News
-
"Cybersecurity Performance Goals: Assessing How CPGs Help Organizations Reduce Cyber Risk"The Cybersecurity and Infrastructure Security Agency (CISA) released the Cybersecurity Performance Goals (CPGs) in October 2022 to help organizations of all sizes and levels of cyber maturity gain confidence in their cybersecurity posture and reduce bu
-
"Russian Hackers Use Old Outlook Vulnerability to Target Polish Orgs"The Polish Cyber Command has warned that the Russian state-backed hacking group Forest Blizzard, also known as Fancy Bear and APT28, has been targeting public and private entities in Poland by exploiting a known Microsoft Outlook vulnerability, tracked
-
"Warning for iPhone Users: Experts Warn of Sneaky Fake Lockdown Mode Attack"Malicious actors can use a new "post-exploitation tampering technique" to trick a target into thinking their Apple iPhone is in Lockdown Mode when it is not, allowing them to perform covert attacks.
-
"WordPress Bug 'Patch' Installs Backdoor for Full Site Takeover"Attackers are targeting WordPress users with a fake security alert about a Remote Code Execution (RCE) flaw. The alert offers a "patch" that actually spreads malicious code capable of hijacking a site.
-
"US Federal Agencies Miss Deadline for Incident Response Requirements"According to the US Goverment Acountability Office (GAO), although US federal agencies have made progress in preparing for and responding to cyber threats, too many have failed to meet the deadline to implement incident response capabilities required b
-
"SpyLoan Android Malware on Google Play Downloaded 12 Million Times"Over a dozen malicious loan apps, collectively known as SpyLoan, have been downloaded more than 12 million times from Google Play this year, but the total is much higher because they are also available on third-party stores and suspicious websites.
-
"Unpatched Loytec Building Automation Flaws Disclosed 2 Years After Discovery"Security researchers at industrial cybersecurity firm TXOne Networks have disclosed the details of 10 unpatched vulnerabilities discovered in building automation products made by Austrian company Loytec more than two years ago.
-
"94 Vulnerabilities Patched in Android With December 2023 Security Updates"Google recently announced that the December 2023 Android security updates deliver patches for 94 vulnerabilities. The first part of the updates resolves 33 vulnerabilities in Android's Framework and System components.
-
"HYAS Infosec Groundbreaking Research on AI-Generated Malware Contributes to the AI Act, Other AI Policies and Regulations"Research from HYAS Infosec's HYAS Labs is contributing to the European Union's Artificial Intelligence (AI) Act. The AI Act is an initiative helping to shape the trajectory of AI governance, with US policies and considerations to follow soon.
-
"Malvertising Attacks Rely on DanaBot Trojan to Spread CACTUS Ransomware"Microsoft discovered ongoing malvertising attacks involving the use of the DanaBot Trojan to spread CACTUS ransomware. Microsoft linked the campaign to Storm-0216, also known as Twisted Spider and UNC2198.
-
"Blue Shield of California Discloses Data Breach, Number of Members Impacted Unclear"It has recently been revealed that data on Blue Shield of California members may have been exposed due to a vulnerability in the MOVEit file transfer platform. The insurer was notified on Sept.
-
"AI Models Wide Open to Cyberattacks, Analyst Warns"According to Lasso Security researchers, while HuggingFace and GitHub developer platforms are important for developing Artificial Intelligence (AI) technologies, they also expose top-level organization accounts from Google, Meta, Microsoft, and VMware