News
-
"New Cyberespionage Campaign Targeting ISPs, Research Entities"ESET researchers have spotted a cyberespionage campaign involving a previously undocumented Korplug variant by the Mustang Panda Advanced Persistent Threat (APT) group. The campaign takes advantage of the war in Ukraine and other European news…
-
"Serious Vulnerability Exploited at Hacking Contest Impacts Over 200 HP Printers"HP has announced that over 200 of its printer models are impacted by a critical Remote Code Execution (RCE) vulnerability disclosed by researchers at the Pwn2Own hacking contest in 2021. The security vulnerability, tracked as CVE-2022-3942, is described…
-
"Bigger Demands, Bigger Payouts Are the Trend in Ransomware, Report Says"Palo Alto Networks’ Unit 42 conducted an analysis of ransomware attacks launched in 2021, finding that large and highly organized cybercrime groups such as Conti are contributing to the increase in the overall cost of ransomware attacks. Cases handled by…
-
"Security Teams are Responsible for Over 165k Asset"Security researchers at JupiterOne have discovered that stretched IT security teams threaten to become overwhelmed by the number of assets they must defend, especially those in the cloud. The security researchers analyzed 370 million assets at nearly 1,…
-
"US and Canada Collaborate to Tackle Cybercrime"The United States and Canada held talks on Tuesday to explore how the countries could collaborate better to counter cross-border illegal activity, including cybercrime. During the meeting, the countries have agreed to work together to improve…
-
"Is a Security Feature on the Way That Makes Computing Faster?"The multiple programs running simultaneously on a device depend on data stored in the device's memory hardware. However, sensitive information may not be shared among all the programs, thus leaving the device exposed to a memory timing side-channel…
-
"CISA, FBI Warn Critical Infrastructure of SATCOM Cyber Threats"The US Homeland Security Department's Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) released a joint advisory warning critical infrastructure organizations about cyber risks associated with…
-
"Pen Testing Tools Increasingly Used by Threat Actors"A recent report from the Managed Detection and Response (MDR) firm Red Canary brings further attention to the use of legitimate penetration testing tools such as Cobalt Strike, Impacket, and RMM by threat actors. Malicious actors have found it to be more…
-
"FBI: Cybercrime Reports Saw 'Unprecedented' Rise Last Year, Costing Nearly $7B"The FBI's Internet Crime Complaint Center (IC3) collects cybercrime complaints and received 847,376 of them last year, with estimated potential losses totaling $6.9 billion, a 64% increase from 2020. The total number of crime reports tallied by the…
-
"Fastest Ransomware Encrypts 100k Files in Four Minutes"A new study by researchers at Splunk has found that network defenders have just 43 minutes to mitigate ransomware attacks once encryption has begun. The security monitoring and data analytics vendor evaluated the speed at which 10 ransomware…
-
"100,000 Google Play Users Infected With Android Password-Stealing Malware"A malicious Android app has been downloaded more than 100,000 times from the Google Play Store. The Android password-stealing malware called FaceStealer is disguised as a cartoonifier app, Craftsart Cartoon Photo Tools. According to security experts…
-
"Vulnerabilities Found in Popular Open-Source Projects on GitHub Could Impact Millions"Cycode researchers discovered critical vulnerabilities in several popular open-source projects that could lead to a supply chain attack through the Continuous Integration (CI) process. According to the researchers, the vulnerabilities exist in…