Massive Sign1 Campaign Infects 39,000+ WordPress Sites with Scam Redirects

22/03/2024 0 Comments 0 tags

A massive malware campaign dubbed Sign1 has compromised over 39,000 WordPress sites in the last six months, using malicious JavaScript injections to redirect users to scam sites. The most recent variant of

Implementing Zero Trust Controls for Compliance

22/03/2024 0 Comments 0 tags

The ThreatLocker® Zero Trust Endpoint Protection Platform implements a strict deny-by-default, allow-by-exception security posture to give organizations the ability to set policy-based controls within their environment and mitigate countless cyber threats, including

China-Linked Group Breaches Networks via Connectwise, F5 Software Flaws

22/03/2024 0 Comments 0 tags

A China-linked threat cluster leveraged security flaws in Connectwise ScreenConnect and F5 BIG-IP software to deliver custom malware capable of delivering additional backdoors on compromised Linux hosts as part of

U.S. Justice Department Sues Apple Over Monopoly and Messaging Security

22/03/2024 0 Comments 0 tags

The U.S. Department of Justice (DoJ), along with 16 other state and district attorneys general, on Thursday accused Apple of illegally maintaining a monopoly over smartphones, thereby undermining, among others, security and

Russian Hackers Target Ukrainian Telecoms with Upgraded ‘AcidPour’ Malware

22/03/2024 0 Comments 0 tags

The data wiping malware called AcidPour may have been deployed in attacks targeting four telecom providers in Ukraine, new findings from SentinelOne show. The cybersecurity firm also confirmed connections between the malware

Making Sense of Operational Technology Attacks: The Past, Present, and Future

21/03/2024 0 Comments 0 tags

When you read reports about cyber-attacks affecting operational technology (OT), it’s easy to get caught up in the hype and assume every single one is sophisticated. But are OT environments

GitHub Launches AI-Powered Autofix Tool to Assist Devs in Patching Security Flaws

21/03/2024 0 Comments 0 tags

GitHub on Wednesday announced that it’s making available a feature called code scanning autofix in public beta for all Advanced Security customers to provide targeted recommendations in an effort to avoid introducing

How to Accelerate Vendor Risk Assessments in the Age of SaaS Sprawl

21/03/2024 0 Comments 0 tags

In today’s digital-first business environment dominated by SaaS applications, organizations increasingly depend on third-party vendors for essential cloud services and software solutions. As more vendors and services are added to

AndroxGh0st Malware Targets Laravel Apps to Steal Cloud Credentials

21/03/2024 0 Comments 0 tags

Cybersecurity researchers have shed light on a tool referred to as AndroxGh0st that’s used to target Laravel applications and steal sensitive data. “It works by scanning and taking out important information from

Over 800 npm Packages Found with Discrepancies, 18 Exploitable to ‘Manifest Confusion’

21/03/2024 0 Comments 0 tags

New research has discovered over 800 packages in the npm registry which have discrepancies from their registry entries, out of which 18 have been found to exploit a technique called manifest