Latest Cybersecurity News and Articles
17 January 2024
Organizations are advised to implement mitigations such as keeping systems updated, securing cloud credentials, and scanning for unrecognized PHP files to reduce the risk of Androxgh0st infections.
17 January 2024
The expansion of online gambling platforms has made cryptocurrency-based money laundering more prevalent, with Tether (USDT) being a popular choice due to its stability and low transaction fees.
17 January 2024
The city council has formed a crisis cabinet to assess the cyberattack's impact and is working with specialists to conduct forensic analyses and restore affected services.
17 January 2024
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) warned that threat actors deploying the AndroxGh0st malware are creating a botnet for "victim identification and exploitation in target networks."
A Python-based malware, AndroxGh0st was first documented by Lacework in December 2022, with the malware
17 January 2024
In the digital age, the battleground for security professionals is not only evolving, it's expanding at an alarming rate. The upcoming webinar, "The Art of Privilege Escalation - How Hackers Become Admins," offers an unmissable opportunity for IT security experts to stay ahead in this relentless cyber war.
Privilege escalation - the term might sound benign, but in the hands of a skilled hacker,
17 January 2024
An analysis by Comparitech revealed a 42% increase in crypto theft incidents in 2023 compared to 2022, with 283 reported cases. However, the total amount stolen decreased by 51% to $1.75 billion.
17 January 2024
VMware Aria Automation platform is affected by a critical missing access control vulnerability (CVE-2023-34063) that allows authenticated attackers to gain unauthorized access to remote organizations and workflows.
17 January 2024
Cybersecurity researchers have identified a "lightweight method" called iShutdown for reliably identifying signs of spyware on Apple iOS devices, including notorious threats like NSO Group's Pegasus, QuaDream's Reign, and Intellexa's Predator.
Kaspersky, which analyzed a set of iPhones that were compromised with Pegasus, said the infections left traces in a file
17 January 2024
The rising sophistication of cybercriminals and state-linked actors is outpacing private industry’s defense capabilities, leading to concerns about severe disruptions to major businesses and critical infrastructure providers.
17 January 2024
Google released updates to fix a zero-day flaw in its Chrome browser related to out-of-bounds memory access in the V8 JavaScript and WebAssembly engine. The update also fixed two other vulnerabilities in V8.
17 January 2024
Three new ransomware groups, 3AM, Rhysida, and Akira, made their mark in 2023 through their distinct tactics, targeting diverse industries and employing advanced technologies.
17 January 2024
This template injection vulnerability allows remote attackers to execute arbitrary code on affected Confluence installs. Versions 8.0.x through 8.5.3 are impacted, but the latest supported versions are not affected.
17 January 2024
Ivanti has reported a surge in hacker activity targeting two vulnerabilities in its Connect Secure VPN product. Over 1,700 devices have been exploited worldwide, prompting the release of a mitigation to address the vulnerabilities.
17 January 2024
GitHub identified and addressed a high-severity vulnerability (CVE-2024-0200) that required rotation of keys, including GitHub commit signing key and customer encryption keys, as a precautionary measure.
17 January 2024
GitHub has revealed that it has rotated some keys in response to a security vulnerability that could be potentially exploited to gain access to credentials within a production container.
The Microsoft-owned subsidiary said it was made aware of the problem on December 26, 2023, and that it addressed the issue the same day, in addition to rotating all potentially exposed credentials out of an
17 January 2024
Remcos RAT is being distributed in South Korea disguised as adult-themed games via webhards, highlighting the deceptive tactics used by threat actors to propagate malware.
17 January 2024
Despite being patched in November 2023, the CVE-2023-36025 Windows SmartScreen bypass vulnerability is still being exploited by malware distributors. The latest threat delivered through this vulnerability is a variant of the Phemedrone Stealer. To mitigate such threats, it's crucial for users and organizations to regularly update their software and educate themselves about safe online practices.
16 January 2024
Citrix is warning of two zero-day security vulnerabilities in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) that are being actively exploited in the wild.
The flaws are listed below -
CVE-2023-6548 (CVSS score: 5.5) - Authenticated (low privileged) remote code execution on Management Interface (requires access to NSIP, CLIP, or SNIP with management
16 January 2024
Google on Tuesday released updates to fix four security issues in its Chrome browser, including an actively exploited zero-day flaw.
The issue, tracked as CVE-2024-0519, concerns an out-of-bounds memory access in the V8 JavaScript and WebAssembly engine, which can be weaponized by threat actors to trigger a crash.
"By reading out-of-bounds memory, an attacker might be able to get secret values,
16 January 2024
A report found that 68% of IT workers feel overwhelmed by the number of technical resources that are required to access the data they need to work.