What’s Wrong with Manufacturing?

16/03/2023 0 Comments 0 tags

In last year’s edition of the Security Navigator we noted that the Manufacturing Industry appeared to be totally over-represented in our dataset of Cyber Extortion victims. Neither the number of businesses nor

Multiple Hacker Groups Exploit 3-Year-Old Vulnerability to Breach U.S. Federal Agency

16/03/2023 0 Comments 0 tags

Multiple threat actors, including a nation-state group, exploited a critical three-year-old security flaw in Progress Telerik to break into an unnamed federal entity in the U.S. The disclosure comes from a joint advisory issued

CISA Issues Urgent Warning: Adobe ColdFusion Vulnerability Exploited in the Wild

16/03/2023 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on March 15 added a security vulnerability impacting Adobe ColdFusion to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The

YoroTrooper Stealing Credentials and Information from Government and Energy Organizations

15/03/2023 0 Comments 0 tags

A previously undocumented threat actor dubbed YoroTrooper has been targeting government, energy, and international organizations across Europe as part of a cyber espionage campaign that has been active since at least June

The Different Methods and Stages of Penetration Testing

15/03/2023 0 Comments 0 tags

The stakes could not be higher for cyber defenders. With the vast amounts of sensitive information, intellectual property, and financial data at risk, the consequences of a data breach can

New Cryptojacking Operation Targeting Kubernetes Clusters for Dero Mining

15/03/2023 0 Comments 0 tags

Cybersecurity researchers have discovered the first-ever illicit cryptocurrency mining campaign used to mint Dero since the start of February 2023. “The novel Dero cryptojacking operation concentrates on locating Kubernetes clusters

Tick APT Targeted High-Value Customers of East Asian Data-Loss Prevention Company

15/03/2023 0 Comments 0 tags

A cyberespionage actor known as Tick has been attributed with high confidence to a compromise of an East Asian data-loss prevention (DLP) company that caters to government and military entities.

Microsoft Rolls Out Patches for 80 New Security Flaws — Two Under Active Attack

15/03/2023 0 Comments 0 tags

Microsoft’s Patch Tuesday update for March 2023 is rolling out with remediations for a set of 80 security flaws, two of which have come under active exploitation in the wild. Eight

Fortinet FortiOS Flaw Exploited in Targeted Cyberattacks on Government Entities

14/03/2023 0 Comments 0 tags

Government entities and large organizations have been targeted by an unknown threat actor by exploiting a security flaw in Fortinet FortiOS software to result in data loss and OS and

Microsoft Warns of Large-Scale Use of Phishing Kits to Send Millions of Emails Daily

14/03/2023 0 Comments 0 tags

An open source adversary-in-the-middle (AiTM) phishing kit has found a number of takers in the cybercrime world for its ability to orchestrate attacks at scale. Microsoft Threat Intelligence is tracking