ToneShell Backdoor Targets IISS Defence Summit Attendees in Latest Espionage Campaign

The ToneShell backdoor, attributed to the Mustang Panda cyber espionage group, has resurfaced in a new attack targeting attendees of the 2024 IISS Defence Summit in Prague.

Cyware News – Latest Cyber News – ​Read More

Healthcare Provider to Pay $65M Settlement Following Ransomware Attack

Lehigh Valley Health Network has agreed to pay a $65 million settlement in a class-action suit filed over a 2023 data breach.

The post Healthcare Provider to Pay $65M Settlement Following Ransomware Attack appeared first on SecurityWeek.

SecurityWeek – ​Read More

Exploiting CI/CD Pipelines for Fun and Profit

On September 8, 2024, a significant exploit chain was discovered, starting from a publicly exposed . git directory, leading to a full server takeover. The vulnerabilities stem from websites exposing their . git folders.

Cyware News – Latest Cyber News – ​Read More

Amateurish ‘CosmicBeetle’ Ransomware Stings SMBs in Turkey

With an immature codebase and a “rather chaotic encryption scheme” prone to failure, the group targets small businesses with custom malware.

darkreading – ​Read More

WordPress Mandates Two-Factor Authentication for Plugin and Theme Developers

WordPress.org has announced a new account security measure that will require accounts with capabilities to update plugins and themes to activate two-factor authentication (2FA) mandatorily.
The enforcement is expected to come into effect starting October 1, 2024.
“Accounts with commit access can push updates and changes to plugins and themes used by millions of WordPress sites worldwide,” the

The Hacker News – ​Read More

Criminal IP Teams Up with IPLocation.io to Deliver Unmatched IP Solutions to Global Audiences

Torrance, United States / California, 12th September 2024, CyberNewsWire

Hackread – Latest Cybersecurity, Tech, Crypto & Hacking News – ​Read More

Flipper Zero gets a big firmware upgrade, and some amazing new features

After three years of development, the portable hacking tool gets its first major firmware update – to version 1.0!

Latest stories for ZDNET in Security – ​Read More

Dark Reading Expands Its Coverage to the Asia-Pacific Region

The latest step in a journey to serve cybersecurity professionals in other regions of the world.

darkreading – ​Read More

Google’s AI Model Faces European Union Scrutiny From Privacy Watchdog

Ireland’s Data Protection Commission said it has opened an inquiry into Google’s Pathways Language Model 2, also known as PaLM2.

The post Google’s AI Model Faces European Union Scrutiny From Privacy Watchdog appeared first on SecurityWeek.

SecurityWeek – ​Read More

Apple Intelligence Promises Better AI Privacy. Here’s How It Actually Works

Private Cloud Compute is an entirely new kind of infrastructure that, Apple’s Craig Federighi tells WIRED, allows your personal data to be “hermetically sealed inside of a privacy bubble.”

Security Latest – ​Read More