An analysis of the numerous LDAP queries that Russian cyberespionage group APT29 had made to the Active Directory system has led to the discovery of a vulnerability in Windows’ ‘credential roaming’ functionality.
Ransomware Gang Offers to Sell Files Stolen From Continental for $50 Million
A notorious ransomware group is offering to sell files allegedly stolen from German car parts giant Continental for $50 million.
ABB Oil and Gas Flow Computer Hack Can Prevent Utilities From Billing Customers
Oil and gas flow computers and remote controllers made by Swiss industrial technology firm ABB are affected by a serious vulnerability that could allow hackers to cause disruptions and prevent utilities from billing their customers, according to industrial cybersecurity firm Claroty.
No Cyberattacks Affected US Vote Counting, Officials Say
No instances of digital interference are known to have affected the counting of the midterm vote after a tense Election Day in which officials were closely monitoring domestic and foreign threats.
Microsoft Patches MotW Zero-Day Exploited for Malware Delivery
Microsoft’s latest Patch Tuesday updates address six zero-day vulnerabilities, including one related to the Mark-of-the-Web (MotW) security feature that has been exploited by cybercriminals to deliver malware.
Security Posture Management Firm Veriti Emerges From Stealth With $18.5M in Funding
Security posture management startup Veriti has emerged from stealth mode with $18.5 million raised in two funding rounds led by Insight Partners and NFX and AMITI.
Gaping Authentication Bypass Holes in VMWare Workspace One
Virtualization technology giant VMware joined the Patch Tuesday train this week to deliver urgent security patches to its VMWare Workspace One product.
Google Pays $45,000 for High-Severity Vulnerabilities Found in Chrome
Google this week announced the release of a Chrome 107 update that resolves 10 vulnerabilities, including six high-severity bugs reported by external researchers.
Attackers Using IPFS for Distributed, Bulletproof Malware Hosting
The InterPlanetary File System (IPFS), considered one of the building blocks of web3, is increasingly being used to provide hidden bulletproof hosting for malware.
“Multiple malware families are currently being hosted within IPFS and retrieved during the initial stages of malware attacks,” say researchers at Cisco Talos.
Citrix Patches Critical Vulnerability in Gateway, ADC
Citrix on Tuesday announced patches for three vulnerabilities impacting its Gateway and ADC products, including one critical-severity flaw.
Widely deployed across on-premises and cloud environments, Citrix Gateway is an SSL VPN solution delivering single sign-on across applications and devices.












