Cyber security aggregate rss news

Cyber security aggregator - feeds history

image for Cybersecurity for Ga ...

 Cybersecurity Awareness Month

Online gaming has become a global pastime, attracting millions of players. But with the rise of multiplayer games, in-game purchases, and digital collectibles, gaming accounts have also become prime targets for cybercriminals. A compromised account can lead to the loss of not only your game progress and digital assets   show more ...

but also personal information that could be misused for identity theft or other malicious activities.  This year, Cybersecurity Awareness Month focuses on the theme "Secure Our World," a reminder that cybersecurity isn't just for businesses—it’s crucial for individuals too, including gamers. As gaming platforms grow more advanced, so do the methods hackers use to exploit them, making it essential to stay vigilant. In the spirit of this cybersecurity awareness month theme, The Cyber Express team has put together ten effective ways to protect your gaming accounts and ensure your digital world remains secure.  10 Ways to Protect Your Gaming Accounts from Hackers [caption id="attachment_91010" align="aligncenter" width="1024"] Source: Freepik[/caption] Use Strong Passwords Make sure your passwords are not only strong but also unique. Weak passwords, especially those using common phrases like "password123" or "qwerty," pose a serious security risk because they can easily be guessed or cracked by automated tools. The risk is even greater if you reuse the same password across multiple accounts—once one account is compromised, every account sharing that password is at risk. A strong password should be complex, using a mix of uppercase and lowercase letters, numbers, and special characters. Avoid using anything personal or easily discoverable about you online. Unique passwords for each account are essential to prevent hackers from gaining access to multiple accounts. To make managing these passwords easier, consider using a password manager, which can generate strong passwords and store them securely, protecting them from unauthorized access. Regularly Update Your Software and Devices Keeping your software up to date—including your operating system, browser, and gaming applications—is vital for maintaining security. Updates often contain patches for newly discovered vulnerabilities, which, if left unaddressed, can leave your system exposed to cyberattacks. Hackers specifically target outdated software because known vulnerabilities are easily exploitable. By neglecting regular updates, you’re leaving a significant gap in your defenses, making it easier for attackers to gain access. Staying current with all software updates is one of the simplest yet most effective ways to protect your gaming accounts and personal information. Monitor Your Account Activity Regularly checking your gaming account for unusual activity can help you spot unauthorized access quickly. Most gaming platforms provide tools to review recent login attempts and account changes. If you see anything suspicious—like logins from unfamiliar locations or unauthorized purchases—change your password right away and reach out to customer support. Additionally, consider enabling notifications for logins or purchases so you can be alerted to any questionable activity in real-time. Avoid Using Public Wi-Fi for Gaming Public Wi-Fi networks are notoriously insecure and can be a prime target for hackers looking to intercept your data. When you connect to these unsecured networks, your information is at risk. Since many public networks lack encryption, cybercriminals can easily capture and view the data you transmit, including login credentials, personal information, and financial details. To safeguard yourself, it’s best to avoid accessing sensitive accounts or financial information over public Wi-Fi. Specifically for your gaming account, refrain from logging in or performing sensitive activities on these networks. If you must use a public connection, consider using a Virtual Private Network (VPN) to encrypt your data and keep it secure from prying eyes. Limit the Amount of Personal Information You Share Sharing too much personal information online can make it easier for hackers to access your gaming account. Details you share through text, headset audio, or even your gamertag can potentially be seen by others. Just as you would be careful about revealing personal information or your location on social media, the same caution should apply to online gaming. Avoid using real names, birthdates, or other identifiable information as usernames or answers to security questions. Hackers often exploit publicly available