Latest Cybersecurity News and Articles
31 July 2023
Zero Trust Network Access (ZTNA) should leverage contextual information, implement continuous authentication mechanisms, and be application-aware to make access decisions and reduce the risk of unauthorized access.
31 July 2023
An unprotected database belonging to the Southern Association of Independent Schools (SAIS) was found exposing sensitive data on students, parents, and teachers, including health records, social security numbers, and confidential security reports.
31 July 2023
The Federal Trade Commission (FTC) has requested commentary following an application for new methods of obtaining parental consent using biometrics.
31 July 2023
The New Jersey Supreme Court agreed to review the legal fight between Merck and several of the world’s top insurance providers involving $1.4 billion in claims stemming from the 2017 NotPetya cyberattack.
31 July 2023
EyeShell is a .NET-based modular backdoor that can contact a remote C2 server and execute commands to enumerate files and directories, download and upload files to and from the host, execute a specified file, delete files, and capture screenshots.
31 July 2023
The P2PInfect peer-to-peer (P2) worm has been observed employing previously undocumented initial access methods to breach susceptible Redis servers and rope them into a botnet.
"The malware compromises exposed instances of the Redis data store by exploiting the replication feature," Cado Security researchers Nate Bill and Matt Muir said in a report shared with The Hacker News.
"A common attack
31 July 2023
Marshall Erwin has been hired as Chief Information Security Officer at Fastly. Erwin was previously Chief Security Officer at Mozilla.
31 July 2023
Apple has announced plans to require developers to submit reasons to use certain APIs in their apps starting later this year with the release of iOS 17, iPadOS 17, macOS Sonoma, tvOS 17, and watchOS 10 to prevent their abuse for data collection.
31 July 2023
Threat actors are creating fake websites hosting trojanized software installers to trick unsuspecting users into downloading a downloader malware called Fruity with the goal of installing remote trojans tools like Remcos RAT.
31 July 2023
MalwareHunterTeam reported a new variant of the Abyss Locker ransomware designed to target Linux-based VMware ESXi servers. It employs SSH brute force attacks to gain unauthorized access to servers. The ransomware has claimed data theft ranging from 35GB to 700GB. Researchers also suspect a connection with HelloKitty ransomware due to similar code elements.
31 July 2023
Security leaders talk about a new advisory released by CISA which warns of web applications about insecure direct object reference (IDOR) vulnerabilities.
31 July 2023
The possibility of a U.S. Cyber Force moved one step closer to reality on Thursday after the Senate approved its version of a massive defense policy bill. The $886 billion National Defense Authorization Act passed in an 86-11 vote.
31 July 2023
Threat actors associated with the hacking crew known as Patchwork have been spotted targeting universities and research organizations in China as part of a recently observed campaign.
The activity, according to KnownSec 404 Team, entailed the use of a backdoor codenamed EyeShell.
Patchwork, also known by the names Operation Hangover and Zinc Emerson, is suspected to be a threat group that
31 July 2023
The shift towards zero-click exploits and new browser mitigations has led to a decrease in browser zero-days, but attackers are still finding ways to exploit vulnerabilities in other components.
31 July 2023
Avant Technologies, Inc. announced the appointment of Dr. Danny Rittman as Chief Information Security Officer (CISO).
31 July 2023
Demand for Virtual CISO services is soaring. According to Gartner, the use of vCISO services among small and mid-size businesses and non-regulated enterprises was expected to grow by a whopping 1900% in just one year, from only 1% in 2021 to 20% in 2022!
Offering vCISO services can be especially attractive for MSPs and MSSPs. By addressing their customers’ needs for proactive cyber resilience,
31 July 2023
New research has highlighted the severe risks posed by forged certificate attacks, which can lead to unauthorized access to important company resources. These attacks are driven by the Shadow Credentials technique.
31 July 2023
The Iranian hacktivist group, Cyber Avengers, has taken responsibility for breaching BAZAN's network and leaked screenshots of the company's SCADA systems on its Telegram channel.
31 July 2023
Python security fixes often happen through "silent" code commits, without an associated Common Vulnerabilities and Exposures (CVE) identifier, according to a group of computer security researchers.
31 July 2023
Abyss Locker is a relatively new ransomware operation that is believed to have launched in March 2023. Like other ransomware operations, the threat actors breach corporate networks, steal data for double-extortion, and encrypt devices on the network.