Tech Target

AMD Processor Vulnerability Inadvertently Leaked Early

AMD is aware of a newly reported processor vulnerability. Execution of the attack requires both local administrator-level access to the system, and the development and execution of malicious microcode.

Researchers Unveil AWS Vulnerabilities, New 'Shadow Resource' Attack Vector

The vulnerabilities were promptly patched by AWS after being reported by Aqua Security researchers. These flaws in services like CloudFormation, CodeStar, and Service Catalog could potentially lead to a full account takeover if exploited.

Update: MOVEit Transfer Vulnerability Targeted Amid Disclosure Drama

The non-profit cybersecurity organization, the Shadowserver Foundation, has observed exploitation attempts against CVE-2024-5806. They noted that the exploitation began soon after the vulnerability details were made public.

ChatGPT Plugin Flaws Introduce Enterprise Security Risks

While third-party ChatGPT plugins can significantly enhance productivity and efficiency, they also present unique security challenges for enterprises, including data privacy, compliance risks, vendor dependencies, and more.

Report: Attacker Dwell Time Down, Ransomware up in 2023

According to a new report by Mandiant, which is based on Mandiant Consulting investigations during 2023, the global median dwell time for attackers fell to its lowest point since the company began tracking the metric in 2011.

Iranian Cyberattacks Targeting U.S. and Israeli Entities

Iranian state-backed actors have consistently targeted the U.S. and Israel with cyberattacks, including destructive malware and influence campaigns, before and after the Israel-Hamas war.

Cohesity, Veritas Combine as New Data Protection Company

The deal will result in the formation of a separate company called DataCo to handle Veritas' remaining assets, while Cohesity will follow a "no customer left behind" approach.

Linux Foundation Announces Post-Quantum Cryptography Alliance

The Post-Quantum Cryptography Alliance aims to drive the adoption of post-quantum cryptography to address security risks posed by quantum computing, with support from industry leaders like Google, IBM, Amazon Web Services, and Cisco.

SonicWall Acquires Banyan to Boost Zero-Trust, SSE Offerings

With its second acquisition in two months, SonicWall aims to help enterprises with growing remote workforces through zero-trust network and security service edge offerings.

Researchers Disclose Zero-Click Exploit for Microsoft Outlook

The vulnerabilities, CVE-2023-35384 and CVE-2023-36710, allow an attacker to bypass security measures and execute code on a victim's machine by tricking Outlook into downloading a specially crafted sound file.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags