Recorded Future Judge: FTC can move forward with plans to impose tough new privacy restrictions on Meta A federal judge will not stop the Federal Trade Commission (FTC) from intensifying restrictions it previously imposed on Meta as part of a record-breaking $5 billion privacy settlement. District Judge Timothy Kelly's Monday ruling allows the FTC to move ahead with a new proposal to impose a "blanket prohibition" on Facebook monetizing youth data. Quest Software annonce sa participation au programme Microsoft Security Copilot Business
Critical Zoom Vulnerability Let Hackers Take Over Meetings, Steal Data By Waqas A critical Zoom Room vulnerability allowed exploiting service accounts for unauthorized tenant access.
Informatica and MongoDB Expand Global Partnership Business News
Tigera Achieves AWS Security Competency Status Product Reviews
Dig Security released ransomware research Security Vulnerability
MITRE ATT&CK Update Includes Wi-Fi Discovery, Defense Evasion and Masquerading Tactics Business News
Google Patches Another Chrome Zero-Day as Browser Attacks Mount Roger Biscay will be joining Qrypt's Board of Advisors Business News
Ukrainian gets 8-year sentence for running marketplace for Americans' data A Ukrainian citizen was sentenced to eight years in U.S. prison for administering a marketplace that sold the personal information of millions of Americans. Vitalii Chychasov, 37, was arrested in March of last year while attempting to enter Hungary and was later extradited to the U.S. Chychasov previously agreed to forfeit $5 million in proceeds
Okta: Breach Affected All Customer Support Users
US Seizes Bitcoin Mixer Sinbad.io Used by Lazarus Group By Waqas US Treasury Sanctions Sinbad.io for Laundering Millions in Stolen Funds Linked to North Korea's Lazarus Group. Patch Now: Attackers Pummel Critical, Easy-to-Exploit OwnCloud Flaw
Google DeepMind GNoME helped to discover 2.2 million new crystals
What Are NMAP scripts? Iranian Hackers Exploit PLCs in Attack on Water Authority in U.S.
Thought GDPR Compliance Was Hard? Buckle Up
Cybercriminals expand targeting of Iranian bank customers with known mobile malware Researchers have uncovered more than 200 fake mobile apps that mimic major Iranian banks to steal information from their customers. The campaign was first discovered in July of this year, but since then, the cybercriminals have expanded their capabilities, according to U.S.-based cybersecurity firm Zimperium. Initially, the threat actor behind the campaign created 40 credential-harvesting
Temporary surveillance extension to ride on defense policy bill U.S. lawmakers are expected to attach a short-term extension of a controversial surveillance tool to this year's final defense policy bill, a congressional source told Recorded Future News. By hitching a temporary renewal of Section 702 of the Foreign Intelligence Surveillance Act - which is set to expire at the end of the calendar year
Comment NumSpot donne corps à son cloud souverain
Cybercriminals Exploit ActiveMQ Flaw to Spread GoTitan Botnet, PrCtrl Rat By Deeba Ahmed The ActiveMQ flaw has been patched, but despite this, numerous threat actors continue to exploit it. North Texas Municipal Water District suffers cyberattack The North Texas Municipal Water District reported that it was hit with a cyberattack that disrupted some of its systems, including phones.
