HackDig : Dig high-quality web security articles

FBI Warns of Proxies and Configurations Used in Credential Stuffing Attacks

The Federal Bureau of Investigation (FBI) has raised an alarm for cybercriminals using proxies and configurations to hide and automate credential stuffing attacks against companies in the United States.Creedential stuffing attacks, also called account cracking, involve trying to access online accounts using username and password combinations from e
Publish At:2022-08-19 16:02 | Read:112 | Comments:0 | Tags:Cyberwarfare Endpoint Security Network Security NEWS & I

TXOne Networks Scores $70M Series B Investment

TXOne Networks, a joint venture between cybersecurity firm Trend Micro and industrial networking solutions provider Moxa, has banked $70 million in new venture capital funding.The company, which maintains dual headquarters in Texas and Taiwan, said the Series B round was led by TGVest Capital and brings the total raised to $94 million.TXOne Networks was crea
Publish At:2022-08-18 16:14 | Read:165 | Comments:0 | Tags:Endpoint Security Network Security NEWS & INDUSTRY Priva

Vulnerability Broker Applies Pressure on Software Vendors Shipping Faulty, Incomplete Patches

Trend Micro’s Zero Day Initiative, a major player in the vulnerability disclosure ecosystem, is ramping up the pressure on software vendors that consistently ship faulty security patches.In a major revision of its disclosure policies, the vulnerability broker said it will set strict 30-day deadlines for critical-level bug reports that result from faulty or i
Publish At:2022-08-17 12:28 | Read:148 | Comments:0 | Tags:Cyberwarfare Endpoint Security Network Security NEWS & I

FTC Looking at Rules to Corral Tech Firms' Data Collection

Whether it’s the fitness tracker on your wrist, the “smart” home appliances in your house or the latest kids’ fad going viral in online videos, they all produce a trove of personal data for big tech companies.How that data is being used and protected has led to growing public concern and officials’ outrage. And now federal regulators are looking at drafting
Publish At:2022-08-12 12:04 | Read:271 | Comments:0 | Tags:NEWS & INDUSTRY Privacy Audits Compliance Privacy &

Twilio Hacked After Employees Tricked Into Giving Up Login Credentials

Enterprise software vendor Twilio (NYSE: TWLO) has been hacked by a relentless threat actor who successfully tricked employees into giving up login credentials that were then used to steal third-party customer data.The San Francisco company fessed up to the breach in an online notice that describes a sophisticated threat actor with clever social engineering
Publish At:2022-08-08 12:04 | Read:264 | Comments:0 | Tags:Cyberwarfare Disaster Recovery Endpoint Security Network Sec

Ghost Security Snags $15M Investment for API Security Tech

Texas startup Ghost Security has joined the list of early-stage companies in the API and application security space attracting venture capital funding.The Austin-based company emerged from stealth this week with $15 million in investments from 468 Capital, DNX Ventures, and Munich Re Ventures."We believe the explosive growth of microservices and APIs in the
Publish At:2022-08-05 16:14 | Read:288 | Comments:0 | Tags:Endpoint Security Network Security NEWS & INDUSTRY Priva

Compliance Automation Startup RegScale Scores $20 Million Investment

RegScale, a Virginia startup building technology to manage continuous compliance automation tasks, has attracted $20 million in early-stage venture capital funding.The Series A round was led by SYN Ventures with participation from SineWave Ventures, VIPC’s Virginia Venture Partners and SecureOctane.RegScale, which maintains headquarters in Tyson’s Corner, Vi
Publish At:2022-08-03 20:12 | Read:333 | Comments:0 | Tags:Endpoint Security Network Security NEWS & INDUSTRY Priva

Robinhood Crypto Penalized $30M for Violating NY Cybersecurity Regulations

The cryptocurrency division of Robinhood has been slapped with a $30 million penalty by New York's Department of Financial Services for significant violations of cybersecurity and money laundering regulations.The $30 million penalty, announced late Tuesday via a consent order, adds to a litany of problems at Robinhood that range from security breaches, to on
Publish At:2022-08-03 16:14 | Read:373 | Comments:0 | Tags:Endpoint Security Network Security NEWS & INDUSTRY Priva

