News
-
"NSA Publishes 2023 Cybersecurity Year in Review"The National Security Agency (NSA) has released its 2023 Cybersecurity Year in Review, covering its recent cybersecurity successes as well as how it is collaborating with partners to deliver on cybersecurity advances aimed at improving national securit
-
"SSH Vulnerability Exploitable in Terrapin Attacks"Security researchers at Ruhr-Universität Bochum discovered a flaw in the SSH cryptographic network protocol that could enable an attacker to reduce the security of the SSH connection by truncating the extension negotiation message.
-
"Unsung GitHub Features Anchor Novel Hacker C2 Infrastructure"Researchers have discovered a GitHub account abusing two different features of the website to host stage-two malware.
-
"Double-Extortion Play Ransomware Strikes 300 Organizations Worldwide"According to a new joint cybersecurity advisory from the US and Australia, the threat actors behind the Play ransomware are estimated to have hit about 300 entities as of October 2023.
-
"More Than 26,000 Vulnerabilities Discovered in 2023"According to security researchers at Qualys Threat Research Unit (TRU), a total of 26,447 vulnerabilities were disclosed in 2023, surpassing the previous year by over 1500 CVEs.
-
"FBI Disrupts BlackCat Ransomware Operation, Creates Decryption Tool"According to the US Department of Justice (DOJ), the FBI successfully breached the BlackCat/ALPHV ransomware operation's servers to monitor activities and obtain decryption keys.
-
"Xfinity Customer Data Compromised in Attack Exploiting CitrixBleed Vulnerability"Comcast’s Xfinity recently announced that customer information had been compromised in a cyberattack that involved exploitation of the vulnerability known as CitrixBleed.
-
"A Computer Scientist Explains How QR Codes Work and What Makes Them Dangerous"There are security risks associated with QR codes, which are graphical representations of digital data that can be printed and later scanned by a smartphone or other device.
-
"Researchers Find Zero-Victim Method to Block Scammers' Websites"Researchers at Palo Alto Networks' Unit 42 developed a Machine Learning (ML) model that feeds on "crumbs of information" left by malicious actors and detects tens of thousands of malicious domains each week before they are used for illegal activities.
-
"Novel SMTP Smuggling Technique Slips Past DMARC, Email Protections"A novel way to exploit a decades-old protocol that has been used to send emails allows attackers to bypass Domain-based Message Authentication, Reporting, and Conformance (DMARC) and other email security mechanisms, putting organizations and individual
-
"Enabling Threat-Informed Cybersecurity: Evolving CISA's Approach to Cyber Threat Information Sharing"The US Cybersecurity and Infrastructure Security Agency (CISA) will launch a strategic effort to modernize its approach to enterprise cyber threat information-sharing in 2024.
-
"CISA Urges Manufacturers Eliminate Default Passwords to Thwart Cyber Threats"The US Cybersecurity and Infrastructure Security Agency (CISA) urges manufacturers to eliminate default passwords on Internet-connected systems, citing serious risks that malicious actors could exploit to gain initial access to and move laterally