Wiz has detailed SeleniumGreed, a campaign in which threat actors target exposed Selenium Grid instances for cryptomining.
The post Selenium Grid Instances Exploited for Cryptomining appeared first on SecurityWeek.
Wiz has detailed SeleniumGreed, a campaign in which threat actors target exposed Selenium Grid instances for cryptomining.
The post Selenium Grid Instances Exploited for Cryptomining appeared first on SecurityWeek.
The vulnerability, tagged as CVE-2024-41110 with a CVSS severity score of 10/10, was originally found and fixed in 2018.
The post Docker Patches Critical AuthZ Plugin Bypass Vulnerability Dating Back to 2018 appeared first on SecurityWeek.
Zest Security emerged from stealth with $5 million funding and an AI-powered platform that resolves the root source of risk in the cloud.
The post Zest Security Aims to Resolve, Not Just Mitigate Cloud Risks appeared first on SecurityWeek.
The new financing brings the total raised by Dazz to $110 million as investors double down on bets in the cloud security remediation space.
The post Dazz Scores Hefty $50M Investment for AI-Powered Risk Remediation Tech appeared first on SecurityWeek.
SAP patches AI Core vulnerabilities allowing attackers to access customer data and take over the service.
The post SAP AI Core Vulnerabilities Allowed Service Takeover, Customer Data Access appeared first on SecurityWeek.
Join us as we explore the latest trends in the world of SaaS security, cyberattacks against cloud infrastructure, data security posture management (DSPM), and the hype and promise of AI and LLM technologies.
The post Virtual Event Today: Cloud & Data Security Summit | 2024 appeared first on SecurityWeek.
Google’s parent company Alphabet is reportedly in advanced talks to acquire the hotshot Israeli data security startup.
The post Google in Advanced Talks to Buy Wiz for $23B: WSJ Report appeared first on SecurityWeek.
Citrix rolls out patches for multiple security vulnerabilities, including critical and high-severity issues in the NetScaler product line.
The post Citrix Patches Critical NetScaler Console Vulnerability appeared first on SecurityWeek.
Kaspersky said the CloudSorcerer APT has been abusing public cloud services to exfiltrate data from Russian government entities.
The post Kaspersky Flags Cyberespionage APT ‘CloudSorcerer’ Targeting Russian Government appeared first on SecurityWeek.
With Living Off the Cloud (LOTC) attacks, hackers abuse APIs of trusted cloud services to remotely control botnets but also to make malicious traffic appear as trusted cloud traffic.
The post Cloudy with a Chance of Cyberattack: Understanding LOTC Attacks and How ZTNA Can Prevent Them appeared first on SecurityWeek.