ThreatLocker Raises $115M in Series D Funding

The round was led by existing investor General Atlantic, with participation from other major investors StepStone Group and the D. E. Shaw group. The company intends to use the funds to drive product innovation and accelerate its global expansion.

Cyware News – Latest Cyber News – ​Read More

Critical WordPress Automatic Plugin Vulnerability Exploited to Inject Backdoors

A vulnerability in the WordPress Automatic plugin is being exploited to inject backdoors and web shells into websites.

The post Critical WordPress Automatic Plugin Vulnerability Exploited to Inject Backdoors appeared first on SecurityWeek.

SecurityWeek – ​Read More

Autodesk Hosting PDF Files Used in Microsoft Phishing Attacks

Researchers discovered a sophisticated phishing campaign that is using compromised email accounts and Autodesk’s file sharing platform to steal Microsoft login credentials from victims.

Cyware News – Latest Cyber News – ​Read More

Researchers Sinkhole PlugX Malware Server With 2.5 Million Unique IPs

Researchers have sinkholed a command and control server for a variant of the PlugX malware and observed in six months more than 2.5 million connections from unique IP addresses.

Cyware News – Latest Cyber News – ​Read More

Transatlantic Cable podcast episode 344 | Kaspersky official blog

Episode 344 of the Transatlantic Cable podcast kicks off with news that Grindr is being sued or sharing sensitive user data with third-parties. From there the team talk about news from the U.K, which shows that a third of 5-7 year old children already have their own mobile phones.

To wrap up, the team talk about news that Meta AI is now inserting itself into Facebook group chats, but it doesn’t always go to plan.

If you like what you heard please consider subscribing.

Grindr sued for allegedly revealing users’ HIV status
Ofcom: Almost a quarter of kids aged 5-7 have smartphones
Meta’s AI tells Facebook user it has disabled, gifted child in response to parent asking for advice

Kaspersky official blog – ​Read More

Hackers Exploiting WP-Automatic Plugin Bug to Create Admin Accounts on WordPress Sites

Threat actors are attempting to actively exploit a critical security flaw in the WP‑Automatic plugin for WordPress that could allow site takeovers.
The shortcoming, tracked as CVE-2024-27956, carries a CVSS score of 9.9 out of a maximum of 10. It impacts all versions of the plugin prior to 3.9.2.0.
“This vulnerability, a SQL injection (SQLi) flaw, poses a severe threat as

The Hacker News – ​Read More

PCI Launches Payment Card Cybersecurity Effort in the Middle East

The payment card industry pushes for more security in financial transactions to help combat increasing fraud in the region.

darkreading – ​Read More

How to change your IP address, why you’d want to – and when you shouldn’t

Looking for more privacy? Or easier access to a network device? Here are the steps for every operating system, and how to avoid address conflicts.

Latest stories for ZDNET in Security – ​Read More

OpenAI’s GPT-4 Can Autonomously Exploit 87% of One-Day Vulnerabilities, Study Finds

Researchers from the University of Illinois Urbana-Champaign found that OpenAI’s GPT-4 is able to exploit 87% of a list of vulnerabilities when provided with their NIST descriptions.

Security | TechRepublic – ​Read More

5 Attack Trends Organizations of All Sizes Should Be Monitoring

Recent trends in breaches and attack methods offer a valuable road map to cybersecurity professionals tasked with detecting and preventing the next big thing.

darkreading – ​Read More