Okta Closes Lapsus$ Breach Probe, Adds New Security Controls

Identity and access management tech firm Okta says it has concluded an investigation into the embarrassing Lapsus$ hacking incident and has severed ties with a third-party company at the center of the breach.
read more

Continue reading Okta Closes Lapsus$ Breach Probe, Adds New Security Controls

SeeMetrics Raises $6M for Portfolio Management Platform

An Israeli startup has raised early-stage funding to build technology to help cybersecurity teams measure, track and simplify security program operations.
read more

Continue reading SeeMetrics Raises $6M for Portfolio Management Platform

Firmware Flaws Allow Disabling Secure Boot on Lenovo Laptops

Computer maker Lenovo has started pushing security patches to address three vulnerabilities impacting the UEFI firmware of more than 110 laptop models.
read more

Continue reading Firmware Flaws Allow Disabling Secure Boot on Lenovo Laptops

Citizen Lab Documents Israeli Surveillance Spyware Infections in Spain

Security researchers have found fresh evidence linking a pair of mercenary Israeli hacking companies to mobile malware attacks on members of Catalan civil society.
read more

Continue reading Citizen Lab Documents Israeli Surveillance Spyware Infections in Spain

Webex Monitors Microphone Even When Muted, Researchers Say

Cisco’s enterprise-facing Webex video conferencing and messaging utility monitors the microphone at all times, even when the user’s microphone is muted in the software, according to warning from a group of academic researchers.
read more

Continue reading Webex Monitors Microphone Even When Muted, Researchers Say

FBI Warns of ‘Reverse’ Instant Payments Phishing Schemes

The Federal Bureau of Investigation (FBI) has issued an alert on a new phishing scheme aimed at tricking victims into making money transfers to accounts controlled by cybercriminals.
read more

Continue reading FBI Warns of ‘Reverse’ Instant Payments Phishing Schemes

GitHub Warns of Private Repositories Downloaded Using Stolen OAuth Tokens

GitHub has sounded the alarm on a cyberattack that resulted in the private repositories of dozens of organizations being downloaded by an unauthorized party abusing stolen OAuth user tokens.
The incident was identified on April 12, when the code hostin… Continue reading GitHub Warns of Private Repositories Downloaded Using Stolen OAuth Tokens

North Korea APT Lazarus Targeting Chemical Sector

Threat hunters at Symantec have spotted signs that North Korea’s Lazarus APT group is targeting companies in the chemical sector in an ongoing cyberespionage campaign that includes fake job lures and clever social engineering.
read more

Continue reading North Korea APT Lazarus Targeting Chemical Sector