60 New Malicious Packages Uncovered in NuGet Supply Chain Attack

12/07/2024 0 Comments 0 tags

Threat actors have been observed publishing a new wave of malicious packages to the NuGet package manager as part of an ongoing campaign that began in August 2023, while also

Palo Alto Networks Patches Critical Flaw in Expedition Migration Tool

12/07/2024 0 Comments 0 tags

Palo Alto Networks has released security updates to address five security flaws impacting its products, including a critical bug that could lead to an authentication bypass. Cataloged as CVE-2024-5910 (CVSS

New Poco RAT Targets Spanish-Speaking Victims in Phishing Campaign

11/07/2024 0 Comments 0 tags

Spanish language victims are the target of an email phishing campaign that delivers a new remote access trojan (RAT) called Poco RAT since at least February 2024. The attacks primarily

Streamlined Security Solutions: PAM for Small to Medium-sized Businesses

11/07/2024 0 Comments 0 tags

Today, all organizations are exposed to the threat of cyber breaches, irrespective of their scale. Historically, larger companies were frequent targets due to their substantial resources, sensitive data, and regulatory

Chinese APT41 Upgrades Malware Arsenal with DodgeBox and MoonWalk

11/07/2024 0 Comments 0 tags

The China-linked advanced persistent threat (APT) group codenamed APT41 is suspected to be using an “advanced and upgraded version” of a known malware called StealthVector to deliver a previously undocumented

PHP Vulnerability Exploited to Spread Malware and Launch DDoS Attacks

11/07/2024 0 Comments 0 tags

Multiple threat actors have been observed exploiting a recently disclosed security flaw in PHP to deliver remote access trojans, cryptocurrency miners, and distributed denial-of-service (DDoS) botnets. The vulnerability in question

GitLab Patches Critical Flaw Allowing Unauthorized Pipeline Jobs

11/07/2024 0 Comments 0 tags

GitLab has shipped another round of updates to close out security flaws in its software development platform, including a critical bug that allows an attacker to run pipeline jobs as

New Ransomware Group Exploiting Veeam Backup Software Vulnerability

10/07/2024 0 Comments 0 tags

A now-patched security flaw in Veeam Backup & Replication software is being exploited by a nascent ransomware operation known as EstateRansomware. Singapore-headquartered Group-IB, which discovered the threat actor in early

True Protection or False Promise? The Ultimate ITDR Shortlisting Guide

10/07/2024 0 Comments 0 tags

It’s the age of identity security. The explosion of driven ransomware attacks has made CISOs and security teams realize that identity protection lags 20 years behind their endpoints and networks.

Microsoft’s July Update Patches 143 Flaws, Including Two Actively Exploited

10/07/2024 0 Comments 0 tags

Microsoft has released patches to address a total of 143 security flaws as part of its monthly security updates, two of which have come under active exploitation in the wild.