News
-
"Researchers Release Details of New RCE Exploit Chain for SharePoint"The researchers who discovered two critical vulnerabilities in Microsoft SharePoint Server have disclosed details of an exploit they created that combines the vulnerabilities to enable Remote Code Execution (RCE) on impacted servers.
-
"LockBit 3.0 Most Active Ransomware Gang in August"According to data from NCC Group, LockBit 3.0 was responsible for the most ransomware attacks in August of this year. Of the month's 390 ransomware attacks, 125 were carried out by LockBit 3.0 hackers, representing a 150 percent increase from July.
-
"Google Rushes to Patch New Zero-Day Exploited by Spyware Vendor"Google has recently rushed to patch another Chrome zero-day vulnerability exploited by a commercial spyware vendor. Google announced that Chrome for Windows, macOS, and Linux has been updated to version 117.0.5938.132.
-
"Remote Workers Are More Aware of Cybersecurity Risks Than In-Office Employees: New Study"According to a new peer-reviewed study by researchers from Miami University and Kent State University, remote employees tend to be more aware of cybersecurity threats and more likely to take preventative measures than those who spend most of their time
-
"ORNL Launches Center for AI Security Research to Study AI's Impacts on Society, Security"The Department of Energy's (DOE) Oak Ridge National Laboratory (ORNL) has announced the establishment of the Center for Artificial Intelligence (AI) Security Research (CAISER) to address existing threats as governments and industries worldwide adopt AI
-
"Vulnerability in Popular 'libwebp' Code More Widespread Than Expected"Cybersecurity experts warn that the scope of a previously disclosed vulnerability impacting various web applications is broader than initially reported.
-
"DarkBeam Leaks Billions of Email and Password Combinations"DarkBeam, a digital risk protection company, exposed records containing user emails and passwords from previously reported and unreported data breaches by leaving an Elasticsearch and Kibana interface unprotected.
-
"Misconfigured TeslaMate Instances Put Tesla Car Owners at Risk"According to security researchers at Redinent, misconfigured TeslaMate instances can leak tons of data on the internet, potentially exposing Tesla cars and their drivers to malicious attacks.
-
"U.S. and Japanese Agencies Issue Advisory about China Linked Actors Hiding in Router Firmware"A joint Cybersecurity Advisory (CSA) titled "People's Republic of China-Linked Cyber Actors Hide in Router Firmware" regarding the activities of the BlackTech cyber actor group has been released by the National Security Agency (NSA), Federal Bure
-
"Hackers Trick Outlook into Showing Fake AV Scans"Threat actors are using an existing technique of zero-point font obfuscation in a novel way to trick Microsoft Outlook users into thinking antivirus scans have successfully vetted phishing emails.
-
"GitHub Repos Bombarded by Info-Stealing Commits Masked as Dependabot"To steal authentication secrets and credentials from developers, hackers are compromising GitHub accounts and inserting malicious code disguised as Dependabot contributions.
-
"New ZenRAT Malware Targeting Windows Users via Fake Password Manager Software"A new malware strain called ZenRAT is distributed via fake installation packages of the Bitwarden password manager. According to Proofpoint researchers, the malware is a modular Remote Access Trojan (RAT) capable of stealing information.