News
-
"XSS Vulnerabilities Found in WordPress Plugin Slider Revolution"Security researchers at Patstack conducted a security audit recently of the Slider Revolution plugin and uncovered two significant vulnerabilities that could compromise the security of WordPress websites. Slider Revolution is a widely used premium
-
"Okta Warns of Credential Stuffing Attacks Targeting Its CORS Feature"Okta, a leading Identity and Access Management (IAM) company, warns that since April, credential stuffing attacks have targeted a Customer Identity Cloud (CIC) feature.
-
"Sonatype Exposes Malicious PyPI Package 'Pytoileur'"Sonatype has disclosed the malicious PyPI package "Pytoileur," which is designed to download and install trojanized Windows binaries that are capable of surveillance, commandeering persistence, and stealing cryptocurrency.
-
"34% of Organizations Lack Cloud Cybersecurity Skills"According to Cado Security, current incident response is too time-consuming and manual, leaving organizations vulnerable to cyber threats.
-
"First American December Data Breach Impacts 44,000 People"First American Financial Corporation, the second-largest title insurance company in the United States, recently revealed that a December cyberattack led to a breach impacting 44,000 individuals.
-
"US Sanctions Three Chinese Men for Operating 911 S5 Botnet"The Treasury Department recently announced sanctions against three Chinese nationals accused of creating and operating a botnet named 911 S5. The Treasury's Office of Foreign Assets Control (OFAC) has designated Yunhe Wang, Jingping Liu, and Yanni
-
"Internet Archive Disrupted by Sustained and 'Mean' DDoS Attack"The Internet Archive has been hit with Distributed Denial-of-Service (DDoS) attacks. The non-profit research library offers free access to millions of historical documents, preserved websites, and media content.
-
"New North Korean Threat Actor Engaging in Espionage, Revenue Generation Attacks"Microsoft reports that a new North Korean threat actor called "Moonstone Sleet" (formerly "Storm-1789") is attacking education, the Defense Industrial Base (DIB), Information Technology (IT) companies, and more to conduct espionage and generate r
-
"NIST Launches ARIA, a New Program to Advance Sociotechnical Testing and Evaluation for AI"The National Institute of Standards and Technology (NIST) is launching a Testing, Evaluation, Validation, and Verification (TEVV) program to improve understanding of Artificial Intelligence (AI) capabilities and impacts.
-
"US Government Sanctions Cybercrime Gang Behind Massive 911 S5 Botnet"The US Treasury Department sanctioned three Chinese nationals and three Thailand-based companies linked to a botnet controlling a residential proxy service called "911 S5." About two years ago, researchers at the Canadian University of Sherbrooke disco