CISA: Vulnerability in ​​Delta Electronics ICS Software Exploited in Attacks

A vulnerability affecting industrial automation software from Delta Electronics appears to have been exploited in attacks, and the US Cybersecurity and Infrastructure Security Agency (CISA) is urging organizations to take action as soon as possible.
re… Continue reading CISA: Vulnerability in ​​Delta Electronics ICS Software Exploited in Attacks

Leaked Docs Show Spyware Firm Offering iOS, Android Hacking Services for $8 Million

Leaked documents appear to show a little-known spyware company offering services that include Android and iOS device exploits for €8 million (roughly $8 million).
read more Continue reading Leaked Docs Show Spyware Firm Offering iOS, Android Hacking Services for $8 Million

Mozilla Patches High-Severity Vulnerabilities in Firefox, Thunderbird

Mozilla this week patched several high-severity vulnerabilities in its Firefox and Thunderbird products.
Firefox 104 — as well as Firefox ESR 91.13 and 102.2 — patches a high-severity address bar spoofing issue related to XSLT error handling. The flaw,… Continue reading Mozilla Patches High-Severity Vulnerabilities in Firefox, Thunderbird

New Air Gap-Jumping Attack Uses Ultrasonic Tones and Smartphone Gyroscope

A researcher from the Ben-Gurion University of the Negev in Israel has shown how a threat actor could stealthily exfiltrate data from air-gapped computers using ultrasonic tones and smartphone gyroscopes.
read more Continue reading New Air Gap-Jumping Attack Uses Ultrasonic Tones and Smartphone Gyroscope

Old, Inconspicuous Vulnerabilities Commonly Targeted in OT Scanning Activity

Data collected by IBM shows that old and inconspicuous vulnerabilities affecting industrial products are commonly targeted in scanning activity seen by organizations that use operational technology (OT). SecurityWeek has talked to several experts to fi… Continue reading Old, Inconspicuous Vulnerabilities Commonly Targeted in OT Scanning Activity

Ethernet LEDs Can Be Used to Exfiltrate Data From Air-Gapped Systems

A researcher from the Ben-Gurion University of the Negev in Israel has published a paper describing a method that can be used to silently exfiltrate data from air-gapped systems using the LEDs of various types of networked devices.
read more Continue reading Ethernet LEDs Can Be Used to Exfiltrate Data From Air-Gapped Systems

LockBit Ransomware Site Hit by DDoS Attack as Hackers Start Leaking Entrust Data

The leak website of the LockBit ransomware operation has been taken offline by a distributed denial-of-service (DDoS) attack that appears to have been launched in response to the cybercriminals publishing data stolen from security company Entrust.
read… Continue reading LockBit Ransomware Site Hit by DDoS Attack as Hackers Start Leaking Entrust Data

Security Firm Discloses CrowdStrike Issue After ‘Ridiculous Disclosure Process’

A security firm has disclosed the details of an issue affecting a CrowdStrike product after what it described as a ‘ridiculous vulnerability disclosure process’. CrowdStrike has provided some clarifications following the disclosure.
read more Continue reading Security Firm Discloses CrowdStrike Issue After ‘Ridiculous Disclosure Process’

Many Media Industry Vendors Slow to Patch Critical Vulnerabilities: Study

A cybersecurity analysis of hundreds of media industry vendors showed that many companies are slow to patch critical vulnerabilities, according to MDR and third-party risk management provider BlueVoyant.
read more Continue reading Many Media Industry Vendors Slow to Patch Critical Vulnerabilities: Study