News
-
"Malicious AI Arrives on the Dark Web"Malicious non-state actors are using Artificial Intelligence (AI) to amplify their malicious activities. Since the release of OpenAI's ChatGPT last year, there has been much discussion on the dark web about methods involving this technology. Dark web…
-
"Hacking Group KittenSec Claims to 'Pwn Anything We See' to Expose Corruption"In the past month, a hacking group known as "KittenSec" claims to have attacked government and private sector computer systems in multiple NATO countries, arguing that it is exposing corruption. KittenSec is part of a line of groups hacking government…
-
"Fraudsters Can Bypass Biometric Facial Recognition"Organizations are increasingly implementing biometrics to streamline and expedite authentication. However, Stuart Wells, CTO of the biometrics authentication company Jumio, identifies potential threats and methods fraudsters may use to circumvent facial…
-
"More Than 3,000 Openfire Servers Exposed to Attacks Using a New Exploit"Vulncheck researchers found over 3,000 Openfire servers vulnerable to attacks due to a path traversal flaw, tracked as CVE-2023-32315. Openfire is a widely used Java-based open-source chat server maintained by Ignite Realtime. The vulnerability impacts…
-
"University of Minnesota Confirms Data Breach, Says Ransomware Not Involved"The University of Minnesota has recently confirmed that a threat actor has exfiltrated data from its systems but says no malware infection was identified. The confirmation comes one month after a threat actor boasted about accessing the university’…
-
"NIST to Standardize Encryption Algorithms That Can Resist Attack by Quantum Computers"Four quantum-resistant algorithms were chosen by the National Institute of Standards and Technology (NIST) last year. The agency has now begun the process of standardizing these algorithms, which is the last step before making these mathematical tools…
-
"Data of 2.6 Million Duolingo Users Leaked on Hacking Forum"Data from 2.6 million users of Duolingo, a language learning platform with over 74 million monthly users, was leaked on a hacking forum. The compromised data, which includes real names, login names, email addresses, and internal service-related…
-
"FBI: Unplug Exploited Barracuda ESG Appliances Now"The FBI has advised Barracuda customers who are still using the vendor's vulnerable Email Security Gateway (ESG) to remove the appliance from operation. Many of the appliances were hit in a zero-day attack discovered in May. The attack was attributed to…
-
"New Telegram Bot 'Telekopye' Powering Large-scale Phishing Scams from Russia"A new operation motivated by financial gain involves a malicious Telegram bot to help threat actors scam their victims. The Telekopye toolkit automates creating a phishing website from a template and sending the URL to potential victims. According to…
-
"North Korea's Lazarus APT Uses GUI Framework to Build Stealthy RAT"In recent attacks targeting healthcare organizations and an Internet infrastructure company, the North Korean state-sponsored cyber threat group Lazarus launched a new highly evasive Remote Access Trojan (RAT) called "QuiteRAT." QuiteRAT is an upgraded…
-
"Lack of Visibility Into Cloud Access Policies Leaves Enterprises Flying Blind"According to Strata Identity, the top security concern in multi-cloud environments is fragmented access policies, as more than 75 percent of enterprises reported not knowing where applications are deployed or who has access to them. Since last year, the…
-
"New Whiffy Recon Malware Uses Wi-Fi to Triangulate Your Location"Cybercriminals responsible for the Smoke Loader botnet are using new malware called Whiffy Recon to triangulate the location of infected devices through Wi-Fi scanning and Google's geolocation Application Programming Interface (API). Google's geolocation…