Latest Cybersecurity News and Articles
17 January 2024
The rising sophistication of cybercriminals and state-linked actors is outpacing private industry’s defense capabilities, leading to concerns about severe disruptions to major businesses and critical infrastructure providers.
17 January 2024
Google released updates to fix a zero-day flaw in its Chrome browser related to out-of-bounds memory access in the V8 JavaScript and WebAssembly engine. The update also fixed two other vulnerabilities in V8.
17 January 2024
Three new ransomware groups, 3AM, Rhysida, and Akira, made their mark in 2023 through their distinct tactics, targeting diverse industries and employing advanced technologies.
17 January 2024
This template injection vulnerability allows remote attackers to execute arbitrary code on affected Confluence installs. Versions 8.0.x through 8.5.3 are impacted, but the latest supported versions are not affected.
17 January 2024
Ivanti has reported a surge in hacker activity targeting two vulnerabilities in its Connect Secure VPN product. Over 1,700 devices have been exploited worldwide, prompting the release of a mitigation to address the vulnerabilities.
17 January 2024
GitHub identified and addressed a high-severity vulnerability (CVE-2024-0200) that required rotation of keys, including GitHub commit signing key and customer encryption keys, as a precautionary measure.
17 January 2024
GitHub has revealed that it has rotated some keys in response to a security vulnerability that could be potentially exploited to gain access to credentials within a production container.
The Microsoft-owned subsidiary said it was made aware of the problem on December 26, 2023, and that it addressed the issue the same day, in addition to rotating all potentially exposed credentials out of an
17 January 2024
Remcos RAT is being distributed in South Korea disguised as adult-themed games via webhards, highlighting the deceptive tactics used by threat actors to propagate malware.
17 January 2024
Despite being patched in November 2023, the CVE-2023-36025 Windows SmartScreen bypass vulnerability is still being exploited by malware distributors. The latest threat delivered through this vulnerability is a variant of the Phemedrone Stealer. To mitigate such threats, it's crucial for users and organizations to regularly update their software and educate themselves about safe online practices.
16 January 2024
Citrix is warning of two zero-day security vulnerabilities in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) that are being actively exploited in the wild.
The flaws are listed below -
CVE-2023-6548 (CVSS score: 5.5) - Authenticated (low privileged) remote code execution on Management Interface (requires access to NSIP, CLIP, or SNIP with management
16 January 2024
Google on Tuesday released updates to fix four security issues in its Chrome browser, including an actively exploited zero-day flaw.
The issue, tracked as CVE-2024-0519, concerns an out-of-bounds memory access in the V8 JavaScript and WebAssembly engine, which can be weaponized by threat actors to trigger a crash.
"By reading out-of-bounds memory, an attacker might be able to get secret values,
16 January 2024
A report found that 68% of IT workers feel overwhelmed by the number of technical resources that are required to access the data they need to work.
16 January 2024
The U.S. Secret Service executed a seizure warrant to recover $34,000 stolen through a fake Norton antivirus renewal email scam. The scam tricked victims into granting remote access to their computers, and then transferring money from their accounts.
16 January 2024
The scheme involved phishing pages to trick users into connecting their wallets with the attackers' infrastructure, resulting in over $87 million in illicit profits from more than 137,000 victims.
16 January 2024
OAuth attacks are on the rise, and organizations must implement strong access controls, fortify identity security for user accounts, and monitor third-party app activity to prevent unauthorized access to SaaS resources.
16 January 2024
According to the Allianz Risk Barometer, cyber incidents (ransomware, data breaches and IT disruptions) are the top global concern of 2024.
16 January 2024
A cloud services firm returned patient data stolen in a ransomware attack by the LockBit gang to a New York hospital alliance. The hospitals had sued LockBit as a legal maneuver to force the storage firm to return the data.
16 January 2024
The evolution of phishing techniques, including the use of advanced AI-driven tools, has led to a surge in highly personalized and convincing phishing attacks, posing a significant challenge to traditional email security solutions.
16 January 2024
The National Defense Industrial Strategy focuses on resilient supply chains, workforce readiness, flexible acquisitions, and economic deterrence to improve defense industrial ecosystem.
16 January 2024
Over 178,000 SonicWall firewalls exposed over the internet are exploitable to at least one of the two security flaws that could be potentially exploited to cause a denial-of-service (DoS) condition and remote code execution (RCE).
“The two issues are fundamentally the same but exploitable at different HTTP URI paths due to reuse of a vulnerable code pattern,” Jon Williams, a senior security