HackDig : Dig high-quality web security articles

HYAS Unveils New Tool for Continuous DNS Monitoring

Canadian security firm HYAS Infosec has released a new DNS protection tool dubbed HYAS Confront that was designed to provide clear visibility into DNS transactions into production networks. While there are existing corporate network DNS products available, Confront is claimed to be the first solution to continuously cover the entire production network r
Publish At:2022-08-08 12:04 | Read:67 | Comments:0 | Tags:Network Security NEWS & INDUSTRY

Twilio Hacked After Employees Tricked Into Giving Up Login Credentials

Enterprise software vendor Twilio (NYSE: TWLO) has been hacked by a relentless threat actor who successfully tricked employees into giving up login credentials that were then used to steal third-party customer data.The San Francisco company fessed up to the breach in an online notice that describes a sophisticated threat actor with clever social engineering
Publish At:2022-08-08 12:04 | Read:62 | Comments:0 | Tags:Cyberwarfare Disaster Recovery Endpoint Security Network Sec

Slack Forces Password Resets After Discovering Software Flaw

Workplace productivity software giant Slack on Friday forced password resets for a tiny fraction of its users after the discovery of a security flaw that exposed Slack credentials.Slack's security response team alerted users to the issue via email and followed up with a blog post warning about the risk of passwords leaking to a skilled attacker."We have no r
Publish At:2022-08-05 16:14 | Read:178 | Comments:0 | Tags:Endpoint Security Network Security NEWS & INDUSTRY Appli

Ghost Security Snags $15M Investment for API Security Tech

Texas startup Ghost Security has joined the list of early-stage companies in the API and application security space attracting venture capital funding.The Austin-based company emerged from stealth this week with $15 million in investments from 468 Capital, DNX Ventures, and Munich Re Ventures."We believe the explosive growth of microservices and APIs in the
Publish At:2022-08-05 16:14 | Read:170 | Comments:0 | Tags:Endpoint Security Network Security NEWS & INDUSTRY Priva

SMBs Exposed to Attacks by Critical Vulnerability in DrayTek Vigor Routers

Many small and medium-sized businesses (SMBs) could be exposed to attacks due to a critical vulnerability that has been found to impact hundreds of thousands of DrayTek Vigor routers.The security hole, discovered by researchers at threat detection and response company Trellix, affects nearly 30 DrayTek Vigor router models that are used by many SMBs. The issu
Publish At:2022-08-04 12:04 | Read:155 | Comments:0 | Tags:Network Security NEWS & INDUSTRY Vulnerabilities Vulnera

Compliance Automation Startup RegScale Scores $20 Million Investment

RegScale, a Virginia startup building technology to manage continuous compliance automation tasks, has attracted $20 million in early-stage venture capital funding.The Series A round was led by SYN Ventures with participation from SineWave Ventures, VIPC’s Virginia Venture Partners and SecureOctane.RegScale, which maintains headquarters in Tyson’s Corner, Vi
Publish At:2022-08-03 20:12 | Read:210 | Comments:0 | Tags:Endpoint Security Network Security NEWS & INDUSTRY Priva

Robinhood Crypto Penalized $30M for Violating NY Cybersecurity Regulations

The cryptocurrency division of Robinhood has been slapped with a $30 million penalty by New York's Department of Financial Services for significant violations of cybersecurity and money laundering regulations.The $30 million penalty, announced late Tuesday via a consent order, adds to a litany of problems at Robinhood that range from security breaches, to on
Publish At:2022-08-03 16:14 | Read:216 | Comments:0 | Tags:Endpoint Security Network Security NEWS & INDUSTRY Priva

The Ever-Increasing Issue of Cyber Threats - and the Zero Trust Answer

The benefits of ZTNA make it hard to ignoreEnsuring that the right people have access to the proper resources when they need them whilst maintaining security and access controls across multiple data centers and cloud environments is one of the biggest technical challenges any organization faces.Having too much security can slow business and create disgruntle
Publish At:2022-08-03 08:05 | Read:228 | Comments:0 | Tags:INDUSTRY INSIGHTS Network Security cyber

