Google researcher discloses the details of an Intel CPU attack method named Downfall that may be remotely exploitable.
The post Downfall: New Intel CPU Attack Exposing Sensitive Information appeared first on SecurityWeek.
Google researcher discloses the details of an Intel CPU attack method named Downfall that may be remotely exploitable.
The post Downfall: New Intel CPU Attack Exposing Sensitive Information appeared first on SecurityWeek.
The cybersecurity industry heads to Las Vegas this week for Black Hat in a state of economic contraction, confusion and excitement. Can the promise of AI overcome the hype cycle to truly solve security problems?
The post Black Hat Preview: The Business of Cyber Takes Center Stage appeared first on SecurityWeek.
A sanctioned Russian missile maker appears to have been targeted by two important North Korean hacking groups.
The post North Korean Hackers Targeted Russian Missile Developer appeared first on SecurityWeek.
Five Eyes government agencies have published a list of the software vulnerabilities that were most frequently exploited in malicious attacks in 2022.
The post Five Eyes Agencies Call Attention to Most Frequently Exploited Vulnerabilities appeared first on SecurityWeek.
Threat actors have exploited a Salesforce email service zero-day vulnerability and abused Meta features in a sophisticated phishing campaign.
The post Salesforce Email Service Zero-Day Exploited in Phishing Campaign appeared first on SecurityWeek.
Microsoft says a Russian government-linked hacking group is using its Microsoft Teams chat app to phish for credentials at targeted organizations.
The post Microsoft Catches Russian Government Hackers Phishing with Teams Chat App appeared first on SecurityWeek.
A new power side-channel attack named Collide+Power can allow an attacker to obtain sensitive information and it works against nearly any modern CPU.
The post Nearly All Modern CPUs Leak Data to New Collide+Power Side-Channel Attack appeared first on SecurityWeek.
The number of ransomware attacks targeting industrial organizations and infrastructure has doubled since the second quarter of 2022, according to Dragos.
The post Ransomware Attacks on Industrial Organizations Doubled in Past Year: Report appeared first on SecurityWeek.
Ivanti EPMM customers have been warned of CVE-2023-35081, a second zero-day vulnerability that has been exploited in targeted attacks.
The post Second Ivanti EPMM Zero-Day Vulnerability Exploited in Targeted Attacks appeared first on SecurityWeek.
Researchers discovered two vulnerabilities in the Ubuntu OverlayFS module: CVE-2023-2640 and CVE-2023-32629 (together dubbed ‘GameOver(lay)’).
The post Two New Vulnerabilities Could affect 40% of Ubuntu Cloud Workloads appeared first on SecurityWeek.