information to guess passwords or security answers. Additionally, take the time to review the privacy settings on your gaming accounts and social media profiles to control what information is visible to others. Backup Your Account Information While backing up your account information won’t stop hackers, it can make recovering your account much easier if it does get compromised. Keep a secure record of your login credentials, security questions, and other important account details. Many platforms let you link your account to additional authentication methods, like a secondary email or phone number, providing extra security if your primary method is compromised. Without backups, critical information like documents, photos, and important files could be lost for good. Store backups in multiple locations, such as external hard drives and cloud services, to ensure you can restore your data even if one source becomes unavailable. Utilize Event Logs In today's gaming landscape, players often switch between multiple devices to access their games, which can complicate network security. To address this challenge, consider using event logs. These logs capture and monitor all activities related to your operating system, applications, and device usage. By tracking events like login attempts from unfamiliar devices, multiple failed logins, password change requests, and multi-factor authentication updates, you can quickly spot any suspicious activity. When such events occur, users receive immediate notifications to confirm whether these actions were authorized, adding an extra layer of security to your gaming experience. Download Games from Legitimate Sources One of the easiest ways gamers unknowingly expose their systems to malware is by downloading files from unverified or unofficial sources. Whether it’s a game, cheat codes, or third-party add-ons, downloading from pirated or untrustworthy websites greatly increases the risk of infecting your device with viruses or malware. To protect yourself, always ensure you're downloading games and related content from official, reputable sources. Double-check the website’s URL before entering any sensitive information or clicking on a download link. Besides the ethical and legal concerns of using pirated games, they also leave your system exposed by preventing access to essential security patches and updates, making it easier for cyber threats to exploit vulnerabilities. Two-factor Authentication (2FA) Two-factor authentication (2FA) is a powerful security measure that adds an extra layer of protection to your gaming accounts. Instead of relying solely on a password, 2FA requires you to verify your identity using a second method, such as a code sent to your mobile device or an authentication app. For instance, when you log into your gaming account, you might first enter your password, followed by a code generated by an app like Google Authenticator or sent via SMS. This way, even if a hacker obtains your password, they still can’t access your account without that second verification step. Enabling 2FA on platforms like Steam, Xbox Live, or PlayStation Network can significantly reduce the risk of unauthorized access and keep your gaming experience secure. Be Cautious of Third-Party Services Be cautious when using third-party services, such as power-leveling or in-game trading platforms. While these services might promise quick boosts or valuable items, they often come with significant risks. For instance, using a power-leveling service might require you to share your account credentials, exposing you to potential account theft. Similarly, engaging in in-game trading through unofficial sites can lead to scams where you may lose valuable items or currency without receiving anything in return. Always think twice before using these services; sticking to official game features can help keep your account secure and your gaming experience enjoyable. To Wrap Up By embracing these strategies to secure your gaming account, you’ll be like a seasoned warrior, dodging cyber threats like a pro and keeping your loot safe from pesky hackers. This month serves as a great reminder that staying informed about the latest security practices is just as crucial as mastering that new move or unlocking hidden levels. Think of it as a side quest: keeping your gaming accounts secure contributes to the larger goal of creating a safer online world for everyone. So gear up, stay sharp, and take charge of your gaming destiny! After all, a secure gaming account means more time enjoying your virtual adventures and less time worrying about the lurking shadows of the internet. Happy gaming, and remember—secure your world, one account at a time!

