Security News

Cybersecurity Blind Spots in IaC and PaC Tools Expose Cloud Platforms to New Attacks
2024-11-25 11:24

Cybersecurity researchers have disclosed two new attack techniques against infrastructure-as-code (IaC) and policy-as-code (PaC) tools like HashiCorp's Terraform and Open Policy Agent (OPA) that...

Hackers breach US firm over Wi-Fi from Russia in 'Nearest Neighbor Attack'
2024-11-22 19:33

Russian state hackers APT28 (Fancy Bear/Forest Blizzard/Sofacy) breached a U.S. company through its enterprise WiFi network while being thousands of miles away, by leveraging a novel technique...

SafePay ransomware gang claims Microlise attack that disrupted prison van tracking
2024-11-22 08:34

Fledgling band of crooks says it stole 1.2 TB of data The new SafePay ransomware gang has claimed responsibility for the attack on UK telematics biz Microlise, giving the company less than 24...

PyPI Attack: ChatGPT, Claude Impersonators Deliver JarkaStealer via Python Libraries
2024-11-22 06:15

Cybersecurity researchers have discovered two malicious packages uploaded to the Python Package Index (PyPI) repository that impersonated popular artificial intelligence (AI) models like OpenAI...

Deepfake attacks occur every five minutes
2024-11-22 04:30

As cybercriminals continue to adapt their techniques to find new ways through defenses, AI-assisted fraud is growing increasingly sophisticated and frequent, according to Entrust. The findings...

Apple Patches Two Zero-Day Attack Vectors
2024-11-21 19:55

Threat actors exploited two vulnerabilities in Intel-based machines. Google’s Threat Analysis Group discovered the flaws.

Warning: Over 2,000 Palo Alto Networks Devices Hacked in Ongoing Attack Campaign
2024-11-21 16:22

As many as 2,000 Palo Alto Networks devices are estimated to have been compromised as part of a campaign abusing the newly disclosed security flaws that have come under active exploitation in the...

Fortinet VPN design flaw hides successful brute-force attacks
2024-11-21 14:38

A design flaw in the Fortinet VPN server's logging mechanism can be leveraged to conceal the successful verification of credentials during a brute-force attack without tipping off defenders of...

2,000 Palo Alto Networks devices compromised in latest attacks
2024-11-21 11:20

Attackers have compromised around 2,000 Palo Alto Networks firewalls by leveraging the two recently patched zero-days (CVE-2024-0012 and CVE-2024-9474), Shadowserver Foundation’s internet-wide...

Mega US healthcare payments network restores system 9 months after ransomware attack
2024-11-20 18:01

Change Healthcare’s $2 billion recovery is still a work in progress Still reeling from its February ransomware attack, Change Healthcare confirms its clearinghouse services are back up and...