News
-
"Android Zero-Day Patched With September 2023 Security Updates"Google recently announced that Android's September 2023 security updates contain patches for 32 vulnerabilities, including one that has been exploited in attacks. Tracked as CVE-2023-35674, the zero-day flaw is described as a high-severity…
-
"Thousands of Popular Websites Leaking Secrets"Security researchers at Truffle Security warn that thousands of the domains in the Alexa top 1 million websites list are leaking secrets, including credentials. The researchers noted that 4,500 of the analyzed websites exposed their .git directory…
-
"MITRE & CISA Release Open-Source MITRE Caldera Extension for Operational Technology"MITRE Caldera for OT is now publicly available as an extension to the open-source Caldera platform, enabling security teams to conduct automated adversary emulation exercises focused on Operational Technology (OT) threats. The first Caldera for OT…
-
"Avoidable Digital Certificate Issues Fuel Data Breaches"According to a report by AppViewX and Forrester Consulting, of the organizations that have experienced data breaches, 58 percent were due to problems with digital certificates. Fifty-seven percent revealed that their organizations have incurred…
-
"Researchers Discover Critical Vulnerability in PHPFusion CMS"Researchers have discovered what they describe as a critical vulnerability in the open-source Content Management System (CMS) PHPFusion, which is widely used. The vulnerability, tracked as CVE-2023-2453, is an authenticated local file inclusion flaw that…
-
"W3LL Phishing Kit Hijacks Thousands of Microsoft 365 Accounts, Bypasses MFA"A threat actor known as W3LL developed a phishing kit to circumvent multi-factor authentication (MFA) and other tools. Over 8,000 Microsoft 365 corporate accounts have been compromised by the phishing kit. In ten months, security researchers discovered…
-
"Phishing Campaigns Deliver New SideTwist Backdoor and Agent Tesla Variant"The Iranian threat actor APT34 has been linked to a new phishing attack that deploys a variant of the SideTwist backdoor. According to NSFOCUS Security Labs, APT34 has a high level of attack technology, the ability to design different intrusion methods…
-
"Carmakers Are Failing the Privacy Test. Owners Have Little or No Control Over Data Collected"A new study reveals that most major car makers acknowledge they may be selling users' personal information. However, they are vague about the buyers. Half of them would share such information with the government or law enforcement without a court order.…
-
"Crypto Casino Stake[.]com Back Online After $40m Heist"Hackers have recently stolen over $40m in cryptocurrency from Curaçao-headquartered Stake[.]com, which offers casino and sports betting for players using cryptocurrency. The firm noted that on Monday, it had spotted unauthorized transactions being…
-
"Better Cybersecurity With New Material"Encryption is the most common method for protecting information. Information is encrypted using a Random Number Generator (RNG), which can be a computer program or the hardware itself. The RNG provides the keys to encrypt and unlock information at the…
-
"Scammers Can Abuse Security Flaws in Email Forwarding to Impersonate High-Profile Domains"Due to flaws in the process that enables email forwarding, it is easier than previously believed to send an email with a forged address, according to a research team led by computer scientists from the University of California San Diego. The issues…
-
"VU Researcher to Develop New Framework for Data Privacy & Utility"Dr. Yongfeng (Felix) Ge of Victoria University will develop an evolutionary computation-based framework to optimize privacy and utility issues associated with data storage and publishing. Recent large-scale data breaches in Australia, which resulted in…