Security News

Are Password Managers Safe to Use? (Benefits, Risks & Best Practices)
2024-06-05 10:50

Password managers are a safer way to manage and secure passwords than any other approach. The user simply logs into the password manager using a master password.

TotalRecall shows how easily data collected by Windows Recall can be stolen
2024-06-05 10:12

Ethical hacker Alexander Hagenah has created TotalRecall, a tool that demonstrates how malicious individuals could abuse Windows' newly announced Recall feature to steal sensitive information. Copilot+ Recall takes snapshots of the computer's screen ever few seconds, encrypts and stores the snapshots locally, uses optical character recognition to extract relevant information that users may search for later, and and stores this data locally in an SQLite database, in plain text.

Rebranded Knight Ransomware Targeting Healthcare and Businesses Worldwide
2024-06-05 10:10

An analysis of a nascent ransomware strain called RansomHub has revealed it to be an updated and rebranded version of Knight ransomware, itself an evolution of another ransomware known as Cyclops....

Zyxel Releases Patches for Firmware Vulnerabilities in EoL NAS Models
2024-06-05 07:10

Zyxel has released security updates to address critical flaws impacting two of its network-attached storage (NAS) devices that have currently reached end-of-life (EoL) status. Successful...

Microsoft paid Tenable a bug bounty for an Azure flaw it says doesn't need a fix, just better documentation
2024-06-05 06:44

Tenable thinks these tags can be abused by a rogue Azure customer to access other customers' stuff - a cross-tenant attack - if those victims rely on Service Tags in their firewall rules. "We appreciate the collaboration with Tenable to responsibly disclose the inherent risk in using Service Tags as a single mechanism for vetting secure network traffic," a Microsoft spokesperson told The Register.

Celebrity TikTok Accounts Compromised Using Zero-Click Attack via DMs
2024-06-05 06:22

Popular video-sharing platform TikTok has acknowledged a security issue that has been exploited by threat actors to take control of high-profile accounts on the platform. The development was first...

No summer break for cybercrime: Why educational institutions need better cyber resilience
2024-06-05 04:30

I'm not just talking about cybersecurity education in schools shaping the technical workforce of the future - America's schools themselves are prime targets for cybercrime today. With risks such as student data getting leaked on the dark web, school districts' reputations getting tarnished by ransomware mishandlings, and the potential of any single attack to not only disrupt classes for days or weeks but also threaten the livelihoods of our youth, the stakes are too high to ignore the cyber resiliency of our school system.

How AI-powered attacks are accelerating the shift to zero trust strategies
2024-06-05 04:00

In this Help Net Security interview, Jenn Markey, Advisor to The Entrust Cybersecurity Institute, discusses the increasing adoption of enterprise-wide zero trust strategies in response to evolving cyber threats. Two-thirds of organizations featured in the 2024 State of Zero Trust & Encryption study cited cyber-risk concerns as the main drivers for implementing a zero-trust strategy.

Cybersecurity jobs available right now: June 5, 2024
2024-06-05 03:30

As a Cyber Security Specialist, you will manage security incidents within the Blue Team or Security Operations, develop Python scripts to automate security operations, create and automate incident response playbooks on SOAR platforms. As a Head of the Security Department, you will be responsible for advising the Director General on security for space matters and on the general security strategy for the Agency, proposing, establishing and maintaining a security strategy and policy for ESA corporate security and ESA space projects and programmes.

Find out which cyber threats you should be concerned about
2024-06-05 03:00

In a year of growing insider threats and people-driven data loss, more CISOs than ever see human risk, in particular negligent employees as a key cybersecurity concern over the next two years. Cloud security incidents are alarmingly on the rise, with 61% of organizations reporting breaches within the last year, marking a significant increase from 24% the year before.