Progress Software Patches Critical Pre-Auth Flaws in WS_FTP Server Product 

Progress Software ships patches for critical-severity flaws in its WS_FTP file transfer software and warns that a pre-authenticated attacker could wreak havoc on the underlying operating system.
The post Progress Software Patches Critical Pre-Auth Flaw… Continue reading Progress Software Patches Critical Pre-Auth Flaws in WS_FTP Server Product 

Chinese Gov Hackers Caught Hiding in Cisco Router Firmware

The NSA and FBI warn that a Chinese state-sponsored APT called BlackTech is hacking into network edge devices and using firmware implants to silently hop around the corporate networks of U.S. and Japanese companies.
The post Chinese Gov Hackers Caught … Continue reading Chinese Gov Hackers Caught Hiding in Cisco Router Firmware

CISA Unveils New HBOM Framework to Track Hardware Components

CISA unveils a new Hardware Bill of Materials (HBOM) framework for buyers and sellers to communicate about components in physical products.
The post CISA Unveils New HBOM Framework to Track Hardware Components appeared first on SecurityWeek.
Continue reading CISA Unveils New HBOM Framework to Track Hardware Components

CrowdStrike to Acquire Application Intelligence Startup Bionic

The cash-and-stock transaction provides capabilities for CrowdStrike to beef up its enterprise cloud security portfolio.
The post CrowdStrike to Acquire Application Intelligence Startup Bionic appeared first on SecurityWeek.
Continue reading CrowdStrike to Acquire Application Intelligence Startup Bionic

HiddenLayer Raises Hefty $50M Round for AI Security Tech

Texas startup attracts major investor interest to build an MLMDR (machine learning detection and response) technology.
The post HiddenLayer Raises Hefty $50M Round for AI Security Tech appeared first on SecurityWeek.
Continue reading HiddenLayer Raises Hefty $50M Round for AI Security Tech

Microsoft AI Researchers Expose 38TB of Data, Including Keys, Passwords and Internal Messages

Exposed data includes backup of employees workstations, secrets, private keys, passwords, and over 30,000 internal Microsoft Teams messages.
The post Microsoft AI Researchers Expose 38TB of Data, Including Keys, Passwords and Internal Messages appeared… Continue reading Microsoft AI Researchers Expose 38TB of Data, Including Keys, Passwords and Internal Messages

Extradited Russian Hacker Behind ‘NLBrute’ Malware Pleads Guilty

Russian hacker Dariy Pankov has pleaded guilty to computer fraud and now faces a maximum penalty of five years in federal prison.
The post Extradited Russian Hacker Behind ‘NLBrute’ Malware Pleads Guilty appeared first on SecurityWeek.
Continue reading Extradited Russian Hacker Behind ‘NLBrute’ Malware Pleads Guilty

Caesars Confirms Ransomware Hack, Stolen Loyalty Program Database

The hijacked data includes driver’s license numbers and/or social security numbers from a Caesars Entertainment loyalty database.
The post Caesars Confirms Ransomware Hack, Stolen Loyalty Program Database appeared first on SecurityWeek.
Continue reading Caesars Confirms Ransomware Hack, Stolen Loyalty Program Database