New Frontiers, Old Tactics: Chinese Espionage Group Targets Africa & Caribbean Govts

23/05/2024 0 Comments 0 tags

The China-linked threat actor known as Sharp Panda has expanded their targeting to include governmental organizations in Africa and the Caribbean as part of an ongoing cyber espionage campaign. “The

The End of an Era: Microsoft Phases Out VBScript for JavaScript and PowerShell

23/05/2024 0 Comments 0 tags

Microsoft on Wednesday outlined its plans to deprecate Visual Basic Script (VBScript) in the second half of 2024 in favor of more advanced alternatives such as JavaScript and PowerShell. “Technology

Ivanti Patches Critical Remote Code Execution Flaws in Endpoint Manager

23/05/2024 0 Comments 0 tags

Ivanti on Tuesday rolled out fixes to address multiple critical security flaws in Endpoint Manager (EPM) that could be exploited to achieve remote code execution under certain circumstances. Six of

Inside Operation Diplomatic Specter: Chinese APT Group’s Stealthy Tactics Exposed

23/05/2024 0 Comments 0 tags

Governmental entities in the Middle East, Africa, and Asia are the target of a Chinese advanced persistent threat (APT) group as part of an ongoing cyber espionage campaign dubbed Operation Diplomatic

Are Your SaaS Backups as Secure as Your Production Data?

23/05/2024 0 Comments 0 tags

Conversations about data security tend to diverge into three main threads: How can we protect the data we store on our on-premises or cloud infrastructure? What strategies and tools or

Rockwell Advises Disconnecting Internet-Facing ICS Devices Amid Cyber Threats

22/05/2024 0 Comments 0 tags

Rockwell Automation is urging its customers to disconnect all industrial control systems (ICSs) not meant to be connected to the public-facing internet to mitigate unauthorized or malicious cyber activity. The

Researchers Warn of Chinese-Aligned Hackers Targeting South China Sea Countries

22/05/2024 0 Comments 0 tags

Cybersecurity researchers have disclosed details of a previously undocumented threat group called Unfading Sea Haze that’s believed to have been active since 2018. The intrusion singled out high-level organizations in South China

The Ultimate SaaS Security Posture Management Checklist, 2025 Edition

22/05/2024 0 Comments 0 tags

Since the first edition of The Ultimate SaaS Security Posture Management (SSPM) Checklist was released three years ago, the corporate SaaS sprawl has been growing at a double-digit pace. In large enterprises,

GHOSTENGINE Exploits Vulnerable Drivers to Disable EDRs in Cryptojacking Attack

22/05/2024 0 Comments 0 tags

Cybersecurity researchers have discovered a new cryptojacking campaign that employs vulnerable drivers to disable known security solutions (EDRs) and thwart detection in what’s called a Bring Your Own Vulnerable Driver (BYOVD) attack.

Critical Veeam Backup Enterprise Manager Flaw Allows Authentication Bypass

22/05/2024 0 Comments 0 tags

Users of Veeam Backup Enterprise Manager are being urged to update to the latest version following the discovery of a critical security flaw that could permit an adversary to bypass