CrowdStrike Reveals Root Cause of Global System Outages

07/08/2024 0 Comments 0 tags

Cybersecurity company CrowdStrike has published its root cause analysis detailing the Falcon Sensor software update crash that crippled millions of Windows devices globally. The “Channel File 291” incident, as originally

New Go-based Backdoor GoGra Targets South Asian Media Organization

07/08/2024 0 Comments 0 tags

An unnamed media organization in South Asia was targeted in November 20233 using a previously undocumented Go-based backdoor called GoGra. “GoGra is written in Go and uses the Microsoft Graph

INTERPOL Recovers $41 Million in Largest Ever BEC Scam in Singapore

06/08/2024 0 Comments 0 tags

INTERPOL said it devised a “global stop-payment mechanism” that helped facilitate the largest-ever recovery of funds defrauded in a business email compromise (BEC) scam.  The development comes after an unnamed

North Korean Hackers Moonstone Sleet Push Malicious JS Packages to npm Registry

06/08/2024 0 Comments 0 tags

The North Korea-linked threat actor known as Moonstone Sleet has continued to push malicious npm packages to the JavaScript package registry with the aim of infecting Windows systems, underscoring the

Suspicious Minds: Insider Threats in The SaaS World

06/08/2024 0 Comments 0 tags

Everyone loves the double-agent plot twist in a spy movie, but it’s a different story when it comes to securing company data. Whether intentional or unintentional, insider threats are a

New Android Spyware LianSpy Evades Detection Using Yandex Cloud

06/08/2024 0 Comments 0 tags

Users in Russia have been the target of a previously undocumented Android post-compromise spyware called LianSpy since at least 2021. Cybersecurity vendor Kaspersky, which discovered the malware in March 2024,

Google Patches New Android Kernel Vulnerability Exploited in the Wild

06/08/2024 0 Comments 0 tags

Google has addressed a high-severity security flaw impacting the Android kernel that it has been actively exploited in the wild. The vulnerability, tracked as CVE-2024-36971, has been described as a

New Zero-Day Flaw in Apache OFBiz ERP Allows Remote Code Execution

06/08/2024 0 Comments 0 tags

A new zero-day pre-authentication remote code execution vulnerability has been disclosed in the Apache OFBiz open-source enterprise resource planning (ERP) system that could allow threat actors to achieve remote code

The Loper Bright Decision: How it Impacts Cybersecurity Law

05/08/2024 0 Comments 0 tags

The Loper Bright decision has yielded impactful results: the Supreme Court has overturned forty years of administrative law, leading to potential litigation over the interpretation of ambiguous laws previously decided

Kazakh Organizations Targeted by ‘Bloody Wolf’ Cyber Attacks

05/08/2024 0 Comments 0 tags

Organizations in Kazakhstan are the target of a threat activity cluster dubbed Bloody Wolf that delivers a commodity malware called STRRAT (aka Strigoi Master). “The program selling for as little