VMware Ships Urgent Patch for Authentication Bypass Security Hole

Virtualization technology giant VMware on Tuesday shipped an urgent, high-priority patch to address an authentication bypass vulnerability in its Workspace ONE Access, Identity Manager and vRealize Automation products.The vulnerability carries VMware’s highest severity rating (CVSSv3 base score of 9.8) and should be remediated without delay, the company said
Publish At:2022-08-02 16:13 | Read:424 | Comments:0 | Tags:Endpoint Security Network Security NEWS & INDUSTRY Priva

Microsoft Catches Austrian Company Exploiting Windows, Adobe Zero-Days

Malware hunters at Microsoft have caught an Austrian hack-for-hire company exploiting zero-day flaws in Windows and Adobe software products in "limited and targeted attacks" against European and Central American computer users.The company, called DSIRF, has been linked to a malware suite called ‘Subzero’ that has been deployed over the last two years via zer
Publish At:2022-07-27 16:13 | Read:450 | Comments:0 | Tags:Cyberwarfare Disaster Recovery Endpoint Security Network Sec

IBM Security: Cost of Data Breach Hitting All-Time Highs

A study commissioned by IBM Security says the global average cost of a data breach reached an all-time high of $4.35 million and warned that the absence of zero trust principles at studied organizations are pushing those costs even higher.The study, which was conducted in partnership with the Ponemon Institute, notes that global average breach costs have cli
Publish At:2022-07-27 12:03 | Read:375 | Comments:0 | Tags:Cyberwarfare Endpoint Security Network Security NEWS & I

European Lawmaker Targeted With Cytrox Predator Surveillance Spyware

A security audit by the European Parliament has unearthed attempts to plant high-end surveillance software on the phone of a Greek lawmaker and there are fresh reports linking the hack attempt to a known North Macedonia spyware vendor.The company, called Cytrox, was previously exposed as the makers of Predator, a tool capable of launching sophisticated explo
Publish At:2022-07-27 00:09 | Read:343 | Comments:0 | Tags:Cyberwarfare Disaster Recovery Endpoint Security Mobile Secu

PrestaShop Confirms Zero Day Attacks Hitting eCommerce Servers

The team behind the open source PrestaShop ecommerce platform has issued a public advisory to warn of zero day SQL injection attacks hitting merchant servers and planting code capable of stealing customer payment information.An urgent advisory from PrestaShop warned that hackers are exploiting a "combination of known and unknown security vulnerabilities" to
Publish At:2022-07-25 20:11 | Read:349 | Comments:0 | Tags:Cyberwarfare Disaster Recovery Endpoint Security Network Sec

SonicWall Warns of Critical GMS SQL Injection Vulnerability

Network security appliance vendor SonicWall late Thursday shipped urgent patches for a critical flaw in its Global Management System (GMS) software, warning that the issue exposes businesses to remote hacker attacks.The vulnerability, which carries a critical-severity rating of CVSS 9.4, provides a pathway for a remote attacker to execute arbitrary SQL queri
Publish At:2022-07-22 20:11 | Read:500 | Comments:0 | Tags:Endpoint Security Network Security NEWS & INDUSTRY Appli

Anvilogic Scores $25 Million Series B to Tackle SOC Modernization

Anvilogic, a Silicon Valley startup working on technology to modernize the Security Operations Center (SOC), has deposited $25 million in a new investment round led by Outpost Ventures.The Palo Alto, Calif. Anvilogic said the $25 million Series B investment also included participation from Xerox Ventures, G Squared, Foundation Capital, Point72 Ventures and C
Publish At:2022-07-21 16:13 | Read:354 | Comments:0 | Tags:Endpoint Security Network Security NEWS & INDUSTRY Appli

Announce

Share high-quality web security related articles with you:)
Tell me why you support me <3

Tag Cloud