GitLab Patches Critical Authentication Bypass Vulnerability

September 19, 2024 at 06:15AM “Virtual event now live: Attack Surface Management Summit. Connect with SecurityWeek for cybersecurity news, webcasts, and virtual events covering topics such as ICS, cyber threats, data breaches, security operations, and risk management. Also, explore sessions on CISO strategy, industrial cybersecurity, funding/M&A, and more.” It seems like the meeting notes are … Read more

Russian GRU Unit Tied to Assassinations Now Linked to Global Cyber Sabotage and Espionage

September 5, 2024 at 02:48PM SecurityWeek Network offers cybersecurity news, webcasts, and virtual events. Topics covered include malware, cyber warfare, data breaches, ransomware, and more. The network also provides information on security operations, incident response, risk management, and cybersecurity funding and M&A. The ICS Cybersecurity Conference and industrial cybersecurity are also featured. It seems like … Read more

US Offering $10 Million Reward for Iranian ICS Hackers

August 8, 2024 at 09:18AM The US Department of State is offering a reward of up to $10 million for information on Iranian nationals accused of hacking industrial control systems. The individuals are linked to Iran’s Islamic Revolutionary Guard Corps and a hacker group named Cyber Av3ngers. The US government believes Cyber Av3ngers is a … Read more

New ICS Malware ‘FrostyGoop’ Targeting Critical Infrastructure

July 23, 2024 at 07:42AM Researchers have identified a new ICS-focused malware, FrostyGoop, which targets industrial control systems using Modbus TCP to disrupt operational technology networks. It was used in a cyber attack on an energy company in Lviv, Ukraine, causing a 48-hour loss of heating services to over 600 apartment buildings. The incident highlights … Read more

Russian Hacktivists Sanctioned for US Critical Infrastructure Attacks

July 22, 2024 at 01:15PM Two members of the Russian hacktivist group Cyber Army Russia Reborn (CARR) were sanctioned by the US Department of Treasury for cyberattacks on US critical infrastructure. Yuliya Pankratova, the leader, and Denis Degtyarenko, the primary hacker, were involved in disrupting operations at water facilities and compromising industrial control systems, but … Read more

Millions of OpenSSH Servers Potentially Vulnerable to Remote regreSSHion Attack

July 1, 2024 at 08:21AM The SecurityWeek Network covers cybersecurity news, webcasts, and virtual events. It includes topics such as malware, cyberwarfare, data breaches, ransomware, and incident response. Additionally, it provides information on security operations, threat intelligence, risk management, and CISO strategy. Furthermore, it focuses on ICS/OT and industrial cybersecurity, as well as cyber insurance … Read more

In Other News: Fuxnet ICS Malware, Google User Tracking, CISA Employee Scams 

June 14, 2024 at 10:27AM SecurityWeek curates a weekly roundup of cybersecurity stories, focusing on diverse developments like Chinese cyberspies hacking Fortinet devices, a White House initiative to secure rural hospitals, vulnerabilities in biometric access systems, ICS malware Fuxnet, EU’s encryption backdoor push, and more. Microsoft will evaluate employees’ cybersecurity work for compensation. US federal … Read more

Rockwell Automation Patches High-Severity Vulnerabilities in FactoryTalk View SE

June 14, 2024 at 06:39AM Rockwell Automation has addressed three high-severity vulnerabilities in its FactoryTalk View Site Edition (SE) HMI software, including an authentication issue and a local privilege escalation vulnerability. These flaws have been patched in version 14, with advisories published by both Rockwell and CISA. Additionally, a vulnerability affecting certain controllers has also … Read more

PoC Published for Exploited Check Point VPN Vulnerability

June 3, 2024 at 08:45AM SecurityWeek Network provides cybersecurity news, webcasts, and virtual events. Their content covers various topics including malware, cyberwarfare, data breaches, ransomware, and more. Additionally, they focus on areas such as incident response, risk management, and CISO strategy, as well as industrial cybersecurity and funding/M&A in the cybersecurity industry. It seems like … Read more

ICS Patch Tuesday: Advisories Published by Siemens, Rockwell, Mitsubishi Electric

May 15, 2024 at 06:36AM Major industrial control systems providers, including Siemens, Rockwell Automation, Mitsubishi Electric, and Johnson Controls, have issued Patch Tuesday advisories addressing vulnerabilities in their products. Siemens has published 15 advisories, addressing critical vulnerabilities in various products, while Rockwell Automation and Mitsubishi Electric also reported high-severity vulnerabilities. CISA has informed organizations about … Read more