News
  • "IBM Patches High-Severity Vulnerabilities in Cloud, Voice, Security Products"
    IBM recently announced patches for multiple high-severity vulnerabilities impacting products such as Netezza for Cloud Pak for Data, Voice Gateway, and SiteProtector.  Three vulnerabilities were resolved in IBM Netezza for Cloud Pak for Data, all of…
  • "Microsoft Publishes Office Symbols to Improve Bug Hunting"
    Microsoft Office has started publishing Office symbols for Windows to help bug hunters find and report security issues.  Microsoft noted that symbols are pieces of information used during debugging and are contained within Symbol files, which are…
  • "IBM Makes Open-Source Tookit Available to Fight Software Supply Chain Attacks"
    In most cases, IBM's X-Force Red ethical hacking team has been able to gain access to Source Code Management (SCM) systems in an adversary simulation engagement. Access to SCM systems provides attackers with opportunities for software supply chain…
  • "Meta Stops Two Cyberespionage Activities in South Asia"
    Meta, Facebook's parent company, took action earlier this year against two cross-platform cyberespionage operations that relied on multiple websites for malware distribution. Bitter APT is the first hacking group that Meta shut down in the second quarter…
  • "Phishers Swim Around 2FA in Coinbase Account Heists"
    In a recently observed phishing campaign aimed at taking over Coinbase accounts and defrauding users of their cryptocurrency balances, threat actors are circumventing two-factor authentication (2FA) and employing other evasion tactics. Coinbase is a…
  • "deBridge Finance Crypto Platform Targeted by Lazarus Hackers"
    Hackers linked to the North Korean Lazarus group attempted to steal cryptocurrency from deBridge Finance, a cross-chain protocol that allows for the decentralized transfer of assets between blockchains. The threat actor tricked company employees into…
  • "Chinese Hackers Targeted Dozens of Industrial Enterprises and Public Institutions"
    Since January 2022, over a dozen military-industrial complex enterprises and public institutions in Afghanistan and Europe have been targeted to steal confidential data using six different backdoors. The attacks were attributed "with a high degree of…
  • "10 Malicious Code Packages Slither into PyPI Registry"
    Following notification from a security vendor, administrators of the Python Package Index (PyPI) removed ten malicious software code packages from the registry. The incident is the most recent in a long line of recent instances in which threat actors…
  • "Open Redirect Flaws in American Express and Snapchat Exploited in Phishing Attacks"
    Security researchers at Inky have discovered that open redirect vulnerabilities affecting American Express and Snapchat websites were exploited earlier this year as part of phishing campaigns targeting Microsoft 365 users.  The researchers noted…
  • "Cyberattacks on Healthcare Organizations Negatively Impact Patient Care"
    Security researchers at Cynerio and the Ponemon Institute have recently studied the current impact of cyberattacks on healthcare facilities and network-connected IoT and medical devices and found multiple alarming trends.  The researchers surveyed…
  • "7-Eleven Closes Stores in Denmark After Cyberattack"
    US convenience store chain 7-Eleven on Monday, August 8th, had to close its outlets in Denmark after a suspected cyberattack knocked out their cash tills.  In a statement, the company noted that all 175 7-Elevens in Denmark could not use the cash…
  • "Twilio Hacked After Employees Tricked Into Giving Up Login Credentials"
    Enterprise software vendor Twilio has recently been hacked by a relentless threat actor who successfully tricked employees into giving up login credentials that were then used to steal third-party customer data.  The company did not provide details…