Mon.Oct 24, 2022

Cybersecurity Event Cancelled After Being Hit By Cybercriminals

Joseph Steinberg

An online cybersecurity event with 2,500 people already logged in had to be cancelled after suspected cybercriminals launched a social engineering attack in the event’s chat window.

GUEST ESSAY: Sure steps to achieve a robust employee cybersecurity awareness training regimen

The Last Watchdog

Employee security awareness is the most important defense against data breaches. Related: Leveraging security standards to protect your company. It involves regularly changing passwords and inventorying sensitive data. Cybercriminals view employees as a path of least resistance. As such, you should limit the amount of information that employees have access to. There are several ways you can protect your business from data breaches. Create security awareness for employees.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Ransomware Barrage Aimed at US Healthcare Sector, Feds Warn

Dark Reading

A CISA advisory warns that the Daixin Team ransomware group has put the US healthcare system in its crosshairs for data extortion, and provides tools to fight back

Cuba ransomware affiliate targets Ukraine, CERT-UA warns

Security Affairs

The Ukraine Computer Emergency Response Team (CERT-UA) warns of Cuba Ransomware attacks against critical networks in the country. The Ukraine Computer Emergency Response Team (CERT-UA) warns of potential Cuba Ransomware attacks against local critical infrastructure.

Successful Change Management with Enterprise Risk Management

Speaker: William Hord, Vice President of ERM Services

Join us as we discuss the various tangents of data and the change management process that will help you make better risk-based business decisions to save time and money for your organization.

Stress Is Driving Cybersecurity Professionals to Rethink Roles

Dark Reading

Burnout has led one-third of cybersecurity staffers to consider changing jobs over the next two years, potentially further deepening the talent shortage, research shows

Download eBook: Top virtual CISOs share 7 tips for vCISO service providers

The Hacker News

More Trending

Optimize and secure your team’s Apple devices with Jamf Now

Tech Republic Security

Learn how Jamf Now’s features can streamline your company’s Apple mobile device management. The post Optimize and secure your team’s Apple devices with Jamf Now appeared first on TechRepublic. Apple Mobility Security Software jamf now mobile security or mobile device security security

Mobile 114

IoT Fingerprinting Helps Authenticate and Secure All Those Devices

Dark Reading

For organizations struggling to protect a rapidly expanding volume of IoT devices, IoT fingerprinting could help with security and management

Chrome extensions with 1 million installs hijack targets’ browsers

Bleeping Computer

Researchers at Guardio Labs have discovered a new malvertizing campaign pushing Google Chrome and Microsoft Edge extensions that hijack searches and insert affiliate links into webpages. [.]. Security

114
114

Employees leaving jobs because of Cyber Attacks

CyberSecurity Insiders

Encore, a security stack management business held a survey recently and found that employees will leave their jobs on a respective note as their business firm has fallen victim to a cyber attack.

Cover Your SaaS: How to Overcome Security Challenges and Risks For Your Organization

Speaker: Ronald Eddings, Cybersecurity Expert and Podcaster

In this webinar, Ronald Eddings, Cybersecurity Expert, will outline the relationship between SaaS apps and IT & security teams, along with several actionable solutions to overcome the new difficulties facing your organization.

Google Chrome to drop support for Windows 7 / 8.1 in Feb 2023

Bleeping Computer

Google announced today that the Google Chrome web browser will likely drop support for Windows 7 and Windows 8.1 starting February 2023. [.]. Google

114
114

Time-Consuming Remediation: Assessing the Impact of Text4Shell

eSecurity Planet

Security researcher Alvaro Muñoz recently warned of a critical vulnerability in versions 1.5 through 1.9 of Apache Commons Text. The flaw, dubbed “Text4Shell” and identified as CVE-2022-42889 , can enable remote code execution via the StringSubstitutor API. In response, version 1.10

Apple fixes new zero-day used in attacks against iPhones, iPads

Bleeping Computer

In security updates released on Monday, Apple has fixed the ninth zero-day vulnerability used in attacks against iPhones since the start of the year. [.]. Apple Security

112
112

CISA says hospitals should be wary of new Daixin Team Ransomware

CyberSecurity Insiders

United States Cybersecurity and Infrastructure Security Agency(CISA) has issued an advisory to all hospitals and healthcare providers about a new ransomware dubbed ‘Daixin Team’ doing rounds on the internet.

How Preparation and Strategy Can Be Used to Fight and Defeat Any Ransomware Attack

Speaker: Karl Camilleri, Cloud Services Product Manager at phoenixNAP

Through a detailed analysis of major attacks and their consequences, Karl Camilleri, Cloud Services Product Manager at phoenixNAP, will discuss the state of ransomware and future predictions, as well as provide best practices for attack prevention and recovery.

Security experts targeted with malicious CVE PoC exploits on GitHub

Security Affairs

Researchers discovered thousands of GitHub repositories that offer fake proof-of-concept (PoC) exploits for various flaws used to distribute malware. A team of researchers at the Leiden Institute of Advanced Computer Science ( Soufian El Yadmani , Robin The , Olga Gadyatskaya ) discovered thousands of repositories on GitHub that offer fake proof-of-concept (PoC) exploits for multiple vulnerabilities.

