Src |
Date (GMT) |
Titre |
Description |
Tags |
Stories |
Notes |
 |
2022-04-28 11:00:27 |
Overcoming Cybersecurity Recruiting Challenges (lien direct) |
Recruiting the best cybersecurity talent is an especially difficult task. Good people are very hard to find in a tight labor market where demand effortlessly outstrips supply.
|
|
|
|
 |
2022-04-28 10:47:39 |
A Chilling Russian Cyber Aim in Ukraine: Digital Dossiers (lien direct) |
Russia's relentless digital assaults on Ukraine may have caused less damage than many anticipated. But most of its hacking is focused on a different goal that gets less attention but has chilling potential consequences: data collection.
|
|
|
|
 |
2022-04-28 10:37:17 |
IETF Publishes RFC 9116 for \'security.txt\' File (lien direct) |
The Internet Engineering Task Force (IETF) has published RFC 9116 for the security.txt file, whose goal is to make it easier for researchers to responsibly disclose the vulnerabilities they find.
|
|
|
|
 |
2022-04-28 10:16:24 |
Over 300,000 Internet-Exposed Databases Identified in 2021 (lien direct) |
Cybersecurity firm Group-IB identified more than 91,000 publicly-exposed databases in the first quarter of 2022, significantly more than in the previous year.
|
|
|
|
 |
2022-04-27 21:08:32 |
Russia Coordinating Cyberattacks With Military Strikes in Ukraine: Microsoft (lien direct) |
A handful of hacker groups aligned with the Russian government have carried out hundreds of cyberattacks against Ukraine since Moscow invaded, US tech giant Microsoft said in a report Wednesday.
It added that in "hybrid" warfare tactics, Russia often matches cyberattacks with military assaults on the battlefield.
|
|
|
|
 |
2022-04-27 20:14:12 |
Privacy Enhancing Tech Startup Enveil Bags $25 Million Investment (lien direct) |
Enveil, an early-stage startup tackling the 'holy grail' of data encryption, has banked another $25 million in funding as investors continue to pour money into the privacy enhancing technology space.
|
|
|
|
 |
2022-04-27 15:29:26 |
(Déjà vu) Watch: The Four Stages of Zero Trust Maturity (lien direct) |
|
|
|
|
 |
2022-04-27 13:54:30 |
Risk Intelligence Company Strider Raises $45 Million (lien direct) |
Risk intelligence startup Strider Technologies today announced that it has raised $45 million in Series B funding, which brings the total investment in the company to $57 million.
The new funding round was led by Valor Equity Partners, with additional investment from DataTribe, One9 Ventures, and Koch Disruptive Technologies.
|
|
|
|
 |
2022-04-27 12:59:53 |
(Déjà vu) Can Tech Visionary Elon Musk Spur Cybersecurity Innovation at Twitter? (lien direct) |
Type:
Story
Image:
Link:
Can Elon Musk Spur Cybersecurity Innovation at Twitter?
Can Tech Visionary Elon Musk Spur Cybersecurity Innovation at Twitter?
|
|
|
|
 |
2022-04-27 12:55:08 |
Internet Outages in French Cities After Cable \'Attacks\': Operator (lien direct) |
Internet and phone services were down or running slowly in several French cities on Wednesday after fibre optic cables were cut overnight in suspected attacks on the crucial data infrastructure, telecom operators said.
|
|
|
|
 |
2022-04-27 12:39:18 |
Can Elon Musk Spur Cybersecurity Innovation at Twitter? (lien direct) |
|
|
|
|
 |
2022-04-27 12:09:40 |
Chinese Cyberspies Targeting Russian Military (lien direct) |
A China-linked state-sponsored cyberespionage group has started targeting the Russian military in recent attacks, which aligns with China's interests in the Russia-Ukraine war, Secureworks reports.
|
|
|
|
 |
2022-04-27 11:52:01 |
ARMO Raises $30 Million for Open Source Kubernetes Security Platform (lien direct) |
ARMO, an Israel-based company that specializes in Kubernetes security, on Wednesday announced raising $30 million in a Series A funding round.
