Washington County implements cybersecurity policy to combat potential ransomware attacks

The Washington County commissioners approved a new “business continuity and disaster recovery policy and plan” designed to take a proactive approach in guarding against another cyber attack like the one that crippled the county government for nearly three weeks earlier Read More …

UN General Assembly adopts milestone cybercrime treaty

The General Assembly on Tuesday adopted the United Nations Convention against Cybercrime, a landmark global treaty aimed at strengthening international cooperation to combat cybercrime and protecting societies from digital threats. The agreement on the legally binding treaty marked the culmination Read More …

US consumer watchdog sues big banks over ‘widespread’ fraud on Zelle payment app

The U.S. Consumer Financial Protection Bureau said on Friday it filed a lawsuit against JPMorgan Chase, Bank of America and Wells Fargo for failing to protect consumers from alleged “widespread fraud” on payments platform Zelle. The lawsuit was initiated as Read More …

How the ransomware attack at Change Healthcare went down – a timeline

A ransomware attack earlier this year on UnitedHealth-owned health tech company Change Healthcare likely stands as one of the largest data breaches of U.S. health and medical data in history. Months after the February data breach, a “substantial proportion of Read More …

BeyondTrust security advisory addresses a vulnerability in the Remote Support and Privileged Remote Access systems

BeyondTrust has released a security advisory that addresses a vulnerability in the Remote Support and Privileged Remote Access systems. Remote Support allows authorised individuals such as IT Helpdesk staff to connect to remote systems. Privileged Remote Access facilitates just-in-time secure Read More …

Proof-of-Concept Released for Critical Apache Struts Vulnerability

Apache has released a security bulletin addressing a critical vulnerability in Apache Struts 2. Apache Struts is an open-source model-view-controller (MVC) framework for creating Java web applications. CVE-2024-53677 is a ‘Unrestricted Upload of File with Dangerous Type’ vulnerability and has Read More …

HiatusRAT Actors Targeting Web Cameras and DVRs

The Federal Bureau of Investigation (FBI) is releasing this Private Industry Notification (PIN) to highlight HiatusRAT1 scanning campaigns against Chinese-branded web cameras and DVRs. Private sector partners are encouraged to implement the recommendations listed in the “Mitigation” column of the Read More …

Maritime Cyber Priority 2024/25: Tackling a growing cybersecurity threat in an increasingly connected industry

The digitalization of the maritime industry is in full flow. Shipowners, ports, cargo owners and many other stakeholders throughout the value chain are increasingly utilizing connected digital technologies to make shipping greener, safer and more efficient. However, DNV’s new Maritime Read More …

Update now! Apple releases new security patches for vulnerabilities in iPhones, Macs, and more

Apple has released security patches for most of its operating systems, including iOS, Mac, iPadOS, Safari, and visionOS. To check if you’re using the latest software version, go to Settings (or System Settings) > General > Software Update. It’s also Read More …

Ivanti Releases Security Updates for Multiple Products

Ivanti has released security advisories addressing vulnerabilities in Cloud Services Application, Connect Secure, and Policy Secure. Ivanti Cloud Services Applicance (CSA) is an appliance that provides secure communication and functionality over the internet. Ivanti Connect Secure and Policy Secure are Read More …