CISA warns of N-able N-central flaws exploited in zero-day attacks

CISA warned on Wednesday that attackers are actively exploiting two security vulnerabilities in N‑able’s N-central remote monitoring and management (RMM) platform. N-central is commonly used by managed services providers (MSPs) and IT departments to monitor, manage, and maintain client networks and devices from a centralized web-based console. According to CISA, the two flaws can allow…

Read More

SonicWall offers 8 new firewalls, expands cyber warranty, embedded Zero Trust Network Access (ZTNA)

The Generation 8 portfolio includes multi-gigabit connectivity even for lower-end desktop models, a new unified management platform. An AI assistant to help administrators with common queries and device management tasks. SonicWall is growing its Gen8 hardware portfolio with new firewalls designed to better handle evolving network security needs. The SonicWall update spans both the desktop…

Read More

Nvidia backs off against Chinese accusations its H20 chips pose a security risk

Nvdia push  response to allegations from Chinese state media that its H20 artificial intelligence chips are a national security risk for China. Earlier in the day, Reuters reported Yuyuan Tantian, an account affiliated with Chinese state broadcaster CCTV, said in an article published on WeChat that the Nvidia H20 chips are not technologically advanced or environmentally…

Read More

Google Confirms Data Breach at Salesforce in ShinyHunters Attack

Google has acknowledged a data breach in one of its Salesforce systems carried out by the hacker group ShinyHunters. The breach, which occurred in early June, compromised one of Google’s internal Salesforce instances, exposing contact information and notes related to small and medium businesses. Back then, Google’s Threat Intelligence Group (GTIG) had already warned about…

Read More

Palo Alto’s $25 billion deal for CyberArk targets rising AI-driven threats

Inks biggest deal to build out identify security business Growing AI threats boost interest, consolidation Palo Alto shares fall 8% on integration concerns  Palo Alto Networks will buy Israeli peer CyberArk Software for about $25 billion, in its biggest deal yet, as CEO Nikesh Arora seeks to build a comprehensive cybersecurity provider to tap into rising…

Read More

ReVault flaws let hackers bypass Windows login on Dell laptops

The five critical vulnerabilities were named “ReVault” by Talos, and are found in Broadcom’s ControlVault3 firmware, as well as associated Windows application programming interfaces (APIs) on a range of Dell business laptops. On June 13, Dell disclosed these vulnerabilities impacting Dell Pro, Latitude, and Precision laptop models. ControlVault3 is a hardware-based security module found in…

Read More

Google suffers data breach in ongoing Salesforce data theft attacks

Google is the latest company to suffer a data breach in an ongoing wave of Salesforce CRM data theft attacks conducted by the ShinyHunters extortion group. In June, Google warned that a threat actor they classify as ‘UNC6040′ is targeting companies’ employees in voice phishing (vishing) social engineering attacks to breach Salesforce instances and download customer data….

Read More

KLM confirms a data breach exposing customer info via third-party system,

KLM Airlines (aka KLM Royal Dutch Airlines), a French-Dutch multinational airline, has notified customers about a recent data breach that exposed certain personal details after a third-party system the company relies on was accessed by an unauthorised party. The breach did not affect core systems or more sensitive data, but it still involves information that…

Read More