Security News

Critical Veeam Backup Enterprise Manager Flaw Allows Authentication Bypass
2024-05-22 03:45

Users of Veeam Backup Enterprise Manager are being urged to update to the latest version following the discovery of a critical security flaw that could permit an adversary to bypass authentication...

CEOs accelerate GenAI adoption despite workforce resistance
2024-05-22 03:30

CEOs are facing workforce, culture and governance challenges as they act quickly to implement and scale generative AI across their organizations, according to IBM. The annual global study of 3,000 CEOs from over 30 countries and 26 industries found that 64% of those surveyed say succeeding with generative AI will depend more on people's adoption than the technology itself. The findings also revealed that 63% of surveyed CEOs say their teams have the skills and knowledge to incorporate generative AI, but few understand how generative AI adoption impacts their organization's workforce and culture.

Technological complexity drives new wave of identity risks
2024-05-22 03:00

Security leaders are facing increased technological and organizational complexity, which is creating a new wave of identity risks for their organizations, according to ConductorOne. "We're now squarely in a new world order in which identity and access must be viewed and managed as a high-priority security risk, not just an IT issue," said Alex Bovee, CEO of ConductorOne.

Uncle Sam to inject $50M into auto-patcher for hospital IT
2024-05-22 00:46

Your profile can be used to present content that appears more relevant based on your possible interests, such as by adapting the order in which content is shown to you, so that it is even easier for you to find content that matches your interests. Content presented to you on this service can be based on your content personalisation profiles, which can reflect your activity on this or other services, possible interests and personal aspects.

GhostEngine mining attacks kill EDR security using vulnerable drivers
2024-05-21 22:30

A malicious crypto mining campaign codenamed 'REF4578,' has been discovered deploying a malicious payload named GhostEngine that uses vulnerable drivers to turn off security products and deploy an XMRig miner. Researchers at Elastic Security Labs and Antiy have underlined the unusual sophistication of these crypto-mining attacks in separate reports and shared detection rules to help defenders identify and stop them.

Veeam warns of critical Backup Enterprise Manager auth bypass bug
2024-05-21 22:24

VBEM is a web-based platform that enables administrators to manage Veeam Backup & Replication installations via a single web console. It's important to note that VBEM isn't enabled by default, and not all environments are susceptible to attacks exploiting the CVE-2024-29849 vulnerability, which Veeam has rated with a CVSS base score of 9.8/10. "This vulnerability in Veeam Backup Enterprise Manager allows an unauthenticated attacker to log in to the Veeam Backup Enterprise Manager web interface as any user," the company explains.

LockBit says they stole data in London Drugs ransomware attack
2024-05-21 21:23

Today, the LockBit ransomware gang claimed they were behind the April cyberattack on Canadian pharmacy chain London Drugs and is now threatening to publish stolen data online after allegedly failed negotiations. Earlier today, the LockBit ransomware operation added London Drugs to its extortion portal, claiming the April cyberattack and threatening to publish data allegedly stolen from the company's systems.

Zoom adds 'post-quantum' encryption for video nattering
2024-05-21 19:45

Your profile can be used to present content that appears more relevant based on your possible interests, such as by adapting the order in which content is shown to you, so that it is even easier for you to find content that matches your interests. Content presented to you on this service can be based on your content personalisation profiles, which can reflect your activity on this or other services, possible interests and personal aspects.

Western Sydney University data breach exposed student data
2024-05-21 19:39

Western Sydney University has notified students and academic staff about a data breach after threat actors breached its Microsoft 365 and Sharepoint environment. In an announcement posted on the Western Sydney University website today, the University warned that hackers had accessed its Microsoft Office 365 environment, including email accounts and SharePoint files.

Bitbucket artifact files can leak plaintext authentication secrets
2024-05-21 19:05

Threat actors were found breaching AWS accounts using authentication secrets leaked as plaintext in Atlassian Bitbucket artifact objects. As developers may not be aware that these secrets are exposed in artifact files, the source code may be published to public repositories where threat actors can steal them.