News
-
"A Repository of Common Penetration Testing Weaknesses"Marisa Midler and Samantha Chaves, penetration testers with the Carnegie Mellon Software Engineering Institute's (SEI) Computer Emergency Response Team (CERT), have introduced a repository of penetration testing findings that is now publicly accessible…
-
"ASU Researcher Bridges Security and AI"The many advancements in Artificial Intelligence (AI) show that the technology is critical. In the realm of national security, experts are taking note of the impact of AI on the collective defense strategy. Paulo Shakarian, an associate professor of…
-
"No Evidence Ransomware Victims With Cyber Insurance Pay Up More Often, UK Report Says"According to new research on the role of the insurance industry in driving the criminal ecosystem, there is no "compelling evidence" that victims of ransomware attacks with cyber insurance are more likely to make extortion payments than those without…
-
"Google: 'Vulnerabilities Persist Too Long on Android'"Google has published its annual report regarding zero-day vulnerabilities. In the report, Google's Threat Analysis Group (TAG) notes that patches are often unavailable to Android users for too long. The research group discovered 41 zero-day…
-
"Administration Launches National Cyber Workforce and Education Strategy to Address Cyber Workforce Needs"The Biden-Harris Administration has unveiled the National Cyber Workforce and Education Strategy (NCWES) to address immediate and long-term cyber workforce needs. Filling the many cyber positions in the US is a national security imperative. The NCWES…
-
"Hackers Exploit BleedingPipe RCE to Target Minecraft Servers, Players"It has recently been discovered that hackers are actively exploiting a "BleedingPipe" remote code execution vulnerability in Minecraft mods to run malicious commands on servers and clients, allowing them to take control of the devices. BleedingPipe…
-
"Android Malware Steals User Credentials Using Optical Character Recognition"Researchers have uncovered malicious Android apps that use optical character recognition to steal credentials displayed on smartphone screens. The malware, dubbed CherryBlos by Trend Micro security researchers, has been embedded in at least four Android…
-
"FBI Says AI Is Making It Easier for Hackers to Write Malware"The FBI has further emphasized that Artificial Intelligence (AI) helps nearly every aspect of cybercriminal activity, from development to deployment, and this trend is continuing. On a recent media call, an FBI official suggested that free, customizable…
-
"Weintek Weincloud Vulnerabilities Allowed Manipulation, Damaging of ICS Devices"Security researchers at TXOne Networks have discovered that several vulnerabilities in a Weintek product could have been exploited to manipulate and damage industrial control systems (ICS). The security holes impact Taiwan-based Weintek's Weincloud…
-
"Hackers Threaten to Auction off DNA Patient Records From Oklahoma Hospital"The Karakurt ransomware group is targeting the McAlester Regional Health Center in Oklahoma, claiming to have stolen over 126 GB of data from the facility, including DNA patient records. Karakurt announced its plans to publish samples and auction 117 GB…
-
"AVRecon Botnet Leveraging Compromised Routers to Fuel Illegal Proxy Service"TheAVRecon botnet has been observed using compromised small office/home office (SOHO) routers since at least May 2021 as part of a multi-year campaign. Lumen Black Lotus Labs disclosed AVRecon earlier this month as malware capable of executing additional…
-
"Linux Version of Abyss Locker Ransomware Targets VMware ESXi Servers"The Abyss Locker operation has developed a Linux encryptor that targets VMware's ESXi Virtual Machine (VM) platform for enterprise-level attacks. As businesses migrate from individual servers to VMs for improved resource management, performance, and…