Volvo retailer leaks sensitive files

The Brazilian retail arm of car manufacturing giant Volvo leaked sensitive files, putting its clientele in the vast South American country in peril. Volvo, a Swedish luxury vehicle manufacturer with over 95,000 employees and sales of nearly 700,000 vehicles annually, is a highly attractive target for criminals since the company caters to a wealthy clientele. […]

The post Volvo retailer leaks sensitive files appeared first on Security Affairs.

Western Digital Cyber Attack a ‘Wake Up Call for ASIC Vendors’

Update: In a statement on the extent of the data breach disclosed last month, Western Digital said it has control of its digital certificate infrastructure and is “equipped to revoke certificates as needed.” “Regarding reports of the potential to fraudulently use digital signing technology allegedly attributed to Western Digital in consumer products, we can confirm […]

The post Western Digital Cyber Attack a ‘Wake Up Call for ASIC Vendors’ appeared first on eSecurityPlanet.

Google fixed the first Chrome zero-day of 2023

Google released an emergency security update to address a zero-day vulnerability in Chrome which is actively exploited in the wild. Google released an emergency security update to address the first Chrome zero-day vulnerability (CVE-2023-2033) in 2023, the company is aware of attacks in the wild exploiting the issue. The vulnerability is a Type Confusion issue that resides in the JavaScript engine […]

The post Google fixed the first Chrome zero-day of 2023 appeared first on Security Affairs.

FDA Loophole for American Candy Gives Cancer to Kids

A NYT report highlights something I’ve been seeing a lot lately in American generative AI logic. …many chemicals are approved under a provision known as Generally Recognized As Safe, which states that a food additive can forego review by th…

For cybercriminal mischief, it’s dark web vs deep web

A new report from cyberthreat intelligence company Cybersixgill sees threat actors swarming to digital bazaars to collaborate, buy and sell malware and credentials.
The post For cybercriminal mischief, it’s dark web vs deep web appeared first on TechRe…

Hikvision fixed a critical flaw in Hybrid SAN and cluster storage products

Chinese video surveillance giant Hikvision addressed a critical vulnerability in its Hybrid SAN and cluster storage products. Chinese video surveillance giant Hikvision addressed an access control vulnerability, tracked as CVE-2023-28808, affecting its Hybrid SAN and cluster storage products. An attacker with network access to the device can exploit the issue to obtain admin permission. The […]

The post Hikvision fixed a critical flaw in Hybrid SAN and cluster storage products appeared first on Security Affairs.

Discord Says Cooperating in Probe of Classified Material Breach

Instant messaging platform Discord says it was cooperating with U.S. law enforcement’s investigation into a leak of secret U.S. documents that has grabbed attention around the world. From a report: The statement comes as questions continue to swirl ove…

How Iran Abuses Identity Repudiation to Enable Terrorist Attacks

An interview with counter-terrorism expert Haim Tomer sheds light on the identity methods used by Iran to shed responsibility for terrorist activity. …the modus operandi of Iran could be characterized by… “deniability.” From February 2008, …