Threat hunters at Symantec are calling global attention to a new, highly sophisticated piece of malware being used by a Chinese threat actor to burrow into — and hijack data from — government and critical infrastructure targets.
CISA, FBI Issue Warnings on WhisperGate, HermeticWiper Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) released indicators of compromise to help threat hunters look for signs of WhisperGate and HermeticWiper, two destructive malware files seen in recent attacks against organizations in Ukraine.
CISA Urges Organizations to Patch Actively Exploited Zimbra XSS Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday announced that it has expanded its Known Exploited Vulnerabilities Catalog with a zero-day recently identified in the Zimbra email platform.
GE SCADA Product Vulnerabilities Show Importance of Secure Configurations
GE Digital has released patches and mitigations for two high-severity vulnerabilities affecting its Proficy CIMPLICITY HMI/SCADA software, which is used by plants around the world to monitor and control operations.
Nigerian Admits in US Court to Hacking Payroll Company
A Nigerian national pleaded guilty in a U.S. court for his role in a scheme to hack into thousands of user accounts maintained by a payroll processing company, to steal payroll deposits.
Cloudflare Plans to Acquire Email Security Startup Area 1
Web infrastructure and DDoS mitigation firm Cloudflare has announced plans to purchase Area 1, a Kleiner-Perkins-backed startup doing business in the competitive email security space.
NSA Informs Cisco of Vulnerability Exposing Nexus Switches to DoS Attacks
Cisco this week announced the availability of patches for four vulnerabilities in its FXOS and NX-OS network operating systems, including one denial of service bug that was reported by the NSA.
New ‘Cyclops Blink’ Malware Linked to Russian State Hackers Targets Firewalls
Salesforce Paid Out $12.2 Million in Bug Bounty Rewards to Date
Customer relationship management services provider Salesforce says it has handed out more than $12.2 million in payouts to the ethical hackers who reported vulnerabilities as part of its bug bounty program.
Astrix Security Nabs $15M to Tackle Attack Surface Sprawl
Israeli startup Astrix Security has banked $15 million in early stage venture capital investment to build technology to help organizations secure third-party app integrations.
The Tel Aviv-based Astrix said the seed round was led by Bessemer Venture Partners and F2 Capital. Venrock and a list of angel investors also participated.