The latest investment, which brings ARMO's total funding to date to $34.5 million, was led by Tiger Global and Hyperwise Ventures, with participation from existing investors Pitango First and Peled Ventures.
|
|
Uber
|
|
 |
2022-04-27 11:15:49 |
(Déjà vu) Chrome 101 Patches 30 Vulnerabilities (lien direct) |
Google this week announced that Chrome 101 was released to the stable channel with 30 security fixes inside, including 25 for vulnerabilities identified by external security researchers.
|
|
|
|
 |
2022-04-27 10:34:42 |
Coca-Cola Investigating Hack Claims Made by Pro-Russia Group (lien direct) |
Coca-Cola has launched an investigation after a cybercrime group claimed to have breached the company's systems, but the hackers' previous claims have been called into question.
The beverage giant said it has notified law enforcement and is trying to “determine the validity of the claim.”
|
Hack
|
|
|
 |
2022-04-27 10:00:15 |
Achieving Sustainable Cybersecurity Through Proper Care and Feeding (lien direct) |
Climate change is probably the greatest threat our planet faces today, but this challenge also presents an opportunity to do the right thing. It's time to step back and look at the role of the IT industry in developing, deploying, maintaining, growing and eventually, sustainably retiring technology and solutions.
|
Threat
|
|
|
 |
2022-04-26 21:22:48 |
Tenable Shells Out $45 Million to Acquire Bit Discovery (lien direct) |
Tenable on Tuesday announced plans to spend $45 million in cash to acquire Bit Discovery, an attack surface management software startup created by cybersecurity pioneers Jeremiah Grossman and Robert Hansen.
|
|
|
|
 |
2022-04-26 21:17:48 |
US Offers $10 Million Reward for Russian Intelligence Officers Behind NotPetya Cyberattacks (lien direct) |
The U.S. Department of State is offering a reward of up to $10 million for information on the attackers behind the June 2017 “NotPetya” cyberattacks that had a massive impact on companies globally.
|
|
NotPetya
NotPetya
|
|
 |
2022-04-26 19:00:51 |
Defending Your Business Against Russian Cyberwarfare (lien direct) |
We are likely to see Russian state sponsored attacks escalate as the West continues to increase sanctions and support Ukraine
|
|
|
|
 |
2022-04-26 16:47:40 |
German Wind Turbine Firm Discloses \'Targeted, Professional Cyberattack\' (lien direct) |
German wind turbine giant Deutsche Windtechnik has issued a notification to warn that some of its IT systems were impacted in a targeted professional cyberattack earlier this month.
|
|
|
|
 |
2022-04-26 16:31:50 |
Web Application Security Firm Source Defense Raises $27 Million (lien direct) |
Source Defense, a provider of web application client-side protection, says it pocketed $27 million in Series B funding, bringing the total investment raised by the company to $47 million.
|
|
|
|
 |
2022-04-26 15:28:06 |
Conti Ransomware Activity Surges Despite Exposure of Group\'s Operations (lien direct) |
Conti ransomware activity has surged in the past weeks despite the recent exposure of the group's operations by a pro-Ukraine hacktivist.
|
Ransomware
|
|
|
 |
2022-04-26 14:30:56 |
Cybersecurity M&A Activity to Continue; Growth Funding to be More Conservative (lien direct) |
|
|
|
|
 |
2022-04-26 13:47:41 |
4-Hour Time-to-Ransom Seen in Quantum Attack as Accelerated Ransomware Increasingly Common (lien direct) |
As part of a recent cyberattack, threat actors deployed ransomware less than four hours after compromising the victim's environment, according to researchers with The DFIR Report.
|
Ransomware
Threat
|
|
|
 |
2022-04-26 11:51:36 |
Webinar Today: The Four Stages of Zero Trust Maturity (lien direct) |
|
|
|
|
 |
2022-04-26 11:00:02 |
Tractor-Trailer Brake Controllers Vulnerable to Remote Hacker Attacks (lien direct) |
|
|
|
|
 |
2022-04-26 10:41:14 |
Organizations Warned of Attacks Exploiting WSO2 Vulnerability (lien direct) |
Products made by enterprise software development solutions provider WSO2 are affected by a critical vulnerability that has been exploited in the wild.
