user's preferred languages in settings.

UN Security Council Confronts Growing Threat of Cyber Attacks
2021-06-29 11:05

The UN Security Council on Tuesday will hold its first formal public meeting on cybersecurity, addressing the growing threat of hacks to countries' key infrastructure, an issue Joe Biden recently raised with his Russian counterpart Vladimir Putin. Tuesday's meeting, called by Estonia which heads the Council for the month of June and is a leader in the fight against hacking, is itself being held online, at a ministerial level.

NVIDIA Patches High-Severity GeForce Spoof-Attack Bug
2021-06-28 20:38

NVIDIA gaming graphics software called GeForce Experience, bundled with the chipmaker's popular GTX GPU, is flawed and opens the door to a remote attacker that can exploit the bug to steal or manipulate data on a vulnerable Windows computer. NVIDIA notified customers late last week of the bug and released a software patch for the flaw, which is present in its GeForce Experience Windows software.

Cybersecurity study: SolarWinds attack cost affected companies an average of $12 million
2021-06-28 19:13

New survey finds that the attack also motivated more information sharing within the industry and improved supply chain security. The good news is that security teams are beefing up network defenses, but the bad news is that most companies have recently suffered a cybersecurity incident that required a board meeting.

Cybersecurity study: SolarWinds attack cost affected US companies an average of $12 million
2021-06-28 12:00

New survey finds that the attack also motivated more information sharing within the industry and improved supply chain security. The good news is that security teams are beefing up network defenses, but the bad news is that most companies have recently suffered a cybersecurity incident that required a board meeting.

Week in review: Preventing ransomware attacks, SOC burnout, and customizing your ATT&CK database
2021-06-27 08:00

SOC burnout is real: 3 preventative steps every CISO must takeFor those that spend every day as a security professional and for anyone who truly appreciates the demands applied to these essential security team members, burnout is a harsh reality. Cloud security skills in high demandCloud security is critically important for organizations across the globe as adoption of cloud infrastructure continues to grow at a rapid clip.

PS3 Players Ban: Latest Victims of Surging Attacks on Gaming Industry
2021-06-25 21:03

After enabling two-factor authentication, one player was able to sign back in without issue, according to posts on the PS3 subreddit, which includes a link to instructions on how to opt into 2FA on the PS3. It appears threat actors have started using the stolen PS3 console IDs for malicious purposes, causing the legitimate players to get banned. Another player on the PSNProfies forum put the stolen PS3 IDs and the ban together back on June 18.

Ransomware-as-a-service business model takes a hit in the aftermath of the Colonial Pipeline attack
2021-06-25 19:09

The response to the Colonial Pipeline ransomware attack may be the first step in doing just that. Bryan Oliver, a senior analyst at Flashpoint said that the response from governments in the wake of the Colonial Pipeline attack has made it harder for ransomware groups to recruit partners.

Bit Discovery Banks $4 Million for Attack Surface Management Tech
2021-06-25 17:22

Jeremiah Grossman's Bit Discovery has banked another $4 million in venture capital funding to compete in the crowded attack surface management space. Bit Discovery has raised a total of $6.6 million to build and sell an attack surface management tool to help security programs to identify and manage Internet-connected assets.