Okta security breach affected all customer support system users All Okta customer support system users were impacted by a security breach announced last month, the company's chief security officer said Wednesday - revealing that the breach was far larger than previously understood. Last month, the company said hackers were able to access "files inside Okta's customer support system associated with 134 Okta customers." Several
A Cutting-Edge Cancer Treatment May Cause Cancer. The FDA Is Investigating
What You Need to Know about the Pennsylvania Water Authority's Breach Pennsylvania Water Authority hit by supply chain attack, demonstrating it's possible to be a victim without being the main target of a cyberattack  Iran affiliated hackers are claiming responsibility  What Happened?  Over the weekend, threat actors took control of a system associated with a booster station at the Municipal Water Authority of Aliquippa in Pennsylvania. The compromised system monitors and regulates water pressure for nearby towns.   A hacking group called Cyber Av3ngers has claimed credit for the attack.    Who is Cyber Av3ngers?  Cyber Av3ngers is an Iranian government-affiliated hacktivist group which has operated for a long time on and […]
AWS annonce deux nouvelles puces IA
Okta data breach dilemma dwarfs earlier estimates
GoTitan Botnet and PrCtrl RAT Exploit Apache Vulnerability
Why Ransomware Could Surge in the Middle East & Africa
Google network displayed ads on sanctioned websites, report shows Google served ads for several Fortune 500 companies and U.S. federal agencies on the website of an Iranian company "specially designated" for sanctions, a new report says. In some cases, ads for these organizations - as well as major political figures and government agencies - also appeared on several hardcore porn websites, according to screenshots
British Afrobeat singer pleads guilty to stealing $6 million in hacks on financial accounts A British man pleaded guilty in the Eastern District of New York on Tuesday to charges related to hacking into email and brokerage accounts and stealing more than $6 million from victims. Idris Dayo Mustapha faces up to 20 years in prison on charges of computer intrusion, securities fraud, wire fraud and access device fraud.
DeleFriend Weakness Puts Google Workspace Security at Risk
Ringleader of Prolific Ransomware Gang Arrested in Ukraine
Cybersecurity Certifications Open Doors to New Career Opportunities
No One Knows How Online Pharmacy Company was Hit with a Data Breach Impacting 2.3 Million Customers This is a cautionary tale of both how your data can legally end up in the hands of an organization you never intended and how victims can be largely left in the dark post-breach.
Okta Breach Impacted All Customer Support Users-Not 1 Percent
Les centres de données, moteurs invisibles du changement
200+ Malicious Apps on Iranian Android Store Installed by Millions of Banking Users
Japan's space agency hit by cyberattack Japan's aerospace exploration agency (JAXA) was hit by a cyberattack, a government representative said during the briefing on Wednesday. The unknown hackers reportedly targeted the agency's network server but failed to gain access to sensitive information. JAXA is responsible for developing and launching satellites into orbit and is also involved in advanced missions such as
Okta Broadens Scope of Data Breach: All Customer Support Users Affected Okta expands scope of October breach, saying hackers stole names and email addresses of all its customer support system users. Discover Why Proactive Web Security Outsmarts Traditional Antivirus Solutions
How Internet Radio Hosting Royalties Fuel the Digital Airwaves By Owais Sultan In today's era, where streaming platforms reign supreme in the music industry, internet radio continues to thrive as…
Server sales down 31% at HPE as enterprises hack spending
AI Boosts Malware Detection Rates by 70%
Zero Trust OT Security is built to provide visibility and security for OT assets and networks, 5G connected assets and remote operations.
What cybersecurity pros can learn from first responders Though they may initially seem very different, there are some compelling similarities between cybersecurity professionals and traditional first responders like police and EMTs. After all, in a world where a cyberattack on critical infrastructure could cause untold damage and harm, cyber responders must be ready for anything. But are they actually prepared? Compared to the […]
CISA Issues ICS Advisories on Mitsubishi, Delta, Franklin Electric, BD & Unitronics PLCs' Active Exploitation
Risk Modeling and Real-Time Intelligence - Part 1
New BLUFFS Bluetooth Attack Methods Can Have Large-Scale Impact: Researcher An academic researcher demonstrates BLUFFS, six novel attacks targeting Bluetooth sessions' forward and future secrecy.
Black Basta ransomware made over $100 million from extortion
Hackers breach US water facility via exposed Unitronics PLCs
Det. Eng. Weekly #49 - There Is No Cow Level
CISA Warns of Unitronics PLC Exploitation Following Water Utility Hack After hackers compromised ICS at a US water utility, CISA issued a warning over the exploitation of the targeted Unitronics PLC.
