Fortinet SIEM issue coincides with spike in brute-force traffic against company’s SSL VPNs

Researchers aren’t aware of any active exploitation of the software, but the issue is being dealt with simultaneously as attackers are trying to brute force the company’s security appliances.

The post Fortinet SIEM issue coincides with spike in brute-force traffic against company’s SSL VPNs appeared first on CyberScoop.

Continue reading Fortinet SIEM issue coincides with spike in brute-force traffic against company’s SSL VPNs

Microsoft Patch Tuesday follows SharePoint attacks, Exchange server warnings

Despite serious alarm raised by officials, organizations have not applied the patch for Microsoft Exchange servers en masse.

The post Microsoft Patch Tuesday follows SharePoint attacks, Exchange server warnings appeared first on CyberScoop.

Continue reading Microsoft Patch Tuesday follows SharePoint attacks, Exchange server warnings

SonicWall pins firewall attack spree on year-old vulnerability

The vendor ruled out a zero-day vulnerability as the root cause, disputing initial assessments from third-party researchers. Fewer than 40 organizations have been impacted since mid-July.

The post SonicWall pins firewall attack spree on year-old vulnerability appeared first on CyberScoop.

Continue reading SonicWall pins firewall attack spree on year-old vulnerability

DARPA’s AI Cyber Challenge reveals winning models for automated vulnerability discovery and patching

The initiative seeks to patch vulnerabilities in open-source code before they are exploited by would-be attackers. Now comes the hard part — putting the systems to the test in the real world.

The post DARPA’s AI Cyber Challenge reveals winning models for automated vulnerability discovery and patching appeared first on CyberScoop.

Continue reading DARPA’s AI Cyber Challenge reveals winning models for automated vulnerability discovery and patching

Microsoft: An organization without a response plan will be hit harder by a security incident

Security leaders shared advice gleaned from customer engagements, and reinforced the importance of planning and following fundamentals for defense.

The post Microsoft: An organization without a response plan will be hit harder by a security incident appeared first on CyberScoop.

Continue reading Microsoft: An organization without a response plan will be hit harder by a security incident

BlackSuit, Royal ransomware group hit over 450 US victims before last month’s takedown

The Department of Homeland Security said the Russian cybercrime collective received at least $370 million in ransom payments, based on current cryptocurrency valuations.

The post BlackSuit, Royal ransomware group hit over 450 US victims before last month’s takedown appeared first on CyberScoop.

Continue reading BlackSuit, Royal ransomware group hit over 450 US victims before last month’s takedown

CISA, Microsoft warn organizations of high-severity Microsoft Exchange vulnerability

The public disclosure and advisories came late Wednesday during Black Hat, but Microsoft said the timing was coordinated.

The post CISA, Microsoft warn organizations of high-severity Microsoft Exchange vulnerability appeared first on CyberScoop.

Continue reading CISA, Microsoft warn organizations of high-severity Microsoft Exchange vulnerability

Nigerian accused of hacking tax preparation businesses extradited to US

Prosecutors accuse Chukwuemeka Victor Amachukwu, who was arrested in France, of multiple fraud schemes, including tax refund fraud and identity theft.

The post Nigerian accused of hacking tax preparation businesses extradited to US appeared first on CyberScoop.

Continue reading Nigerian accused of hacking tax preparation businesses extradited to US

SonicWall firewalls hit by active mass exploitation of suspected zero-day

About 20 organizations have been impacted and the pace of attacks is rising. Threat researchers and SonicWall are scrambling to determine the root cause.

The post SonicWall firewalls hit by active mass exploitation of suspected zero-day appeared first on CyberScoop.

Continue reading SonicWall firewalls hit by active mass exploitation of suspected zero-day

Google addresses six vulnerabilities in August’s Android security update

Android partners and customers have experienced a temporary respite from double-digit vulnerabilities this summer. Google issued no security patches in its update last month.

The post Google addresses six vulnerabilities in August’s Android security update appeared first on CyberScoop.

Continue reading Google addresses six vulnerabilities in August’s Android security update