image for Reaction isn’t def ...

 Cyber Essentials

By Satnam Narang, Sr. Staff Research Engineer, Tenable We all know that cyber risk is a problem but do we truly grasp the scale? Nearly two-thirds of businesses across the globe have fallen victim to ransomware and only 30% of organizations say they are cyber resilient. Here’s a staggering fact: by 2027, cybercrime   show more ...

is forecast to cost a jaw-dropping $23.84 trillion globally. All of this is despite increasing cybersecurity investments. So, why aren’t things improving? Adversaries know how to exploit or circumvent defenses, and often work in the shadows of an organization’s network for months before a compromise or breach is even detected. According to IBM, shadow data plays a huge role in this—data is multiplying so fast that tracking and safeguarding it all has become a Herculean task. Even with top-tier tools and skilled teams, detecting threats can feel like finding a needle in a haystack. The flood of alerts and data is overwhelming, often leaving cybersecurity teams reacting instead of defending. But reacting isn’t enough. To stay ahead of the game, organizations need to shift from a reactive to a proactive defense strategy—threat hunting—a preventive approach that empowers teams to identify and neutralize risks before cybercriminals strike. Why Proactive Threat Hunting is Challenging? Imagine looking for needles in a haystack. Now imagine some of those needles are hidden even deeper, inside of haystacks within haystacks. That’s what threat hunters face every day. Modern threats are highly sophisticated, and security tools designed to detect suspicious behavior often miss the full picture. They demand advanced skills—like malware analysis, packet analysis, and threat intelligence—that many teams don’t fully possess. On top of that, most tools focus on isolated data points, creating silos instead of a cohesive view of the network. Without comprehensive and continuous monitoring across every platform and device, organizations are left vulnerable. Worse yet, without proper context— connecting the dots—teams are buried under a mountain of data and miss crucial indicators of compromise. Cybercriminals thrive on persistence and stealth. Periodic scans and checks aren’t enough to catch them because their attacks aren’t periodic—they’re continuous, evolving, and patient. To combat this, organizations need continuous monitoring and vigilant hunting for suspicious activity and telltale signs of compromise. How to Proactively Hunt Threats? Enterprise environments are large, and complex and can span multiple segments of a network and sites across the world. Domain-specific security tools or point solutions make it very difficult to build a comprehensive asset inventory, compile vulnerability statuses, detect changes, and assess threats. While the data and insights gathered from point tools are valuable for understanding asset-specific risk, it isn’t enough to proactively hunt for threats as they create data silos. An organization’s network has several cybersecurity layers, and it’s essential to proactively hunt across the entire attack surface. Focusing only on initial access points, teams miss escalating threats or allow a stealth actor to bypass detection. Proactively hunting for signs of an attacker’s lateral movement through the network, identifying unauthorized privilege escalation, access rights abuse, and other threats, helps reveal potential risks that wouldn’t have been identified initially. Effective threat hunting boils down to three things: visibility, context, and action. To achieve this, organizations need the right tools in place to actively monitor the entire attack surface — including vulnerabilities, misconfigurations on-prem and in the cloud, users, assets, and attack paths. When combined, business intelligence and threat intelligence,  provide context to security teams to help identify suspicious or malicious activity. Focusing resources on the most critical vulnerabilities with the greatest potential to impact your operations ensures targeted, effective resolution and maximizes the effectiveness of a security program. If threats aren’t proactively identified, organizations have no way of knowing if a malicious actor is lurking within their systems. Cybercriminals that breach an organization's systems can remain within the network for long periods, collecting data, and looking for sensitive information and credentials that will allow them to access systems deeper into an organization. The threat posed by attackers can lead to irrevocable financial and reputational ramifications. Proactive threat hunting allows organizations to identify and eradicate malicious actors, who get past initial defenses, preventing further compromise before it can occur.

image for Understanding the Ei ...

 Firewall Daily

The Ethereum restaking protocol EigenLayer recently faced a security breach, leading to the theft of approximately $5.7 million in tokens. On October 4, EigenLayer's team revealed that they were investigating suspicious selling activities linked to a specific wallet address ending in "f10D." This wallet   show more ...

was found to have sold around 1.6 million EIGEN tokens, raising alarms within the crypto community.   Following their initial investigation, EigenLayer reported on October 5 that the unauthorized selling was indeed the result of a cyberattack. The attackers had compromised an email thread related to an investor’s token transfer, allowing them to divert the tokens to their wallet. [caption id="attachment_90989" align="alignnone" width="750"] an attacker compromised an email thread for a token transfer (Source: EigenLayer on X)[/caption] EigenLayer’s statement described the process, noting that "the attacker sold these stolen EIGEN tokens via a decentralized swap platform and transferred stablecoins to centralized exchanges."   EigenLayer Hack: Incident Details and Response   In response to the EigenLayer hack, the team took immediate steps to mitigate the damage. They reached out to relevant platforms and law enforcement agencies to coordinate efforts for recovery. According to their update, some of the stolen funds have already been frozen, illustrating their proactive approach to the situation.   [caption id="attachment_90987" align="alignnone" width="741"] EigenLayer Confirms Suspicious Activity (Source: EigenLayer on X)[/caption] Despite the severity of the incident, EigenLayer emphasized that the cyberattack on EigenLayer did not expose any vulnerabilities within their protocol. They assured the community that their ecosystem remains intact and unaffected. This incident was isolated and does not impact our broader ecosystem," EigenLayer stated, reinforcing the idea that the integrity of their protocol and token contracts remains secure.   The team clarified that the EigenLayer cyberattack was strictly due to external factors and not related to any functionality within their on-chain operations.   Market Impact  The timing of the EigenLayer cyberattack has raised concerns about the overall market performance of EIGEN tokens. On October 1, following the unlocking of EIGEN tokens, the price was set at $3.85 on Binance, which translated to a fully diluted valuation (FDV) of approximately $6.5 billion, securing a spot in the top 100 market rankings. However, by October 5, following the cyberattack on EigenLayer, the token's value had dropped to around $3.38, leading to an FDV of $5.6 billion and a subsequent decline to the 99th position in market capitalization.   The EigenLayer community has expressed mixed reactions to the incident, with many emphasizing the need for increased security measures in the rapidly evolving landscape of cryptocurrency.   The EigenLayer team continues to investigate the incident and has pledged to keep their users updated. They aim to provide clarity and assurance to rebuild trust within the community following the data breach at EigenLayer. 

