News
-
"Dormant Accounts Are a Low-Hanging Fruit for Attackers"According to Oort, zero-day flaws are no longer required for successful system attacks, as threat actors increasingly focus on compromising identities through techniques such as evading multi-factor authentication (MFA), hijacking sessions, and brute-…
-
"Dish Network Confirms Ransomware Outage"Satellite television company Dish Network has recently revealed that ransomware was the cause of a multi-day outage impacting customers. The Colorado-headquartered firm, which also owns wireless service provider Boost Mobile and streaming provider…
-
"New MortalKombat Ransomware Decryptor Recovers Your Files for Free"Bitdefender has released a free decryptor for the MortalKombat ransomware that victims can use to recover their files without paying the demanded ransom. The release of a functional decryptor for the strain follows its emergence in January 2023, when…
-
"Pernicious Permissions: How Kubernetes Cryptomining Became an AWS Cloud Data Heist"A vulnerable Kubernetes container and weak permissions enabled an adversary to transform an opportunistic cryptojacking attack into a widespread invasion impacting intellectual property and sensitive data. The attack, dubbed "SCARLETEEL" by the cloud…
-
"BlackLotus Becomes First UEFI Bootkit Malware to Bypass Secure Boot on Windows 11"BlackLotus, a stealthy Unified Extensible Firmware Interface (UEFI) bootkit, is the first publicly known malware that can circumvent Secure Boot protections, making it a major cyber threat. According to a report by ESET, this bootkit can operate on…
-
"Clemson University Joins Nation's Frontline Defense against Cyberattacks on the Transportation System"Clemson University is opening a National Center where researchers will develop new methods to bolster the transportation system security against cyberattacks. The new National Center for Transportation Cybersecurity and Resilience (TraCR) will receive a…
-
"How ChatGPT Can Help Cybersecurity Pros Beat Attacks"There has been much discussion about how hackers might benefit from ChatGPT, the OpenAI-trained Artificial Intelligence (AI) chatbot, but it is important to also examine how cybersecurity experts can use this tool. In 2022, the Large Language Model (LLM…
-
"CISA Red Team Shares Key Findings to Improve Monitoring and Hardening of Networks"The US Homeland Security Department's Cybersecurity and Infrastructure Security Agency (CISA) has released a Cybersecurity Advisory (CSA) titled "CISA Red Team Shares Key Findings to Improve Monitoring and Hardening of Networks," describing a red team…
-
"State-Sponsored Hackers Are Diversifying Tactics, Targeting Small Businesses"According to SonicWall's 2023 Cyber Threat Report, state-sponsored threat actors are shifting their attention toward small and midsize businesses (SMBs). While large companies, public services, and crucial national infrastructure have historically been…
-
"88 Percent of Organizations Have Suffered Cyber Breaches in the Last Two Years"Pentera surveyed 300 CIOs, CISOs, and security leaders from businesses in Europe and the US, revealing that a cyberattack had impacted 88 percent of organizations over the past two years. The Pentera study finds that this is the case despite companies…
-
"US Gov. Agencies Have 30 Days to Remove TikTok, Canada Follows Suit"The White House has given federal agencies 30 days to remove TikTok from all government-issued devices following the December 2022 ban on the social media app. The announcement comes from Shalanda Young, director of the office of management and…
-
"Vulnerabilities Being Exploited Faster Than Ever: Analysis"Security researchers at Rapid7 discovered that in 2022, the widespread exploitation of new vulnerabilities was down 15% over the previous year, zero-day attacks declined 52% from 2021, and there were 33% fewer vulnerabilities known to have been exploited…