Jeux P2E, escroqueries aux œuvres de bienfaisance et deepfakes vocaux : ce que 2024 réserve au grand public Malwares
4ème Trophée Européen de la Femme Cyber du CEFCYS : les noms des grandes finalistes de l'édition 2023 sont dévoilés ! British Library begins contacting customers as Rhysida leaks data dump
Hackers vs Hacktivistes Récemment, la Direction Interministérielle du Numérique (DINUM) a lancé un programme de bug bounty visant à rémunérer les hackers qui arriveraient à identifier des vulnérabilités sur France Connect, la plateforme mise en place par le gouvernement pour faciliter la connexion aux services publics et démarches en ligne. Un exercice loin d'être rare pour des hackers […]
Breaking Laptop Fingerprint Sensors Security researchers Jesse D'Aguanno and Timo Teräs write that, with varying degrees of reverse-engineering and using some external hardware, they were able to fool the Goodix fingerprint sensor in a Dell Inspiron 15, the Synaptic sensor in a Lenovo ThinkPad T14, and the ELAN sensor in one of Microsoft's own Surface Pro Type Covers. These are just three laptop models from the wide universe of PCs, but one of these three companies usually does make the fingerprint sensor in every laptop we've reviewed in the last few years. It's likely that most Windows PCs with fingerprint readers will be vulnerable to similar exploits...
Get the AT&T Cybersecurity Insights Report: Focus on Transportation The robust quantitative field survey reached 1,418 security, IT, application development, and line of business professionals worldwide. The qualitative research tapped subject matter experts across the cybersecurity industry. Transportation-specific respondents equal 202. At the onset of our research, we established the following hypotheses. Momentum edge computing has in the market. Approaches to connecting and securing the edge ecosystem – including the role of trusted advisors to achieve edge goals. Perceived risk and perceived benefit of the common use cases in each industry surveyed. The results focus on common edge use cases in seven vertical industries – healthcare, retail, finance, manufacturing, energy and utilities, transportation, and U.S. SLED- delivering actionable advice for securing and connecting an edge ecosystem, including external trusted advisors. Finally, it examines cybersecurity and the broader edge ecosystem of networking, service providers, and top use cases. The role of IT is shifting, embracing stakeholders at the ideation phase of development. Edge computing is a transformative technology that brings together various stakeholders and aligns their interests to drive integrated business outcomes. The emergence of edge computing has been fueled by a generation of visionaries who grew up in the era of smartphones and limitless possibilities. Look at the infographic below for a topline summary of key findings in the transportation industry. In this paradigm, the role of IT has shifted from being the sole leader to a collaborative partner in delivering innovative edge computing solutions. In addition, we found that transportation leaders are budgeting differently for edge use cases. These two things, along with an expanded approach to securing edge computing, were prioritized by our respondents in the 2023 AT&T Cybersecurity Insights Report: Edge Ecosystem. One of the most promising aspects of edge computing is its potential to effectively use near-real-time data for tighter control of variable operations such as inventory and supply chain management that deliver improved operational efficiency. Adding new endpoints is essential for collecting the data, but how they're connected can make them vulnerable to cyberattacks. Successful cyberattacks can disrupt services, highlighting the need for robust cybersecurity measures. Edge computing brings the data closer to where decisions are made. With edge computing, the intelligence required to make decisions, the networks used to capture and transmit data, and the use case management are distributed. Distributed means things work faster because nothing is backhauled to a central processing area such as a data center and delivers the near-real-time experience. With this level of complexity, it's common to re-evaluate decisions regarding security, data storage, or networking. The report shares emerging trends as transportation continues exploring edge computing use cases. Government departments dismissing cyber insurance despite breaches in their thousands Special Reports
Okta Discloses Broader Impact Linked to October 2023 Support System Breach DJVU Ransomware's Latest Variant 'Xaro' Disguised as Cracked Software Piratage de l'un des leaders de l'hébergement touristique
UK government rings the death knell for SIM farms
les groupes militants soutenus par l'Iran passent du bitcoin au tron pour financer leurs activités.
