Advertisement
Top

Category: Cybersecurity


Cybersecurity, Security

7 Uses for Generative AI to Enhance Security Operations

November 30, 2023

Via: The Hacker News

Welcome to a world where Generative AI revolutionizes the field of cybersecurity. Generative AI refers to the use of artificial intelligence (AI) techniques to generate or create new data, such as images, text, or sounds. It has gained significant attention […]


Cybersecurity, Security

This Free Solution Provides Essential Third-Party Risk Management for SaaS

November 30, 2023

Via: The Hacker News

Wing Security recently announced that basic third-party risk assessment is now available as a free product. But it raises the questions of how SaaS is connected to third-party risk management (TPRM) and what companies should do to ensure a proper […]


Cybersecurity, Security

Alert: Microsoft Releases Patch Updates for 5 New Zero-Day Vulnerabilities

November 15, 2023

Via: The Hacker News

Microsoft has released fixes to address 63 security bugs in its software for the month of November 2023, including three vulnerabilities that have come under active exploitation in the wild. Of the 63 flaws, three are rated Critical, 56 are […]


Cybersecurity, Security

Oracle open-sources Jipher for FIPS-compliant SSL

November 8, 2023

Via: InfoWorld

Oracle is open-sourcing Jipher, a Java Cryptography Architecture (JCA) provider built for security and performance that has been used by the company’s cloud platform, the company said on November 7. Jipher was developed for environments with FIPS (Federal Information Processing […]


Cybersecurity, Security

VMware exploited 34 vulnerable device drivers to gain full control of Windows 11

November 6, 2023

Via: TechSpot

Bug hunters at the VMware Threat Analysis Unit (TAU) discovered 34 unique vulnerable Windows drivers, with 237 different file hashes belonging to legacy devices. Even though many of these drivers have revoked or expired security certificates, companies and other organizations […]


Cybersecurity, Security

Predictive AI in Cybersecurity: Outcomes Demonstrate All AI is Not Created Equally

November 3, 2023

Via: The Hacker News

Here is what matters most when it comes to artificial intelligence (AI) in cybersecurity: Outcomes. As the threat landscape evolves and generative AI is added to the toolsets available to defenders and attackers alike, evaluating the relative effectiveness of various […]


Cybersecurity, Security

Warning: Unpatched Cisco Zero-Day Vulnerability Actively Targeted in the Wild

October 17, 2023

Via: The Hacker News

Cisco has warned of a critical, unpatched security flaw impacting IOS XE software that’s under active exploitation in the wild. Rooted in the web UI feature, the zero-day vulnerability is tracked as CVE-2023-20198 and has been assigned the maximum severity […]


Cybersecurity, Security

Exploring the Realm of Malicious Generative AI: A New Digital Security Challenge

October 17, 2023

Via: The Hacker News

Recently, the cybersecurity landscape has been confronted with a daunting new reality – the rise of malicious Generative AI, like FraudGPT and WormGPT. These rogue creations, lurking in the dark corners of the internet, pose a distinctive threat to the […]


Cybersecurity, Security

The Fast Evolution of SaaS Security from 2020 to 2024 (Told Through Video)

October 16, 2023

Via: The Hacker News

SaaS Security’s roots are in configuration management. An astounding 35% of all security breaches begin with security settings that were misconfigured. In the past 3 years, the initial access vectors to SaaS data have widened beyond misconfiguration management. “SaaS Security […]


Cybersecurity, Security

U.S. Cybersecurity Agency Warns of Actively Exploited Adobe Acrobat Reader Vulnerability

October 11, 2023

Via: The Hacker News

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a high-severity flaw in Adobe Acrobat Reader to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. Tracked as CVE-2023-21608 (CVSS score: 7.8), the vulnerability has been […]


Cybersecurity, Security

HTTP/2 Rapid Reset Zero-Day Vulnerability Exploited to Launch Record DDoS Attacks

October 10, 2023

Via: The Hacker News

Amazon Web Services (AWS), Cloudflare, and Google on Tuesday said they took steps to mitigate record-breaking distributed denial-of-service (DDoS) attacks that relied on a novel technique called HTTP/2 Rapid Reset. The layer 7 attacks were detected in late August 2023, […]


Cybersecurity, Security

Wing Disrupts the Market by Introducing Affordable SaaS Security

October 4, 2023

Via: The Hacker News

Today, mid-sized companies and their CISOs are struggling to handle the growing threat of SaaS security with limited manpower and tight budgets. Now, this may be changing. By focusing on the critical SaaS security needs of these companies, a new […]


Cybersecurity, Security

Researcher Reveals New Techniques to Bypass Cloudflare’s Firewall and DDoS Protection

October 3, 2023

Via: TheHackersNews

Firewall and distributed denial-of-service (DDoS) attack prevention mechanisms in Cloudflare can be circumvented by exploiting gaps in cross-tenant security controls, defeating the very purpose of these safeguards, it has emerged. “Attackers can utilize their own Cloudflare accounts to abuse the […]


Cybersecurity, Security

API Security Trends 2023 – Have Organizations Improved their Security Posture?

October 3, 2023

Via: TheHackersNews

APIs, also known as application programming interfaces, serve as the backbone of modern software applications, enabling seamless communication and data exchange between different systems and platforms. They provide developers with an interface to interact with external services, allowing them to […]


Cybersecurity, Security

Update Chrome Now: Google Releases Patch for Actively Exploited Zero-Day Vulnerability

September 28, 2023

Via: TheHackersNews

Google on Wednesday rolled out fixes to address a new actively exploited zero-day in the Chrome browser. Tracked as CVE-2023-5217, the high-severity vulnerability has been described as a heap-based buffer overflow in the VP8 compression format in libvpx, a free […]


Cybersecurity, Security

Critical libwebp Vulnerability Under Active Exploitation – Gets Maximum CVSS Score

September 27, 2023

Via: TheHackersNews

Google has assigned a new CVE identifier for a critical security flaw in the libwebp image library for rendering images in the WebP format that has come under active exploitation in the wild. Tracked as CVE-2023-5129, the issue has been […]


Cybersecurity, Security

LibreOffice 7.6.2 fixes a critical WebP vulnerability

September 26, 2023

Via: TechSpot

LibreOffice is a powerful and free office suite, a successor to OpenOffice, used by millions of people around the world. Its clean interface and feature-rich tools help you unleash your creativity and enhance your productivity. LibreOffice includes several applications that […]


Cybersecurity, Security

How to get a handle on shadow AI

September 5, 2023

Via: InfoWorld

CIOs and CISOs have long grappled with the challenge of shadow IT—technology that is being used within an enterprise but that is not officially sanctioned by the IT or security department. According to Gartner research, 41% of employees acquired, modified, […]


Cybersecurity, Security

Cybersecurity Agencies Warn Against IDOR Bugs Exploited for Data Breaches

July 28, 2023

Via: The Hacker News

Cybersecurity agencies in Australia and the U.S. have published a joint cybersecurity advisory warning against security flaws in web applications that could be exploited by malicious actors to orchestrate data breach incidents and steal confidential data. This includes a specific […]


Cybersecurity, Security

Critical Zero-Days in Atera Windows Installers Expose Users to Privilege Escalation Attacks

July 24, 2023

Via: The Hacker News

Zero-day vulnerabilities in Windows Installers for the Atera remote monitoring and management software could act as a springboard to launch privilege escalation attacks. The flaws, discovered by Mandiant on February 28, 2023, have been assigned the identifiers CVE-2023-26077 and CVE-2023-26078, […]