Alert: Threat Actors Can Leverage AWS STS to Infiltrate Cloud Accounts

06/12/2023 0 Comments 0 tags

Threat actors can take advantage of Amazon Web Services Security Token Service (AWS STS) as a way to infiltrate cloud accounts and conduct follow-on attacks. The service enables threat actors

Russia’s AI-Powered Disinformation Operation Targeting Ukraine, U.S., and Germany

05/12/2023 0 Comments 0 tags

The Russia-linked influence operation called Doppelganger has targeted Ukrainian, U.S., and German audiences through a combination of inauthentic news sites and social media accounts. These campaigns are designed to amplify

Warning for iPhone Users: Experts Warn of Sneaky Fake Lockdown Mode Attack

05/12/2023 0 Comments 0 tags

A new “post-exploitation tampering technique” can be abused by malicious actors to visually deceive a target into believing that their Apple iPhone is running in Lockdown Mode when it’s actually

Microsoft Warns of Kremlin-Backed APT28 Exploiting Critical Outlook Vulnerability

05/12/2023 0 Comments 0 tags

Microsoft on Monday said it detected Kremlin-backed nation-state activity exploiting a now-patched critical security flaw in its Outlook email service to gain unauthorized access to victims’ accounts within Exchange servers.

New Threat Actor ‘AeroBlade’ Emerges in Espionage Attack on U.S. Aerospace

05/12/2023 0 Comments 0 tags

A previously undocumented threat actor has been linked to a cyber attack targeting an aerospace organization in the U.S. as part of what’s suspected to be a cyber espionage mission.

15,000 Go Module Repositories on GitHub Vulnerable to Repojacking Attack

05/12/2023 0 Comments 0 tags

New research has found that over 15,000 Go module repositories on GitHub are vulnerable to an attack called repojacking. “More than 9,000 repositories are vulnerable to repojacking due to GitHub

Generative AI Security: Preventing Microsoft Copilot Data Exposure

05/12/2023 0 Comments 0 tags

Microsoft Copilot has been called one of the most powerful productivity tools on the planet. Copilot is an AI assistant that lives inside each of your Microsoft 365 apps —

Microsoft Warns of Malvertising Scheme Spreading CACTUS Ransomware

04/12/2023 0 Comments 0 tags

Microsoft has warned of a new wave of CACTUS ransomware attacks that leverage malvertising lures to deploy DanaBot as an initial access vector. The DanaBot infections led to “hands-on-keyboard activity

LogoFAIL: UEFI Vulnerabilities Expose Devices to Stealth Malware Attacks

04/12/2023 0 Comments 0 tags

The Unified Extensible Firmware Interface (UEFI) code from various independent firmware/BIOS vendors (IBVs) has been found vulnerable to potential attacks through high-impact flaws in image parsing libraries embedded into the

New P2PInfect Botnet MIPS Variant Targeting Routers and IoT Devices

04/12/2023 0 Comments 0 tags

Cybersecurity researchers have discovered a new variant of an emerging botnet called P2PInfect that’s capable of targeting routers and IoT devices. The latest version, per Cado Security Labs, is compiled for Microprocessor