News

US Gov Rolls Out National Cyber Workforce, Education Strategy

The Biden administration on Monday rolled out its first-ever National Cyber Workforce and Education Strategy (NCWES), announcing a series of “generational investments” to  address immediate and long-term cyber workforce needs.  The new strategy seeks to transform cyber education in K-12 schools, community colleges and technical schools, invest in teachers and cyber education systems and make training more accessible and affordable.  “Filling the hundreds of thousands of cyber job vacancies across our nation is a national…

Read More

US, Australia Issue Warning Over Access Control Vulnerabilities in Web Applications

New guidance from the Australian Cyber Security Centre (ACSC), the US Cybersecurity and Infrastructure Security Agency (CISA), and National Security Agency (NSA) warns developers, vendors, and organizations of access control vulnerabilities in web applications. Described as insecure direct object reference (IDOR) issues, they allow threat actors to read or tamper with sensitive data via application programming interface (API) requests that include the identifier of a valid user. These requests are successful because the authentication or…

Read More

In Other News: Data Breach Cost Rises, Russia Targets Diplomats, Tracker Alerts in Android 

SecurityWeek is publishing a weekly cybersecurity roundup that provides a concise compilation of noteworthy stories that might have slipped under the radar. We provide a valuable summary of stories that may not warrant an entire article, but are nonetheless important for a comprehensive understanding of the cybersecurity landscape. Each week, we will curate and present a collection of noteworthy developments, ranging from the latest vulnerability discoveries and emerging attack techniques to significant policy changes and…

Read More

Exploitation of Recent Citrix ShareFile RCE Vulnerability Begins

Threat intelligence company Greynoise says it has observed the first attempts to exploit a recent critical remote code execution (RCE) vulnerability in Citrix ShareFile. A popular cloud-based file-sharing and collaboration solution, ShareFile allows users to store files in their own data centers, via a storage zones controller (or storage center), a .NET web application running under Internet Information Services (IIS). The vulnerability, tracked as CVE-2023-24489 (CVSS score of 9.1), was the result of errors leading…

Read More

US Senator Wyden Accuses Microsoft of ‘Cybersecurity Negligence’

Oregon senator Ron Wyden wants the U.S. government to hold Microsoft responsible for what he describes as “negligent cybersecurity practices” that enabled “a successful Chinese espionage campaign against the United States government.” In a strongly worded letter to Attorney General Merrick Garland and the heads of CISA and the FTC, Wyden said the software giant “bears significant responsibility” for the M365 cloud hack that started with the theft of a Microsoft encryption key. “Since the…

Read More

Ex-NSA Official Harry Coker Tapped for National Cyber Director Job

Former Navy commander and senior official in the NSA and CIA Harry Coker has been formally tapped to replace the retired Chris Inglis as the U.S. government’s National Cyber Director. Coker’s nomination, announced by the Biden administration on Wednesday, puts him in line to lead the implementation of the government’s newly formed national cybersecurity strategy and manage the tricky relationship between the federal government and big-tech vendors struggling to cope with nonstop malicious hacker attacks.…

Read More

OneTrust Raises $150 Million at $4.5 Billion Valuation

Data privacy and governance provider OneTrust today announced that it has raised $150 million in new funding, bringing the total raised by the company to over $1 billion. Founded in 2016, the Atlanta-based firm offers a trust intelligence platform to help organizations visualize the data entering their environment, manage it, meet compliance requirements, and ensure transparency. According to OneTrust, its privacy and security compliance tools are suited for small to large organizations, delivering a holistic…

Read More

Microsoft Cloud Hack Exposed More Than Exchange, Outlook Emails

Researchers at cloud security startup Wiz have an urgent warning for organizations running Microsoft’s M365 platform: That stolen Microsoft Azure AD enterprise signing key gave Chinese hackers access to data beyond Exchange Online and Outlook.com. “Our researchers concluded that the compromised MSA key could have allowed the threat actor to forge access tokens for multiple types of Azure Active Directory applications, including every application that supports personal account authentication, such as SharePoint, Teams, OneDrive,” Wiz…

Read More

In Other News: Military Emails Leaked, Google Restricts Internet Access, Chinese Spyware

SecurityWeek is publishing a weekly cybersecurity roundup that provides a concise compilation of noteworthy stories that might have slipped under the radar. We provide a valuable summary of stories that may not warrant an entire article, but are nonetheless important for a comprehensive understanding of the cybersecurity landscape. Each week, we will curate and present a collection of noteworthy developments, ranging from the latest vulnerability discoveries and emerging attack techniques to significant policy changes and…

Read More