CERT/CC Warns of Unpatched Critical Vulnerability in Microchip ASF

Microchip Advanced Software Framework (ASF) 3 is affected by a critical vulnerability that could lead to remote code execution.

The post CERT/CC Warns of Unpatched Critical Vulnerability in Microchip ASF appeared first on SecurityWeek.

SecurityWeek – ​Read More

What Is Threat Hunting In Cybersecurity?

Cyber threat hunting involves taking proactive measures to detect potential threats or malicious activities. Learn about threat-hunting techniques and how they work.

Security | TechRepublic – ​Read More

Versa Networks Patches Vulnerability Exposing Authentication Tokens

Versa Networks has released patches for a Versa Director vulnerability for which proof-of-concept (PoC) code exists.

The post Versa Networks Patches Vulnerability Exposing Authentication Tokens appeared first on SecurityWeek.

SecurityWeek – ​Read More

Keycloak Vulnerability Puts SAML Authentication at Risk

The vulnerability lies in Keycloak’s XMLSignatureUtil class, which incorrectly verifies SAML signatures, disregarding the vital “Reference” element that specifies the signed portion of the document.

Cyware News – Latest Cyber News – ​Read More

US DoJ Charged Two Men With Stealing and Laundering $230 Million Worth of Cryptocurrency

Two suspects, Malone Lam and Jeandiel Serrano, were arrested by the US Department of Justice for stealing and laundering over $230 million worth of cryptocurrency in Miami.

Cyware News – Latest Cyber News – ​Read More

Picus Security Raises $45M in Funding

Picus Security, a San Francisco, CA-based security validation company, raised $45M in funding. The round, which brought total funds raised to $80M, was led by Riverwood Capital, with participation from existing investor Earlybird Digital East Fund.

Cyware News – Latest Cyber News – ​Read More

Cybersecurity Products Conking Out After macOS Sequoia Update

macOS Sequoia updates are causing cybersecurity software failures and breaking network connectivity for many.

The post Cybersecurity Products Conking Out After macOS Sequoia Update appeared first on SecurityWeek.

SecurityWeek – ​Read More

Lumma Stealer Malware Campaign Exploits Fake CAPTCHA Pages

The Lumma Stealer malware is being distributed through deceptive human verification pages that trick Windows users into running malicious PowerShell commands, leading to sensitive information theft.

Cyware News – Latest Cyber News – ​Read More

SambaSpy RAT Targets Italian Users in a Unique Malware Campaign

This unique malware campaign stood out for its precise targeting of Italian victims, with checks implemented to ensure the system language was set to Italian before infecting the device.

Cyware News – Latest Cyber News – ​Read More

New PondRAT Malware Hidden in Python Packages Targets Software Developers

Threat actors with ties to North Korea have been observed using poisoned Python packages as a way to deliver a new malware called PondRAT as part of an ongoing campaign.
PondRAT, according to new findings from Palo Alto Networks Unit 42, is assessed to be a lighter version of POOLRAT (aka SIMPLESEA), a known macOS backdoor that has been previously attributed to the Lazarus Group and deployed in

The Hacker News – ​Read More