Security News

Organizations under pressure to modernize their IT infrastructures
2024-03-22 05:30

The use of hybrid multicloud models is forecasted to double over the next one to three years as IT decision makers are facing new pressures to modernize IT infrastructures because of drivers like AI, security, and sustainability, according to Nutanix. "Whether it be because of AI, sustainability, or security imperatives, IT organizations are facing ever-increasing pressure to modernize their IT infrastructure quickly," said Lee Caswell, SVP, Product and Solutions Marketing at Nutanix.

Hackers earn $1,132,500 for 29 zero-days at Pwn2Own Vancouver
2024-03-22 05:13

Pwn2Own Vancouver 2024 has ended with security researchers collecting $1,132,500 after demoing 29 zero-days. Vendors have 90 days to release security fixes for zero-day vulnerabilities reported during Pwn2Own contests before TrendMicro's Zero Day Initiative discloses them publicly.

Inside the book – See Yourself in Cyber: Security Careers Beyond Hacking
2024-03-22 05:00

The book, published by Wiley, explores the breadth and depth of cybersecurity careers. It debunks myths and stereotypes about cybersecurity careers and highlights opportunities the industry offers to those with business, legal, communications, and other non-technical backgrounds.

95% of companies face API security problems
2024-03-22 04:30

95% of respondents surveyed by Fastly said they had experienced API security problems in the last twelve months. "The results of our survey show that decision-makers know that increased reliance on APIs creates a risk of serious cyberattacks. But so far they are not doing enough about it. This is surprising given that the operational and reputational cost of a breach far outweighs the price of deploying a consolidated web application and API security solution from a single provider," said Jay Coley, Senior Security Architect at Fastly.

Russian Hackers May Have Targeted Ukrainian Telecoms with Upgraded 'AcidPour' Malware
2024-03-22 03:06

The data wiping malware called AcidPour may have been deployed in attacks targeting four telecom providers in Ukraine, new findings from SentinelOne show. The cybersecurity firm also confirmed...

Truck-to-truck worm could infect – and disrupt – entire US commercial fleet
2024-03-22 00:03

While there are some 880 devices registered, "Only a few tens of distinct ELD models" have hit the road in commercial trucks. They used bench level testing systems for the demo, as well as additional testing on a moving 2014 Kenworth T270 Class 6 research truck equipped with a vulnerable ELD. "In our evaluation of ELD units procured from various resellers, we discovered that they are distributed with factory default firmware settings that present considerable security risks," the authors noted.

FBI v the bots: Feds urge denial-of-service defense after critical infrastructure alert
2024-03-21 22:20

The US government has recommended a series of steps that critical infrastructure operators should take to prevent distributed-denial-of-service attacks. The joint guide, entitled Understanding and Responding to Distributed Denial-Of-Service Attacks [PDF], distinguishes between denial-of-service and DDoS attacks.

Microsoft faces bipartisan criticism for alleged censorship on Bing in China
2024-03-21 21:25

Microsoft is the subject of growing criticism in the US over allegations that its Bing search engine censors results for users in China that relate to sensitive subjects the state wants blocked. Republican Senator Marco Rubio has added his voice to criticism of the Redmond software giant for reportedly removing search results from Bing on human rights, democracy, climate change, and other sticky issues within China.

Congress votes unanimously to ban brokers selling American data to enemies
2024-03-21 20:30

The US House of Representatives has passed a bill that would prohibit data brokers from selling Americans' data to foreign adversaries with an unusual degree of bipartisan support: It passed without a single opposing vote. The Protecting Americans' Data from Foreign Adversaries Act of 2024 was introduced in the house earlier this month alongside the recently-passed TikTok ban bill and gives the Federal Trade Commission authority to go after any data broker that sells PII to North Korea, Russia, China or Iran, or any company controlled by those countries.

Windows 11 Notepad finally gets spellcheck and autocorrect
2024-03-21 20:07

Microsoft continues to add new features to the Windows Notepad, today announcing a preview release with built-in spellchecking and an autocorrect feature. Windows Notepad languished without new features for years while more modern text editors, like Notepad2 and Notepad++, were developed and released.