Aggregator
Threat actors are stepping up their tactics to bypass email protections
Although most organizations use emails with built-in security features that filter out suspicious messages, criminals always find a way to bypass these systems. With the development of AI technology, phishing is becoming increasingly difficult to recognize, allowing them to circumvent security measures. While most attempts do not succeed, it only takes one to cause significant damage to a company’s operations. Mick Leach, Field CISO at Abnormal Security, discusses why the automotive industry is the new … More →
The post Threat actors are stepping up their tactics to bypass email protections appeared first on Help Net Security.
CVE-2024-7472 | lunary-ai lunary up to 1.4.9 API send-verification extractFirstName special elements into a different plane (special element injection)
CVE-2024-5823 | gaizhenbiao ChuanhuChatGPT up to 20240410 Setting file inclusion
CVE-2024-7042 | langchain-ai langchainjs up to 0.3.0 GraphCypherQAChain sql injection
CVE-2024-8143 | gaizhenbiao ChuanhuChatGPT up to 20240628 Private Chat data access operations outside of expected data manager component
UnitedHealth Hires Longtime Cybersecurity Executive as CISO
FBI: Iranian cyber group targeted Summer Olympics with attack on French display provider
Microsoft: Chinese hackers use Quad7 botnet to steal credentials
Stalker Online - 1,385,472 breached accounts
Infosec products of the month: October 2024
Here’s a look at the most interesting products from the past month, featuring releases from: Action1, Balbix, BreachLock, Commvault, Dashlane, Data Theorem, Edgio, ExtraHop, Fastly, Frontegg, GitGuardian, IBM, Ivanti, Jumio, Kusari, Legit Security, Metomic, Nametag, Neon, Nucleus Security, Okta, Qualys, Rubrik, SAFE Security, Sectigo, Securiti, Veeam Software, and XM Cyber. Qualys Enterprise TruRisk Management unifies asset inventory and risk factors Qualys launched the Risk Operations Center (ROC) with Enterprise TruRisk Management (ETM). The solution enables … More →
The post Infosec products of the month: October 2024 appeared first on Help Net Security.
Zenity Gets $38M Series B for Agentic AI Security Expansion
Zenity has closed a $38 million Series B round to advance its agentic AI security platform and extend its no-code and low-code application support. With investment from Third Point Ventures and DTCP, the funding enables Zenity to cater to clients in sectors like financial services and healthcare.
Mac Malware Threat: Hackers Seek Cryptocurrency Holders
Cryptocurrency-seeking hackers are increasingly targeting macOS users. So warn security researchers as they track a rise in macOS backdoors and information-stealing malware, much of which traces back to a well-known cryptocurrency heist culprit: North Korea.
Sophos Discloses Half Decade of Sustained Chinese Attack
Firewall maker Sophos disclosed Thursday a half-decade worth of efforts by multiple nation-state Chinese hacking groups to infiltrate its appliances, calling the admission a wake-up call for the cybersecurity industry. Targeting firewall appliances is a known nation-state tactic.
Breach Roundup: S&P Says Poor Remediation A Material Risk
This week: S&P said poor material vulnerability remediaton can be a material risk factor, OnePoint in the United States and French ISP Free suffered data breaches, a Russian court sentenced REvil members, Five Eyes published security guidelines for small businesses.