Ivanti Zero-Day Exploited by APT Since at Least April in Norwegian Government Attack

The recently patched Ivanti EPMM zero-day CVE-2023-35078 has been exploited to hack the Norwegian government since at least April 2023.
The post Ivanti Zero-Day Exploited by APT Since at Least April in Norwegian Government Attack appeared first on Se… Continue reading Ivanti Zero-Day Exploited by APT Since at Least April in Norwegian Government Attack

Nearly All Modern CPUs Leak Data to New Collide+Power Side-Channel Attack

A new power side-channel attack named Collide+Power can allow an attacker to obtain sensitive information and it works against nearly any modern CPU.
The post Nearly All Modern CPUs Leak Data to New Collide+Power Side-Channel Attack appeared first on S… Continue reading Nearly All Modern CPUs Leak Data to New Collide+Power Side-Channel Attack

Ransomware Attacks on Industrial Organizations Doubled in Past Year: Report

The number of ransomware attacks targeting industrial organizations and infrastructure has doubled since the second quarter of 2022, according to Dragos.
The post Ransomware Attacks on Industrial Organizations Doubled in Past Year: Report appeared firs… Continue reading Ransomware Attacks on Industrial Organizations Doubled in Past Year: Report

Second Ivanti EPMM Zero-Day Vulnerability Exploited in Targeted Attacks

Ivanti EPMM customers have been warned of CVE-2023-35081, a second zero-day vulnerability that has been exploited in targeted attacks.
The post Second Ivanti EPMM Zero-Day Vulnerability Exploited in Targeted Attacks appeared first on SecurityWeek.
Continue reading Second Ivanti EPMM Zero-Day Vulnerability Exploited in Targeted Attacks

Industry Reactions to New SEC Cyber Incident Disclosure Rules: Feedback Friday

Several industry professionals comment on the SEC’s new cybersecurity incident disclosure rules and their implications.
The post Industry Reactions to New SEC Cyber Incident Disclosure Rules: Feedback Friday appeared first on SecurityWeek.
Continue reading Industry Reactions to New SEC Cyber Incident Disclosure Rules: Feedback Friday