News
-
"Dark Web Sees 'Surge' of X Gold Accounts on Sale"According to CloudSEK researchers, the dark web is experiencing a "gold rush" as threat actors target verified accounts on X, formerly Twitter, for large-scale attacks.
-
"Guidelines for Secure AI System Development""This document recommends guidelines for providers of any systems that use artificial intelligence (AI), whether those systems have been created from scratch or built on top of tools and services provided by others.
-
"Russia Spies on Kyiv Defenses via Hacked Cameras Before Missile Strikes"The Security Service of Ukraine (SSU) has recently revealed that Russian intelligence hacked online surveillance cameras to spy on air defense activities and critical infrastructure in Kyiv ahead of recent missile strikes.
-
"NSA - Cybersecurity Speaker Series: Preparing for Post-Quantum"For the nation's most sensitive systems, cryptography is both the first and last line of defense. The quantum threat exists, and it is critical to modernize in order to protect these systems.
-
"Cybercriminals Share Millions of Stolen Records During Holiday Break"In the days leading up to Christmas, cybercriminals leaked 50 million records on the dark web containing sensitive personal information.
-
"Xerox Confirms Data Breach at US Subsidiary Following Ransomware Attack"Printing solutions giant Xerox recently confirmed that its US-based subsidiary Xerox Business Solutions experienced a data breach.
-
"CISA Warns of Actively Exploited Bugs in Chrome and Excel Parsing Library"The US Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities to the Known Exploited Vulnerabilities (KEV) catalog.
-
"29 Malware Families Target 1,800 Banking Apps Worldwide"According to Zimperium, the rise in mobile banking is accompanied by a significant increase in financial fraud. Zimperium's research found that 29 malware families targeted 1,800 banking apps in 61 countries last year.
-
"Malware Using Google MultiLogin Exploit to Maintain Access Despite Password Reset"Malware that steals information is exploiting an undocumented Google OAuth endpoint called MultiLogin to hijack user sessions and enable continuous access to Google services even if a password is reset.
-
"Understanding the Escalating Threat of Web DDoS Tsunami Attacks"According to Uri Dorot, senior security solutions lead at Radware, a new breed of destructive Distributed Denial-of-Service (DDoS) attacks, called the Web DDoS Tsunami, is causing significant problems worldwide.
-
"Hackers Use LinkedIn to Target UK Nuclear Waste Firm"According to The Guardian, cybercriminals have targeted Radioactive Waste Management (RWM) through a spear phishing campaign involving LinkedIn.
-
"Hacktivists Shut Down Top State-Owned Belarusian News Agency"The Belarusian Cyber-Partisans hacktivist group shut down the country's leading state-owned media outlet, the Belarusian Telegraph Agency (BelTA), claiming to have wiped the news organization's website servers and backups.