Scores of Biometrics Bugs Emerge, Highlighting Authentication Risks

Face scans stored like passwords inevitably will be compromised, like passwords are. But there’s a crucial difference between the two that organizations can rely on when their manufacturers fail.

darkreading – ​Read More

Cleveland City Hall Shuts Down After Cyber Incident

As city officials continue to investigate, it’s unclear which systems were affected and whether it was a ransomware attack.

darkreading – ​Read More

Ukraine Arrests Cryptor Specialist Aiding Conti and LockBit Ransomware

Ukrainian Police have arrested a ransomware cryptor developer in connection with the notorious Conti and LockBit groups. This arrest was the result of Operation Endgame, a major operation that aims to dismantle key elements of these cybercriminal organizations.

Hackread – Latest Cybersecurity, Tech, Crypto & Hacking News – ​Read More

Mandiant Report: Snowflake Users Targeted for Data Theft and Extortion

A threat actor exploited the Snowflake platform to target organizations for data theft and extortion using compromised credentials. Learn how to protect your business from this threat.

Security | TechRepublic – ​Read More

LockBit & Conti Ransomware Hacker Busted in Ukraine

Accused cybercriminal has special skills that helped Conti and LockBit ransomware evade detection, according to law enforcement.

darkreading – ​Read More

Google Warns of Pixel Firmware Zero-Day Under Limited, Targeted Exploitation

The zero-day is tagged as CVE-2024-32896 and described as an elevation of privilege issue in Pixel Firmware.

The post Google Warns of Pixel Firmware Zero-Day Under Limited, Targeted Exploitation appeared first on SecurityWeek.

SecurityWeek – ​Read More

Black Basta Ransomware Suspected of Exploiting Windows 0-day Before Patch

The cybersecurity researchers at Symantec have found “strong evidence” suggesting that the Black Basta ransomware gang exploited a critical Windows vulnerability (CVE-2024-26169) before it was patched by Microsoft on March 12, 2024, through its regular Patch Tuesday updates.

Hackread – Latest Cybersecurity, Tech, Crypto & Hacking News – ​Read More

TellYouthePass Ransomware Group Exploits Critical PHP Flaw

An RCE vulnerability that affects the Web scripting language on Windows systems is easy to exploit and can provide a broad attack surface.

darkreading – ​Read More

Businesses’ cloud security fails are ‘concerning’ – as AI threats accelerate

Not enough organizations are conducting regular audits to ensure their cloud environments are secured.

Latest stories for ZDNET in Security – ​Read More

Microsoft Patches Zero-Click Outlook Vulnerability That Could Soon Be Exploited

Microsoft’s June 2024 Patch Tuesday updates resolve a zero-click Outlook vulnerability leading to remote code execution.

The post Microsoft Patches Zero-Click Outlook Vulnerability That Could Soon Be Exploited appeared first on SecurityWeek.

SecurityWeek – ​Read More