Security Flaw in Styra’s OPA Exposes NTLM Hashes to Remote Attackers

22/10/2024 0 Comments 0 tags

Details have emerged about a now-patched security flaw in Styra’s Open Policy Agent (OPA) that, if successfully exploited, could have led to leakage of New Technology LAN Manager (NTLM) hashes.

A Comprehensive Guide to Finding Service Accounts in Active Directory

22/10/2024 0 Comments 0 tags

Service accounts are vital in any enterprise, running automated processes like managing applications or scripts. However, without proper monitoring, they can pose a significant security risk due to their elevated

Malicious npm Packages Target Developers’ Ethereum Wallets with SSH Backdoor

22/10/2024 0 Comments 0 tags

Cybersecurity researchers have discovered a number of suspicious packages published to the npm registry that are designed to harvest Ethereum private keys and gain remote access to the machine via

Bumblebee and Latrodectus Malware Return with Sophisticated Phishing Strategies

22/10/2024 0 Comments 0 tags

Two malware families that suffered setbacks in the aftermath of a coordinated law enforcement operation called Endgame have resurfaced as part of new phishing campaigns. Bumblebee and Latrodectus, which are

VMware Releases vCenter Server Update to Fix Critical RCE Vulnerability

22/10/2024 0 Comments 0 tags

VMware has released software updates to address an already patched security flaw in vCenter Server that could pave the way for remote code execution. The vulnerability, tracked as CVE-2024-38812 (CVSS

CISA Adds ScienceLogic SL1 Vulnerability to Exploited Catalog After Active Zero-Day Attack

22/10/2024 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical security flaw impacting ScienceLogic SL1 to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation

Chinese Nation-State Hackers APT41 Hit Gambling Sector for Financial Gain

21/10/2024 0 Comments 0 tags

The prolific Chinese nation-state actor known as APT41 (aka Brass Typhoon, Earth Baku, Wicked Panda, or Winnti) has been attributed to a sophisticated cyber attack targeting the gambling and gaming

THN Cybersecurity Recap: Top Threats, Tools and News (Oct 14 – Oct 20)

21/10/2024 0 Comments 0 tags

Hi there! Here’s your quick update on the latest in cybersecurity. Hackers are using new tricks to break into systems we thought were secure—like finding hidden doors in locked houses.

Guide:  The Ultimate Pentest Checklist for Full-Stack Security

21/10/2024 0 Comments 0 tags

Pentest Checklists Are More Important Than Ever Given the expanding attack surface coupled with the increasing sophistication of attacker tactics and techniques, penetration testing checklists have become essential for ensuring

Researchers Discover Severe Security Flaws in Major E2EE Cloud Storage Providers

21/10/2024 0 Comments 0 tags

Cybersecurity researchers have discovered severe cryptographic issues in various end-to-end encrypted (E2EE) cloud storage platforms that could be exploited to leak sensitive data. “The vulnerabilities range in severity: in many