HTTP/2 Rapid Reset Zero-Day Vulnerability Exploited to Launch Record DDoS Attacks

11/10/2023 0 Comments 0 tags

Amazon Web Services (AWS), Cloudflare, and Google on Tuesday said they took steps to mitigate record-breaking distributed denial-of-service (DDoS) attacks that relied on a novel technique called HTTP/2 Rapid Reset.

Gaza-Linked Cyber Threat Actor Targets Israeli Energy and Defense Sectors

09/10/2023 0 Comments 0 tags

A Gaza-based threat actor has been linked to a series of cyber attacks aimed at Israeli private-sector energy, defense, and telecommunications organizations. Microsoft, which revealed details of the activity in

North Korea’s Lazarus Group Launders $900 Million in Cryptocurrency

06/10/2023 0 Comments 0 tags

As much as $7 billion in cryptocurrency has been illicitly laundered through cross-chain crime, with the North Korea-linked Lazarus Group linked to the theft of roughly $900 million of those

Supermicro’s BMC Firmware Found Vulnerable to Multiple Critical Vulnerabilities

06/10/2023 0 Comments 0 tags

Multiple security vulnerabilities have been disclosed in the Intelligent Platform Management Interface (IPMI) firmware for Supermicro baseboard management controllers (BMCs) that could result in privilege escalation and execution of malicious

GitHub’s Secret Scanning Feature Now Covers AWS, Microsoft, Google, and Slack

06/10/2023 0 Comments 0 tags

GitHub has announced an improvement to its secret scanning feature that extends validity checks to popular services such as Amazon Web Services (AWS), Microsoft, Google, and Slack. Validity checks, introduced by the Microsoft subsidiary

New OS Tool Tells You Who Has Access to What Data

06/10/2023 0 Comments 0 tags

Ensuring sensitive data remains confidential, protected from unauthorized access, and compliant with data privacy regulations is paramount. Data breaches result in financial and reputational damage but also lead to legal

Chinese Hackers Target Semiconductor Firms in East Asia with Cobalt Strike

06/10/2023 0 Comments 0 tags

Threat actors have been observed targeting semiconductor companies in East Asia with lures masquerading as Taiwan Semiconductor Manufacturing Company (TSMC) that are designed to deliver Cobalt Strike beacons. The intrusion

Cisco Releases Urgent Patch to Fix Critical Flaw in Emergency Responder Systems

05/10/2023 0 Comments 0 tags

Cisco has released updates to address a critical security flaw impacting Emergency Responder that allows unauthenticated, remote attackers to sign into susceptible systems using hard-coded credentials. The vulnerability, tracked as CVE-2023-20101 (CVSS

QakBot Threat Actors Still in Action, Using Ransom Knight and Remcos RAT in Latest Attacks

05/10/2023 0 Comments 0 tags

Despite the disruption to its infrastructure, the threat actors behind the QakBot malware have been linked to an ongoing phishing campaign since early August 2023 that led to the delivery

Microsoft Warns of Cyber Attacks Attempting to Breach Cloud via SQL Server Instance

05/10/2023 0 Comments 0 tags

Microsoft has detailed a new campaign in which attackers unsuccessfully attempted to move laterally to a cloud environment through an SQL Server instance. “The attackers initially exploited a SQL injection vulnerability