image for Chinese Hackers Expl ...

 Firewall Daily

Chinese hackers have infiltrated the U.S. court wiretap system, as highlighted by the Wall Street Journal. The hackers compromised the networks of major telecommunications companies, including Verizon Communications, AT&T, and Lumen Technologies.    The breach appears to have provided these Chinese hackers   show more ...

extensive access to the systems that facilitate court-authorized wiretapping in the United States. The Wall Street Journal reported that the hackers may have maintained access for several months, allowing them to tap into vital network infrastructure utilized by broadband providers to comply with lawful government requests for communication data.   Chinese Hackers Breach U.S. Court's Wiretap System   The cyberattack was orchestrated by a Chinese hacking group identified as “Salt Typhoon.” This group has been implicated in previous cyber espionage activities, and this latest breach poses a serious risk to U.S. national security. The implications of such access are profound, as it potentially enables foreign entities to gain insights into sensitive U.S. governmental operations.   The impact of this cyberattack extends beyond immediate data breaches. Experts fear that the infiltration could lead to disruptions in U.S. systems, especially in the event of heightened tensions between China and the United States. Government officials have voiced concerns that such attacks might be strategically aimed at undermining U.S. capabilities during critical times.   China has consistently denied allegations of state-sponsored hacking, claiming that it has no involvement in cyber intrusions aimed at foreign governments. In response to the Wall Street Journal’s report, a spokesperson for China's foreign ministry stated they were unaware of the alleged attack and accused the United States of creating a “false narrative” to malign China. They emphasized the need for cooperative international efforts to combat cybersecurity threats rather than pointing fingers.   Implications of the Cyberattack on Telecom Companies The implications of the cyberattack on telecom companies are serious, especially as the U.S. has already experienced heightened concerns regarding cyberattacks linked to Chinese hackers. Earlier this year, American law enforcement disrupted another Chinese hacking group known as “Flax Typhoon,” following heightened scrutiny of cyber espionage activities attributed to Beijing, which was part of a broader campaign referred to as “Volt Typhoon.”   The potential for hackers to exploit vulnerabilities in the U.S. court wiretap system is particularly troubling, as this system is critical for law enforcement and national security agencies. The sensitivity of wiretap requests means that unauthorized access could lead to the exposure of confidential investigations and the methods used to obtain evidence against suspects.   The domino effect of such cyberattacks, particularly those linked to state-sponsored groups like Salt Typhoon, highlights the ongoing challenges faced by the U.S. in safeguarding its information systems against foreign intrusions. The Cyber Express will be closely monitoring the situation. We’ll update this post once we have more information about the cyberattack of telecom companies by the Chinese hackers.    Media Disclaimer: This report is based on internal and external research obtained through various means. The information provided is for reference purposes only, and users bear full responsibility for their reliance on it. The Cyber Express assumes no liability for the accuracy or consequences of using this information. 

image for Atos and French Stat ...

