Ransomware Attacks on Industrial Firms Surged in Q2 2024

Dragos has seen a significant increase in ransomware attacks on industrial organizations in Q2 2024 compared to the previous quarter.

The post Ransomware Attacks on Industrial Firms Surged in Q2 2024 appeared first on SecurityWeek.

SecurityWeek – ​Read More

Beyond the Hype: Unveiling the Realities of WormGPT in Cybersecurity

Though WormGPT tools may not be a major problem now, organizations can’t let their guard down.

darkreading – ​Read More

Russian-Linked Hackers Target Eastern European NGOs and Media

Russian and Belarusian non-profit organizations, Russian independent media, and international non-governmental organizations active in Eastern Europe have become the target of two separate spear-phishing campaigns orchestrated by threat actors whose interests align with that of the Russian government.
While one of the campaigns – dubbed River of Phish – has been attributed to COLDRIVER, an

The Hacker News – ​Read More

How Can Organizations Navigate SEC’s Cyber Materiality Disclosures?

Inconsistencies and lack of information in cybersecurity disclosures highlight the need for organizations to establish a robust materiality assessment framework.

darkreading – ​Read More

Nearly All Google Pixel Phones Are Left Exposed by Unpatched Flaw in Hidden Android App

A fix is coming, but data analytics giant Palantir says it’s ditching Android devices altogether because Google’s response to the vulnerability has been troubling.

Security Latest – ​Read More

SolarWinds Issues Hotfix for Critical Web Help Desk Vulnerability

SolarWinds has released a hotfix for a critical Java deserialization remote code execution vulnerability in Web Help Desk.

The post SolarWinds Issues Hotfix for Critical Web Help Desk Vulnerability appeared first on SecurityWeek.

SecurityWeek – ​Read More

Google Disrupts Iranian Hacking Activity Targeting US Presidential Election

Google says it blocked Iranian APT42 hackers from accessing the personal email accounts of individuals affiliated with the US elections.

The post Google Disrupts Iranian Hacking Activity Targeting US Presidential Election appeared first on SecurityWeek.

SecurityWeek – ​Read More

Palo Alto Networks Patches Unauthenticated Command Execution Flaw in Cortex XSOAR

Palo Alto Networks has patched multiple vulnerabilities, including ones rated high severity, in several products.

The post Palo Alto Networks Patches Unauthenticated Command Execution Flaw in Cortex XSOAR appeared first on SecurityWeek.

SecurityWeek – ​Read More

Identity Threat Detection and Response Solution Guide

The Emergence of Identity Threat Detection and Response
Identity Threat Detection and Response (ITDR) has emerged as a critical component to effectively detect and respond to identity-based attacks. Threat actors have shown their ability to compromise the identity infrastructure and move laterally into IaaS, Saas, PaaS and CI/CD environments. Identity Threat Detection and Response solutions help

The Hacker News – ​Read More

RansomHub Group Deploys New EDR-Killing Tool in Latest Cyber Attacks

A cybercrime group with links to the RansomHub ransomware has been observed using a new tool designed to terminate endpoint detection and response (EDR) software on compromised hosts, joining the likes of other similar programs like AuKill (aka AvNeutralizer) and Terminator.
The EDR-killing utility has been dubbed EDRKillShifter by cybersecurity company Sophos, which discovered the tool in

The Hacker News – ​Read More