Paperbug Attack: New Politically-Motivated Surveillance Campaign in Tajikistan

27/04/2023 0 Comments 0 tags

A little-known Russian-speaking cyber-espionage group has been linked to a new politically-motivated surveillance campaign targeting high-ranking government officials, telecom services, and public service infrastructures in Tajikistan. The intrusion set, dubbed Paperbug by

Chinese Hackers Spotted Using Linux Variant of PingPull in Targeted Cyberattacks

26/04/2023 0 Comments 0 tags

The Chinese nation-state group dubbed Alloy Taurus is using a Linux variant of a backdoor called PingPull as well as a new undocumented tool codenamed Sword2033. That’s according to findings from Palo

Apache Superset Vulnerability: Insecure Default Configuration Exposes Servers to RCE Attacks

26/04/2023 0 Comments 0 tags

The maintainers of the Apache Superset open source data visualization software have released fixes to plug an insecure default configuration that could lead to remote code execution. The vulnerability, tracked as CVE-2023-27524 (CVSS score:

Browser Security Survey: 87% of SaaS Adopters Exposed to Browser-borne Attacks

26/04/2023 0 Comments 0 tags

The browser serves as the primary interface between the on-premises environment, the cloud, and the web in the modern enterprise. Therefore, the browser is also exposed to multiple types of

Chinese Hackers Using MgBot Malware to Target International NGOs in Mainland China

26/04/2023 0 Comments 0 tags

The advanced persistent threat (APT) group referred to as Evasive Panda has been observed targeting an international non-governmental organization (NGO) in Mainland China with malware delivered via update channels of legitimate applications

Charming Kitten’s New BellaCiao Malware Discovered in Multi-Country Attacks

26/04/2023 0 Comments 0 tags

The prolific Iranian nation-state group known as Charming Kitten targeted multiple victims in the U.S., Europe, the Middle East and India with a novel malware dubbed BellaCiao, adding to its ever-expanding list of

NIST’s SBIR Program Could be for You

26/04/2023 0 Comments 0 tags

Fascination with technological innovation is built into America’s DNA. Today’s legions of U.S. scientific and engineering researchers are directly connected to the independent mechanics, artisans, and tinkerers of colonial and

VMware Releases Critical Patches for Workstation and Fusion Software

26/04/2023 0 Comments 0 tags

VMware has released updates to resolve multiple security flaws impacting its Workstation and Fusion software, the most critical of which could allow a local attacker to achieve code execution. The

Hackers Exploit Outdated WordPress Plugin to Backdoor Thousands of WordPress Sites

25/04/2023 0 Comments 0 tags

Threat actors have been observed leveraging a legitimate but outdated WordPress plugin to surreptitiously backdoor websites as part of an ongoing campaign, Sucuri revealed in a report published last week. The plugin

Study: 84% of Companies Use Breached SaaS Applications – Here’s How to Fix it for Free!

25/04/2023 0 Comments 0 tags

A recent review by Wing Security, a SaaS security company that analyzed the data of over 500 companies, revealed some worrisome information. According to this review, 84% of the companies had