The US is Preparing Criminal Charges in Iran Hack Targeting Trump, AP Sources Say
Fri, 13 Sep 2024 00:57:31 +0000
The prospect of criminal charges comes as the Justice Department has raised alarms about aggressive efforts by countries including Russia and Iran to meddle in the presidential election.
The post The US is Preparing Criminal Charges in Iran Hack Targeting Trump, AP Sources Say appeared first on SecurityWeek.
https://www.securityweek.com/the-us-is-preparing-criminal-charges-in-iran-hack-targeting-trump-ap-sources-say/
New Android Malware ‘Ajina.Banker’ Steals Financial Data and Bypasses 2FA via Telegram
Thu, 12 Sep 2024 21:42:00 +0530
Bank customers in the Central Asia region have been targeted by a new strain of Android malware codenamed Ajina.Banker since at least November 2024 with the goal of harvesting financial information and intercepting two-factor authentication (2FA) messages.
Singapore-headquartered Group-IB, which discovered the threat in May 2024, said the malware is propagated via a network of Telegram channels
https://thehackernews.com/2024/09/new-android-malware-ajinabanker-steals.html
New Chrome Features Protect Users Against Threats, Provide More Control Over Personal Data
Thu, 12 Sep 2024 16:01:00 +0000
Google is rolling out new features in Chrome to better protect users online and to improve their control over personal data.
The post New Chrome Features Protect Users Against Threats, Provide More Control Over Personal Data appeared first on SecurityWeek.
https://www.securityweek.com/new-chrome-features-protect-users-against-threats-provide-more-control-over-personal-data/
Urgent: GitLab Patches Critical Flaw Allowing Unauthorized Pipeline Job Execution
Thu, 12 Sep 2024 21:25:00 +0530
GitLab on Wednesday released security updates to address 17 security vulnerabilities, including a critical flaw that allows an attacker to run pipeline jobs as an arbitrary user.
The issue, tracked as CVE-2024-6678, carries a CVSS score of 9.9 out of a maximum of 10.0
“An issue was discovered in GitLab CE/EE affecting all versions starting from 8.14 prior to 17.1.7, starting from 17.2 prior to
https://thehackernews.com/2024/09/urgent-gitlab-patches-critical-flaw.html
Operant AI Lands $10M Investment to Boost Runtime Protection for Cloud and AI
Thu, 12 Sep 2024 15:52:43 +0000
Operant AI, a startup specializing in runtime protection for cloud applications, APIs, and AI systems, secures new $10 million investment.
The post Operant AI Lands $10M Investment to Boost Runtime Protection for Cloud and AI appeared first on SecurityWeek.
https://www.securityweek.com/operant-ai-lands-10m-investment-to-boost-runtime-protection-for-cloud-and-ai/
Realm.Security Emerges From Stealth With $5 Million in Seed Funding
Thu, 12 Sep 2024 14:10:00 +0000
Realm.Security has emerged from stealth with $5 million in funding and a solution that helps organizations manage security data.
The post Realm.Security Emerges From Stealth With $5 Million in Seed Funding appeared first on SecurityWeek.
https://www.securityweek.com/realm-security-emerges-from-stealth-with-5-million-in-seed-funding/
Beware: New Vo1d Malware Infects 1.3 Million Android TV Boxes Worldwide
Thu, 12 Sep 2024 19:16:00 +0530
Nearly 1.3 million Android-based TV boxes running outdated versions of the operating system and belonging to users spanning 197 countries have been infected by a new malware dubbed Vo1d (aka Void).
“It is a backdoor that puts its components in the system storage area and, when commanded by attackers, is capable of secretly downloading and installing third-party software,” Russian antivirus
https://thehackernews.com/2024/09/beware-new-vo1d-malware-infects-13.html
Evasion Tactics Used By Cybercriminals To Fly Under The Radar
Thu, 12 Sep 2024 13:24:58 +0000
Relentless in their methods, attackers will continue employing evasion tactics to circumvent traditional security measures.
The post Evasion Tactics Used By Cybercriminals To Fly Under The Radar appeared first on SecurityWeek.
https://www.securityweek.com/evasion-tactics-used-by-cybercriminals-to-fly-under-the-radar/
Palo Alto Networks Patches Dozens of Vulnerabilities
Thu, 12 Sep 2024 13:09:15 +0000
Palo Alto Networks has fixed medium- and high-severity vulnerabilities in PAN-OS, Cortex XDR, ActiveMQ Content Pack, and Prisma Access Browser.
The post Palo Alto Networks Patches Dozens of Vulnerabilities appeared first on SecurityWeek.
https://www.securityweek.com/palo-alto-networks-patches-dozens-of-vulnerabilities/
Non-Human IAM Provider Aembit Raises $25 Million
Thu, 12 Sep 2024 13:00:00 +0000
Aembit has raised $25 million in Series A funding to protect non-human identities and minimize attack surface.
The post Non-Human IAM Provider Aembit Raises $25 Million appeared first on SecurityWeek.
https://www.securityweek.com/non-human-iam-provider-aembit-raises-25-million/
Exposed Selenium Grid Servers Targeted for Crypto Mining and Proxyjacking
Thu, 12 Sep 2024 18:26:00 +0530
Internet-exposed Selenium Grid instances are being targeted by bad actors for illicit cryptocurrency mining and proxyjacking campaigns.