 Cyber News

Atos SE ("Atos") today provided an update on ongoing discussions with the French State concerning the potential acquisition of its Advanced Computing, Mission-Critical Systems, and Cybersecurity Products businesses, operated under its Bull Defense and Security (BDS) division. These discussions, which have been   show more ...

part of a broader strategic initiative involving the French government's interest in maintaining control over critical national infrastructure, remain a key focus for both parties as Atos navigates its financial restructuring process. Expiry of the Confirmatory Offer The non-binding confirmatory offer received from the French State on June 12, and revised on September 30, 2024, for the acquisition of BDS’s Advanced Computing, Mission-Critical Systems, and Cybersecurity Products businesses officially expired on October 4 without the two sides reaching a final agreement. Despite this setback, Atos remains committed to continuing negotiations. The company has submitted an alternative proposal to the French State, which is structured to align with its ongoing financial restructuring efforts. Cybersecurity and Computing in France’s National Security The Advanced Computing and Cybersecurity divisions under Atos are critical to national security and technological sovereignty for France. These units are responsible for delivering high-performance computing (HPC) solutions, mission-critical systems, and advanced cybersecurity services, all of which are integral to the nation’s defense, aerospace, and security sectors. These sectors are of immense strategic value, driving the French State's interest in retaining oversight and control over these operations. Atos’s cybersecurity portfolio, in particular, has gained prominence as Europe’s leading provider of cloud and cybersecurity solutions, offering robust defenses against the ever-evolving cyber threat landscape. Its tailored end-to-end cybersecurity offerings are crucial for protecting critical infrastructure across various industries, including government, healthcare, financial services, and defense. Safeguarding Sovereign Interests To ensure the protection of France’s national interests, Atos and the French State had previously discussed measures to maintain sovereign control over these sensitive operations. In line with these commitments, Atos has continued the process of granting the French State protective rights over critical and sensitive operations through the issuance of a preferred share (action de préférence) in Bull SA, the legal entity under which these activities are organized. This share will provide the French State with specific oversight and decision-making powers related to the defense and cybersecurity assets, safeguarding these strategically vital resources. The issuance of this preferred share is on track and expected to be finalized by the end of the year. Impact on Financial Restructuring The expiry of the French State’s non-binding offer does not affect Atos’s current financial restructuring plan. This plan, which was largely approved by the affected parties on September 27, includes provisions for the continuation of the Advanced Computing, Mission-Critical Systems, and Cybersecurity businesses within Atos’s organizational structure. As part of this restructuring, Atos is focused on preserving the value of these critical assets while ensuring the company’s long-term financial stability. The restructuring plan will be submitted to the Nanterre Commercial Court on October 15 for approval as part of Atos’s accelerated safeguard procedure. This judicial process will provide a legal framework for implementing the restructuring, protecting the interests of creditors and other stakeholders while ensuring that Atos remains on a sustainable path forward. Atos Alternative Proposal to Continue Discussions In light of the expired offer, Atos has taken proactive steps to keep discussions with the French State alive. The company has proposed an alternative solution that is compatible with its financial restructuring plan. Should these talks prove successful, any potential transaction will require the approval of the Nanterre Commercial Court, ensuring that all legal and financial considerations are fully addressed. This proposal emphasizes Atos's commitment to maintaining a constructive dialogue with the French State, particularly around its sovereign interests in the cybersecurity, advanced computing, and mission-critical systems sectors. As these divisions are considered essential to national security, any potential sale or restructuring of these assets will likely be subject to extensive scrutiny to ensure that France’s strategic interests are fully safeguarded. The Strategic Importance of Cybersecurity As digital transformation accelerates across industries, the importance of cybersecurity continues to grow. Atos has been a leader in this space, delivering comprehensive cybersecurity services to protect critical infrastructure and secure sensitive data. Cyber threats are becoming increasingly sophisticated, and governments and businesses alike are under pressure to enhance their defenses. Atos's offerings, including threat detection, incident response, and data protection, position it as a key player in the cybersecurity ecosystem. For France, the control of cybersecurity assets is not just about business—it's about maintaining the integrity and security of its critical systems. Whether in protecting government networks, defending against cyberattacks on critical infrastructure, or securing sensitive communications, the French State's involvement in these discussions underscores the high stakes at play. As the process moves forward, all eyes will be on the outcome of Atos’s alternative proposal and the eventual implementation of the preferred share in Bull SA, which will provide the French State with essential oversight over its most sensitive operations.

image for Apple Patches iOS Se ...

