News
-
"Cybercriminals Increasingly Using EvilProxy Phishing Kit to Target Executives"There has been an increase in the use of a Phishing-as-a-Service (PhaaS) toolkit called EvilProxy by threat actors to conduct account takeover attacks targeting high-ranking executives at well-known companies. According to Proofpoint, an ongoing hybrid…
-
"Hackers Use Open-Source Merlin Post-Exploitation Toolkit in Attacks"Ukraine warns of a wave of attacks using Merlin, an open-source post-exploitation and command-and-control (C2) framework, against state organizations. Merlin is a Go-based, cross-platform post-exploitation toolkit that is freely available via GitHub and…
-
"White House Launches AI Cyber Challenge to Make Software More Secure"The Biden-Harris Administration has launched a two-year competition to protect the most critical software in the US using Artificial Intelligence (AI). The AI Cyber Challenge (AIxCC) calls on competitors across the US to identify and fix software…
-
"'MoustachedBouncer' APT Spies on Embassies, Likely via ISPs"An Advanced Persistent Threat (APT) group with ties to Belarus spied on staff in at least four embassies operating in the country, most likely by abusing the country's local Internet Service Provider (ISP). According to malware researcher Matthieu Faou…
-
"MITRE and Robust Intelligence Tackle AI Supply Chain Risks in Open-Source Models"MITRE is collaborating with Robust Intelligence, a provider of Artificial Intelligence (AI) solutions, to improve a free tool that helps organizations assess the supply chain risks of publicly available AI models online. Indiana University is also…
-
"Five Papers by CSE Researchers Presented at USENIX Security 2023"Computer Science and Engineering (CSE) researchers from the University of Michigan are presenting their papers at the 32nd USENIX Security Symposium. The university has compiled a list of papers authored by the CSE researchers being presented at the…
-
"Balada Injector Still at Large – New Domains Discovered"Cybernews researchers found an address that shed light on WordPress-orientated "hack waves" caused by the Balada Injector malware. Evidence indicates that the malware is still highly active, evading security software by using new domain names and small…
-
"LockBit Threatens to Leak Medical Data of Cancer Patients Stolen From Varian Medical Systems"The LockBit ransomware group claims to have targeted the healthcare company Varian Medical Systems, Inc. The group threatens to leak cancer patients' medical records stolen from the healthcare company. Varian Medical Systems, Inc. designs, manufactures,…
-
"Summer Spending Pressure Fuels Loan Fee Fraud Fears"The UK’s financial regulatory recently warned consumers to be on the lookout for loan fee fraudsters after revealing new research claiming that many Brits are worried about their finances this summer. The Financial Conduct Authority (FCA) said it…
-
"How Randomized Data Can Improve Our Security"Technical devices have two essential units to process data: a processor and Random Access Memory (RAM). Since memory is much slower at providing data than the processor is at processing it, modern processors use a cache to function as a bridge between…
-
"Ukraine Says It Thwarted Attempt to Breach Military Tablets"The SBU, Ukraine's security service, thwarted a Russian state-controlled hacking group's attempt to break into the Ukrainian military's battlefield management system. A recently published technical report reveals that Russian hackers attempted to infect…
-
"Breach Connected to MOVEit Flaw Affects Missouri Medicaid Recipients"The Missouri Department of Social Services (DSS) recently issued an alert urging residents to safeguard their personal information following a cyberattack originating from a data security breach at IBM Consulting in May 2023. DSS stated that this…