News
-
"Adobe Patch Tuesday: Critical Bugs in Acrobat, Reader, ColdFusion"Adobe recently rolled out a massive batch of security fixes to cover critical-severity flaws in its Acrobat and Reader, ColdFusion, inDesign, inCopy, and Audition products.
-
"82% of Attacks Show Cybercriminals Targeting Telemetry Data"According to security researchers at Sophos, cybercriminals have been observed disabling or wiping out logs in 82% of incidents. The researchers stated that time is critical when responding to an active threat.
-
"CacheWarp: CISPA Researchers Discover New Security Vulnerability in AMD SEV Technology"AMD developed Secure Encrypted Virtualization (SEV) to make its cloud services more secure, but even the latest versions of the security feature, SEV-ES (Encrypted State) and SEV-SNP (Secure Nested Paging), were vulnerable to a software-based attack.
-
"22 Energy Firms Hacked in Largest Coordinated Attack on Denmark’s Critical Infrastructure"Non-profit cybersecurity center for critical sectors SektorCERT recently revealed that hackers compromised 22 energy organizations in a coordinated attack against Denmark’s critical infrastructure.
-
"DHS Cybersecurity and Infrastructure Security Agency Releases Roadmap for Artificial Intelligence"The US Cybersecurity and Infrastructure Security Agency (CISA) has released its first Roadmap for Artificial Intelligence (AI), adding to the Department of Homeland Security (DHS) and broader whole-of-government initiative to ensure the se
-
"Molerats Group Wields Custom Cybertool to Steal Secrets in the Middle East"TA402, also known as Molerats and Frankenstein, a pro-Palestinian cyber espionage group focused on compromising government targets in the Middle East, is using a sophisticated initial access downloader.
-
"Juniper Networking Devices Under Attack"The US Cybersecurity and Infrastructure Security Agency (CISA) requires US federal agencies to patch five vulnerabilities exploited by attackers to compromise Juniper networking devices.
-
"Meet the Unique New 'Hacking' Group: AlphaLock"Researchers have discovered a new hacking group named "AlphaLock," which presents itself as a "pentesting training organization" that provides training to hackers and then monetizes their services through a dedicated affiliate program.
-
"OracleIV DDoS Botnet Targets Public Docker Engine APIs to Hijack Containers"Threat actors are targeting publicly accessible Docker Engine Application Programming Interface (API) instances as part of a campaign to co-opt the machines into the OracleIV Distributed Denial-of-Service (DDoS) botnet.
-
"Royal Ransomware Possibly Rebranding After Targeting 350 Organizations Worldwide"Since its inception, the Royal ransomware gang has targeted at least 350 organizations worldwide, with ransom demands exceeding $275 million.
-
"In a First, Cryptographic Keys Protecting SSH Connections Stolen in New Attack"Researchers have demonstrated for the first time that a large portion of the cryptographic keys used to protect data in computer-to-server SSH traffic are vulnerable to complete compromise when natural computational errors happen during the establishin
-
"Gone Phishing: Hackers Leverage Automation to Launch MFA Attacks and SEO Poisoning"With new automation tools, cybercriminals can now exploit users in many new ways, but at least two stand out as particularly concerning this year: Multi-Factor Authentication (MFA) attacks and Search Engine Optimization (SEO) poisoning.