Critical Vulnerabilities Found in Anti-Spam Plugin Used by 200,000 WordPress Sites

Two vulnerabilities in the Anti-Spam by CleanTalk WordPress plugin allowed attackers to execute arbitrary code remotely.

The post Critical Vulnerabilities Found in Anti-Spam Plugin Used by 200,000 WordPress Sites appeared first on SecurityWeek.

SecurityWeek – ​Read More

Starbucks, Grocery Stores Hit by Blue Yonder Ransomware Attack

Supply chain management software provider Blue Yonder has been targeted in a ransomware attack that caused significant disruptions for some customers.

The post Starbucks, Grocery Stores Hit by Blue Yonder Ransomware Attack appeared first on SecurityWeek.

SecurityWeek – ​Read More

CISA Urges Agencies to Patch Critical “Array Networks” Flaw Amid Active Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched critical security flaw impacting Array Networks AG and vxAG secure access gateways to its Known Exploited Vulnerabilities (KEV) catalog following reports of active exploitation in the wild.
The vulnerability, tracked as CVE-2023-28461 (CVSS score: 9.8), concerns a case of missing authentication that

The Hacker News – ​Read More

Retailers struggle after ransomware attack on supply chain tech provider Blue Yonder

The company’s customers range from supermarket chains like Morrisons to consumer goods firms like Amway, Anheuser-Busch, Dole and Gap. Other customers include Microsoft, Ford, Lenovo, Mitsubishi and Nestle.

The Record from Recorded Future News – ​Read More

Ransomware Attack on Blue Yonder Hits Starbucks, Supermarkets

The incident is typical of the heightened threats organizations face during the holidays, when most companies reduce their security operations staff by around 50%.

darkreading – ​Read More

Phishing Prevention Framework Reduces Incidents by Half

The anti-fraud plan calls for companies to create a pipeline for compiling attack information, along with formal processes to disseminate that intelligence across business groups.

darkreading – ​Read More

New York fines Geico, Travelers $11 million for exposed driver’s license numbers

New York Attorney General Letitia James and New York State Department of Financial Services Superintendent Adrienne Harris hit both companies with penalties for having “poor data security” which allowed the sensitive information to be exposed.

The Record from Recorded Future News – ​Read More

GLASSBRIDGE: Google Blocks Thousands of Pro-China Fake News Sites

Google reveals GLASSBRIDGE: A network of thousands of fake news sites pushing pro-China narratives globally. These sites, run by PR firms, spread disinformation and lack transparency.

Hackread – Latest Cybersecurity, Tech, Crypto & Hacking News – ​Read More

China’s Salt Typhoon hackers target telecom firms in Southeast Asia with new malware

Salt Typhoon has been in the spotlight recently following a China-linked espionage campaign that compromised the networks of multiple U.S. telecom firms including Verizon, AT&T, Lumen Technologies and T-Mobile.

The Record from Recorded Future News – ​Read More

Cyber Resiliency in the AI Era: Building the Unbreakable Shield 

Digital networks are the backbone of global business and communication, making cyber resiliency essential for organizations to thrive.…

Hackread – Latest Cybersecurity, Tech, Crypto & Hacking News – ​Read More