HackDig : Dig high-quality web security articles

Twilio Hacked After Employees Tricked Into Giving Up Login Credentials

Enterprise software vendor Twilio (NYSE: TWLO) has been hacked by a relentless threat actor who successfully tricked employees into giving up login credentials that were then used to steal third-party customer data.The San Francisco company fessed up to the breach in an online notice that describes a sophisticated threat actor with clever social engineering
Publish At:2022-08-08 12:04 | Read:62 | Comments:0 | Tags:Cyberwarfare Disaster Recovery Endpoint Security Network Sec

Slack Forces Password Resets After Discovering Software Flaw

Workplace productivity software giant Slack on Friday forced password resets for a tiny fraction of its users after the discovery of a security flaw that exposed Slack credentials.Slack's security response team alerted users to the issue via email and followed up with a blog post warning about the risk of passwords leaking to a skilled attacker."We have no r
Publish At:2022-08-05 16:14 | Read:178 | Comments:0 | Tags:Endpoint Security Network Security NEWS & INDUSTRY Appli

Ghost Security Snags $15M Investment for API Security Tech

Texas startup Ghost Security has joined the list of early-stage companies in the API and application security space attracting venture capital funding.The Austin-based company emerged from stealth this week with $15 million in investments from 468 Capital, DNX Ventures, and Munich Re Ventures."We believe the explosive growth of microservices and APIs in the
Publish At:2022-08-05 16:14 | Read:170 | Comments:0 | Tags:Endpoint Security Network Security NEWS & INDUSTRY Priva

Compliance Automation Startup RegScale Scores $20 Million Investment

RegScale, a Virginia startup building technology to manage continuous compliance automation tasks, has attracted $20 million in early-stage venture capital funding.The Series A round was led by SYN Ventures with participation from SineWave Ventures, VIPC’s Virginia Venture Partners and SecureOctane.RegScale, which maintains headquarters in Tyson’s Corner, Vi
Publish At:2022-08-03 20:12 | Read:210 | Comments:0 | Tags:Endpoint Security Network Security NEWS & INDUSTRY Priva

Robinhood Crypto Penalized $30M for Violating NY Cybersecurity Regulations

The cryptocurrency division of Robinhood has been slapped with a $30 million penalty by New York's Department of Financial Services for significant violations of cybersecurity and money laundering regulations.The $30 million penalty, announced late Tuesday via a consent order, adds to a litany of problems at Robinhood that range from security breaches, to on
Publish At:2022-08-03 16:14 | Read:216 | Comments:0 | Tags:Endpoint Security Network Security NEWS & INDUSTRY Priva

VMware Ships Urgent Patch for Authentication Bypass Security Hole

Virtualization technology giant VMware on Tuesday shipped an urgent, high-priority patch to address an authentication bypass vulnerability in its Workspace ONE Access, Identity Manager and vRealize Automation products.The vulnerability carries VMware’s highest severity rating (CVSSv3 base score of 9.8) and should be remediated without delay, the company said
Publish At:2022-08-02 16:13 | Read:234 | Comments:0 | Tags:Endpoint Security Network Security NEWS & INDUSTRY Priva

Microsoft Connects USB Worm Attacks to 'EvilCorp' Ransomware Gang

Cybersleuths at Microsoft have found a link between the recent 'Raspberry Robin' USB-based worm attacks and EvilCorp, a notorious Russian ransomware operation sanctioned by the U.S. government.According to fresh data from Redmond’s threat intelligence team, a ransomware-as-a-service gang it tracks as DEV-0206 has been caught rigging online ads to trick targe
Publish At:2022-07-29 16:13 | Read:483 | Comments:0 | Tags:Cyberwarfare Disaster Recovery Endpoint Security Network Sec

Calls Mount for US Gov Clampdown on Mercenary Spyware Merchants

Cybersecurity professionals from Google's threat hunting unit and the University of Toronto's Citizen Lab are upping the pressure on mercenary hacking firms selling high-end surveillance spyware with fresh calls for the U.S. government to urgently clamp down on these businesses.In prepared remarks during a House Intelligence Committee hearing this week, Goog
Publish At:2022-07-28 16:13 | Read:290 | Comments:0 | Tags:Cyberwarfare Disaster Recovery Endpoint Security Network Sec

