News
-
"LockBit and Clop Responsible for About 40% Of Ransomware Attacks"Last month, 475 ransomware attacks were observed, according to Flashpoint's June Cyber Threat Intelligence Report. Most of these attacks, 97 in total, were carried out by LockBit. Clop followed with the launch of 91 attacks. They accounted for around 40…
-
"Owner of Cybercrime Website BreachForums Pleads Guilty"The owner of the infamous cybercrime website BreachForums has recently pleaded guilty in a US court to conspiracy to commit device fraud, access device fraud, and possession of child pornography. The man, Conor Brian Fitzpatrick, 21, of Peekskill,…
-
"Sorillus RAT and Phishing Attacks Exploit Google Firebase Hosting"According to security researchers at eSentire, attackers have been observed using the notorious Sorillus remote access trojan (RAT) and phishing attacks to exploit Google Firebase Hosting infrastructure. The researchers stated that the attackers…
-
"Rogue Azure AD Guests Can Steal Data via Power Apps"Guest accounts in Azure AD (AAD) provide external third parties with limited access to corporate resources. The objective is to facilitate collaboration without excessive risk of exposure. However, enterprises may inadvertently overshare access to…
-
"CERT-UA Uncovers Gamaredon's Rapid Data Exfiltration Tactics Following Initial Compromise"Gamaredon, a threat actor with connections to Russia, was observed conducting data exfiltration operations within an hour of the initial compromise. As a vector of primary compromise, emails and messages in messengers (i.e., Telegram, WhatsApp, Signal)…
-
"Thousands of Images on Docker Hub Leak Auth Secrets, Private Keys"Researchers from the RWTH Aachen University in Germany have published a study revealing tens of thousands of container images hosted on Docker Hub containing confidential secrets, exposing software, online platforms, and users to attacks. Docker Hub is a…
-
"Critical XSS Vulnerability in Zimbra Exploited in the Wild"Attackers are exploiting a critical cross site scripting (XSS) vulnerability tracked as CVE-2023-34192 in the open source email collaboration suite Zimbra. The vulnerability could enable an authenticated remote threat actor to execute arbitrary code via…
-
"MOVEit Hack: Number of Impacted Organizations Exceeds 340"Brett Callow, a threat analyst at Emsisoft, has been monitoring the MOVEit attack carried out by a notorious cybercrime gang, and he is currently aware of 347 impacted organizations, including 58 educational institutions in the United States. …
-
"Researchers at NHL Stenden Launch Database That Exposes Cyber Hacking in the Worldwide Maritime Industry"A team of researchers led by Dr. Stephen McCombie, Professor of Maritime Information Technology (IT) Security at NHL Stenden University of Applied Sciences, have created the Maritime Cyber Attack Database (MCAD), which consists of incidents involving the…
-
"Three Grove School Faculty Join $12 Million Google Cybersecurity Research Project"The City College of New York is participating in a $12 million Google initiative aimed at boosting the cybersecurity ecosystem and positioning New York City as the global leader in cybersecurity. Other institutions involved in the Google Cyber NYC…
-
"New Members to Enhance CyManII's Mission to Support"The University of Texas at San Antonio-based Cybersecurity Manufacturing Innovation Institute (CyManII) welcomes three new members to support its mission to secure and sustain US manufacturing. Each member will contribute to the institute's efforts to…
-
"picoCTF-Africa Sees Significant Growth in Competition's Second Year"Cybersecurity remains a global concern, with a lack of skilled professionals worsening the problem. Therefore, Carnegie Mellon's picoCTF-Africa, a computer security competition for high school, undergraduate, and graduate students on the African…