In the leadership and communications section, Proactive Boards Enable More Reliable Cyber Governance, CISO Best Practices for Managing Cyber Risk, The Evolution of Work: How Can Companies Prepare for What’s to Come?, and more!
The categories of security tools that we're most familiar with have struggled to keep up with how modern apps are designed and what modern devs need. What if instead of being beholden to categories, we created tools that solved problems devs have today in the types of apps they build today? And what if we had more dev leadership to influence securi...
New IMAPLoader malware attacks deployed by Iranian threat operation New watering hole attacks have been launched by Iranian state-sponsored advanced persistent threat operation Tortoiseshell, also known as TA456, Imperial Kitten, Yellow Liderc, and Crimson Sandstorm, to facilitate the distribution of the IMAPLoader malware, The Hacker News reports.
More than a million Windows and Linux systems have been compromised by the sophisticated StripedFly malware framework between 2017 and 2022, according to BleepingComputer.
Healthcare organizations leveraging NextGen HealthCare's open source data integration solution Mirth Connect, which was touted as the "Swiss Army knife of healthcare integration" for enabling standardized data exchange and communications across various systems, have been urged to immediately apply updates to remediate a critical remote code execution flaw, tracked as CVE-2023-43208, which could be exploited to facilitate initial systems access or sensitive data compromise, The Hacker News reports.
Vulnerable Citrix NetScaler Application Delivery Controller and NetScaler Gateway instances impacted by the recently remediated critical severity Citrix Bleed information disclosure bug, tracked as CVE-2023-4966, could have their authentication session cookies stolen and be hijacked through a new proof-of-concept exploit discovered by Assetnote researchers, reports BleepingComputer.
Newly emergent ransomware operation Hunters International has exposed pre-operation photos of patients stolen from the systems of a U.S. plastic surgeon's clinic, The Register reports.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.