Fake Researcher Profiles Spread Malware through GitHub Repositories as PoC Exploits

14/06/2023 0 Comments 0 tags

At least half of dozen GitHub accounts from fake researchers associated with a fraudulent cybersecurity company have been observed pushing malicious repositories on the code hosting service. All seven repositories,

Over Half of Security Leaders Lack Confidence in Protecting App Secrets, Study Reveals

13/06/2023 0 Comments 0 tags

It might come as a surprise, but secrets management has become the elephant in the AppSec room. While security vulnerabilities like Common Vulnerabilities and Exposures (CVEs) often make headlines in

Beware: New DoubleFinger Loader Targets Cryptocurrency Wallets with Stealer

13/06/2023 0 Comments 0 tags

A novel multi-stage loader called DoubleFinger has been observed delivering a cryptocurrency stealer dubbed GreetingGhoul in what’s an advanced attack targeting users in Europe, the U.S., and Latin America. “DoubleFinger is deployed

Critical FortiOS and FortiProxy Vulnerability Likely Exploited – Patch Now!

13/06/2023 0 Comments 0 tags

Fortinet on Monday disclosed that a newly patched critical flaw impacting FortiOS and FortiProxy may have been “exploited in a limited number of cases” in attacks targeting government, manufacturing, and critical infrastructure

Two Russian Nationals Charged for Masterminding Mt. Gox Crypto Exchange Hack

13/06/2023 0 Comments 0 tags

The U.S. Department of Justice (DoJ) has charged two Russian nationals in connection with masterminding the 2014 digital heist of the now-defunct cryptocurrency exchange Mt. Gox. According to unsealed indictments

Webinar – Mastering API Security: Understanding Your True Attack Surface

13/06/2023 0 Comments 0 tags

Believe it or not, your attack surface is expanding faster than you realize. How? APIs, of course! More formally known as application programming interfaces, API calls are growing twice as

Adversary-in-the-Middle Attack Campaign Hits Dozens of Global Organizations

13/06/2023 0 Comments 0 tags

“Dozens” of organizations across the world have been targeted as part of a broad business email compromise (BEC) campaign that involved the use of adversary-in-the-middle (AitM) techniques to carry out

Apple’s Safari Private Browsing Now Automatically Removes Tracking Parameters in URLs

12/06/2023 0 Comments 0 tags

Apple is introducing major updates to Safari Private Browsing, offering users better protections against third-party trackers as they browse the web. “Advanced tracking and fingerprinting protections go even further to help

Critical RCE Flaw Discovered in Fortinet FortiGate Firewalls – Patch Now!

12/06/2023 0 Comments 0 tags

Fortinet has released patches to address a critical security flaw in its FortiGate firewalls that could be abused by a threat actor to achieve remote code execution. The vulnerability, tracked

Beware: 1,000+ Fake Cryptocurrency Sites Trap Users in Bogus Rewards Scheme

12/06/2023 0 Comments 0 tags

A previously undetected cryptocurrency scam has leveraged a constellation of over 1,000 fraudulent websites to ensnare users into a bogus rewards scheme since at least January 2021. “This massive campaign