Latest Cybersecurity News and Articles


Manufacturing is the most targeted sector by cyber criminals

22 August 2024
A new report details the top threat trends observed in the first half of 2024, including the most targeted industries. 

New 'ALBeast' Vulnerability Exposes Weakness in AWS Application Load Balancer

22 August 2024
As many as 15,000 applications using Amazon Web Services' (AWS) Application Load Balancer (ALB) for authentication are potentially susceptible to a configuration-based issue that could expose them to sidestep access controls and compromise applications. That's according to findings from Israeli cybersecurity company Miggo, which dubbed the problem ALBeast. "This vulnerability allows attackers to

8 vulnerabilities found in macOS operating system Microsoft apps

22 August 2024
Researchers discovered 8 vulnerabilities in macOS operating system Microsoft apps, and security leaders are sharing their insights. 

45% of tech leaders have experienced a SaaS cybersecurity incident

22 August 2024
A report found that 78% of technology leaders are concerned about security threats in Software-as-a-Service for application and software development.

Ingress-NGINX Annotation Validation Bypass Flaw (CVE-2024-7646) Allows Command Injection

22 August 2024
The vulnerability allows attackers to inject malicious content into annotations, leading to arbitrary command injection and potential access to controller credentials, enabling full access to cluster secrets.

Google Fixes Ninth Chrome Zero-Day Exploited in Attacks This Year

22 August 2024
Google released an emergency security update to fix the ninth zero-day vulnerability exploited in attacks this year. The vulnerability, known as CVE-2024-7971, involves a type confusion weakness in Chrome's V8 JavaScript engine.

Critical Flaw in LiteSpeed Cache Plugin Actively Exploited: Over 30,000 Attacks Blocked in 24 Hours

22 August 2024
The widely used LiteSpeed Cache plugin for WordPress is being actively exploited through a critical security vulnerability, CVE-2024-28000, with over 30,000 attack attempts blocked in just 24 hours.

The Facts About Continuous Penetration Testing and Why It’s Important

22 August 2024
What is Continuous Attack Surface Penetration Testing or CASPT? Continuous Penetration Testing or Continuous Attack Surface Penetration Testing (CASPT) is an advanced security practice that involves the continuous, automated, and ongoing penetration testing services of an organization's digital assets to identify and mitigate security vulnerabilities. CASPT is designed for enterprises with an

MegaMedusa, RipperSec’s Public Web DDoS Attack Tool

22 August 2024
RipperSec, a pro-Palestinian hacktivist group based in Malaysia, has released MegaMedusa, a publicly available Web DDoS attack tool that simplifies launching large-scale DDoS attacks.

Google Fixes High-Severity Chrome Flaw Actively Exploited in the Wild

22 August 2024
Google has rolled out security fixes to address a high-severity security flaw in its Chrome browser that it said has come under active exploitation in the wild. Tracked as CVE-2024-7971, the vulnerability has been described as a type confusion bug in the V8 JavaScript and WebAssembly engine. "Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap

Critical Flaw in WordPress LiteSpeed Cache Plugin Allows Hackers Admin Access

22 August 2024
Cybersecurity researchers have disclosed a critical security flaw in the LiteSpeed Cache plugin for WordPress that could permit unauthenticated users to gain administrator privileges. "The plugin suffers from an unauthenticated privilege escalation vulnerability which allows any unauthenticated visitor to gain Administrator level access after which malicious plugins could be uploaded and

GitHub Patches Critical Security Flaw in Enterprise Server Granting Admin Privileges

22 August 2024
GitHub has released fixes to address a set of three security flaws impacting its Enterprise Server product, including one critical bug that could be abused to gain site administrator privileges. The most severe of the shortcomings has been assigned the CVE identifier CVE-2024-6800, and carries a CVSS score of 9.5. "On GitHub Enterprise Server instances that use SAML single sign-on (SSO)

New Malware PG_MEM Targets PostgreSQL Databases for Crypto Mining

22 August 2024
Cybersecurity researchers have unpacked a new malware strain dubbed PG_MEM that's designed to mine cryptocurrency after brute-forcing their way into PostgreSQL database instances. "Brute-force attacks on Postgres involve repeatedly attempting to guess the database credentials until access is gained, exploiting weak passwords," Aqua security researcher Assaf Morag said in a technical report. "

Microsoft Patches Critical Copilot Studio Vulnerability Exposing Sensitive Data

21 August 2024
Cybersecurity researchers have disclosed a critical security flaw impacting Microsoft's Copilot Studio that could be exploited to access sensitive information. Tracked as CVE-2024-38206 (CVSS score: 8.5), the vulnerability has been described as an information disclosure bug stemming from a server-side request forgery (SSRF) attack. "An authenticated attacker can bypass Server-Side Request

New research: Malicious actors are imitating tech companies

21 August 2024
New research reveals that malicious actors are imitating tech companies in an effort to compromise corporate systems.

North Korean Hackers Deploy New MoonPeak Trojan in Cyber Campaign

21 August 2024
A new remote access trojan called MoonPeak has been discovered as being used by a state-sponsored North Korean threat activity cluster as part of a new campaign. Cisco Talos attributed the malicious cyber campaign to a hacking group it tracks as UAT-5394, which it said exhibits some level of tactical overlaps with a known nation-state actor codenamed Kimsuky. MoonPeak, under active development

Ubuntu Addresses Multiple OpenJDK 8 Vulnerabilities

21 August 2024
Canonical has released security fixes for multiple OpenJDK 8 vulnerabilities that could result in denial of service, information disclosure, or arbitrary code execution on certain Ubuntu releases.

Novel Phishing Method Used in Android and iOS Financial Fraud Campaigns

21 August 2024
This method was first disclosed by CSIRT KNF in Poland in July 2023 and later observed in Czechia by ESET analysts. Similar campaigns were also observed targeting banks in Hungary and Georgia.

Critical Remote Code Execution Vulnerability Addressed in GiveWP Plugin

21 August 2024
The vulnerability, identified as CVE-2024-5932, arises from inadequate validation of user-provided serialized data, allowing attackers to inject harmful PHP objects through the give_title parameter.

TA453 Targets Religious Figure with Fake Podcast Invite Delivering New BlackSmith Malware Toolset

21 August 2024
Iran-linked TA453 targeted a religious figure with a fake podcast interview invitation, attempting to deliver the BlackSmith malware toolkit. The initial lure involved an email leading to a malicious link containing the AnvilEcho PowerShell trojan.