News
-
"US Military Targeted in Recent HiatusRAT Attack"According to security researchers at Lumen, a recent HiatusRAT campaign has been targeting a US military procurement system for reconnaissance. Initially observed at the beginning of the year, HiatusRAT has been targeting high-bandwidth routers…
-
"Australian Energy Software Firm Energy One Hit by Cyberattack"Energy One, an Australian company that provides software products and services to the energy sector, has recently been hit by a cyberattack. In a statement issued on Monday, the company said the incident was detected on August 18, impacting some…
-
"Juniper Networks Fixes Flaws Leading To RCE in Firewalls and Switches"Juniper Networks has patched four vulnerabilities, tracked as CVE-2023-36844, CVE-2023-36845, CVE-2023-36846, and CVE-2023-36847, in Junos OS that, if chained, could enable Remote Code Execution (RCE) on the company's SRX firewalls and EX switches. Junos…
-
"New Variant of XLoader macOS Malware Disguised as 'OfficeNote' Productivity App"A new variant of the macOS malware XLoader has emerged, masking its malicious capabilities with the office productivity app OfficeNote. The new version of XLoader is packaged within a standard Apple disk image named "OfficeNote[.]dmg," according to an…
-
"Chinese APT Targets Hong Kong in Supply Chain Attack"Researchers have discovered that an emerging China-backed Advanced Persistent Threat (APT) group dubbed Carderbee targeted Hong Kong organizations in a supply chain attack involving legitimate software to deploy the PlugX/Korplug backdoor. The Symantec…
-
"TP-Link Smart Bulbs Can Let Hackers Steal Your Wi-Fi Password"Researchers from Universita di Catania and the University of London have discovered four vulnerabilities in the TP-Link Tapo L530E smart bulb and the TP-Link Tapo app that could enable attackers to steal the Wi-Fi password of their target. The TP-Link…
-
"Spoofing an Apple Device and Tricking Users Into Sharing Sensitive Data"At the DEF CON hacker conference, white hat hackers demonstrated how to spoof an Apple device and deceive users into divulging sensitive information. Conference attendees who use iPhones saw pop-up messages prompting them to connect their Apple ID or…
-
"Software Must Be Secure by Design, and Artificial Intelligence Is No Exception"In discussions about Artificial Intelligence (AI), the functioning of an AI system is often shrouded in mystery. However, the truth is much simpler as AI is a software system. According to the Cybersecurity and Infrastructure Security Agency's (CISA)…
-
"Thousands of Illicit Cyber Networks Disrupted in Africa Operation"INTERPOL and AFRIPOL coordinated an operation across 25 African countries that led to the arrest of 14 suspected cybercriminals and the identification of 20,674 suspicious cyber networks, underscoring the rise of digital insecurity and cyber threats in…
-
"CISA Conducts Largest Annual Election Security Drills Amid Threats Targeting Voting Systems"The Cybersecurity and Infrastructure Security Agency (CISA) recently led the largest annual election security exercise in the US, collaborating with the Justice Department, the FBI, and other federal participants to strengthen voting systems in the US.…
-
"FBI, Air Force Warn of Cyberattacks on Space Industry by 'Foreign Intelligence Operations'"According to US intelligence agencies, unnamed Foreign Intelligence Entities (FIEs) are escalating cyberattacks against US-based space companies. The FBI, the National Counterintelligence and Security Center (NCSC), and the Air Force Office of Special…
-
"Ivanti Ships Urgent Patch for API Authentication Bypass Vulnerability"Ivanti’s problems with security defects in its enterprise-facing products are starting to pile up. The IT software company recently shipped urgent patches for a critical-severity vulnerability in the Ivanti Sentry (formerly MobileIron Sentry)…