How Attack Surface Management Supports Continuous Threat Exposure Management

11/05/2023 0 Comments 0 tags

According to Forrester, External Attack Surface Management (EASM) emerged as a market category in 2021 and gained popularity in 2022. In a different report, Gartner concluded that vulnerability management vendors

Babuk Source Code Sparks 9 Different Ransomware Strains Targeting VMware ESXi Systems

11/05/2023 0 Comments 0 tags

Multiple threat actors have capitalized on the leak of Babuk (aka Babak or Babyk) ransomware code in September 2021 to build as many as nine different ransomware families capable of

Andoryu Botnet Exploits Critical Ruckus Wireless Flaw for Widespread Attack

11/05/2023 0 Comments 0 tags

A nascent botnet called Andoryu has been found to exploit a now-patched critical security flaw in the Ruckus Wireless Admin panel to break into vulnerable devices. The flaw, tracked as CVE-2023-25717 (CVSS score: 9.8), stems from improper

GitHub Extends Push Protection to Prevent Accidental Leaks of Keys and Other Secrets

11/05/2023 0 Comments 0 tags

GitHub has announced the general availability of a new security feature called push protection, which aims to prevent developers from inadvertently leaking keys and other secrets in their code. The Microsoft-owned

Twitter Finally Rolling Out Encrypted Direct Messages — Starting with Verified Users

11/05/2023 0 Comments 0 tags

Twitter is officially beginning to roll out support for encrypted direct messages (DMs) on the platform, more than six months after its chief executive Elon Musk confirmed plans for the feature in November 2022.

Google Announces New Privacy, Safety, and Security Features Across Its Services

10/05/2023 0 Comments 0 tags

Google unveiled a slew of new privacy, safety, and security features today at its annual developer conference, Google I/O. The tech giant’s latest initiatives are aimed at protecting its users

Sophisticated DownEx Malware Campaign Targeting Central Asian Governments

10/05/2023 0 Comments 0 tags

Government organizations in Central Asia are the target of a sophisticated espionage campaign that leverages a previously undocumented strain of malware dubbed DownEx. Bitdefender, in a report shared with The Hacker News, said

Experts Detail New Zero-Click Windows Vulnerability for NTLM Credential Theft

10/05/2023 0 Comments 0 tags

Cybersecurity researchers have shared details about a now-patched security flaw in Windows MSHTML platform that could be abused to bypass integrity protections on targeted machines. The vulnerability, tracked as CVE-2023-29324 (CVSS score:

NIST Revises SP 800-171 Guidelines for Protecting Sensitive Information

10/05/2023 0 Comments 0 tags

Draft Revision 3 aligns the publication’s language with NIST’s 800-53 catalog of cybersecurity safeguards.

Mastermind Behind Twitter 2020 Hack Pleads Guilty and Faces up to 70 Years in Prison

10/05/2023 0 Comments 0 tags

A U.K. national has pleaded guilty in connection with the July 2020 Twitter attack affecting numerous high-profile accounts and defrauding other users of the platform. Joseph James O’Connor, who also