Tools advertised as being capable of cracking passwords for HMIs, PLCs and other industrial products have been found to exploit a zero-day vulnerability, and threat actors are using these tools to deliver malware.
SecurityWeek Analysis: Over 230 Cybersecurity M&A Deals Announced in First Half of 2022
Unpatched WPBakery WordPress Plugin Vulnerability Increasingly Targeted in Attacks
The Wordfence team at WordPress security company Defiant warns of an increase in attacks targeting an unpatched vulnerability in the Kaswara addon for the WPBakery Page Builder WordPress plugin.
Supply Chain Attack Technique Spoofs GitHub Commit Metadata
Security researchers at Checkmarx are warning of a new supply chain attack technique that relies on spoofed commit metadata to add legitimacy to malicious GitHub repositories.
Critical Infrastructure Operators Implementing Zero Trust in OT Environments
A survey commissioned by cybersecurity company Xage shows that zero trust is on track to being implemented in many operational technology (OT) environments, particularly in critical infrastructure organizations.
Powerful ‘Mantis’ DDoS Botnet Hits 1,000 Organizations in One Month
Web protection firm Cloudflare warns that a small but powerful botnet has launched distributed denial-of-service (DDoS) attacks on roughly 1,000 organizations over the past month alone.
Microsoft: North Korean Hackers Target SMBs With H0lyGh0st Ransomware
Microsoft this week sounded the alarm on a North Korean threat actor using the H0lyGh0st ransomware in attacks targeting small and midsize businesses worldwide.
Software Vendors Start Patching Retbleed CPU Vulnerabilities
Vendors have started rolling out software updates to address the recently disclosed Retbleed speculative execution attack targeting Intel and AMD processors.
Bot Battle: The Tech That Could Decide Twitter’s Musk Lawsuit

If Twitter’s lawsuit over Elon Musk’s $44 billion buyout bid ever reaches trial, the case will likely center on a ubiquitous and often unloved technology: bots.
Log4j Software Flaw ‘Endemic,’ New Cyber Safety Panel Says
A computer vulnerability discovered last year in a ubiquitous piece of software is an “endemic” problem that will pose security risks for potentially a decade or more, according to a new cybersecurity panel created by President Joe Biden.













