Palo Alto Networks Releases Fixes for Firewall Zero-Day as First Attribution Attempts Emerge

Palo Alto Networks has started releasing hotfixes for the firewall zero-day CVE-2024-3400, which some have linked to North Korea’s Lazarus. 

The post Palo Alto Networks Releases Fixes for Firewall Zero-Day as First Attribution Attempts Emerge appeared first on SecurityWeek.

SecurityWeek – ​Read More

Palo Alto Networks Releases Urgent Fixes for Exploited PAN-OS Vulnerability

Palo Alto Networks has released hotfixes to address a maximum-severity security flaw impacting PAN-OS software that has come under active exploitation in the wild.
Tracked as CVE-2024-3400 (CVSS score: 10.0), the critical vulnerability is a case of command injection in the GlobalProtect feature that an unauthenticated attacker could weaponize to execute arbitrary code with root

The Hacker News – ​Read More

NIST Seeks Input on Cyber Risk Management Draft

The public draft – titled Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile, was published by NIST on April 3. The agency is seeking public comments on the draft through May 20.

Cyware News – Latest Cyber News – ​Read More

Cybercriminal Campaign Spreads Infostealers, Highlighting Risks to Web3 Gaming

The campaign targets Web3 gamers, exploiting their potential lack of cyber hygiene in the pursuit of profits. It represents a significant cross-platform threat, utilizing a variety of malware to compromise users’ systems.

Cyware News – Latest Cyber News – ​Read More

Cyberattacks Cost Financial Firms $12 Billion, Says IMF

Financial services firms have been hit with $12bn in losses over the last two decades as a result of cyber attacks, according to a recently published report from the International Monetary Fund (IMF).

Cyware News – Latest Cyber News – ​Read More

US Data Breach Reports Surge 90% Annually in Q1

The first three months of 2024 saw 841 publicly reported “data compromises” – up 90% on the same period last year, according to the Identity Theft Resource Center (ITRC).

Cyware News – Latest Cyber News – ​Read More

CISA Makes its “Malware Next-Gen” Analysis System Publicly Available

Malware Next-Gen was originally designed to allow U.S. federal, state, local, tribal, and territorial government agencies to submit suspicious files and receive automated malware analysis through static and dynamic analysis tools.

Cyware News – Latest Cyber News – ​Read More

Russia Tops Global Cybercrime Index, New Study Reveals

Russia is the most significant source of global cybercrime and serves as the top hub for digital threat actors worldwide, according to the newly released World Cybercrime Index.

Cyware News – Latest Cyber News – ​Read More

Update: Hackers Deploy Python Backdoor in Palo Alto Zero-Day Attack

Threat actors have been exploiting the newly disclosed zero-day flaw in Palo Alto Networks PAN-OS software dating back to March 26, 2024, nearly three weeks before it came to light yesterday.

Cyware News – Latest Cyber News – ​Read More

CISA Adds Multiple D-Link NAS Device Bugs to its Known Exploited Vulnerabilities Catalog

According to BOD 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Cyware News – Latest Cyber News – ​Read More