According to WSO2's website, its products are used by many major companies worldwide, including Fortune 500 firms, which could all be at risk.
|
Vulnerability
|
|
|
 |
2022-04-26 09:59:46 |
Code Security Firm SonarSource Raises $412 Million at $4.7 Billion Valuation (lien direct) |
Geneva-based code quality company is cashing in on heightened investor interest in the software supply chain security space
|
|
|
|
 |
2022-04-25 20:45:22 |
North Dakota-Based Healthcare Billing Services Group Hacked (lien direct) |
Federal investigators say a cyber attack on a North Dakota-based company that provides software and billing services for doctors and healthcare professionals affected more than a half-million customers.
|
|
|
|
 |
2022-04-25 16:19:26 |
Why Ransomware Response Matters More Than Protection (lien direct) |
As high-profile attacks of the Albuquerque Public School District, Kronos, CS Energy, Kaseya, |
Ransomware
|
|
|
 |
2022-04-25 15:48:10 |
Former DNC CISO Bob Lord Joins CISA Cybersecurity Division (lien direct) |
The U.S. government's Cybersecurity and Infrastructure Security Agency (CISA) has added former DNC security chief Bob Lord to its roster of technical advisors.
|
|
|
|
 |
2022-04-25 14:42:27 |
State TV Says Iran Foiled Cyberattacks on Public Services (lien direct) |
Iran's state television said authorities have foiled massive cyberattacks that sought to target public services, both government and privately owned.
|
|
|
|
 |
2022-04-25 11:27:42 |
Atlassian Patches Critical Authentication Bypass Vulnerability in Jira (lien direct) |
Atlassian last week announced that its popular issue and project tracking software Jira is affected by a critical vulnerability, and advised customers to take action.
|
Vulnerability
|
|
|
 |
2022-04-25 10:58:44 |
\'Hack DHS\' Participants Awarded $125,000 for Over 100 Vulnerabilities (lien direct) |
The Department of Homeland Security (DHS) has announced the results of the first phase of its “Hack DHS” bug bounty program.
|
|
|
|
 |
2022-04-25 10:25:53 |
Lapsus$ Hackers Gained Access to T-Mobile Systems, Source Code (lien direct) |
T-Mobile has admitted that its systems were breached recently, but the telecoms giant claimed the hackers did not steal anything of value.
T-Mobile is another high-profile victim of the hacker group named Lapsus$. The gang has targeted several major companies, in many cases leaking large amounts of source code and other data stolen from their systems.
|
|
|
|
 |
2022-04-24 18:39:15 |
Spain Vows to be Transparent in Probe of Pegasus Spyware Use (lien direct) |
Spanish authorities are pledging full transparency as they launch inquiries into allegations that the phones of dozens of supporters of Catalan independence were hacked with powerful and controversial spyware only sold to government agencies.
|
|
|
|
 |
2022-04-23 09:46:23 |
Cyberattack Causes Chaos in Costa Rica Government Systems (lien direct) |
Nearly a week into a ransomware attack that has crippled Costa Rican government computer systems, the country refused to pay a ransom as it struggled to implement workarounds and braced itself as hackers began publishing stolen information.
|
Ransomware
|
|
|
 |
2022-04-22 17:18:36 |
Strike Security Scores Funding for \'Perpetual Pentesting\' for SMBs (lien direct) |
South American startup Strike Security has secured $5.4 million to fund an ambitious plan to disrupt the penetration testing and attack surface management business.