Microsoft Catches Austrian Company Exploiting Windows, Adobe Zero-Days

Malware hunters at Microsoft have caught an Austrian hack-for-hire company exploiting zero-day flaws in Windows and Adobe software products in "limited and targeted attacks" against European and Central American computer users.The company, called DSIRF, has been linked to a malware suite called ‘Subzero’ that has been deployed over the last two years via zer
Publish At:2022-07-27 16:13 | Read:349 | Comments:0 | Tags:Cyberwarfare Disaster Recovery Endpoint Security Network Sec

AWS Announces Enhancements to Cloud Security, Privacy, Compliance

Amazon Web Services (AWS) is hosting its re:Inforce 2022 conference these days and the cloud giant has taken the opportunity to unveil several enhancements to its security offerings.Security, privacy, compliance and identityAWS has announced a new Customer Incident Response Team (CIRT), whose goal is to provide assistance to customers during active security
Publish At:2022-07-27 12:03 | Read:333 | Comments:0 | Tags:NEWS & INDUSTRY Privacy Incident Response Compliance Ris

IBM Security: Cost of Data Breach Hitting All-Time Highs

A study commissioned by IBM Security says the global average cost of a data breach reached an all-time high of $4.35 million and warned that the absence of zero trust principles at studied organizations are pushing those costs even higher.The study, which was conducted in partnership with the Ponemon Institute, notes that global average breach costs have cli
Publish At:2022-07-27 12:03 | Read:273 | Comments:0 | Tags:Cyberwarfare Endpoint Security Network Security NEWS & I

What’s New in the 2022 Cost of a Data Breach Report

The average cost of a data breach reached an all-time high of $4.35 million this year, according to newly published 2022 Cost of a Data Breach Report, an increase of 2.6% from a year ago and 12.7% since 2020. New research in this year’s report also reveals for the first time that 83% of organizations in the study have experienced more than one data br
Publish At:2022-07-27 05:13 | Read:337 | Comments:0 | Tags:Zero Trust Intelligence & Analytics Artificial Intelligence

European Lawmaker Targeted With Cytrox Predator Surveillance Spyware

A security audit by the European Parliament has unearthed attempts to plant high-end surveillance software on the phone of a Greek lawmaker and there are fresh reports linking the hack attempt to a known North Macedonia spyware vendor.The company, called Cytrox, was previously exposed as the makers of Predator, a tool capable of launching sophisticated explo
Publish At:2022-07-27 00:09 | Read:269 | Comments:0 | Tags:Cyberwarfare Disaster Recovery Endpoint Security Mobile Secu

PrestaShop Confirms Zero Day Attacks Hitting eCommerce Servers

The team behind the open source PrestaShop ecommerce platform has issued a public advisory to warn of zero day SQL injection attacks hitting merchant servers and planting code capable of stealing customer payment information.An urgent advisory from PrestaShop warned that hackers are exploiting a "combination of known and unknown security vulnerabilities" to
Publish At:2022-07-25 20:11 | Read:270 | Comments:0 | Tags:Cyberwarfare Disaster Recovery Endpoint Security Network Sec

SonicWall Warns of Critical GMS SQL Injection Vulnerability

Network security appliance vendor SonicWall late Thursday shipped urgent patches for a critical flaw in its Global Management System (GMS) software, warning that the issue exposes businesses to remote hacker attacks.The vulnerability, which carries a critical-severity rating of CVSS 9.4, provides a pathway for a remote attacker to execute arbitrary SQL queri
Publish At:2022-07-22 20:11 | Read:438 | Comments:0 | Tags:Endpoint Security Network Security NEWS & INDUSTRY Appli

Announce

Share high-quality web security related articles with you:)
Tell me why you support me <3

Tag Cloud