“Selenium Grid is a server that facilitates running test cases in parallel across different browsers and versions,” Cado Security researchers Tara Gould and Nate Bill said in an analysis published today.
“However, Selenium Grid’s default configuration lacks
https://thehackernews.com/2024/09/exposed-selenium-grid-servers-targeted.html
Mastercard to Acquire Threat Intelligence Firm Recorded Future for $2.6 Billion
Thu, 12 Sep 2024 12:27:39 +0000
Financial services giant Mastercard is acquiring Recorded Future from private equity firm Insight Partners for $2.6 billion.
The post Mastercard to Acquire Threat Intelligence Firm Recorded Future for $2.6 Billion appeared first on SecurityWeek.
https://www.securityweek.com/mastercard-to-acquire-threat-intelligence-firm-recorded-future-for-2-6-billion/
Cisco Patches High-Severity Vulnerabilities in Network Operating System
Thu, 12 Sep 2024 11:12:12 +0000
Cisco has announced security updates that patch eight vulnerabilities in IOS XR software, including six high-severity bugs.
The post Cisco Patches High-Severity Vulnerabilities in Network Operating System appeared first on SecurityWeek.
https://www.securityweek.com/cisco-patches-high-severity-vulnerabilities-in-network-operating-system/
Top 3 Threat Report Insights for Q2 2024
Thu, 12 Sep 2024 16:21:00 +0530
Cato CTRL (Cyber Threats Research Lab) has released its Q2 2024 Cato CTRL SASE Threat Report. The report highlights critical findings based on the analysis of a staggering 1.38 trillion network flows from more than 2,500 of Cato’s global customers, between April and June 2024.
Key Insights from the Q2 2024 Cato CTRL SASE Threat Report
The report is packed with unique insights that are based on
https://thehackernews.com/2024/09/top-3-threat-report-insights-for-q2-2024.html
Iranian Cyber Group OilRig Targets Iraqi Government in Sophisticated Malware Attack
Thu, 12 Sep 2024 16:19:00 +0530
Iraqi government networks have emerged as the target of an “elaborate” cyber attack campaign orchestrated by an Iran state-sponsored threat actor called OilRig.
The attacks singled out Iraqi organizations such as the Prime Minister’s Office and the Ministry of Foreign Affairs, cybersecurity company Check Point said in a new analysis.
OilRig, also called APT34, Crambus, Cobalt Gypsy, GreenBug,
https://thehackernews.com/2024/09/iranian-cyber-group-oilrig-targets.html
Ireland’s Watchdog Launches Inquiry into Google’s AI Data Practices in Europe
Thu, 12 Sep 2024 16:02:00 +0530
The Irish Data Protection Commission (DPC) has announced that it has commenced a “Cross-Border statutory inquiry” into Google’s foundational artificial intelligence (AI) model to determine whether the tech giant has adhered to data protection regulations in the region when processing the personal data of European users.
“The statutory inquiry concerns the question of whether Google has complied
https://thehackernews.com/2024/09/irelands-watchdog-launches-inquiry-into.html
Iranian Hackers Targeting Iraqi Government: Security Firm
Thu, 12 Sep 2024 10:00:00 +0000
Hackers believed to be operating on behalf of the Iranian government have deployed malware to Iraqi government networks.
The post Iranian Hackers Targeting Iraqi Government: Security Firm appeared first on SecurityWeek.
https://www.securityweek.com/iranian-hackers-targeting-iraqi-government-security-firm/
WordPress Mandates Two-Factor Authentication for Plugin and Theme Developers
Thu, 12 Sep 2024 10:27:00 +0530
WordPress.org has announced a new account security measure that will require accounts with capabilities to update plugins and themes to activate two-factor authentication (2FA) mandatorily.
The enforcement is expected to come into effect starting October 1, 2024.
“Accounts with commit access can push updates and changes to plugins and themes used by millions of WordPress sites worldwide,” the
https://thehackernews.com/2024/09/wordpress-mandates-two-factor.html
Quad7 Botnet Expands to Target SOHO Routers and VPN Appliances
Wed, 11 Sep 2024 21:50:00 +0530
The operators of the mysterious Quad7 botnet are actively evolving by compromising several brands of SOHO routers and VPN appliances by leveraging a combination of both known and unknown security flaws.
Targets include devices from TP-LINK, Zyxel, Asus, Axentra, D-Link, and NETGEAR, according to a new report by French cybersecurity company Sekoia.
“The Quad7 botnet operators appear to be
https://thehackernews.com/2024/09/quad7-botnet-expands-to-target-soho.html
DragonRank Black Hat SEO Campaign Targeting IIS Servers Across Asia and Europe
Wed, 11 Sep 2024 21:09:00 +0530
A “simplified Chinese-speaking actor” has been linked to a new campaign that has targeted multiple countries in Asia and Europe with the end goal of performing search engine optimization (SEO) rank manipulation.
The black hat SEO cluster has been codenamed DragonRank by Cisco Talos, with victimology footprint scattered across Thailand, India, Korea, Belgium, the Netherlands, and China.
”
https://thehackernews.com/2024/09/dragonrank-black-hat-seo-campaign.html