 Cyber News

Apple has released new updates for iOS and iPadOS to fix two important security problems affecting many iPhone and iPad models. These Apple updates, now available as iOS 18.0.1 and iPadOS 18.0.1, fix issues that could have put users' privacy at risk, including a bug that allowed saved passwords to be spoken out   show more ...

loud using Apple's VoiceOver assistive technology. Password Vulnerability: CVE-2024-44204 The first vulnerability tracked as CVE-2024-44204, was discovered by security researcher Bistrit Daha and affects the Passwords app on iPhones and iPads. The flaw stems from a logic issue within the app, allowing passwords stored on the device to be read aloud by VoiceOver, a feature designed to assist visually impaired users by narrating the content on their screen. VoiceOver, a gesture-based screen reader, enables users to navigate their iPhones even without viewing the screen by providing audible descriptions of elements such as battery levels, incoming calls, and other screen content. While this feature is invaluable for accessibility, the vulnerability could allow malicious actors to exploit it, gaining access to sensitive information, including stored passwords. According to Apple's advisory, the issue has now been resolved with improved validation processes. Apple credits Daha with identifying and reporting the vulnerability, highlighting the importance of independent security researchers in uncovering potential risks to users. The affected devices include: iPhone XS and later iPad Pro 13-inch and 12.9-inch (3rd generation and later) iPad Pro 11-inch (1st generation and later) iPad Air (3rd generation and later) iPad (7th generation and later) iPad mini (5th generation and later) Apple strongly encourages users of these devices to update to iOS 18.0.1 or iPadOS 18.0.1 to secure their systems against this vulnerability. Audio Vulnerability in iPhone 16 Models: CVE-2024-44207 In addition to the VoiceOver flaw, Apple has also addressed a security issue exclusive to its newly launched iPhone 16 models. This second vulnerability, identified as CVE-2024-44207, involves the device's Media Session component and could allow audio messages to capture a few seconds of audio before the microphone indicator is activated. The microphone indicator, a privacy feature that lights up to inform users when the microphone is in use, is designed to prevent unauthorized audio recordings. However, this flaw allowed for a brief capture of audio even before the indicator was turned on, potentially exposing users' private conversations. This vulnerability was discovered by security researcher Michael Jimenez and another anonymous researcher. Apple's advisory notes that the issue has now been fixed, ensuring that audio capture cannot occur before the microphone indicator is engaged. Importance of Timely Apple Updates With both vulnerabilities now resolved, Apple is urging all users to update their devices to the latest software versions—iOS 18.0.1 and iPadOS 18.0.1. These updates not only patch the security flaws but also improve the overall stability and functionality of Apple devices. Security patches like these address vulnerabilities that could be exploited by attackers to gain access to personal data, intercept communications, or compromise the integrity of the device. These vulnerabilities, particularly the one involving password exposure, highlight how even the most innocuous features like screen readers can become security risks if left unaddressed, Regular software updates are one of the simplest and most effective ways to protect personal data. How to Update Your iPhone or iPad Wirelessly Apple has made updating devices a straightforward process. Users can update their iPhones or iPads over Wi-Fi by following these simple steps: Back up your device using iCloud or your computer to ensure your data is safe in case anything goes wrong during the update process. Plug your device into power and connect to the internet with Wi-Fi. Go to Settings > General, then tap Software Update. If more than one update option is available, select the one you want to install. Tap Install Now. If the option to download appears first, tap Download and Install, enter your passcode if prompted, and then tap Install Now to complete the update. By updating to iOS 18.0.1 and iPadOS 18.0.1, Apple users can safeguard their devices against these specific vulnerabilities. Moving forward, it is crucial for users to stay informed about security updates and take prompt action to keep their devices and personal information secure.

image for American Water Works ...

 Cyber News

American Water Works has reported an unspecified cyberattack on its IT systems, but its OT systems were unaffected. The company, which provides water and wastewater services to customers in 14 states, reported the breach in an SEC filing. American Water Works Cyberattack On Oct. 3, American Water Works said it   show more ...

