Article Summary : π Finite State raises $20 million in growth round led by Energy Impact Partners to address cybersecurity challenges and advance innovative solutions for securing connected devices and critical infrastructure. π Investment empowers Finite State to accelerate product development effo…
Category: Cyber Security News
Article Summary : π€ President Joe Biden nominated Michael Sulmeyer to be assistant secretary of defense for cyber policy at the Pentagon, the first individual to hold the position. π‘ Sulmeyer currently serves as the principal cyber advisor to the secretary of the Army, advising on cyber readiness an…
Summary: π Pwn2Own Vancouver 2024 concluded with security researchers earning $1,132,500 by demonstrating 29 zero-day vulnerabilities. π― Various categories were targeted, including web browsers, cloud-native/container, virtualization, and automotive systems. π° The total prize pool exceeded $1.3 mill…
**Summary:** π Greensboro College faces a class action lawsuit following a data breach affecting over 52,000 individuals. π‘οΈ Hedgecock alleges that the college failed to safeguard personal information adequately. π The breach occurred in August 2023 due to a ransomware attack. π The exposed data inc…
**Summary:** — π Threat actors are targeting enterprise software and network infrastructure vulnerabilities at a higher rate, according to Recorded Future’s annual threat analysis report. π The number of high-risk vulnerabilities exploited in attacks against enterprise software and network infrast…
Anti-Phishing, DMARC , Cyberwarfare / Nation-State Attacks , Fraud Management & Cybercrime Proofpoint Researchers Say Beware of Phishing Emails, Embedded Links in PDFs Prajeet Nair (@prajeetspeaks) β’ March 23, 2024 Image: Shutterstock Iran-aligned threat actor TA450 is using fake s…
Mozilla has released security updates to fix two zero-day vulnerabilities in the Firefox web browser exploited during the Pwn2Own Vancouver 2024 hacking competition. Manfred Paul (@_manfp) earned a $100,000 award and 10 Master of Pwn points after exploiting an out-of-bounds (OOB) write flaw (CVE-202…
An Illinois county on the border with Iowa is the latest local government in the U.S. to fall victim to a ransomware attack. Henry County has been dealing with a wide-ranging cyberattack since March 18, Mat Schnepple, director of the Emergency Management (OEM) office in Henry County, confirmed to Re…
Researchers disclosed vulnerabilities today that impact 3 million Saflok electronic RFID locks deployed in 13,000 hotels and homes worldwide, allowing the researchers to easily unlock any door in a hotel by forging a pair of keycards. The series of security flaws, dubbed “Unsaflok,” was discove…
The US government has published new distributed denial-of-service (DDoS) attack guidance for public sector entities to help prevent disruption to critical services.The document is designed to serve as a comprehensive resource to address the specific needs and challenges faced by federal, state and l…
Security researchers have released a proof-of-concept (PoC) exploit for a critical vulnerability in Fortinet’s FortiClient Enterprise Management Server (EMS) software, which is now actively exploited in attacks. Tracked as CVE-2023-48788, this security flaw is an SQL injection in the DB2 Administrat…
Amid the constant drumbeat of successful cyberattacks, some fake data breaches have also cropped up to make sensational headlines. Unfortunately, even fake data breaches can have real repercussions. Earlier this year, a hacker on a criminal forum claimed to have stolen data on some 50 million Europc…
The Department of Transportation (DOT) will review data collection practices for the country’s 10 largest airlines in a bid to improve passenger privacy protections, Secretary Pete Buttigieg said on Thursday. The department said it will examine airline policies and training in handling passeng…
The South China Athletic Association (SCAA) was rocked by a cyberattack as unauthorized third parties breached the organizationβs computer servers, sparking concerns over the security of member data. In response to the SCAA cyberattack, the Association swiftly implemented measures to address the bre…
WebCopilot is an open-source automation tool that enumerates a targetβs subdomains and discovers bugs using various free tools. It simplifies the application security workflow and reduces reliance on manual scripting. βI built this solution to streamline the application security process, specificall…