The Mystery of the Targeted Ad and the Library Patron

An attorney discovered that the mobile ads she saw were reflecting her recent library audiobook borrowing habits, raising concerns about the privacy of library patron data and the potential for targeted advertising based on that information.

Cyware News – Latest Cyber News – ​Read More

Cybercriminals Shift Tactics to Pressure More Victims Into Paying Ransoms

Cybercriminals’ new tactics led to a 64% increase in ransomware claims in 2023, driven by a 415% rise in “indirect” incidents and remote access vulnerabilities, pressuring more victims to pay ransoms, according to At-Bay.

Cyware News – Latest Cyber News – ​Read More

Fortinet FortiSIEM Command Injection Flaw (CVE-2023-34992) Deep-Dive

Researchers at Horizon3.ai discovered a critical remote code execution vulnerability (CVE-2023-34992) in Fortinet FortiSIEM, allowing unauthenticated attackers to execute commands as root users and gain access to sensitive information.

Cyware News – Latest Cyber News – ​Read More

CyberArk Snaps up Venafi for $1.54B to Ramp up in Machine-to-Machine Security

The acquisition will allow CyberArk to expand its capabilities in securing machine-to-machine communications and address the growing attack surface in the cloud-first, AI-driven, and post-quantum world.

Cyware News – Latest Cyber News – ​Read More

GitCaught Campaign Leverages GitHub Repositories and Fake Profiles for Malicious Infrastructure

Insikt Group uncovered a sophisticated campaign led by Russian-speaking actors who used GitHub profiles to spoof legitimate software apps and distribute various malware, including Atomic macOS Stealer (AMOS) and Vidar.

Cyware News – Latest Cyber News – ​Read More

NextGen Healthcare Mirth Connect Under Attack – CISA Issues Urgent Warning

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a security flaw impacting NextGen Healthcare Mirth Connect to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
The flaw, tracked as CVE-2023-43208 (CVSS score: N/A), concerns a case of unauthenticated remote code execution arising from an incomplete

The Hacker News – ​Read More

“Linguistic Lumberjack” Vulnerability Discovered in Popular Logging Utility Fluent Bit

Cybersecurity researchers have discovered a critical security flaw in a popular logging and metrics utility called Fluent Bit that could be exploited to achieve denial-of-service (DoS), information disclosure, or remote code execution.
The vulnerability, tracked as CVE-2024-4323, has been codenamed Linguistic Lumberjack by Tenable Research. It impacts versions from 2.0.7 through

The Hacker News – ​Read More

DoJ Shakes Up North Korea's Widespread IT Freelance Scam Operation

Fraudsters based in the US and Europe indicted for helping North Korea’s nation-state groups establish fake freelancer identities and evade sanctions.

darkreading – ​Read More

Google Pitches Workspace as Microsoft Email Alternative, Citing CSRB Report

The new Secure Alternative Program from Google aims to entice customers away from Exchange Online and break Microsoft’s dominance in enterprise.

darkreading – ​Read More

HP Catches Cybercriminals 'Cat-Phishing' Users

Post Content

darkreading – ​Read More