“learned of unauthorized activity within its computer networks and systems, which the Company determined to be the result of a cybersecurity incident. Upon learning of this activity, the Company immediately activated its incident response protocols and third-party cybersecurity experts to assist with containment and mitigation activities and to investigate the nature and scope of the incident. The Company also promptly notified law enforcement and is coordinating fully with them.” American Water Works said it is “currently unable to predict the full impact of this incident” but it “believes that none of its water or wastewater facilities or operations have been negatively impacted by this incident.” IT teams continue to take action to protect systems and data, “including disconnecting or deactivating certain of its systems.” While the company didn’t specify the nature of the attack, speculation immediately arose among cybersecurity analysts that the incident was likely a ransomware attack. If water systems remain unaffected by the cyberattack, American Water Works may have gotten one critical infrastructure cybersecurity best practice right: separating IT and OT systems via network segmentation and other methods. American Water Works serves 1700 communities in 14 states, mainly in the Central and Eastern U.S., in addition to California and Hawaii. Other states the company operates in include Iowa, Missouri, Illinois, Indiana, Kentucky, Tennessee, Georgia, West Virginia, Virginia, Pennsylvania, Maryland, and New Jersey. Water Systems Increasingly Under Attack The incident follows a similar attack in Arkansas just two weeks ago, and a recent GAO reported called for greater EPA protections for water utilities. Cyble researchers recently alerted clients to the growing cyber threats facing water utilities from hacktivist groups like the Russia-linked People’s Cyber Army and a high number of internet-exposed SCADAView CSX monitoring and control systems. “Considering the increasing number of internet-exposed Water Utility assets across the United States, continuing use of outdated systems, and inadequate security protocols in such critical facilities, there is an urgent need to implement robust security measures,” Cyble researchers wrote. “The Environmental Protection Agency (EPA) too has echoed these concerns, noting that a staggering 70% of inspected water utilities do not meet basic cybersecurity standards.” The Cyble report concluded, “these weaknesses in Water utilities not only pose threats of operational disruptions but also contamination of drinking water supplies, posing significant risks to public health.” The Cyble report also listed a number of recommendations for strengthening water utility security, including network segmentation and hardening human-machine interfaces (HMIs) for monitoring and controlling central telemetry units (CTUs).

image for Kaspersky apps are n ...

 Products

Weve recently been informed by the Google Play store that our developer account has been terminated and all Kaspersky apps have been removed from the store. Googles decision refers to recent U.S. government actions restricting the distribution and sales of Kaspersky products in the United States after September 29.   show more ...

Although these restrictions have no material legal effect outside the U.S., Google unilaterally decided to remove our products from Google Play ahead of September 29 – depriving users worldwide of access to industry-leading cybersecurity protection. We believe that Googles decision is based on overinterpretation of the U.S. restrictions, which was not backed by a confirmation from the U.S. Department of Commerce. The U.S. restrictive measures dont prohibit the sales and distribution of Kasperskys products and services outside the United States. We have communicated this understanding to the U.S. Department of Commerce, and we hope to receive additional guidance from the Department shortly. What will happen to already-installed Kaspersky apps for Android? Apps that were installed from Google Play will continue to work normally and receive database updates through our cloud infrastructure. All paid app features will also continue to work. Unfortunately, you wont be able to update or reinstall an app directly from Google Play. How to install and update Kaspersky apps for Android now? To keep your mobile devices protected, we recommend downloading our apps for Android from other mobile stores – including Galaxy Store, Huawei AppGallery, Xiaomi GetApps and others, or directly from our site. The range of available Kaspersky products for Android is the same in each store. Here you can find links to all Kaspersky products for Android in other stores and instructions for installing and activating them.

 Feed

GenGravSSTIExploit is a proof of concept Python script that exploits an authenticated server-side template injection (SSTI) vulnerability in Grav CMS versions 1.7.44 and below. This vulnerability allows a user with editor permissions to execute OS commands on a remote server.

