News
-
"Iranian Hackers Breach US Aviation Org via Zoho, Fortinet Bugs"The US Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and the US Cyber Command (USCYBERCOM) published a joint advisory revealing that state-sponsored hacking groups exploited critical Zoho and Fortinet vulnerabilities to compromise a…
-
"Weaponized Windows Installers Target Graphic Designers in Crypto Heist"A cryptocurrency-mining campaign targeting 3D modelers and graphic designers with malicious versions of a legitimate Windows installer tool has been ongoing since at least November 2021. According to a report by Cisco Talos Threat Researcher Chetan…
-
"Apple Rushes to Patch Zero-Day Flaws Exploited for Pegasus Spyware on iPhones"Apple has released emergency security updates for iOS, iPadOS, macOS, and watchOS to patch two zero-day vulnerabilities exploited in the wild to deliver NSO Group's Pegasus mercenary spyware. The first vulnerability, tracked as CVE-2023-41061, is a…
-
"Trustwave Releases New SpiderLabs Research Focused on Actionable Cybersecurity Intelligence for the Hospitality Industry"In a report titled "2023 Hospitality Sector Threat Landscape: Trustwave Threat Intelligence Briefing and Mitigation Strategies," Trustwave shares research on the cybersecurity risks faced by the hospitality industry. Trustwave SpiderLabs has documented…
-
"Exposing Deepfake Imagery"Deepfakes, or images and videos created or altered by Artificial Intelligence (AI), are becoming increasingly sophisticated, causing widespread concern among scientists, journalists, and government officials. Rushit Dave, a computer scientist at…
-
"Hiding Undetected: Why Security Teams Can No Longer Overlook HTTPS Decryption"Decrypting HTTPS (TLS/SSL) traffic at the network perimeter is crucial in the protection against malware and other online threats. Much of today's web traffic is encrypted, offering a hiding place for threat actors to deliver cyberattacks. Many network…
-
"Emerging Cyber Threats in 2023 From AI to Quantum to Data Poisoning"As hackers gain access to new technologies and devise novel exploits for old vulnerabilities, the nature of the threats is constantly changing. According to the 2023 Comcast Business Cybersecurity Threat Report, nine out of ten attempts to compromise…
-
"AI Abuse Grows Beyond Phishing to Multistage Cyberattacks"Researchers predict that cybercriminals' abuse of Artificial Intelligence (AI) will soon lead to an influx of automated and multistage cyberattacks. Attack data collected between May and July indicate that cybercriminals are increasingly using social…
-
"Cl0p Study Sheds Light on Rising Ransom Gang"Mayank Sahariya, a cyber threat intelligence researcher at FalconFeeds[.]io, notes that among the many ransomware families that have launched attacks against businesses, institutions, and individuals, Cl0p stands out for its advanced techniques and…
-
"See Tickets Alerts 300,000 Customers After Another Web Skimmer Attack"Ticketing services agency See Tickets recently notified more than 300,000 individuals that their payment card data was stolen in a new web skimmer attack. Owned by Vivendi SA, See Tickets provides ticketing services for a broad range of event types…
-
"UK and US Sanction 11 Russians Connected to Notorious Trickbot Group"Authorities in the US and UK have sanctioned 11 Russian nationals alleged to have been part of the criminal group responsible for the Trickbot malware and Conti ransomware schemes. According to the US Treasury, the sanctioned individuals include key…
-
"Chinese Cyberspies Obtained Microsoft Signing Key From Windows Crash Dump Due to a Mistake"Microsoft announced in July that it had mitigated an email-targeting attack by a threat actor with ties to China, tracked as Storm-0558. Storm-0558 threat actors have been observed conducting cyber espionage, data theft, and credential access attacks…