Latest Cybersecurity News and Articles
11 December 2023
Identity management solution provider Opal Security has managed to raise $22 million in a Series B round to expand its team and develop new AI-powered tools for identity and access risk remediation.
11 December 2023
The Apache Software Foundation has released security updates to address a critical file upload vulnerability in the Struts 2 framework, which could allow for remote code execution.
11 December 2023
Red Roof confirmed that the organization experienced a data breach in late September of 2023. The breach did not involve any Red Roof guest data.
11 December 2023
Researchers have identified new techniques employed by the GuLoader malware to enhance its evasion capabilities and make analysis more challenging. The highly evasive shellcode downloader malware was found leveraging Vectored Exception Handler (VEH) capability. Organizations can leverage the latest YARA rules from Elastic Security to detect malware.
11 December 2023
Insider threats, including both malicious attacks and unintentional risks, are on the rise, with privilege escalation exploits being a significant component of unauthorized activity.
11 December 2023
Tactical and targeting overlaps have been discovered between the enigmatic advanced persistent threat (APT) called Sandman and a China-based threat cluster that's known to use a backdoor known as KEYPLUG.
The assessment comes jointly from SentinelOne, PwC, and the Microsoft Threat Intelligence team based on the fact that the adversary's Lua-based malware LuaDream and KEYPLUG have been
11 December 2023
New study reveals that organizations appear to struggle in their ability to assess and remediate data encryption risks and policy violations.
11 December 2023
The collaboration aims to strengthen cybersecurity, safeguard critical infrastructure, and reinforce the resilience of digital products in the face of increasing cyber threats.
11 December 2023
The Lazarus Group, a North Korea-linked threat actor, has been conducting a global campaign called Operation Blacksmith. They are exploiting security flaws in Log4j to deploy remote access trojans (RATs) on compromised hosts.
11 December 2023
The United Kingdom has imposed sanctions on individuals and entities involved in Southeast Asia's online scamming industry, targeting both human traffickers and companies connected to scam operations.
11 December 2023
The notorious North Korea-linked threat actor known as the Lazarus Group has been attributed to a new global campaign that involves the opportunistic exploitation of security flaws in Log4j to deploy previously undocumented remote access trojans (RATs) on compromised hosts.
Cisco Talos is tracking the activity under the name Operation Blacksmith, noting the use of three DLang-based
11 December 2023
The vulnerability allows threat actors physical access to a device, exposing sensitive data in users' Google accounts. Google has been aware of this issue for at least six months but has not yet addressed it, according to researcher Jose Rodriguez.
11 December 2023
Organizations must shift their data security approach to safeguard sensitive workloads from the moment they enter the data pipeline, rather than relying on securing data only in the cloud data warehouse.
11 December 2023
Companies are advised to establish a relationship with their local FBI field office and contact them soon after a cyber incident is discovered to assist with the FBI's review and determine if a disclosure delay is necessary.
11 December 2023
In an increasingly digital world, no organization is spared from cyber threats. Yet, not every organization has the luxury of hiring a full-time, in-house CISO. This gap in cybersecurity leadership is where you, as a vCISO, come in. You are the person who will establish, develop, and solidify the organization's cybersecurity infrastructure, blending strategic guidance with actionable
11 December 2023
As per a recent study by Bitwarden, approximately one-third of Americans use sports-related terms in their passwords, with professional sports teams being twice as likely to inspire these passwords compared to college sports teams.
11 December 2023
The malware is typically spread through phishing campaigns, and its creators have continuously improved its ability to bypass security features. One recent change involves an enhancement to its Vectored Exception Handling (VEH) capability.
11 December 2023
In the ever-evolving cybersecurity landscape, one method stands out for its chilling effectiveness – social engineering. But why does it work so well? The answer lies in the intricate dance between the attacker's mind and human psychology.
Our upcoming webinar, "Think Like a Hacker, Defend Like a Pro," highlights this alarming trend. We delve deep into social engineering, exploring its
11 December 2023
According to a report from Veracode, two years after the disclosure of a critical vulnerability in Apache Log4j, nearly 2 in 5 applications are still using vulnerable versions, highlighting the persistence of security risks in software development.
11 December 2023
According to an Apple-commissioned study conducted by a professor at MIT, ransomware attacks have seen a steep rise, with a nearly 70% increase in such attacks in the first nine months of 2023, primarily targeting organizations with sensitive data.