Vulnerabilities Category - Security Boulevard https://securityboulevard.com/category/blogs/threats-breaches/vulnerabilities/ The Home of the Security Bloggers Network Mon, 24 Jul 2023 19:06:16 +0000 en-US hourly 1 https://wordpress.org/?v=6.2.2 https://securityboulevard.com/wp-content/uploads/2021/10/android-chrome-256x256-1-32x32.png Vulnerabilities Category - Security Boulevard https://securityboulevard.com/category/blogs/threats-breaches/vulnerabilities/ 32 32 133346385 Google Launches Red Team to Secure AI Systems Against Attacks https://securityboulevard.com/2023/07/google-launches-red-team-to-secure-ai-systems-against-attacks/ Mon, 24 Jul 2023 19:06:16 +0000 https://securityboulevard.com/?p=1982549 red team SEC data security privacy How to Bring DevOps and Security Teams Closer Together

Google is rolling out a red team charged with testing the security of AI systems by running simulated but realistic attacks to uncover vulnerabilities or other weaknesses that could be exploited by cybercriminals.

The post Google Launches Red Team to Secure AI Systems Against Attacks appeared first on Security Boulevard.

]]>
1982549
‘China’ Azure Breach: MUCH Worse Than Microsoft Said https://securityboulevard.com/2023/07/azure-breach-worse-richixbw/ Mon, 24 Jul 2023 17:03:58 +0000 https://securityboulevard.com/?p=1982521 Satya Nadella and President Xi Jinping

Storm-0558 Breaks: Satya and Pooh, sitting in a tree, K.I.S.S.I.N.G.

The post ‘China’ Azure Breach: MUCH Worse Than Microsoft Said appeared first on Security Boulevard.

]]>
1982521
GitHub Developers Targeted by North Korea’s Lazarus Group https://securityboulevard.com/2023/07/github-developers-targeted-by-north-koreas-lazarus-group/ Fri, 21 Jul 2023 19:51:33 +0000 https://securityboulevard.com/?p=1982351 GitHub satellite cyberattack Strontium cyberwarfare counter-drone The Legality of Waging War in Cyberspace

The Lazarus Group is behind a social engineering campaign that uses repository invitations and malicious npm packages to target developers on GitHub.

The post GitHub Developers Targeted by North Korea’s Lazarus Group appeared first on Security Boulevard.

]]>
1982351
Software Supply Chain Attackers Targeting Banks, Checkmarx Says https://securityboulevard.com/2023/07/software-supply-chain-attackers-targeting-banks-checkmarx-says/ Fri, 21 Jul 2023 15:46:14 +0000 https://securityboulevard.com/?p=1982335 supply chain SMB Cowbell Cyber cyberattack colonial ransomware insurance attacks access

Two banks earlier this year were the targets of open source supply chain attacks, the first of their kind in the industry.

The post Software Supply Chain Attackers Targeting Banks, Checkmarx Says appeared first on Security Boulevard.

]]>
1982335
R.I.P. Kevin Mitnick, 1963–2023 https://securityboulevard.com/2023/07/rip-kevin-mitnick-richixbw/ Fri, 21 Jul 2023 13:33:00 +0000 https://securityboulevard.com/?p=1982320 Kevin Mitnick

Kevin is Free: Hackers’ hacker dies, aged 59.

The post R.I.P. Kevin Mitnick, 1963–2023 appeared first on Security Boulevard.

]]>
1982320
Cleantech and Quantum Computing: Critical Infrastructure Cybersecurity https://securityboulevard.com/2023/07/cleantech-and-quantum-computing-critical-infrastructure-cybersecurity/ Fri, 21 Jul 2023 13:00:32 +0000 https://securityboulevard.com/?p=1981936 quantum data scraping

As cleantech becomes a bigger part of U.S. critical infrastructure, it faces a bigger risk from cyberattackers leveraging quantum attacks.

The post Cleantech and Quantum Computing: Critical Infrastructure Cybersecurity appeared first on Security Boulevard.

