Netwrix Acquires Remediant for PAM Technology

Data security software vendor Netwrix has acquired Remediant, an early-stage startup working on technology in the PAM (privileged access management) category.
Financial terms of the acquisition were not disclosed. 
read more Continue reading Netwrix Acquires Remediant for PAM Technology

Russian APT Gamaredon Changes Tactics in Attacks Targeting Ukraine

Russia-linked Gamaredon, a hacking group known for providing services to other advanced persistent threat (APT) actors, is one of the most intrusive, continuously active APTs targeting Ukraine, Palo Alto Networks’ Unit 42 warns.
read more Continue reading Russian APT Gamaredon Changes Tactics in Attacks Targeting Ukraine

Investors Bet $31 Million on Sphere for Identity Hygiene Tech

Venture capital investors have invested another $31 million into Sphere Technology Solutions, a New Jersey startup building technology to help defenders manage identities and access to sensitive data.
read more Continue reading Investors Bet $31 Million on Sphere for Identity Hygiene Tech

Microsoft Warns of New Zero-Day; No Fix Yet For Exploited Exchange Server Flaws

Microsoft on Tuesday released software fixes to address more than 90 security defects affecting products in the Windows ecosystem and warned that one of the vulnerabilities was already being exploited as zero-day in the wild.
read more Continue reading Microsoft Warns of New Zero-Day; No Fix Yet For Exploited Exchange Server Flaws

Push Security Banks $4 Million Seed Funding

Push Security, a British startup building technology to help defenders manage cloud software sprawl and shadow IT, has banked $4 million in early-stage venture capital funding.
read more Continue reading Push Security Banks $4 Million Seed Funding

Drupal Patches ‘High-Risk’ Third-Party Library Flaws

The Drupal security team has released a “moderately critical” advisory to call attention to serious vulnerabilities in a third-party library and warned that hackers can exploit the bugs to remotely hijack Drupal-powered websites.
read more

Continue reading Drupal Patches ‘High-Risk’ Third-Party Library Flaws

Microsoft Finds Major Security Flaws in Pre-Installed Android Apps

Bug hunters at Microsoft are calling attention to several high-severity vulnerabilities in a mobile framework used in pre-installed Android System apps, warning that exploitation could have allowed the implantation of a persistent backdoor on Android d… Continue reading Microsoft Finds Major Security Flaws in Pre-Installed Android Apps

Google Sees More APTs Using Ukraine War-Related Themes

Researchers at Google’s Threat Analysis Group (TAG) say the number of advanced threat actors using Ukraine war-related themes in cyberattacks went up in April with a surge in malware attacks targeting critical infrastructure.
read more

Continue reading Google Sees More APTs Using Ukraine War-Related Themes

Cyberespionage Group Targeting M&A, Corporate Transactions Personnel

Security researchers at Mandiant are documenting the discovery of a new hacking group focused on cyberespionage targeting employees responsible for corporate development, large corporate transactions, and mergers and acquisitions.
read more

Continue reading Cyberespionage Group Targeting M&A, Corporate Transactions Personnel

Firmware Flaws Allow Disabling Secure Boot on Lenovo Laptops

Computer maker Lenovo has started pushing security patches to address three vulnerabilities impacting the UEFI firmware of more than 110 laptop models.
read more

Continue reading Firmware Flaws Allow Disabling Secure Boot on Lenovo Laptops