SecurityWeek

Powerful ‘Brokewell’ Android Trojan Allows Attackers to Takeover Devices

Security Week - Fri, 04/26/2024 - 10:08am

A new Android trojan named Brokewell can steal user’s sensitive information and allows attackers to take over devices.

The post Powerful ‘Brokewell’ Android Trojan Allows Attackers to Takeover Devices appeared first on SecurityWeek.

Categories: SecurityWeek

Over 1,400 CrushFTP Instances Vulnerable to Exploited Zero-Day

Security Week - Fri, 04/26/2024 - 9:44am

More than 1,400 CrushFTP servers remain vulnerable to an actively exploited zero-day for which PoC has been published.

The post Over 1,400 CrushFTP Instances Vulnerable to Exploited Zero-Day appeared first on SecurityWeek.

Categories: SecurityWeek

Self-Spreading PlugX USB Drive Malware Plagues Over 90k IP Addresses

Security Week - Fri, 04/26/2024 - 9:41am

More than 90,000 unique IPs are still infected with a PlugX worm variant that spreads via infected flash drives.

The post Self-Spreading PlugX USB Drive Malware Plagues Over 90k IP Addresses appeared first on SecurityWeek.

Categories: SecurityWeek

In Other News: China Hacked Volkswagen, DDoS Service Shutdown, Rubrik IPO

Security Week - Fri, 04/26/2024 - 8:00am

Noteworthy stories that might have slipped under the radar: Volkswagen hacked by Chinese threat group, DDoS service shut down, Rubrik IPO.

The post In Other News: China Hacked Volkswagen, DDoS Service Shutdown, Rubrik IPO appeared first on SecurityWeek.

Categories: SecurityWeek

Darktrace to be Taken Private in $5.3 Billion Sale to Thoma Bravo

Security Week - Fri, 04/26/2024 - 7:32am

UK cybersecurity firm Darktace has agreed to sell itself to private equity giant Thoma Bravo for approximately $5.32 million in cash.

The post Darktrace to be Taken Private in $5.3 Billion Sale to Thoma Bravo appeared first on SecurityWeek.

Categories: SecurityWeek

Critical WordPress Automatic Plugin Vulnerability Exploited to Inject Backdoors

Security Week - Fri, 04/26/2024 - 5:34am

A vulnerability in the WordPress Automatic plugin is being exploited to inject backdoors and web shells into websites.

The post Critical WordPress Automatic Plugin Vulnerability Exploited to Inject Backdoors appeared first on SecurityWeek.

Categories: SecurityWeek

Predictive Security Startup BforeAI Raises $15 Million

Security Week - Thu, 04/25/2024 - 11:47am

Predictive attack intelligence and risk protection startup BforeAI has raised $15 million in a Series A funding round led by SYN Ventures.

The post Predictive Security Startup BforeAI Raises $15 Million appeared first on SecurityWeek.

Categories: SecurityWeek

Palo Alto Networks Shares Remediation Advice for Hacked Firewalls

Security Week - Thu, 04/25/2024 - 9:24am

Palo Alto Networks has shared remediation instructions for organizations whose firewalls have been hacked via CVE-2024-3400.

The post Palo Alto Networks Shares Remediation Advice for Hacked Firewalls appeared first on SecurityWeek.

Categories: SecurityWeek

Autodesk Drive Abused in Phishing Attacks 

Security Week - Thu, 04/25/2024 - 8:25am

A new phishing campaign abuses compromised email accounts and targets corporate users with PDF files hosted on Autodesk Drive.

The post Autodesk Drive Abused in Phishing Attacks  appeared first on SecurityWeek.

Categories: SecurityWeek

FTC Sending $5.6 Million in Refunds to Ring Customers Over Security Failures

Security Week - Thu, 04/25/2024 - 8:10am

The FTC is sending a total of $5.6 million in refunds to over 117,000 Ring customers as result of a 2023 settlement.

The post FTC Sending $5.6 Million in Refunds to Ring Customers Over Security Failures appeared first on SecurityWeek.

