CISO Conversations: Jaya Baloo From Rapid7 and Jonathan Trull From Qualys

CSOs Jaya Baloo and Jonathan Trull discuss the route, role, and requirements in becoming and being a successful CISO.

The post CISO Conversations: Jaya Baloo From Rapid7 and Jonathan Trull From Qualys appeared first on SecurityWeek.

SecurityWeek – ​Read More

Hacktivists Exploits WinRAR Vulnerability in Attacks Against Russia and Belarus

A hacktivist group known as Head Mare has been linked to cyber attacks that exclusively target organizations located in Russia and Belarus.
“Head Mare uses more up-to-date methods for obtaining initial access,” Kaspersky said in a Monday analysis of the group’s tactics and tools.
“For instance, the attackers took advantage of the relatively recent CVE-2023-38831 vulnerability in WinRAR, which

The Hacker News – ​Read More

Canonical Addresses Critical Linux Kernel AWS Vulnerabilities with New Patches

Security researchers have identified six vulnerabilities, including a race condition in the Bluetooth RFCOMM protocol driver that can crash the system, a race condition in the Bluetooth subsystem, and a double-free error in the net/mlx5e module.

Cyware News – Latest Cyber News – ​Read More

Improved Software Supply Chain Resilience Equals Increased Security

Understanding through visibility, managing through governance, and anticipating through continuous deployment will better prepare organizations for the next supply chain attack.

darkreading – ​Read More

Researchers Link ManticoraLoader Malware to Ares Malware Developer

Researchers have traced the new ManticoraLoader malware-as-a-service (MaaS) to the cybercriminal group ‘DarkBLUP,’ previously associated with distributing AresLoader and AiDLocker ransomware from the DeadXInject group.

Cyware News – Latest Cyber News – ​Read More

Verkada to Pay $2.95 Million Over FTC Probe Into Security Camera Hacking

The FTC complaint alleges that Verkada’s failures allowed a hacker to access customers’ security cameras.

The post Verkada to Pay $2.95 Million Over FTC Probe Into Security Camera Hacking appeared first on SecurityWeek.

SecurityWeek – ​Read More

Rocinante Trojan Poses as Banking Apps to Steal Sensitive Data from Brazilian Android Users

Mobile users in Brazil are the target of a new malware campaign that delivers a new Android banking trojan named Rocinante.

“This malware family is capable of performing keylogging using the Accessibility Service, and is also able to steal PII from its victims using phishing screens posing as different banks,” Dutch security company ThreatFabric said.

“Finally, it can use all this exfiltrated

The Hacker News – ​Read More

City of Columbus Sues Researcher Who Disclosed Impact of Ransomware Attack

The City of Columbus sued a researcher who disclosed the impact of the data breach caused by a recent ransomware attack.

The post City of Columbus Sues Researcher Who Disclosed Impact of Ransomware Attack appeared first on SecurityWeek.

SecurityWeek – ​Read More

The 6 Best Antivirus Software Options for Windows in 2024

Bitdefender GravityZone is best overall when it comes to our top choices for protection from malware like viruses, spyware, trojans, and bots.

Security | TechRepublic – ​Read More

Researchers Find SQL Injection Flaw to Bypass Airport TSA Security Checks

Security researchers discovered a SQL injection vulnerability in FlyCASS, a third-party web service used by airlines to manage the Known Crewmember (KCM) program and the Cockpit Access Security System (CASS).

Cyware News – Latest Cyber News – ​Read More