Iran’s atomic energy agency confirms hack after stolen data leaked online

Bleeping Computer

The Iranian Atomic Energy Organization (AEOI) has confirmed that one of its subsidiaries' email servers was hacked after the ''Black Reward' hacking group published stolen data online. [.]. Security

Malicious Clicker apps in Google Play have 20M+ installs

Security Affairs

Researchers discovered 16 malicious clicker apps in the official Google Play store that were downloaded by 20M+ users. Security researchers at McAfee have discovered 16 malicious clicker apps available in the official Google Play store that were installed more than 20 million times. One of these apps, called DxClean, has more than five million times and its user rating was of 4.1 out of 5 stars.

Cybersecurity's Role in Combating Midterm Election Disinformation

Dark Reading

A multilayered attack technique that took center stage in 2020 and has only grown more endemic

How to Avoid the Pain and Cost of PCI Compliance While Optimizing Payments

Speaker: P. Andrew Sjogren, Sr. Product Marketing Manager at Very Good Security, Matt Doka, Co-Founder and CTO of Fivestars, and Steve Andrews, President & CEO of the Western Bankers Association

In this webinar, we have a great set of panelists who will take you through how Zero Data strategies can be used as part of a well-rounded compliance and security approach, and get you to market much sooner by also allowing for payment optimization. They’ll share how to grow your business faster and minimize costs for both security and compliance

Norway PM warns of Russia cyber threat to oil and gas industry

Security Affairs

Norway ’s prime minister warned last week that Russia poses “a real and serious threat” to the country’s oil and gas industry. Norway ’s prime minister Jonas Gahr Støre warned that Russia poses “a real and serious threat” to the country’s oil and gas industry. The minister claims its country is going slow in adopting necessary measures to protect organizations and critical infrastructure operators in the energy sector from cyberattacks.

Apple Releases Patch for New Actively Exploited iOS and iPadOS Zero-Day Vulnerability

The Hacker News

Tech giant Apple on Monday rolled out updates to remediate a zero-day flaw in iOS and iPadOS that it said has been actively exploited in the wild.

72

Hot on the Trail of a Mass-School-Shooting Hoaxer

WIRED Threat Level

For months, an anonymous caller has terrorized communities around the US by reporting false shooting threats. We know how they did it. The question is, why? Security Security / National Security

69

BrandPost: Cybersecurity Executives Say These are the Most Pressing Challenges They Face

CSO Magazine

Most cybersecurity teams grapple with similar issues, from defending against the ever-changing threat landscape to finding time for training and upskilling opportunities.

CSO 98

Back to the Office: Privacy and Security Solutions to Compliance Issues for 2021 and Beyond

Speaker: Mike Cramer, Director of HIPAA & Data Security at The Word & Brown Companies

Now that companies are slowly allowing employees to return to work at the office, it's time to re-evaluate your company’s posture towards privacy and security. Join Mike Cramer, Director of HIPAA & Data Security at The Word & Brown Companies, for a discussion that will focus on compliance and the types of privacy and security measures your company should be aware of, as well as tips and methods for implementing these measures.

Health Orgs Are Target of Daixin Team Ransomware

SecureWorld News

The FBI, U.S. Department of Health and Human Services, and U.S. Cybersecurity Infrastructure Security Agency (CISA) have issued a joint cybersecurity advisory with information about "Daixin Team," a cybercrime group actively targeting U.S. businesses with ransomware and data extortion operations.

VPN 67

Uptycs Introduces Detections that Correlate Threat Activity from the Kubernetes Control Plane and Container Runtime

Dark Reading

Comprehensive CNAPP coverage for Kubernetes and containers in a single solution

66

Cuba ransomware affiliate targets Ukrainian govt agencies

Bleeping Computer

The Computer Emergency Response Team of Ukraine (CERT-UA) has issued an alert about potential Cuba Ransomware attacks against critical networks in the country. [.]. Security

Apple fixed the ninth actively exploited zero-day this year

Security Affairs

Apple released security updates that addressed the ninth zero-day vulnerability actively exploited in the wild since the start of the year. . Apple has addressed the ninth zero-day vulnerability exploited in attacks in the wild since the start of the year.

Apple megaupdate: Ventura out, iOS and iPad kernel zero-day – act now!

Naked Security

Ventura hits the market with 112 patches, Catalina's gone missing, and iPhones and iPads get a critical kernel-level zero-day patch. Apple iOS OS X Vulnerability 0 day CVE-2022-42827 Exploit ios iPad iPhone mac vulnerability zer-day

Hornetsecurity Launches Next-Generation Security Awareness Training to Help Organizations Strengthen Their Human Firewall

Dark Reading

Best-in-class awareness training comes after a marked increase in cybersecurity risks and attacks in 2022

5 reasons to keep your software and devices up to date

We Live Security

Next time you're tempted to hold off on installing software updates, remember why these updates are necessary in the first place. The post 5 reasons to keep your software and devices up to date appeared first on WeLiveSecurity. Cybersecurity

Embracing the Next Generation of Business Developers

Dark Reading

Security teams that embrace low-code/no-code can change the security mindset of business users

62

A New-ish Mobile Attack: Zero-Click Spyware

SecureWorld News

Bloomberg is reporting that in July 2020, an Azerbaijani journalist was the victim of a zero-click attack, commonly used by governments to target political opponents. The journalist's iPhone received a command to open the Apple Music app without the victim's knowledge or even touching the phone.

Nok Nok, a Global Leader in Customer Passwordless Authentication, Releases Full Support for Passkeys

Dark Reading

Nok Nok, an inventor of FIDO authentication standards, announces full support for passkeys in its S3 Authentication Suite that allows organizations to replace passwords