State-Sponsored Hackers Exploit Zero-Day to Backdoor Palo Alto Networks Firewalls

A state-sponsored threat actor has been exploiting a zero-day in Palo Alto Networks firewalls for the past two weeks.

The post State-Sponsored Hackers Exploit Zero-Day to Backdoor Palo Alto Networks Firewalls appeared first on SecurityWeek.

SecurityWeek – ​Read More

Change Healthcare Faces Another Ransomware Threat—and It Looks Credible

Change Healthcare ransomware hackers already received a $22 million payment. Now a second group is demanding money, and it has sent WIRED samples of what they claim is the company’s stolen data.

Security Latest – ​Read More

CISA Issues Emergency Directive After Midnight Blizzard Microsoft Hits

Though Federal Civilian Executive Branch (FCEB) agencies are the primary targets, CISA encourages all organizations to up their security, given the high risk.

darkreading – ​Read More

Apple Alerts iPhone Users in 92 Countries to Mercenary Spyware Attacks

Apple recommends that iPhone users install software updates, use strong passwords and 2FA, and don’t open links or attachments from suspicious emails to keep their device safe from spyware.

Security | TechRepublic – ​Read More

Wiz Acquires Gem Security, Pushes Security Tools Consolidation

Financial terms of the translation were not disclosed but reports out of Tel Aviv valued the deal in the range of $350 million.

The post Wiz Acquires Gem Security, Pushes Security Tools Consolidation appeared first on SecurityWeek.

SecurityWeek – ​Read More

LastPass Dodges Deepfake Scam: CEO Impersonation Attempt Thwarted

By Waqas

Cybercriminals using deepfakes to target businesses! LastPass narrowly avoids security breach after employee identifies fake CEO in WhatsApp call. Read how LastPass is urging awareness against evolving social engineering tactics.

This is a post from HackRead.com Read the original post: LastPass Dodges Deepfake Scam: CEO Impersonation Attempt Thwarted

Hackread – Latest Cybersecurity, Tech, Crypto & Hacking News – ​Read More

The Race for AI-Powered Security Platforms Heats Up

Microsoft, Google, and Simbian each offer generative AI systems that allow security operations teams to use natural language to automate cybersecurity tasks.

darkreading – ​Read More

Sisense’s data breach is serious enough that CISA is investigating. Here’s what you need to do

A major breach left Sisense customer credentials open to hackers.

Latest stories for ZDNET in Security – ​Read More

Popular Rust Crate liblzma-sys Compromised with XZ Utils Backdoor Files

“Test files” associated with the XZ Utils backdoor have made their way to a Rust crate known as liblzma-sys, new findings from Phylum reveal.
liblzma-sys, which has been downloaded over 21,000 times to date, provides Rust developers with bindings to the liblzma implementation, an underlying library that is part of the XZ Utils data compression software. The

The Hacker News – ​Read More

Sophos Study: 94% of Ransomware Victims Have Their Backups Targeted By Attackers

Research has found that criminals can demand higher ransom when they compromise an organisation’s backup data in a ransomware attack. Discover advice from security experts on how to properly protect your backup.

Security | TechRepublic – ​Read More