Latest Cybersecurity News and Articles
27 February 2024
Two cryptocurrency addresses linked to a company operating in a notorious scam compound in Myanmar have received nearly $100 million worth of deposits in less than two years.
27 February 2024
The deprecated FCKeditor plugin is being abused to create open redirects on university, government, and corporate websites, allowing threat actors to poison search engine results with malicious content.
27 February 2024
The tool offers a wide range of features including IP info, SSL chain, DNS records, cookies, headers, server location, open ports, and more, making it a valuable resource for both OSINT investigations and general curiosity.
27 February 2024
The threat actors hijack abandoned subdomains and domains of well-known companies, allowing the emails to bypass spam filters and appear legitimate. Brands like MSN, VMware, and eBay have been unwittingly involved.
27 February 2024
Processing alerts quickly and efficiently is the cornerstone of a Security Operations Center (SOC) professional's role. Threat intelligence platforms can significantly enhance their ability to do so. Let's find out what these platforms are and how they can empower analysts.
The Challenge: Alert Overload
The modern SOC faces a relentless barrage of security alerts generated by SIEMs and EDRs.
27 February 2024
The Joint Ransomware Task Force aims to enhance collaboration to identify ransomware groups and drive a comprehensive government and societal response to protect critical infrastructure and businesses.
27 February 2024
Cybersecurity and intelligence agencies from the Five Eyes nations have released a joint advisory detailing the evolving tactics of the Russian state-sponsored threat actor known as APT29.
The hacking outfit, also known as BlueBravo, Cloaked Ursa, Cozy Bear, Midnight Blizzard (formerly Nobelium), and The Dukes, is assessed to be affiliated with the Foreign Intelligence Service (SVR) of the
27 February 2024
Fake wallet apps for China's digital currency are circulating, leading to warnings from the Ministry of Industry and Information Technology about potential scams and data theft.
27 February 2024
Cybersecurity researchers have found that it's possible to compromise the Hugging Face Safetensors conversion service to ultimately hijack the models submitted by users and result in supply chain attacks.
"It's possible to send malicious pull requests with attacker-controlled data from the Hugging Face service to any repository on the platform, as well as hijack any models that are submitted
27 February 2024
A new report by the Office of the National Cyber Director (ONCD) highlighted that up to 70% of security vulnerabilities are due to memory safety issues in certain programming languages.
27 February 2024
Security teams often rely on manual Excel work to manage their cybersecurity operations, despite the limitations and inefficiencies of using spreadsheets for such critical tasks.
27 February 2024
A critical security flaw (CVE-2024-1071) in the Ultimate Member WordPress plugin allowed unauthenticated attackers to perform SQL injection and extract sensitive data, affecting users who enabled the "Enable custom table for usermeta" option.
27 February 2024
A report from Coalition predicts a 25% increase in common vulnerabilities and exposures (CVEs) in 2024, reaching 34,888 vulnerabilities. This sharp rise in CVEs raises concerns about software vulnerability and the potential for ransomware attacks.
27 February 2024
The attackers employed sophisticated techniques such as code injection, execution modules, and dynamic loading of Windows API functions to evade detection by automated security products.
27 February 2024
MGM Resorts is facing regulatory investigations and potential fines following a cyberattack that disrupted its operations, with the possibility of incurring losses from legal proceedings.
27 February 2024
Boards have a legal responsibility to understand and manage cyber-governance within their organizations and should seek practical guidance to enhance their cybersecurity understanding.
27 February 2024
PayPal has filed a patent application for a method to detect when "super-cookies" are stolen, aiming to improve cookie-based authentication and prevent account takeover attacks.
27 February 2024
The attack involved a multi-stage infection chain, including spear phishing, obfuscated JavaScript files, and DLL hijacking, ultimately leading to the deployment of a Cobalt Strike payload.
27 February 2024
A critical security flaw has been disclosed in a popular WordPress plugin called Ultimate Member that has more than 200,000 active installations.
The vulnerability, tracked as CVE-2024-1071, carries a CVSS score of 9.8 out of a maximum of 10. Security researcher Christiaan Swiers has been credited with discovering and reporting the flaw.
In an advisory published last week, WordPress
26 February 2024
According to the report, more than 90% of enterprises are currently experiencing limitations integrating AI into their technology stack.