les répercussions inattendues du soutien financier de l'UE à l'Ukraine : une augmentation des activités cybercriminelles
GoTitan Botnet Spotted Exploiting Recent Apache ActiveMQ Vulnerability
A Fifth of UK SMBs Can't Spot Scams
OwnCloud "graphapi" App Vulnerability Exposes Sensitive Data Deeba Ahmed The vulnerability is tracked as CVE-2023-49103 and declared critical with a CVSS v3 Base Score 10. GoTitan Botnet Spotted Exploiting Recent Apache ActiveMQ Vulnerability 2023-11-29T10:37:00+00:00 https://thehackernews.com/2023/11/gotitan-botnet-spotted-exploiting.html www.secnews.physaphae.fr/article.php?IdArticle=8417700 False Vulnerability None 2.0000000000000000 InfoSecurity Mag - InfoSecurity Magazine A Fifth of UK SMBs Can\'t Spot Scams 2023-11-29T10:30:00+00:00 https://www.infosecurity-magazine.com/news/a-fifth-uk-smbs-cant-spot-scams/ www.secnews.physaphae.fr/article.php?IdArticle=8417763 False None None 3.0000000000000000 HackRead - Chercher Cyber OwnCloud “graphapi” App Vulnerability Exposes Sensitive Data Deeba Ahmed The vulnerability is tracked as CVE-2023-49103 and declared critical with a CVSS v3 Base Score 10. Anticiper l'intégration de l'IA en entreprise : un virage stratégique et éthique
Transmit Security integrates new AI capabilities into Customer Identity Security platform Product Reviews
Lutte contre la pédopornographie : nouvelles arrestations
Hackers Exploit Critical Vulnerability in ownCloud
Zero-Day Alert: Google Chrome Under Active Attack, Exploiting New Vulnerability AWS et Nvidia renforcent leur collaboration sur la GenAI
KO définitif pour LockerGoga
CyberSecura formalisiert seine Partnerschaft mit Serenys Assurances, einem Versicherungsmaklerunternehmen für Cyberrisiken Business
Google Fixes Sixth Chrome Zero-Day Bug of the Year
CyberSecura formalises its partnership with Serenys Assurances, an insurance brokerage firm covering cyber risks Business News
Sophos Anticipates AI-Based Attack Techniques and Prepares Detections Special Reports
Okta: October data breach affects all customer support system users
Filmora 13, le logiciel de montage vidéo assisté par IA, sort sa nouvelle version Suite
Trend Micro Incorporated annonce Trend Vision One™ Produits
Découvrez Gerry, l'enregistreur d'écran open-source pour Mac
Zero Trust and (Why It Isn't Always About) Identity
Japan's space agency suffers cyber attack, points finger at Active Directory
Hamas-Linked Group This is a post from HackRead.com Read the original post: Hamas-Linked Group Revives SysJoker Malware, Leverages OneDrive]]> 2023-11-29T06:51:24+00:00 https://www.hackread.com/hamas-group-sysjoker-malware-leverages-onedrive/ www.secnews.physaphae.fr/article.php?IdArticle=8417711 False None None 2.0000000000000000 ComputerWeekly - Computer Magazine Scope of Okta helpdesk breach widens to impact all users 2023-11-29T05:45:00+00:00 https://www.computerweekly.com/news/366561432/Scope-of-Okta-helpdesk-breach-widens-to-impact-all-users www.secnews.physaphae.fr/article.php?IdArticle=8417756 False None None 2.0000000000000000 The State of Security - Magazine Américain Holiday Shopping: Tips and Best Practices to Help you Stay Secure 2023-11-29T03:04:33+00:00 https://www.tripwire.com/state-of-security/holiday-shopping-tips-and-best-practices-help-you-stay-secure www.secnews.physaphae.fr/article.php?IdArticle=8417729 False None None 2.0000000000000000 The State of Security - Magazine Américain Building Fortra as Your Cybersecurity Ally 2023-11-29T03:04:30+00:00 https://www.tripwire.com/state-of-security/building-fortra-your-cybersecurity-ally www.secnews.physaphae.fr/article.php?IdArticle=8417730 False None None 2.0000000000000000 CyberScoop - scoopnewsgroup.com special Cyber Pennsylvania water facility hit by Iran-linked hackers An anti-Israel hacking