Chinese Hacker Group ‘Flea’ Targets American Ministries with Graphican Backdoor

22/06/2023 0 Comments 0 tags

Foreign affairs ministries in the Americas have been targeted by a Chinese state-sponsored actor named Flea as part of a recent campaign that spanned from late 2022 to early 2023. The cyber

Critical ‘nOAuth’ Flaw in Microsoft Azure AD Enabled Complete Account Takeover

22/06/2023 0 Comments 0 tags

A security shortcoming in Microsoft Azure Active Directory (AD) Open Authorization (OAuth) process could have been exploited to achieve full account takeover, researchers said. California-based identity and access management service

Startup Security Tactics: Friction Surveys

22/06/2023 0 Comments 0 tags

When we do quarterly planning, my team categorizes our goals within four evergreen outcomes: Reduce the risk of information security incidents Increase trust in Vanta’s information security program Reduce the friction

New Report Exposes Operation Triangulation’s Spyware Implant Targeting iOS Devices

22/06/2023 0 Comments 0 tags

More details have emerged about the spyware implant that’s delivered to iOS devices as part of a campaign called Operation Triangulation. Kaspersky, which discovered the operation after becoming one of the targets

ScarCruft Hackers Exploit Ably Service for Stealthy Wiretapping Attacks

22/06/2023 0 Comments 0 tags

The North Korean threat actor known as ScarCruft has been observed using an information-stealing malware with previous undocumented wiretapping features as well as a backdoor developed using Golang that exploits

Introducing AI-guided Remediation for IaC Security / KICS

21/06/2023 0 Comments 0 tags

While the use of Infrastructure as Code (IaC) has gained significant popularity as organizations embrace cloud computing and DevOps practices, the speed and flexibility that IaC provides can also introduce

Researchers Discover New Sophisticated Toolkit Targeting Apple macOS Systems

21/06/2023 0 Comments 0 tags

Cybersecurity researchers have uncovered a set of malicious artifacts that they say is part of a sophisticated toolkit targeting Apple macOS systems. “As of now, these samples are still largely

New Mystic Stealer Malware Targets 40 Web Browsers and 70 Browser Extensions

21/06/2023 0 Comments 0 tags

A new information-stealing malware called Mystic Stealer has been found to steal data from about 40 different web browsers and over 70 web browser extensions. First advertised on April 25, 2023, for

Rogue Android Apps Target Pakistani Individuals in Sophisticated Espionage Campaign

21/06/2023 0 Comments 0 tags

Individuals in the Pakistan region have been targeted using two rogue Android apps available on the Google Play Store as part of a new targeted campaign. Cybersecurity firm Cyfirma attributed

Over 100,000 Stolen ChatGPT Account Credentials Sold on Dark Web Marketplaces

21/06/2023 0 Comments 0 tags

Over 101,100 compromised OpenAI ChatGPT account credentials have found their way on illicit dark web marketplaces between June 2022 and May 2023, with India alone accounting for 12,632 stolen credentials.