News
-
"Microsoft Teams Targeted in Midnight Blizzard Phishing Attacks"Microsoft Threat Intelligence has recently announced that it detected a series of highly targeted social engineering attacks employing credential theft phishing lures delivered as Microsoft Teams chats. Microsoft stated that these attacks have been…
-
"Google Awards Over $60,000 for V8 Vulnerabilities Patched With Chrome 115 Update"Google recently announced a Chrome 115 update that patches 17 vulnerabilities, including 11 flaws reported by external researchers. Google noted that the browser update resolves three high-severity type confusion bugs in the V8 JavaScript and…
-
"U.S. and International Cybersecurity Partners Warn Organizations of Routinely Exploited Vulnerabilities"The Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), the Federal Bureau of Investigation (FBI), and international cybersecurity partners have published an advisory on the Common Vulnerabilities and Exposures (…
-
"Python Versions of Stealer Malware Discovered Targeting Facebook Business Accounts"Researchers have discovered a previously unknown phishing campaign that targets Facebook business accounts and distributes two variants of a Python-written infostealer. Palo Alto Networks Unit 42 reported finding Python variants of the NodeStealer…
-
"Salesforce Email Service Zero-Day Exploited in Phishing Campaign"According to security researchers at Guardio, threat actors have exploited a Salesforce zero-day vulnerability and abused Meta features in a sophisticated phishing campaign. Attackers sent out legitimate-looking emails designed to lure targeted…
-
"OWASP Top 10 for LLM (Large Language Model) Applications"The Open Worldwide Application Security Project (OWASP) has released the "OWASP Top 10 for Large Language Model (LLM) Applications" list, which highlights the most critical vulnerabilities impacting LLM applications. The project aims to educate…
-
"Humans Unable to Reliably Detect Deepfake Speech"Researchers from the University College London (UCL) have discovered that humans cannot detect deepfake speech 27% of the time. During the study, the researchers presented 529 individuals with genuine and deepfake audio samples and asked them to…
-
"NSA Releases Guide to Harden Cisco Next Generation Firewalls"The National Security Agency (NSA) has issued a new Cybersecurity Technical Report (CTR) titled "Cisco Firepower Hardening Guide" to help network and system administrators configure these next generation firewalls (NGFWs). The CTR covers properly…
-
"Tesla Jailbreak Unlocks Theft of In-Car Paid Features"Tesla cars are vulnerable to a nearly irreversible jailbreak of their onboard infotainment systems, which would enable owners to gain access to a variety of paid in-car features for free. According to a team of researchers, the stolen benefits can range…
-
"Russian APT Phished Government Employees via Microsoft Teams"Microsoft reports that an Advanced Persistent Threat (APT) group with ties to Russia's Foreign Intelligence Service has used Microsoft Teams to launch phishing attacks against employees of dozens of global organizations. To host and execute their social…
-
"'Mysterious Team Bangladesh' Targeting India with DDoS Attacks and Data Breaches"Since June 2022, the hacktivist group Mysterious Team Bangladesh has been linked to more than 750 Distributed Denial-of-Service (DDoS) attacks and 78 website defacements. According to Group-IB, the group primarily targets logistics, government, and…
-
"Over 640 Citrix Servers Backdoored With Web Shells in Ongoing Attacks"Hundreds of Citrix Netscaler ADC and Gateway servers have been compromised and backdoored in a series of attacks targeting a critical Remote Code Execution (RCE) flaw, tracked as CVE-2023-3519. The vulnerability has been exploited as a zero-day to breach…