Latest Cybersecurity News and Articles
12 January 2024
Picture a cybersecurity landscape where defenses are impenetrable, and threats are nothing more than mere disturbances deflected by a strong shield. Sadly, this image of fortitude remains a pipe dream despite its comforting nature. In the security world, preparedness is not just a luxury but a necessity. In this context, Mike Tyson's famous adage, "Everyone has a plan until they get punched in
12 January 2024
The breach occurred when a threat actor impersonated Framework's CEO and tricked an accountant into sharing a spreadsheet containing customer data, including names, email addresses, and outstanding balances.
12 January 2024
The attacks leverage a misconfiguration in YARN's ResourceManager in Hadoop and a misconfiguration in Apache Flink, allowing remote threat actors to execute arbitrary code without authentication.
12 January 2024
The exploit devised by VulnCheck demonstrates that arbitrary in-memory code execution is possible, highlighting the importance of patching and securing systems running Apache OfBiz.
12 January 2024
The regulation strengthens the role of CERT-EU as a hub for cybersecurity assistance and information exchange, with EU agencies obligated to share incident-related information with the body.
12 January 2024
The first vulnerability enables an attacker to reset the API key and access sensitive log information, while the second vulnerability allows for arbitrary script injection into affected web pages.
12 January 2024
A team of computer scientists has developed a method called Baldur, which uses artificial intelligence to automatically generate proofs and verify the correctness of software, aiming to reduce software bugs and vulnerabilities.
12 January 2024
Infrastructure takedowns by law enforcement can have a short-term impact on cybercriminal activity, but criminals can quickly adapt and resume their operations using new tools and techniques.
12 January 2024
While payload delivery and command-and-control obfuscation are common methods, GitHub is also used as a dead drop resolver, and for phishing and malicious traffic redirection.
12 January 2024
Cybersecurity researchers have identified a new attack that exploits misconfigurations in Apache Hadoop and Flink to deploy cryptocurrency miners within targeted environments.
"This attack is particularly intriguing due to the attacker's use of packers and rootkits to conceal the malware," Aqua security researchers Nitzan Yaakov and Assaf Morag said in an analysis published earlier
12 January 2024
Google has released patches for 58 vulnerabilities in the Android platform, including high-severity issues in the Framework and System components. Users are advised to update their devices promptly to protect against potential exploits.
12 January 2024
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical security vulnerability impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
The issue, tracked as CVE-2023-29357 (CVSS score: 9.8), is a privilege escalation flaw that could be exploited by an attacker to gain
11 January 2024
According to a recent Forescout report, the second wave of 2023 Danish energy sector cyberattacks took advantage of unpatched firewalls.
11 January 2024
Data privacy within the automotive industry was analyzed in a report, finding that 72% of drivers are uncomfortable automakers sharing their data.
11 January 2024
The NCSC-FI has warned of increased Akira ransomware attacks in December. These attacks targeted companies in Finland and involved wiping backups, making it difficult for victims to recover their data without paying a ransom.
11 January 2024
Organisations are encouraged to take immediate action to mitigate vulnerabilities affecting Ivanti Connect Secure (ICS) and Ivanti Policy Secure (IPS) gateways (CVE-2023-46805 and CVE-2024-21887), and follow the latest vendor advice.
11 January 2024
A new Python-based hacking tool called FBot has been discovered, targeting web servers, cloud services, content management systems, and SaaS platforms like Amazon Web Services and Microsoft 365.
11 January 2024
MC2 Security Fund has completed its acquisition of Trustwave, a managed security services provider, expanding its reach and placing Trustwave in front of Chertoff Group customers in the commercial and public sectors.
11 January 2024
The ubiquity of GitHub in information technology (IT) environments has made it a lucrative choice for threat actors to host and deliver malicious payloads and act as dead drop resolvers, command-and-control, and data exfiltration points.
“Using GitHub services for malicious infrastructure allows adversaries to blend in with legitimate network traffic, often bypassing traditional security
11 January 2024
Fallon Ambulance, a medical transportation company based in Boston, is being investigated for a data breach including patient and employee data.