Update: Palo Alto Networks Fixes Zero-Day Exploited to Backdoor Firewalls

This maximum severity security flaw (CVE-2024-3400) affects PAN-OS 10.2, PAN-OS 11.0, and PAN-OS 11.1 firewalls with device telemetry and GlobalProtect (gateway or portal) enabled.

Cyware News – Latest Cyber News – ​Read More

Cloned Voice Tech Is Coming for Bank Accounts

At many financial institutions, your voice is your password. Tiny variations in pitch, tone and timbre make human voices unique – apparently making them an ideal method for authenticating customers phoning for service.

Cyware News – Latest Cyber News – ​Read More

Iran-Backed Hackers Blast Out Threatening Texts to Israelis

Handala threat group claims to have hacked radar systems in Israel as tensions rise between the two nations.

darkreading – ​Read More

Intel and Lenovo BMCs Contain Unpatched Lighttpd Server Flaw

A security flaw impacting the Lighttpd web server used in baseboard management controllers (BMCs) has remained unpatched by device vendors like Intel and Lenovo, new findings from Binarly reveal.
While the original shortcoming was discovered and patched by the Lighttpd maintainers way back in August 2018 with version 1.4.51, the lack of a CVE identifier or an advisory meant that

The Hacker News – ​Read More

US Cyber Command Expanded ‘Hunt Forward’ Operations in 2023

A secretive U.S. cyber military force ramped up global operations in 2023, executing more than double the average number of “hunt forward” campaigns than the previous five years, according to the head of U.S. Cyber Command.

Cyware News – Latest Cyber News – ​Read More

Cyderes Acquires Ipseity Security to Enhance IAM

Global cybersecurity services provider Cyderes has acquired Ipseity Security, a Canadian company specializing in identity and access management (IAM). The financial terms of the deal were not disclosed.

Cyware News – Latest Cyber News – ​Read More

Web3 Game Developers Targeted in Crypto Theft Scheme

A Russian-language cyberattack campaign impersonates legitimate game operations to spread various cross-platform infostealers.

darkreading – ​Read More

Critical Vulnerability in Delinea Secret Server Allows Auth Bypass, Admin Access

Organizations with on-prem installations of Delinea Secret Server are urged to update them immediately, to plug a critical vulnerability that may allow attackers to bypass authentication, gain admin access and extract secrets.

Cyware News – Latest Cyber News – ​Read More

NightVision Raises $5.4 Million for Application Security Testing

NightVision, an early stage startup in the application security testing space, has raised $5.4 million in seed funding.

The post NightVision Raises $5.4 Million for Application Security Testing appeared first on SecurityWeek.

SecurityWeek – ​Read More

Upstream Security Gets Cisco Investment to Protect Connected Vehicles and Devices

Upstream Security, an Israeli auto cybersecurity startup, said on Wednesday it received an undisclosed investment from Cisco Investments as demand grows for internet-connected vehicles and other devices.

Cyware News – Latest Cyber News – ​Read More