News
-
"CISA: Second SharePoint Flaw Disclosed at Pwn2Own Exploited in Attacks"CISA recently added a second SharePoint flaw, demonstrated last year at a Pwn2Own hacking competition, to its Known Exploited Vulnerabilities (KEV) list.
-
"Hackers Exploit Ray Framework Flaw to Breach Servers, Hijack Resources"A new hacking campaign called "ShadowRay" exploits an unpatched vulnerability in Ray, a popular open source Artificial Intelligence (AI) framework, to hijack computing power and leak sensitive data.
-
"Malicious NuGet Package Linked to Industrial Espionage Targets Developers"Researchers at ReversingLabs have discovered a suspicious package in the NuGet package manager that is likely aimed at developers using tools developed by a Chinese company specializing in industrial and digital equipment manufacturing.
-
"Researchers Discover 40,000-Strong EOL Router, IoT Botnet"Security researchers at Lumen Technologies recently discovered a 40,000-strong botnet packed with end-of-life routers and IoT devices being used in cybercriminal activities.
-
"US Targets Crypto Firms Aiding Russia Sanctions Evasion"The US government is trying to close gaps in its sanctions program against Russia by going after blockchain and virtual currency firms, which it says have helped entities circumvent existing controls.
-
"Apple Patches Code Execution Vulnerability in iOS, macOS"Apple has recently released fresh security updates for iOS and macOS devices to resolve an arbitrary code execution vulnerability.
-
Science of Security Virtual InstitutesThe Science of Security (SoS) initiative has announced its newest iteration of collaborative academic research, th
-
"CISA Seeks to Curtail 'Unforgivable' SQL Injection Defects"Supply chains are facing SQL injection vulnerabilities, which have prompted a joint warning from the US Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) to develop safer software products.
-
"US Treasury Slaps Sanctions on China-Linked APT31 Hackers"The U.S. government recently announced a fresh round of sanctions against a pair of Chinese hackers, who are said to be responsible for “malicious cyber operations targeting U.S. entities that operate within U.S.
-
"New Tycoon 2FA Phishing Kit Raises Cybersecurity Concerns"The Sekoia Threat Detection and Research (TDR) team discovered a new phishing kit called "Tycoon 2FA" in October 2023.