Apple discloses actively exploited zero-day affecting iOS, iPadOS and macOS

The defect, which affects the company’s most popular devices, has been exploited in an “extremely sophisticated attack against specific targeted individuals,” Apple said.

The post Apple discloses actively exploited zero-day affecting iOS, iPadOS and macOS appeared first on CyberScoop.

Continue reading Apple discloses actively exploited zero-day affecting iOS, iPadOS and macOS

CrowdStrike warns of uptick in Silk Typhoon attacks this summer

The China-affiliated espionage group, which CrowdStrike tracks as Murky Panda, has been linked to more than a dozen incident response cases since late spring.

The post CrowdStrike warns of uptick in Silk Typhoon attacks this summer appeared first on CyberScoop.

Continue reading CrowdStrike warns of uptick in Silk Typhoon attacks this summer

Officials gain control of Rapper Bot DDoS botnet, charge lead developer and administrator

The DDoS botnet was among the powerful on record, allegedly exceeding six terrabits per second during its largest attack, authorities said. Victims are spread across 80 countries.

The post Officials gain control of Rapper Bot DDoS botnet, charge lead developer and administrator appeared first on CyberScoop.

Continue reading Officials gain control of Rapper Bot DDoS botnet, charge lead developer and administrator

Cisco discloses maximum-severity defect in firewall software

The vulnerability, which Cisco said it discovered during internal security testing, could allow unauthenticated attackers to execute high-privilege commands.

The post Cisco discloses maximum-severity defect in firewall software appeared first on CyberScoop.

Continue reading Cisco discloses maximum-severity defect in firewall software

US widens sanctions on Russian crypto exchange Garantex, its successor and affiliate firms

The State Department also announced financial rewards totaling up to $6 million for information leading to the arrest or conviction of Garantex’s leaders.

The post US widens sanctions on Russian crypto exchange Garantex, its successor and affiliate firms appeared first on CyberScoop.

Continue reading US widens sanctions on Russian crypto exchange Garantex, its successor and affiliate firms

Fortinet SIEM issue coincides with spike in brute-force traffic against company’s SSL VPNs

Researchers aren’t aware of any active exploitation of the software, but the issue is being dealt with simultaneously as attackers are trying to brute force the company’s security appliances.

The post Fortinet SIEM issue coincides with spike in brute-force traffic against company’s SSL VPNs appeared first on CyberScoop.

Continue reading Fortinet SIEM issue coincides with spike in brute-force traffic against company’s SSL VPNs

Microsoft Patch Tuesday follows SharePoint attacks, Exchange server warnings

Despite serious alarm raised by officials, organizations have not applied the patch for Microsoft Exchange servers en masse.

The post Microsoft Patch Tuesday follows SharePoint attacks, Exchange server warnings appeared first on CyberScoop.

Continue reading Microsoft Patch Tuesday follows SharePoint attacks, Exchange server warnings

SonicWall pins firewall attack spree on year-old vulnerability

The vendor ruled out a zero-day vulnerability as the root cause, disputing initial assessments from third-party researchers. Fewer than 40 organizations have been impacted since mid-July.

The post SonicWall pins firewall attack spree on year-old vulnerability appeared first on CyberScoop.

Continue reading SonicWall pins firewall attack spree on year-old vulnerability

DARPA’s AI Cyber Challenge reveals winning models for automated vulnerability discovery and patching

The initiative seeks to patch vulnerabilities in open-source code before they are exploited by would-be attackers. Now comes the hard part — putting the systems to the test in the real world.

The post DARPA’s AI Cyber Challenge reveals winning models for automated vulnerability discovery and patching appeared first on CyberScoop.

Continue reading DARPA’s AI Cyber Challenge reveals winning models for automated vulnerability discovery and patching

Microsoft: An organization without a response plan will be hit harder by a security incident

Security leaders shared advice gleaned from customer engagements, and reinforced the importance of planning and following fundamentals for defense.

The post Microsoft: An organization without a response plan will be hit harder by a security incident appeared first on CyberScoop.

Continue reading Microsoft: An organization without a response plan will be hit harder by a security incident