News
-
"AndroxGh0st Malware Targets Laravel Apps to Steal Cloud Credentials"Researchers have detailed "AndroxGh0st," a tool used to target Laravel applications and steal sensitive data. It scans and extracts important information from .env files, revealing login information for Amazon Web Services (AWS) and Twilio.
-
"Fake Data Breaches: Countering the Damage"Vitaly Simonovich, a threat intelligence researcher at Cato Networks, points out that even a fake data breach can have serious consequences.
-
"House Passes Bill Barring Sale of Personal Information to Foreign Adversaries"The House of Representatives recently passed new legislation prohibiting data brokers from selling Americans' personal information to foreign adversary countries or entities under their control.
-
"Hackers Claim to Have Breached Israeli Nuclear Facility's Computer Network"An Iran-linked hacking group claims to have infiltrated a sensitive Israeli nuclear facility's computer network in an incident described by the hackers as a protest against the war in Gaza.
-
"Evasive Sign1 Malware Campaign Infects 39,000 WordPress Sites"The website security company Sucuri discovered a malware campaign dubbed "Sign1" that has infected more than 39,000 WordPress websites in the last six months, causing visitors to get unwanted redirects and popup ads.
-
"AWS Fixes 1-Click Apache Airflow Session Hijack Flaw"Amazon Web Services (AWS) Managed Workflows for Apache Airflow (MWAA) had a vulnerability that enabled session hijacking with a single click.
-
"Siemens, Other Vendors Patch Critical ICS Product Vulnerabilities"The US Cybersecurity and Infrastructure Security Agency (CISA) recently released 15 advisories addressing serious vulnerabilities in industrial control products from Siemens, Mitsubishi Electric, Delta Electronics, and more.
-
"Microsoft Patches Xbox Vulnerability Following Public Disclosure"Microsoft has recently released a patch for an Xbox vulnerability after initially telling the reporting researcher that it was not a security issue. The vulnerability is tracked as CVE-2024-2891, and it impacts Xbox Gaming Services.
-
"How AI Can Be Hacked With Prompt Injection: NIST Report"In "Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations," the National Institute of Standards and Technology (NIST) defines different Adversarial Machine Learning (AML) tactics and cyberattacks, as well as provides guida
-
"RaaS Groups Increasing Efforts to Recruit Affiliates"According to GuidePoint Security, smaller Ransomware-as-a-Service (RaaS) groups are trying to recruit new and "displaced" LockBit and Alphv/BlackCat affiliates by offering better payout splits, full-time support, and more.
-
"'Fluffy Wolf' Spreads Meta Stealer in Corporate Phishing Campaign"A threat actor, tracked as "Fluffy Wolf," is spreading different types of malware using accounting report lures in a phishing campaign that relies on malicious and legitimate software.
-
"Study Uncovers 27% Spike in Ransomware; 8% Yield to Demands"According to the 2024 Thales Data Threat Report, ransomware attacks increased by 27 percent in 2023, with 8 percent of impacted organizations deciding to pay the demanded ransom.