Bumblebee Malware Returns with New Tricks, Targeting U.S. Businesses

15/02/2024 0 Comments 0 tags

The infamous malware loader and initial access broker known as Bumblebee has resurfaced after a four-month absence as part of a new phishing campaign observed in February 2024. Enterprise security firm Proofpoint

Cybersecurity Tactics FinServ Institutions Can Bank On in 2024

15/02/2024 0 Comments 0 tags

The landscape of cybersecurity in financial services is undergoing a rapid transformation. Cybercriminals are exploiting advanced technologies and methodologies, making traditional security measures obsolete. The challenges are compounded for community

Ubuntu ‘command-not-found’ Tool Could Trick Users into Installing Rogue Packages

15/02/2024 0 Comments 0 tags

Cybersecurity researchers have found that it’s possible for threat actors to exploit a well-known utility called command-not-found to recommend their own rogue packages and compromise systems running Ubuntu operating system.

Microsoft, OpenAI Warn of Nation-State Hackers Weaponizing AI for Cyberattacks

15/02/2024 0 Comments 0 tags

Nation-state actors associated with Russia, North Korea, Iran, and China are experimenting with artificial intelligence (AI) and large language models (LLMs) to complement their ongoing cyber attack operations. The findings

PikaBot Resurfaces with Streamlined Code and Deceptive Tactics

13/02/2024 0 Comments 0 tags

The threat actors behind the PikaBot malware have made significant changes to the malware in what has been described as a case of “devolution.” “Although it appears to be in

Glupteba Botnet Evades Detection with Undocumented UEFI Bootkit

13/02/2024 0 Comments 0 tags

The Glupteba botnet has been found to incorporate a previously undocumented Unified Extensible Firmware Interface (UEFI) bootkit feature, adding another layer of sophistication and stealth to the malware. “This bootkit can intervene

Alert: CISA Warns of Active ‘Roundcube’ Email Attacks – Patch Now

13/02/2024 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a medium-severity security flaw impacting Roundcube email software to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.

Ivanti Vulnerability Exploited to Install ‘DSLog’ Backdoor on 670+ IT Infrastructures

13/02/2024 0 Comments 0 tags

Threat actors are leveraging a recently disclosed security flaw impacting Ivanti Connect Secure, Policy Secure, and ZTA gateways to deploy a backdoor codenamed DSLog on susceptible devices. That’s according to findings from Orange Cyberdefense,

Midnight Blizzard and Cloudflare-Atlassian Cybersecurity Incidents: What to Know

13/02/2024 0 Comments 0 tags

The Midnight Blizzard and Cloudflare-Atlassian cybersecurity incidents raised alarms about the vulnerabilities inherent in major SaaS platforms. These incidents illustrate the stakes involved in SaaS breaches — safeguarding the integrity

U.S. Offers $10 Million Bounty for Info Leading to Arrest of Hive Ransomware Leaders

13/02/2024 0 Comments 0 tags

The U.S. Department of State has announced monetary rewards of up to $10 million for information about individuals holding key positions within the Hive ransomware operation. It is also giving away an