News
-
"Threat Actors Favor Rclone, WinSCP and cURL as Data Exfiltration Tools"The top three data exfiltration tools used by threat actors between September 2023 and July 2024 were Rclone, WinSCP, and cURL, according to ReliaQuest. Data exfiltration may involve threat actor–owned infrastructure or third-party cloud services.
-
"Vulnerability Allowed Eavesdropping via Sonos Smart Speakers"NCC Group researchers discovered vulnerabilities in Sonos smart speakers, including a flaw that could have enabled attackers to eavesdrop on users.
-
"CISA Warns About Actively Exploited Apache OFBiz RCE Flaw"The US Cybersecurity and Infrastructure Security Agency (CISA) warns of two vulnerabilities, including a path traversal flaw affecting Apache OFBiz.
-
"Phishing Attack Exploits Google, WhatsApp to Steal Data"Researchers at Menlo Security found a sophisticated phishing campaign that exploits users' trust in Google Drawings and WhatsApp.
-
"Warnings Issued Over Cisco Device Hacking, Unpatched Vulnerabilities"The US Cybersecurity and Infrastructure Security Agency (CISA) is warning organizations about threat actors targeting improperly configured Cisco devices.
-
"Cost of a Data Breach: The Healthcare Industry"The "2024 Cost of Data Breach Study" by IBM and the Ponemon Institute details the financial costs of cyberattacks across different industries.
-
"Iran Is Targeting the US Election With Fake News Sites and Cyber Operations, Research Says"With the goal of creating division, Iran is adding to Russia’s and China’s efforts to sow distrust and chaos in the upcoming US election. Iran has been using websites and social media feeds directed to both politically left and right voters.
-
"Malware Force-Installs Chrome Extensions on 300,000 Browsers, Patches DLLs"ReasonLabs researchers discovered a malware campaign that forced the installation of malicious Google Chrome and Microsoft Edge browser extensions in more than 300,000 browsers, modifying the browser's executables to take over homepages and steal brows
-
"Ransomware in 2024: More Attacks, More Leaks, and Increased Sophistication"Rapid7's "Ransomware Radar Report 2024" highlights key findings from the analysis of visible leak sites, ransomware code, and underground forum chatter.
-
"Ethical Hackers Steal and Return $12m to Ronin Network"A popular Ethereum blockchain, which was the victim of the largest ever crypto-heist back in 2022, recently suffered a $12m loss but had the stolen funds returned by ethical hackers.
-
"BlackSuit/Royal Ransomware Group Has Demanded $500m"The US Cybersecurity and Infrastructure Security Agency (CISA) has recently discovered that a prolific ransomware group has demanded more than $500m from its victims in less than two years.
-
"ADT Confirms Data Breach After Customer Info Leaked on Hacking Forum"American building security giant ADT recently confirmed it suffered a data breach after threat actors leaked allegedly stolen customer data on a popular hacking forum.