News
How CISOs can manage sovereign-cloud security risks
15+ min ago (604+ words) Selecting and adopting cloud services from non-U. S. regional providers requires solid cyber risk and security assessment. As geopolitical tensions rise, organizations face new challenges for protecting their data in the cloud: shifting regulations and increased cyber risk. That means, in…...
Iranian government, not hacktivist group, breached LA Metro system, security firm says
1+ day, 23+ hour ago (205+ words) A report by Israel-based Gambit Security dismisses the hackers" claims of being patriotic but unaffiliated activists. The U. S. -Israeli war against Iran has emboldened Tehran"s hackers to pursue cyberattacks against critical infrastructure in the U. S. and other Western countries, leading to…...
FBI warns about Phaa S platform used to access Microsoft 365 environments
2+ day, 19+ min ago (504+ words) The FBI is warning about a phishing-as-a-service platform, called Kali365, that allows hackers to access Microsoft 365 tokens and bypass multifactor authentication without a user's credentials." The Kali365 platform subscription lets hackers access OAuth tokens and gain persistent access to the M365 environments of…...
Iran-linked hackers target key US, allied sectors with sophisticated spear-phishing messages
6+ day, 17+ min ago (432+ words) Companies, particularly those in the affected industries, should harden their defenses against impersonation schemes, Palo Alto Networks said. Iranian government-backed hackers are using spear-phishing attacks and remote access Trojans (RATs) to spy on "high-value sectors" in the U. S. and the Middle…...
New York regulator calls for additional cyber mitigation amid heightened threat environment
6+ day, 54+ min ago (396+ words) The guidance from the state Department of Financial Services arises from concerns about frontier AI and threats linked to the Iran war and other geopolitical risks. The New York State Department of Financial Services (DFS) sent a letter on Thursday…...
CISA asks cybersecurity community to alert it to vulnerability exploitation
1+ week, 18+ min ago (337+ words) The agency wants to ensure that its public catalog of actively exploited flaws is as comprehensive as possible. CISA on Thursday published a form that technology vendors, independent researchers and anyone else can use to warn CISA that hackers are…...
Grafana Labs links Git Hub environment breach to Tan Stack npm supply chain attack
1+ week, 28+ min ago (325+ words) The company behind the widely used observability platform refused an extortion demand and has since taken steps to harden its security. Grafana Labs on Tuesday said the breach of its Git Hub environment earlier this month originated from the Tan…...
Compromised coding tool helped hackers breach thousands of Git Hub repositories | Cybersecurity Dive
1+ week, 1+ day ago (312+ words) The attack is the latest example of hackers" intense focus on open-source packages. Hackers stole data from thousands of Git Hub repositories, the code-hosting giant said on Tuesday. "While we currently have no evidence of impact to customer information stored…...
Telecom sector launches its own private ISAC
1+ week, 2+ day ago (1041+ words) Federal government involvement in an existing group chilled some cybersecurity discussions among major telecom providers. The new group is intended to alleviate those anxieties. Major U. S. telecommunications companies launched a new information sharing group on Tuesday in a bid to redouble…...
Patch bypass allows hackers to exploit prior flaw in Sonic Wall SSL-VPN
1+ week, 2+ day ago (365+ words) Researchers said a wave of attacks began in February targeting firewalls that appeared to be protected. A threat group has successfully been exploiting a two-year-old vulnerability in Sonic Wall SSL-VPN appliances since February, despite the flaw being patched, according to…...