Categories: SecurityWeek

Vulnerabilities Expose Brocade SAN Appliances, Switches to Hacking

Security Week - Thu, 04/25/2024 - 7:53am

The Brocade SANnav management application is affected by multiple vulnerabilities, including a publicly available root password.

The post Vulnerabilities Expose Brocade SAN Appliances, Switches to Hacking appeared first on SecurityWeek.

Categories: SecurityWeek

Endpoint Security Firm ThreatLocker Raises $115 Million in Series D Funding

Security Week - Thu, 04/25/2024 - 6:10am

Zero trust endpoint security company ThreatLocker has announced a $115 million Series D funding round that brings the total to $240 million. 

The post Endpoint Security Firm ThreatLocker Raises $115 Million in Series D Funding appeared first on SecurityWeek.

Categories: SecurityWeek

IBM Acquiring HashiCorp for $6.4 Billion

Security Week - Thu, 04/25/2024 - 4:55am

IBM is acquiring HashiCorp for $6.4 billion for its infrastructure lifecycle management and security lifecycle management capabilities.

The post IBM Acquiring HashiCorp for $6.4 Billion appeared first on SecurityWeek.

Categories: SecurityWeek

Cisco Systems Joins Microsoft, IBM in Vatican Pledge to Ensure Ethical Use and Development of AI

Security Week - Wed, 04/24/2024 - 9:17pm

Pope Francis has called for an international treaty to ensure AI is developed and used ethically, devoting his annual peace message this year to the topic.

The post Cisco Systems Joins Microsoft, IBM in Vatican Pledge to Ensure Ethical Use and Development of AI appeared first on SecurityWeek.

Categories: SecurityWeek

Cisco Raises Alarm for ‘ArcaneDoor’ Zero-Days Hitting ASA Firewall Platforms

Security Week - Wed, 04/24/2024 - 1:25pm

Cisco warns that nation state-backed hackers are exploiting at least two zero-day vulnerabilities in its ASA firewall platforms to plant malware on telecommunications and energy sector networks.

The post Cisco Raises Alarm for ‘ArcaneDoor’ Zero-Days Hitting ASA Firewall Platforms appeared first on SecurityWeek.

Categories: SecurityWeek

KnowBe4 Plans to Acquire Egress for Email Security Tech

Security Week - Wed, 04/24/2024 - 11:16am

KnowBe4 boasts that the merger will create “the largest, advanced AI-driven cybersecurity platform for managing human risk.”

The post KnowBe4 Plans to Acquire Egress for Email Security Tech appeared first on SecurityWeek.

Categories: SecurityWeek

Navigating Vendor Speak: A Security Practitioner’s Guide to Seeing Through the Jargon

Security Week - Wed, 04/24/2024 - 11:08am

As a security industry, we need to focus our energies on those professionals among us who know how to walk the walk.

The post Navigating Vendor Speak: A Security Practitioner’s Guide to Seeing Through the Jargon appeared first on SecurityWeek.

Categories: SecurityWeek

North Korean Hackers Hijack Antivirus Updates for Malware Delivery

Security Week - Wed, 04/24/2024 - 10:44am

A North Korea-linked threat actor hijacked the update mechanism of eScan antivirus to deploy backdoors and cryptocurrency miners.

The post North Korean Hackers Hijack Antivirus Updates for Malware Delivery appeared first on SecurityWeek.

Categories: SecurityWeek

Tines Bags $50 Million Funding for Security Workflow Automation

Security Week - Wed, 04/24/2024 - 9:11am

Irish startup Tines raises $50 million in new venture capital funding as investors make big bets on automation and orchestration startups.

The post Tines Bags $50 Million Funding for Security Workflow Automation appeared first on SecurityWeek.

Categories: SecurityWeek

Google Patches Critical Chrome Vulnerability

Security Week - Wed, 04/24/2024 - 8:48am

Google patches CVE-2024-4058, a critical Chrome vulnerability for which researchers earned a $16,000 reward. 

The post Google Patches Critical Chrome Vulnerability appeared first on SecurityWeek.

Categories: SecurityWeek

Pages