Latest Cybersecurity News and Articles
12 January 2024
The FTC has prohibited X-Mode Social and Outlogic from selling or sharing sensitive data to settle allegations regarding precise location data.
12 January 2024
Passkeys in Bitwarden are generated using the PRF WebAuthn extension, which derives a unique encryption key from the passkey and enhances security. The passkey feature is currently in beta and available in Chromium-based browsers.
12 January 2024
As many as five different malware families were deployed by suspected nation-state actors as part of post-exploitation activities leveraging two zero-day vulnerabilities in Ivanti Connect Secure (ICS) VPN appliances since early December 2023.
"These families allow the threat actors to circumvent authentication and provide backdoor access to these devices," Mandiant said in an
12 January 2024
Researchers from Qualys have warned of a new wave of job scams on Facebook's Meta platform. Scammers are using Facebook ads to lure users with offers of remote work and then stealing their personal data and banking credentials.
12 January 2024
The threat actors associated with the Medusa ransomware have ramped up their activities following the debut of a dedicated data leak site on the dark web in February 2023 to publish sensitive data of victims who are unwilling to agree to their demands.
“As part of their multi-extortion strategy, this group will provide victims with multiple options when their data is posted on their
12 January 2024
Cybersecurity researchers warn that the recent attacks on Denmark's energy sector highlight the need for critical infrastructure organizations across Europe to remain vigilant against exploits targeting unpatched network infrastructure devices.
12 January 2024
GitLab has released security updates to address two critical vulnerabilities, including one that could be exploited to take over accounts without requiring any user interaction.
Tracked as CVE-2023-7028, the flaw has been awarded the maximum severity of 10.0 on the CVSS scoring system and could facilitate account takeover by sending password reset emails to an unverified email address.
The
12 January 2024
The leaked data, containing names, phone numbers, and addresses, appears to be accurate according to users listed in the file. Customers should be cautious of potential smishing attacks and the misuse of their information for fraudulent purposes.
12 January 2024
The complexity of attributing cyber incidents to specific entities, such as nation-states or criminal groups, poses challenges when applying exclusions in insurance policies.
12 January 2024
The World Economic Forum's Global Risks Report 2024 highlights the increasing threat of cyber threats, with misinformation and disinformation being identified as the most severe risk globally.
12 January 2024
Picture a cybersecurity landscape where defenses are impenetrable, and threats are nothing more than mere disturbances deflected by a strong shield. Sadly, this image of fortitude remains a pipe dream despite its comforting nature. In the security world, preparedness is not just a luxury but a necessity. In this context, Mike Tyson's famous adage, "Everyone has a plan until they get punched in
12 January 2024
The breach occurred when a threat actor impersonated Framework's CEO and tricked an accountant into sharing a spreadsheet containing customer data, including names, email addresses, and outstanding balances.
12 January 2024
The attacks leverage a misconfiguration in YARN's ResourceManager in Hadoop and a misconfiguration in Apache Flink, allowing remote threat actors to execute arbitrary code without authentication.
12 January 2024
The exploit devised by VulnCheck demonstrates that arbitrary in-memory code execution is possible, highlighting the importance of patching and securing systems running Apache OfBiz.
12 January 2024
The regulation strengthens the role of CERT-EU as a hub for cybersecurity assistance and information exchange, with EU agencies obligated to share incident-related information with the body.
12 January 2024
The first vulnerability enables an attacker to reset the API key and access sensitive log information, while the second vulnerability allows for arbitrary script injection into affected web pages.
12 January 2024
A team of computer scientists has developed a method called Baldur, which uses artificial intelligence to automatically generate proofs and verify the correctness of software, aiming to reduce software bugs and vulnerabilities.
12 January 2024
Infrastructure takedowns by law enforcement can have a short-term impact on cybercriminal activity, but criminals can quickly adapt and resume their operations using new tools and techniques.
12 January 2024
While payload delivery and command-and-control obfuscation are common methods, GitHub is also used as a dead drop resolver, and for phishing and malicious traffic redirection.
12 January 2024
Cybersecurity researchers have identified a new attack that exploits misconfigurations in Apache Hadoop and Flink to deploy cryptocurrency miners within targeted environments.
"This attack is particularly intriguing due to the attacker's use of packers and rootkits to conceal the malware," Aqua security researchers Nitzan Yaakov and Assaf Morag said in an analysis published earlier