SonicWall Authentication Flaw Faces Active Exploitation Threat

Security researchers warn of ongoing exploitation of a critical vulnerability in SonicWall’s SonicOS. Key Findings: Ongoing Exploitation and Threat Landscape SonicWall initially patched CVE-2024-53704 after researchers from Computest Security disclosed the flaw. At the time of the patch release, the company stated it had no evidence of active exploitation. However, subsequent findings suggest otherwise. Researchers […]

PayPal Fined $2 Million Over Data Breach Impacting 35,000 Social Security Numbers

Digital payments leader PayPal has agreed to pay a $2 million fine following a cybersecurity incident in December 2022 that exposed thousands of Social Security numbers, according to New York state regulators. The penalty resolves violations of New York’s financial cybersecurity regulations, which require companies like PayPal to employ qualified personnel to manage critical cybersecurity […]

Over 100 Security Vulnerabilities Identified in LTE and 5G Network Implementations

A team of researchers has uncovered over 100 security vulnerabilities affecting LTE and 5G network implementations, which could potentially be exploited to disrupt services or gain unauthorized access to cellular core networks. The study identified 119 vulnerabilities, with 97 assigned unique CVE identifiers, spanning seven LTE implementations—Open5GS, Magma, OpenAirInterface, Athonet, SD-Core, NextEPC, and srsRAN—and three […]

Government Payments Contractor Conduent Confirms Cyberattack Impacting Multiple States

Conduent, a New Jersey-based contractor that provides technology solutions for social service agencies and transit systems across the U.S., has confirmed that it was the target of a cyberattack. The incident disrupted operations and caused delays in child support payment processing in multiple states, including Wisconsin. The attack first came to light when Wisconsin officials […]