VMware Ships Urgent Patch for Authentication Bypass Security Hole

Virtualization technology giant VMware on Tuesday shipped an urgent, high-priority patch to address an authentication bypass vulnerability in its Workspace ONE Access, Identity Manager and vRealize Automation products.The vulnerability carries VMware’s highest severity rating (CVSSv3 base score of 9.8) and should be remediated without delay, the company said
Publish At:2022-08-02 16:13 | Read:234 | Comments:0 | Tags:Endpoint Security Network Security NEWS & INDUSTRY Priva

Microsoft Connects USB Worm Attacks to 'EvilCorp' Ransomware Gang

Cybersleuths at Microsoft have found a link between the recent 'Raspberry Robin' USB-based worm attacks and EvilCorp, a notorious Russian ransomware operation sanctioned by the U.S. government.According to fresh data from Redmond’s threat intelligence team, a ransomware-as-a-service gang it tracks as DEV-0206 has been caught rigging online ads to trick targe
Publish At:2022-07-29 16:13 | Read:483 | Comments:0 | Tags:Cyberwarfare Disaster Recovery Endpoint Security Network Sec

Calls Mount for US Gov Clampdown on Mercenary Spyware Merchants

Cybersecurity professionals from Google's threat hunting unit and the University of Toronto's Citizen Lab are upping the pressure on mercenary hacking firms selling high-end surveillance spyware with fresh calls for the U.S. government to urgently clamp down on these businesses.In prepared remarks during a House Intelligence Committee hearing this week, Goog
Publish At:2022-07-28 16:13 | Read:290 | Comments:0 | Tags:Cyberwarfare Disaster Recovery Endpoint Security Network Sec

Microsoft Catches Austrian Company Exploiting Windows, Adobe Zero-Days

Malware hunters at Microsoft have caught an Austrian hack-for-hire company exploiting zero-day flaws in Windows and Adobe software products in "limited and targeted attacks" against European and Central American computer users.The company, called DSIRF, has been linked to a malware suite called ‘Subzero’ that has been deployed over the last two years via zer
Publish At:2022-07-27 16:13 | Read:349 | Comments:0 | Tags:Cyberwarfare Disaster Recovery Endpoint Security Network Sec

IBM Security: Cost of Data Breach Hitting All-Time Highs

A study commissioned by IBM Security says the global average cost of a data breach reached an all-time high of $4.35 million and warned that the absence of zero trust principles at studied organizations are pushing those costs even higher.The study, which was conducted in partnership with the Ponemon Institute, notes that global average breach costs have cli
Publish At:2022-07-27 12:03 | Read:273 | Comments:0 | Tags:Cyberwarfare Endpoint Security Network Security NEWS & I

European Lawmaker Targeted With Cytrox Predator Surveillance Spyware

A security audit by the European Parliament has unearthed attempts to plant high-end surveillance software on the phone of a Greek lawmaker and there are fresh reports linking the hack attempt to a known North Macedonia spyware vendor.The company, called Cytrox, was previously exposed as the makers of Predator, a tool capable of launching sophisticated explo
Publish At:2022-07-27 00:09 | Read:269 | Comments:0 | Tags:Cyberwarfare Disaster Recovery Endpoint Security Mobile Secu

PrestaShop Confirms Zero Day Attacks Hitting eCommerce Servers

The team behind the open source PrestaShop ecommerce platform has issued a public advisory to warn of zero day SQL injection attacks hitting merchant servers and planting code capable of stealing customer payment information.An urgent advisory from PrestaShop warned that hackers are exploiting a "combination of known and unknown security vulnerabilities" to
Publish At:2022-07-25 20:11 | Read:270 | Comments:0 | Tags:Cyberwarfare Disaster Recovery Endpoint Security Network Sec

Announce

Share high-quality web security related articles with you:)
Tell me why you support me <3

Tag Cloud