New BIFROSE Linux Malware Variant Using Deceptive VMware Domain for Evasion

02/03/2024 0 Comments 0 tags

Cybersecurity researchers have discovered a new Linux variant of a remote access trojan (RAT) called BIFROSE (aka Bifrost) that uses a deceptive domain mimicking VMware. “This latest version of Bifrost

4 Instructive Postmortems on Data Downtime and Loss

02/03/2024 0 Comments 0 tags

More than a decade ago, the concept of the ‘blameless’ postmortem changed how tech companies recognize failures at scale. John Allspaw, who coined the term during his tenure at Etsy, argued postmortems

New Phishing Kit Leverages SMS, Voice Calls to Target Cryptocurrency Users

02/03/2024 0 Comments 0 tags

A novel phishing kit has been observed impersonating the login pages of well-known cryptocurrency services as part of an attack cluster designed to primarily target mobile devices. “This kit enables

GitHub Rolls Out Default Secret Scanning Push Protection for Public Repositories

01/03/2024 0 Comments 0 tags

GitHub on Thursday announced that it’s enabling secret scanning push protection by default for all pushes to public repositories. “This means that when a supported secret is detected in any

Five Eyes Agencies Warn of Active Exploitation of Ivanti Gateway Vulnerabilities

01/03/2024 0 Comments 0 tags

The Five Eyes (FVEY) intelligence alliance has issued a new cybersecurity advisory warning of cyber threat actors exploiting known security flaws in Ivanti Connect Secure and Ivanti Policy Secure gateways,

New Silver SAML Attack Evades Golden SAML Defenses in Identity Systems

29/02/2024 0 Comments 0 tags

Cybersecurity researchers have disclosed a new attack technique called Silver SAML that can be successful even in cases where mitigations have been applied against Golden SAML attacks. Silver SAML “enables the exploitation

Lazarus Exploits Typos to Sneak PyPI Malware into Dev Systems

29/02/2024 0 Comments 0 tags

The notorious North Korean state-backed hacking group Lazarus uploaded four packages to the Python Package Index (PyPI) repository with the goal of infecting developer systems with malware. The packages, now

New Backdoor Targeting European Officials Linked to Indian Diplomatic Events

29/02/2024 0 Comments 0 tags

A previously undocumented threat actor dubbed SPIKEDWINE has been observed targeting officials in European countries with Indian diplomatic missions using a new backdoor called WINELOADER. The adversary, according to a report from Zscaler ThreatLabz,

Lazarus Hackers Exploited Windows Kernel Flaw as Zero-Day in Recent Attacks

29/02/2024 0 Comments 0 tags

The notorious Lazarus Group actors exploited a recently patched privilege escalation flaw in the Windows Kernel as a zero-day to obtain kernel-level access and disable security software on compromised hosts.

How to Prioritize Cybersecurity Spending: A Risk-Based Strategy for the Highest ROI

29/02/2024 0 Comments 0 tags

As an IT leader, staying on top of the latest cybersecurity developments is essential to keeping your organization safe. But with threats coming from all around — and hackers dreaming