 Feed

This script exploits the issue noted in CVE-2024-45409 that allows an unauthenticated attacker with access to any signed SAML document issued by the IDP to forge a SAML Response/Assertion and gain access as any user on GitLab. Ruby-SAML versions below or equal to 12.2 and versions 1.13.0 through 1.16.0 do not properly verify the signature of the SAML Response.

 Feed

ABB Cylon Aspect versions 3.08.01 and below suffer from an unauthenticated arbitrary file disclosure vulnerability. Input passed through the logFile GET parameter via the logYumLookup.php script is not properly verified before being used to download log files. This can be exploited to disclose the contents of arbitrary and sensitive files via directory traversal attacks.

 Feed

Ubuntu Security Notice 7056-1 - Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, obtain sensitive information across domains, or execute arbitrary code. Masato Kinugawa   show more ...

discovered that Firefox did not properly validate javascript under the "resource://pdf.js" origin. An attacker could potentially exploit this issue to execute arbitrary javascript code and access cross-origin PDF content.

 Feed

Debian Linux Security Advisory 5786-1 - Integer overflows flaws were discovered in the Compound Document Binary File format parser of libgsf, the GNOME Project G Structured File Library, which could result in the execution of arbitrary code if a specially crafted file is processed.

 Feed

Debian Linux Security Advisory 5785-1 - Dom Walden discovered that the AbuseFilter extension in MediaWiki, a website engine for collaborative work, performed incomplete authorisation checks.

 Feed

Europe's top court has ruled that Meta Platforms must restrict the use of personal data harvested from Facebook for serving targeted ads even when users consent to their information being used for advertising purposes, a move that could have serious consequences for ad-driven companies operating in the region. "An online social network such as Facebook cannot use all of the personal data

 Feed

A critical security flaw has been disclosed in the Apache Avro Java Software Development Kit (SDK) that, if successfully exploited, could allow the execution of arbitrary code on susceptible instances. The flaw, tracked as CVE-2024-47561, impacts all versions of the software prior to 1.11.4. "Schema parsing in the Java SDK of Apache Avro 1.11.3 and previous versions allows bad actors to execute

 Feed

Ever heard of a "pig butchering" scam? Or a DDoS attack so big it could melt your brain? This week's cybersecurity recap has it all – government showdowns, sneaky malware, and even a dash of app store shenanigans. Get the scoop before it's too late! ⚡ Threat of the Week Double Trouble: Evil Corp & LockBit Fall: A consortium of international law enforcement agencies took steps to arrest four

 Feed

Google has announced that it's piloting a new security initiative that automatically blocks sideloading of potentially unsafe Android apps in India, after similar tests in Singapore, Thailand, and Brazil. The enhanced fraud protection feature aims to keep users safe when they attempt to install malicious apps from sources other than the Google Play Store, such as web browsers, messaging apps,

 Feed

Organizations are losing between $94 - $186 billion annually to vulnerable or insecure APIs (Application Programming Interfaces) and automated abuse by bots. That’s according to The Economic Impact of API and Bot Attacks report from Imperva, a Thales company. The report highlights that these security threats account for up to 11.8% of global cyber events and losses, emphasizing the escalating

 Feed

The interest in passwordless authentication has increased due to the rise of hybrid work environments and widespread digitization. This has led to a greater need for reliable data security and user-friendly interfaces. Without these measures, organizations are at risk of experiencing data breaches, leaks, and significant financial losses.  While traditional password-based systems offer

 Feed

Cybersecurity researchers have discovered a new botnet malware family called Gorilla (aka GorillaBot) that is a variant of the leaked Mirai botnet source code. Cybersecurity firm NSFOCUS, which identified the activity last month, said the botnet "issued over 300,000 attack commands, with a shocking attack density" between September 4 and September 27, 2024. No less than 20,000 commands designed

 Guest blog

When Sean Kelly bought a top-of-the-line vacuum cleaner, he imagined he was making a safe purchase. Little did he know that the cleaning machine scuttling about his family's feet contained a security flaw that could let anyone see and hear their every move. Read more in my article on the Hot for Security blog.

2024-10
Aggregator history
Monday, October 07
TUE
WED
THU
FRI
SAT
SUN
MON
OctoberNovemberDecember