News
-
"Torrent of Image-Based Phishing Emails Are Harder to Detect and More Convincing"A torrent of image-based phishing emails has been released. They contain QR codes to bypass security protections and provide a level of customization that makes it easier to deceive recipients. In many cases, the emails are sent from a compromised email…
-
"miniOrange's WordPress Social Login and Register Plugin Was Affected by a Critical Auth Bypass Bug"Wordfence researchers have found a vulnerability in miniOrange's WordPress Social Login and Register plugin that allows an unauthenticated attacker to gain access to any account on a website by knowing the associated email address. Instead of requiring…
-
"Russian Satellite Telecom Dozor Allegedly Hit by Hackers"Hackers aligned with the Private Military Corporation (PMC) Wagner attacked Dozor-Teleport, a satellite communications provider used by Russia's Ministry of Defense and security services. Attackers targeted the infrastructure of the satellite…
-
"Medtronic Fixes Critical Flaw in Cardiac Device Data System"Medtronic's heart monitor data management system contains a vulnerability of critical severity that, if exploited, could lead to Remote Code Execution (RCE) or a Denial-of-Service (DoS) condition. The deserialization of untrusted data flaw, tracked as…
-
"200,000 WordPress Sites Exposed to Attacks Exploiting Flaw in ‘Ultimate Member’ Plugin"Over 200,000 WordPress websites have recently been exposed to ongoing attacks targeting a critical vulnerability in the Ultimate Member plugin. The plugin is designed to make it easy for users to register and log in on sites and allows site owners…
-
"Researcher Outlines Known RFC Vulnerabilities in SAP Software That Lead to Unauthenticated Remote Code Execution"A researcher has identified what he deems to be several critical vulnerabilities impacting enterprise software solutions operating on ubiquitous SAP platforms. In a paper presented at a recent European cybersecurity conference, Fabian Hagg describes his…
-
"LockBit Claims TSMC Hack, Demands $70m Ransom"National Hazard Agency, a sub-group of the LockBit ransomware gang, has recently posted the name of Taiwan Semiconductor Manufacturing Company (TSMC), the world’s largest chip manufacturer, on LockBit’s dark web leak site on June 29, 2023. The…
-
"Pro-Russia DDoSia Hacktivist Project Sees 2,400% Membership Increase"The pro-Russia crowdsourced Distributed Denial-of-Service (DDoS) project called "DDoSia" has grown 2,400 percent in less than a year, with thousands of people participating in the launch of attacks against Western organizations. The project was initiated…
-
"Fluhorse: Flutter-Based Android Malware Targets Credit Cards and 2FA Codes"Cybersecurity researchers have shared details regarding the "Fluhorse" Android malware family. According to Fortinet FortiGuard Labs, the malware represents a significant transition because it includes malicious components directly within the Flutter…
-
"CyberSentry Program Launches Webpage"CyberSentry is a US Cybersecurity and Infrastructure Security Agency (CISA)-managed capability for threat detection and monitoring, governed by an agreement between CISA and voluntarily participating critical infrastructure partners that operate major…
-
"6 Ways Cybersecurity Is Gut-Checking the ChatGPT Frenzy"Generative Artificial Intelligence (AI), ChatGPT, OpenAI, and Large Language Models (LLMs) are now almost daily topics of conversation within the cybersecurity community. Some small and large security vendors have incorporated AI chatbots into their…
-
"Global Rise in DDoS Attacks Threatens Digital Infrastructure"According to Nexusguard, the total number of Distributed Denial-of-Service (DDoS) attacks increased by 115.1 percent in 2022 compared to 2021 globally. The data also revealed that attackers continued to change their threat vectors by focusing on Internet…