group with links to Iran forced a water facility in Pennsylvania to go into manual operations. ]]> 2023-11-29T00:31:06+00:00 https://cyberscoop.com/pennsylvania-water-facility-hack-iran/ www.secnews.physaphae.fr/article.php?IdArticle=8417662 False None None 3.0000000000000000 WatchGuard - Fabricant Matériel et Logiciels Les prédictions cyber 2024 du Threat Lab WatchGuard 2023-11-29T00:00:00+00:00 https://www.watchguard.com/fr/wgrd-news/press-releases/manipulation-de-modeles-linguistiques-piratage-de-casques-vr-renouveau-des www.secnews.physaphae.fr/article.php?IdArticle=8417803 False Prediction None 3.0000000000000000 ProofPoint - Cyber Firms Proofpoint\'s 2024 Predictions: Brace for Impact 2023-11-28T23:05:04+00:00 https://www.proofpoint.com/us/blog/ciso-perspectives/proofpoints-2024-predictions-brace-impact www.secnews.physaphae.fr/article.php?IdArticle=8417740 False Prediction None 3.0000000000000000 SonarSource - Blog Sécu et Codage Sonar is “On the Radar”: New Omdia Report 2023-11-28T23:00:00+00:00 https://www.sonarsource.com/blog/sonar-is-on-the-radar-new-omdia-report www.secnews.physaphae.fr/article.php?IdArticle=8417869 False None None None Recorded Future - FLux Recorded Future Experts warn of critical ownCloud vulnerability being exploited Several security research companies are warning that a recently disclosed vulnerability affecting ownCloud is being exploited by hackers, ramping up the urgency for organizations to address the bug as soon as possible. ownCloud is a popular open-source software used to share files, contacts and calendar info. Last Tuesday, the company warned of CVE-2023-49103 - a]]> 2023-11-28T22:15:00+00:00 https://therecord.media/experts-warn-of-owncloud-vulnerability-being-exploited www.secnews.physaphae.fr/article.php?IdArticle=8417646 False None None 2.0000000000000000 Dark Reading - Informationweek Branch CISA to Congress: US Under Threat of Chemical Attacks 2023-11-28T22:00:00+00:00 https://www.darkreading.com/cyber-risk/cisa-to-congress-us-under-threat-of-chemical-attacks www.secnews.physaphae.fr/article.php?IdArticle=8417647 False None None 3.0000000000000000 RiskIQ - cyber risk firms (now microsoft) Ransomware Spotlight: Trigona 2023-11-28T21:56:39+00:00 https://community.riskiq.com/article/c02ee065 www.secnews.physaphae.fr/article.php?IdArticle=8417638 False None None 3.0000000000000000 Dark Reading - Informationweek Branch Critical Vulns Found in Ray Open Source Framework for AI/ML Workloads 2023-11-28T21:55:00+00:00 https://www.darkreading.com/vulnerabilities-threats/researchers-discover-trio-of-critical-vulns-in-ray-open-source-framework-for-scaling-ai-ml-workloads www.secnews.physaphae.fr/article.php?IdArticle=8417636 False None None 2.0000000000000000 Global Security Mag - Site de news francais Cisco annonce une nouvelle solution de visibilité et d\'analyse des performances pour les applications modernes sur AWS Produits]]> 2023-11-28T20:49:51+00:00 https://www.globalsecuritymag.fr/Cisco-annonce-une-nouvelle-solution-de-visibilite-et-d-analyse-des-performances.html www.secnews.physaphae.fr/article.php?IdArticle=8417624 False None None None Recorded Future - FLux Recorded Future Healthcare manufacturer Henry Schein expects platform restored this week after cyberattack One of the largest distributors of healthcare products in the U.S. has restored some of its systems this week after more than a month of disruptions related to multiple cyberattacks. Henry Schein, which reported more than $12.5 billion in sales last year and has more than one million customers worldwide, said on Monday it has]]> 2023-11-28T20:45:00+00:00 https://therecord.media/healthcare-giant-henry-schein-recovers-from-cyber-incident www.secnews.physaphae.fr/article.php?IdArticle=8417622 False None None None