-
"Critical SQL Injection Flaws in Gentoo Soko Can Lead To Remote Code Execution"Researchers at SonarSource discovered two SQL injection vulnerabilities in Gentoo Soko, tracked collectively as CVE-2023-28424 with a CVSS score of 9.1, which a remote attacker can exploit to execute arbitrary code on vulnerable systems. Soko is deployed…
-
"Mobile Malware and Phishing Surge in 2022"According to security researchers at Zimperium, the volume of mobile malware, phishing sites dedicated to mobiles, and mobile vulnerabilities increased significantly in 2022. The researchers found that the percentage of phishing sites targeting…
-
"EncroChat Bust Leads to 6500 Arrests in Three Years"Europol recently announced that dismantling an encrypted chat platform used by organized crime gangs (OCGs) has led to 6558 arrests in the past three years, including 197 "high-value targets." Europol noted that EncroChat was used by tens of thousands of…
-
"MIT Researchers Devise a Way to Evaluate Cybersecurity Methods"Observing a computer program's behavior, such as how much time it spends accessing the computer's memory, enables a skilled hacker to obtain sensitive data, such as a password. Approaches to security that completely block these side-channel attacks are…
-
"Sensitive Information Stolen in LetMeSpy Stalkerware Hack"Radeal, the Polish developer of Android stalkerware "LetMeSpy," is informing users that their personal information and collected data was stolen due to a cyberattack. LetMeSpy is a free application that collects information from the phones it has…
-
"New Ongoing Campaign Targets npm Ecosystem with Unique Execution Chain"Cybersecurity researchers have uncovered a new ongoing campaign targeting the npm ecosystem that involves a unique execution chain to deliver an unknown payload to victim systems. According to the software supply chain security company Phylum, the…
-
"Jscrambler Launches JavaScript Scanner for PCI DSS 4.0 Compliance"Jscrambler has released a free tool to help businesses check the JavaScript code on their e-commerce sites and bring it into compliance with Payment Card Industry Data Security Standards (PCI DSS) 4.0. In March 2022, the PCI Security Standards Council…
-
"8Base Ransomware Gang Escalates Double Extortion Attacks in June"A ransomware gang named "8Base" has been targeting organizations worldwide in double-extortion attacks, with a constant stream of new victims. The ransomware group appeared for the first time in March 2022, maintaining a low profile with few notable…
-
"ChatGPT Shows Promise in Detecting Phishing Sites"Researchers wanted to know whether ChatGPT can reliably detect phishing sites. They tested 5,265 URLs (2,322 phishing and 2,943 safe). They asked ChatGPT (GPT-3.5) the question: "Does this link lead to a phish website?" The Artificial Intelligence (AI)…
-
SoS Musings #74 - Cybercriminals Ramping Up Business Email Compromise (BEC) AttacksSoS Musings #74 - Cybercriminals Ramping Up Business Email Compromise (BEC) Attacks
-
Cybersecurity Snapshots #43 - Rorschach RansomwareCybersecurity Snapshots #43 - Rorschach Ransomware
-
Cyber Scene #81 - California Gold Rush: AI, Chips, and the Tech Arms RaceCyber Scene #81 - California Gold Rush: AI, Chips, and the Tech Arms Race
News