Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
North Carolina Ports is recovering from a cyberattack that forced a switch to manual processing after its IT system was hacked by an outside actor or group. The attack is contained, and the Coast Guard along with state officials are investigating the incident.
Cisco released updates to address multiple critical security vulnerabilities in Catalyst SD-WAN and IOS XE Software, including three with a CVSS score of 9.9. The vulnerabilities were discovered during internal security testing and are not known to be actively exploited, but customers are urged to apply the necessary updates for protection.
Cisco has released patches to address 12 critical vulnerabilities affecting its Catalyst SD-WAN and IOS XE Software, including three flaws with a CVSS score of 9.9. These vulnerabilities, discovered during internal security testing using AI models, impact Cisco Catalyst SD-WAN Software across all configurations and IOS XE Software in autonomous or controller modes.
Connor Riley Moucka, a 26-year-old Canadian, pleaded guilty to computer fraud and conspiracy for hacking and extorting over 165 organizations using Snowflake, and stealing call and text history records of over 100 million AT&T customers. The hackers targeted accounts without multi-factor authentication, leading Snowflake to enforce stronger security measures.
Connor Riley Moucka, a 26-year-old Canadian, pleaded guilty to computer fraud and conspiracy for hacking and extorting over 165 organizations using Snowflake, and stealing call and text history records of over 100 million AT&T customers. The hackers targeted accounts without multi-factor authentication, leading Snowflake to enforce stronger security measures.
MIT CSAIL researchers discovered a new interrupt injection attack that can bypass Spectre v2 mitigations on Intel and AMD CPUs, allowing an unprivileged program to leak kernel memory. The exploit targets the gap between branch predictor sanitization and kernel use, and a Linux kernel patch has been released to address the vulnerability.