Mandiant Shines Spotlight on APT45 Behind North Korea’s Digital Military Machine

A fresh Mandiant report documents North Korea’s APT45 as a distinct hacking team conducting cyberespionage and ransomware operations.

The post Mandiant Shines Spotlight on APT45 Behind North Korea’s Digital Military Machine appeared first on SecurityWeek.

SecurityWeek – ​Read More

Russia-Linked Brute-Force Campaign Targets EU via Microsoft Infrastructure

The attackers are primarily targeting High-Value Targets (HVTs) in key infrastructure cities like Edinburgh and Dublin. Over half of the attack IPs are from Moscow, with the rest traced back to Amsterdam and Brussels.

Cyware News – Latest Cyber News – ​Read More

Phone Lines Down in Multiple Courts Across California After Ransomware Attack

Phone lines down in multiple courts across California after ransomware attack on state’s largest trial court in Los Angeles County.

The post Phone Lines Down in Multiple Courts Across California After Ransomware Attack appeared first on SecurityWeek.

SecurityWeek – ​Read More

Google Boosts Chrome Protections Against Malicious Files

Google has announced improved protections for Chrome users when downloading files from the internet.

The post Google Boosts Chrome Protections Against Malicious Files appeared first on SecurityWeek.

SecurityWeek – ​Read More

Okta Browser Plugin Reflected Cross-Site Scripting CVE-2024-0981

Okta Browser Plugin versions 6.5.0 through 6.31.0 are vulnerable to cross-site scripting, prompting users to save credentials in Okta Personal. The issue was fixed in version 6.32.0 for Chrome, Edge, Firefox, and Safari.

Cyware News – Latest Cyber News – ​Read More

CISA Warns of Exploitable Vulnerabilities in Popular BIND 9 DNS Software

The Internet Systems Consortium (ISC) has released patches to address multiple security vulnerabilities in the Berkeley Internet Name Domain (BIND) 9 Domain Name System (DNS) software suite that could be exploited to trigger a denial-of-service (DoS) condition.
“A cyber threat actor could exploit one of these vulnerabilities to cause a denial-of-service condition,” the U.S. Cybersecurity and

The Hacker News – ​Read More

Nvidia Patches High-Severity Vulnerabilities in AI, Networking Products

Nvidia has patched high-severity vulnerabilities in its Jetson, Mellanox OS, OnyX, Skyway, and MetroX products.

The post Nvidia Patches High-Severity Vulnerabilities in AI, Networking Products appeared first on SecurityWeek.

SecurityWeek – ​Read More

CISA Adds Two Known Exploited Vulnerabilities to Catalog

The vulnerabilities are as follows: CVE-2012-4792, a decade-old vulnerability in Internet Explorer allowing remote code execution, and CVE-2024-39891, an information disclosure flaw in Twilio Authy.

Cyware News – Latest Cyber News – ​Read More

Zest Security Aims to Resolve Cloud Risks

Cybersecurity startup Zest Security emerged from stealth with an AI-powered cloud risk resolution platform to reduce time from discovery to remediation.

darkreading – ​Read More

New Chrome Feature Scans Password-Protected Files for Malicious Content

Google said it’s adding new security warnings when downloading potentially suspicious and malicious files via its Chrome web browser.
“We have replaced our previous warning messages with more detailed ones that convey more nuance about the nature of the danger and can help users make more informed decisions,” Jasika Bawa, Lily Chen, and Daniel Rubery from the Chrome Security team said.
To that

The Hacker News – ​Read More