Aggregator
Microsoft Warns of New StilachiRAT Stealing Remote Desktop Protocol Sessions Data
Microsoft has issued an urgent security advisory regarding a newly discovered malware strain called StilachiRAT, which specifically targets and exfiltrates data from Remote Desktop Protocol (RDP) sessions. The sophisticated malware has been observed in targeted attacks against financial institutions, government agencies, and critical infrastructure organizations across multiple regions. Security experts warn that this new threat […]
The post Microsoft Warns of New StilachiRAT Stealing Remote Desktop Protocol Sessions Data appeared first on Cyber Security News.
Google Agrees to Acquire Wiz in $30B Deal
Google today revealed it has acquired Wiz, a provider of a cloud-native application protection platform (CNAPP) for $32 billion cash after initially being rebuffed last year.
The post Google Agrees to Acquire Wiz in $30B Deal appeared first on Security Boulevard.
331 Malicious Apps with 60 Million Downloads on Google Play Bypass Android 13 Security
Security researchers from Bitdefender have uncovered a large-scale ad fraud campaign involving 331 malicious apps on the Google Play Store. These apps, which have accumulated over 60 million downloads, exploit vulnerabilities in Android 13 to bypass security restrictions and carry out phishing attacks, ad fraud, and credential theft. The campaign demonstrates an alarming level of […]
The post 331 Malicious Apps with 60 Million Downloads on Google Play Bypass Android 13 Security appeared first on Cyber Security News.
Whistic announces next generation of Assessment Copilot
Whistic announced the next generation of its Assessment Copilot, a third-party risk management (TPRM) solution that integrates AI into the vendor assessment process for a fully automated workflow. With this release, Whistic builds upon the initial release of Assessment Copilot and the Whistic AI suite of capabilities launched in May 2024. Whistic delivers a modern, AI-first approach that improves the efficiency and pace of TPRM assessments, reduces costs, achieves more in-depth insights, and enhances risk … More →
The post Whistic announces next generation of Assessment Copilot appeared first on Help Net Security.
Unpatched Windows Zero-Day Flaw Exploited by 11 State-Sponsored Threat Groups Since 2017
周五是否应该成为新的周六?
CVE-2024-5744 | WP-FeedStats wp-eMember Plugin up to 10.6.6 on WordPress Attribute $_SERVER['REQUEST_URI'] cross site scripting
CVE-2024-5280 | WP-FeedStats wp-affiliate-platform Plugin up to 6.5.0 on WordPress cross-site request forgery
CVE-2024-5284 | WP-FeedStats wp-affiliate-platform Plugin up to 6.5.0 on WordPress cross-site request forgery
CVE-2024-5034 | SULly Plugin up to 4.3.0 on WordPress cross-site request forgery
CVE-2024-5076 | WP-FeedStats wp-eMember Plugin up to 10.6.5 on WordPress cross-site request forgery
CVE-2024-5033 | SULly Plugin up to 4.3.0 on WordPress cross-site request forgery
CVE-2024-39735 | IBM Datacap Navigator 9.1.5/9.1.6/9.1.7/9.1.8/9.1.9 Web UI cross site scripting (XFDB-296002)
CVE-2024-39728 | IBM Datacap Navigator 9.1.5/9.1.6/9.1.7/9.1.8/9.1.9 Web UI cross site scripting (XFDB-295967)
CVE-2024-6345 | pypa setuptools up to 69.1.1 package_index code injection (Nessus ID 207922)
How AI and automation are reshaping security leadership
The contemporary SOC is transforming as it starts to realize the benefits of GenAI and utilize the manifestations of autonomous agentic AI, according to Tines. Additionally, the promise of security automation is coming to fruition. In theory and practice, security automation should truncate the time SOCs spend investigating and mitigating alerts. However, the tried and true saying about technology still applies: Cybersecurity still relies on the combination of people, processes, and technology. For some time, … More →
The post How AI and automation are reshaping security leadership appeared first on Help Net Security.