Why Honeytokens Are the Future of Intrusion Detection

10/05/2023 0 Comments 0 tags

A few weeks ago, the 32nd edition of RSA, one of the world’s largest cybersecurity conferences, wrapped up in San Francisco. Among the highlights, Kevin Mandia, CEO of Mandiant at

Microsoft’s May Patch Tuesday Fixes 38 Flaws, Including Active Zero-Day Bug

10/05/2023 0 Comments 0 tags

Microsoft has rolled out Patch Tuesday updates for May 2023 to address 38 security flaws, including one zero-day bug that it said is being actively exploited in the wild. Trend Micro’s Zero

U.S. Government Neutralizes Russia’s Most Sophisticated Snake Cyber Espionage Tool

10/05/2023 0 Comments 0 tags

The U.S. government on Tuesday announced the court-authorized disruption of a global network compromised by an advanced malware strain known as Snake wielded by Russia’s Federal Security Service (FSB). Snake, dubbed the

U.S. Authorities Seize 13 Domains Offering Criminal DDoS-for-Hire Services

09/05/2023 0 Comments 0 tags

U.S. authorities have announced the seizure of 13 internet domains that offered DDoS-for-hire services to other criminal actors. The takedown is part of an ongoing international initiative dubbed Operation PowerOFF that’s aimed

Product Security: Harnessing the Collective Experience and Collaborative Tools in DevSecOps

09/05/2023 0 Comments 0 tags

In the fast-paced cybersecurity landscape, product security takes center stage. DevSecOps swoops in, seamlessly merging security practices into DevOps, empowering teams to tackle challenges. Let’s dive into DevSecOps and explore

Operation ChattyGoblin: Hackers Targeting Gambling Firms via Chat Apps

09/05/2023 0 Comments 0 tags

A gambling company in the Philippines was the target of a China-aligned threat actor as part of a campaign that has been ongoing since October 2021. Slovak cybersecurity firm ESET

Researchers Uncover SideWinder’s Latest Server-Based Polymorphism Technique

09/05/2023 0 Comments 0 tags

The advanced persistent threat (APT) actor known as SideWinder has been accused of deploying a backdoor in attacks directed against Pakistan government organizations as part of a campaign that commenced

Microsoft Warns of State-Sponsored Attacks Exploiting Critical PaperCut Vulnerability

09/05/2023 0 Comments 0 tags

Iranian nation-state groups have now joined financially motivated actors in actively exploiting a critical flaw in PaperCut print management software, Microsoft said. The tech giant’s threat intelligence team said it

New Ransomware Strain ‘CACTUS’ Exploits VPN Flaws to Infiltrate Networks

09/05/2023 0 Comments 0 tags

Cybersecurity researchers have shed light on a new ransomware strain called CACTUS that has been found to leverage known flaws in VPN appliances to obtain initial access to targeted networks.

MSI Data Breach: Private Code Signing Keys Leaked on the Dark Web

08/05/2023 0 Comments 0 tags

The threat actors behind the ransomware attack on Taiwanese PC maker MSI last month have leaked the company’s private code signing keys on their dark website. “Confirmed, Intel OEM private