|
|
|
|
 |
2022-04-22 14:45:38 |
When Attacks Surge, Turn to Data to Strengthen Detection and Response (lien direct) |
News of cyber criminals and nation-state actors capitalizing on events, planned or unplanned, for financial gain or to wreak havoc have dominated the headlines over the past few years. From COVID to elections to devastating weather events, and now the tragic conflict in Ukraine. We've seen threat actors launch ransomware, supply chain attacks and other sophisticated tactics to compromise organizations and the services they deliver. But the human spirit is strong.
|
Threat
|
|
|
 |
2022-04-22 13:34:23 |
Motorola Launches Cyber Threat Information Sharing Hub for Public Safety (lien direct) |
Motorola Solutions announced this week the creation of the Public Safety Threat Alliance, a cyber threat intelligence sharing hub for the public safety community.
|
Threat
|
|
|
 |
2022-04-22 12:28:23 |
Several Critical Vulnerabilities Affect SmartPPT, SmartICS Industrial Products (lien direct) |
A security researcher has discovered several vulnerabilities, including ones rated critical- and high-severity, in industrial products made by Elcomplus, a Russian company specializing in professional radio communications and industrial automation.
|
|
|
|
 |
2022-04-22 11:07:48 |
Unpatched Vulnerability Allows Hackers to Steal Emails of RainLoop Users (lien direct) |
An unpatched vulnerability affecting the RainLoop webmail client can be exploited to hijack a user's session and steal their emails, according to application security firm Sonar.
|
Vulnerability
|
|
|
 |
2022-04-22 11:01:03 |
VMware\'s Head of Cybersecurity Strategy Discusses Modern Bank Heists (lien direct) |
Digital Bank Heists – Because That's Where the Money Is Today
The financial sector is in the crosshairs of criminal cartels and nation-state actors. Criminals seek a lucrative market, and nation-states treat profit as a form of sanctions-busting.
|
|
|
|
 |
2022-04-22 10:55:31 |
Audio Codec Made by Apple Introduced Serious Vulnerabilities in Millions of Android Phones (lien direct) |
An open source audio codec developed by Apple is affected by serious vulnerabilities that have been pushed to millions of Android devices by some of the world's largest mobile chipset manufacturers.
|
|
|
|
 |
2022-04-21 19:45:26 |
Catalan Chief Accuses Spain\'s Intelligence Agency of Hacking (lien direct) |
The head of Catalonia's regional government is accusing Spain's intelligence agency of conducting what he calls “massive political espionage” on the northeastern region's independence movement and says that relations with Spain's national authorities are “on hold” as a consequence.
|
|
|
|
 |
2022-04-21 18:12:22 |
Google, Mandiant Share Data on Record Pace of Zero-Day Discoveries (lien direct) |
Google and Mandiant separately called attention to a dramatic surge in the discovery of in-the-wild zero-day attacks and warned that nation-state APT actors, ransomware gangs and private mercenary exploit firms are burning through zero-days at record pace.
|
Ransomware
|
|
|
 |
2022-04-21 17:27:09 |
Meta Offers Rewards for Flaws Allowing Attackers to Bypass Integrity Checks (lien direct) |
Facebook parent company Meta today announced that its bug bounty program will cover vulnerabilities that can be exploited to bypass integrity safeguards.
|
|
|
|
 |
2022-04-21 15:08:25 |
ICS Exploits Earn Hackers $400,000 at Pwn2Own Miami 2022 (lien direct) |
Pwn2Own Miami 2022, a hacking contest focusing on industrial control systems (ICS), has come to an end, with contestants earning a total of $400,000 for their exploits.
|
|
|
|
 |
2022-04-21 13:23:27 |
Today\'s Network is Different, Not Dead - Here\'s How You Secure It (lien direct) |
Rapid changes to a network can easily result in gaps in protection and enforcement
|
|
|
|
 |
2022-04-21 12:43:17 |
Access Bypass, Data Overwrite Vulnerabilities Patched in Drupal (lien direct) |
Drupal on Wednesday announced the release of security updates to resolve a couple vulnerabilities that could lead to access bypass and data overwrite.
|
Guideline
|
|
|