]]>
1981936
New P2P Worm Puts Windows and Linux Redis Servers in its Sights https://securityboulevard.com/2023/07/new-p2p-worm-puts-windows-and-linux-redis-servers-in-its-sights/ Thu, 20 Jul 2023 16:35:18 +0000 https://securityboulevard.com/?p=1982166 P2PInfect network security, phishing, ChatGPT, AI, identity, hacking, AI, Chat GPT, ChatGPT malware threat ransomware CNA REvil EtterSilent ransomware dark web

A new peer-to-peer (P2P) worm, P2PInfect, is spreading across instances of the Redis open source database software in the cloud.

The post New P2P Worm Puts Windows and Linux Redis Servers in its Sights appeared first on Security Boulevard.

]]>
1982166
FIN8 Group Using Modified Sardonic Malware for Deployment of BlackCat Ransomware https://securityboulevard.com/2023/07/fin8-group-using-modified-sardonic-malware-for-deployment-of-blackcat-ransomware/ https://securityboulevard.com/2023/07/fin8-group-using-modified-sardonic-malware-for-deployment-of-blackcat-ransomware/#respond Thu, 20 Jul 2023 14:37:38 +0000 https://blog.eclecticiq.com/fin8-group-using-modified-sardonic-malware-for-deployment-of-blackcat-ransomware tap 13 - 2023

FIN8 Group Using Modified Sardonic Malware for Deployment of BlackCat Ransomware     

According to the Symantec Threat Hunter Team, the financially motivated threat actor known as FIN8 has been observed using an updated version of a malware called Sardonic to deliver the BlackCat ransomware. The update on the Sardonic malware is an attempt on the part of the e-crime group to diversify its focus and maximize profits from infected entities. [1

The C++ based Sardonic backdoor has the ability to harvest system information and execute commands, and has a plugin system designed to load and execute additional malware payloads delivered as DLLs. Unlike the previous variant of Sardonic, which was designed in C++, the latest iteration packs in significant alterations, with most of the source code rewritten in C and modified so as to deliberately avoid similarities. 

In the latest incident analyzed by Symantec, Sardonic malware is embedded into a PowerShell script that was deployed into the targeted system after obtaining initial access. The script is designed to launch a .NET loader, which then decrypts and executes an injector module to ultimately run the implant. Successful infection leads to the deployment of BlackCat ransomware.    

The post FIN8 Group Using Modified Sardonic Malware for Deployment of BlackCat Ransomware appeared first on Security Boulevard.

]]>
https://securityboulevard.com/2023/07/fin8-group-using-modified-sardonic-malware-for-deployment-of-blackcat-ransomware/feed/ 0 1982184
Why Generative AI is a Threat to API Security https://securityboulevard.com/2023/07/why-generative-ai-is-a-threat-to-api-security/ Thu, 20 Jul 2023 12:00:28 +0000 https://securityboulevard.com/?p=1980401 API Skyhawk Security modeling threat CosmicStrand insider threats Threat Modeling - Secure Coding - Cybersecurity - Security

Generative AI can be used to amplify cybercriminals' nefarious deeds against web applications, especially those that rely heavily on APIs.

The post Why Generative AI is a Threat to API Security appeared first on Security Boulevard.

]]>
1980401
Attacker ID’ed After Infecting Own Computer With Malware https://securityboulevard.com/2023/07/attacker-ided-after-infecting-own-computer-with-malware/ Wed, 19 Jul 2023 20:22:51 +0000 https://securityboulevard.com/?p=1982053 attack, hackers, black hat attacker celebrity Trickbot Emotet Black Shadow McAfee REvil ransomware Kaseya

A threat actor that goes by the name of “La_Citrix” inadvertently infected his own computer. Cyberthreat research firm sent his information on to law enforcement.

The post Attacker ID’ed After Infecting Own Computer With Malware appeared first on Security Boulevard.

]]>
1982053