CSO Security News

Exchange Autodiscovery feature can cause Outlook to leak credentials.

Views expressed in this cybersecurity-intelligence update are those of the reporters and correspondents.

Accessed on 26 September 2021, 1301 UTC.

Source:

https://www.csoonline.com/news/

Please scroll down to read your selections.

News

cso security hack breach water leak gettyimages 466029458 by firmafotografen 2400x1600px
Ransomware  >  An encrypted system, held ransom with lock + chain, displays a dollar sign.

USA / United States of America stars + stripes and binary code superimposed over The White House

Software cybersecurity labels face practical, cost challenges

The federal government wants consumer software to have cybersecurity labels; experts question the feasibility of the mandate.

locked data / bitcoins

Biden sanctions Suex cryptocurrency exchange to stifle ransomware payments

In the wake of significant ransomware attacks, President Biden has sanctioned cryptocurrency exchange Suex in a clear attempt to prevent ransomware payments.

security threats and vulnerabilities

APT actors exploit flaw in ManageEngine single sign-on solution

US government agencies urge immediate action to look for indicators of compromise and, if found, take recommended steps to mitigate.

danger lurking in mobile binary code

How APTs become long-term lurkers: Tools and techniques of a targeted attack

A new McAfee report details the tools and techniques an APT group used to go undetected on a client network for over a year.

CIO | Middle East  >  UAE / United Arab Emirates  >  Flag

3 former US intel officers turned cyber mercenaries plead guilty: An insider threat case study

Three U.S. nationals, working as cyber mercenaries on behalf of the United Arab Emirates, have pleaded guilty to exploiting U.S. entities using U.S.-controlled technologies.

Unitd States cybersecurity   >   U.S. flag with a digital network of locks instead of stars

Federal agencies face new zero-trust cybersecurity requirements

The OMB and CISA issue guidance to move all federal agencies to a shared zero-trust maturity model for FY22-24. The catch: No new funding.

A magnifying lens exposes an exploit amid binary code.

Critical flaw in Atlassian Confluence actively exploited

The remote code execution vulnerability was recently patched for affected versions of Atlassian Confluence Server and Data Center; users are advised to apply the patch or upgrade.

a hooded figure targets a coding vulnerability

Cosmos DB users advised to regenerate their keys following serious vulnerability

The Azure vulnerability, which affects only those using the Jupyter Notebook feature, gives attackers access to data in databases.

radar grid / computer circuits / intrusion detection / scanning

LockFile ransomware uses intermittent encryption to evade detection

This newly discovered ransomware works fast, has multiple ways to avoid detection, and preys on Windows systems with known vulnerabilities.

A laptop displays binary code and the flag of China.

China’s PIPL privacy law imposes new data handling requirements

The Personal Information Protection Law will force global companies doing business in China to be more careful with cross-border flow of personal information.

joe biden cyberceomeeting public domain wh

Tech giants pledge at least $30 billion to improve cybersecurity following White House meeting

Technology, financial, and education leaders commit to a wide range of initiatives to enhance the nation’s cybersecurity posture in collaboration with the Biden Administration.

Conceptual image of a network of executives / silhouettes of executives in motion.

New US CISO appointments, August 2021

Keep up with news of CSO, CISO, and other senior security executive appointments.

blind spot side view mirror car vehicle

Security blind spots persist as companies cross-breed security with devops

As devops matures into devsecops, cultural obstacles continue to exert drag.

ransomware breach hackers dark web

OnePercent ransomware group hits companies via IceID banking Trojan

This new, aggressive ransomware group also uses Cobalt Strike to move laterally across the network.

Ransomware  >  A masked criminal ransoms data for payment.

4 most dangerous emerging ransomware threat groups to watch

New research identifies four emerging ransomware groups currently affecting organizations and that show signs of becoming bigger threats in the future.

network security concept

Amazon Sidewalk highlights network security visibility risks consumer services pose

Research warns consumer-grade services can undermine risk assessment of corporate networks amid remote working as Houdini malware spoofs devices to exfiltrate data.

iot internet of things chains security by mf3d getty

IoT devices have serious security deficiencies due to bad random number generation

It’s not the IoT vendors’ fault. Lack of a cryptographically secure pseudo-random number generator subsystem for the internet of things devices will be vulnerable.

Security system alert, warning of a cyberattack.

Wave of native IIS malware hits Windows servers

IIS malware presents diverse, persistent, and growing threats from old and new threat actors.

LOAD MORE

For the latest cybersecurity, cybercrime, cyberwar, and information security news, please check the blog sidebar, links, and twitter posts.  Thanks for joining us today.

Russ Roberts

https://cyber-security-intelligence.org.

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Google photo

You are commenting using your Google account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s