Cybersecurity

Lazarus luring employees with trojanized coding challenges: The case of a Spanish aerospace company

ESET researchers have uncovered a Lazarus attack against an aerospace company in Spain, where the group deployed several tools, most notably a publicly undocumented backdoor we named LightlessCan. Lazarus operators obtained initial access to the company’s network last year after a successful spearphishing campaign, masquerading as a recruiter for Meta – the company behind Facebook, […]

Cybersecurity

Nexusflow raises $10.6M to build a conversational interface for security tools | TechCrunch

Nexusflow, a startup using generative AI to help companies make sense of cybersecurity data, today announced that it raised $10.6 million in a seed round led by Point72 Ventures with participation from Fusion Fund and several AI luminaries in Silicon Valley. The tranche, which values Nexusflow at $53 million post-money, will be put toward hiring, […]

Cybersecurity

Hackers Set Sights on Apache NiFi Flaw That Exposes Many Organizations to Attacks

A high-severity remote code execution (RCE) vulnerability in Apache NiFi, for which an exploitation tool already exists, can lead to unauthorized access and data breaches, cybersecurity firm Cyfirma warns. An open-source data integration and automation tool, Apache NiFi is used for the processing and distribution of data. Tracked as CVE-2023-34468 (CVSS score of 8.8) and […]

Cybersecurity

Misconfigured WBSC server leaks thousands of passports

Misconfigured WBSC server leaks thousands of passports Pierluigi Paganini September 29, 2023 The World Baseball Softball Confederation (WBSC) left open a data repository exposing nearly 50,000 files, some of which were highly sensitive, the Cybernews research team has discovered. On June 5th, our researchers discovered a misconfigured Amazon Web Services (AWS) bucket storing nearly 48,000 […]

Cybersecurity

Tech industry leaders and White House clash over plan for improved cloud security

The Biden administration is moving forward with a plan to enhance cloud infrastructure security by requiring companies to collect personal information from users, despite intensifying backlash from executives at Amazon and other tech giants. The White House says the proposed cloud security policy — dubbed Know Your Customer (KYC) — is crucial for disrupting hackers […]

Cybersecurity

Budworm Strikes Again: Updated SysUpdate Targets Government and Telecom Sectors

The Budworm APT group is evolving its cyber arsenal. In the latest discovery, Symantec’s Threat Hunter Team identified that Budworm has adapted and upgraded one of its primary tools. Two significant entities, an Asian government and a Middle Eastern telecommunication firm, were targeted with this renewed strategy. Diving into the Details In August 2023, Budworm, […]

Cybersecurity

Russian flight booking system suffers ‘massive’ cyberattack

A Russian flight booking system was hit by a cyberattack on Thursday, causing delays at airports. A “massive” distributed denial-of-service (DDoS) attack on the local airline booking system Leonardo was carried out by “foreign hackers,” reported one of the system’s developers, Russian state defense company Rostec. The incident lasted about an hour and affected the […]