Experts Discover Flaw in U.S. Govt’s Chosen Quantum-Resistant Encryption Algorithm

06/03/2023 0 Comments 0 tags

A group of researchers has revealed what it says is a vulnerability in a specific implementation of CRYSTALS-Kyber, one of the encryption algorithms chosen by the U.S. government as quantum-resistant last

Security and IT Teams No Longer Need To Pay For SaaS-Shadow IT Discovery

06/03/2023 0 Comments 0 tags

This past January, a SaaS Security Posture Management (SSPM) company named Wing Security (Wing) made waves with the launch of its free SaaS-Shadow IT discovery solution. Cloud-based companies were invited to

New FiXS ATM Malware Targeting Mexican Banks

06/03/2023 0 Comments 0 tags

A new ATM malware strain dubbed FiXS has been observed targeting Mexican banks since the start of February 2023. “The ATM malware is hidden inside another not-malicious-looking program,” Latin American cybersecurity firm

New Flaws in TPM 2.0 Library Pose Threat to Billions of IoT and Enterprise Devices

06/03/2023 0 Comments 0 tags

A pair of serious security defects has been disclosed in the Trusted Platform Module (TPM) 2.0 reference library specification that could potentially lead to information disclosure or privilege escalation. One

Chinese Hackers Targeting European Entities with New MQsTTang Backdoor

06/03/2023 0 Comments 0 tags

The China-aligned Mustang Panda actor has been observed using a hitherto unseen custom backdoor called MQsTTang as part of an ongoing social engineering campaign that commenced in January 2023. “Unlike most of

U.S. Cybersecurity Agency Raises Alarm Over Royal Ransomware’s Deadly Capabilities

06/03/2023 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released a new advisory about Royal ransomware, which emerged in the threat landscape last year. “After gaining access to victims’ networks, Royal actors disable

Hackers Exploit Containerized Environments to Steal Proprietary Data and Software

06/03/2023 0 Comments 0 tags

A sophisticated attack campaign dubbed SCARLETEEL is targeting containerized environments to perpetrate theft of proprietary data and software. “The attacker exploited a containerized workload and then leveraged it to perform privilege escalation

New Cryptojacking Campaign Leverages Misconfigured Redis Database Servers

06/03/2023 0 Comments 0 tags

Misconfigured Redis database servers are the target of a novel cryptojacking campaign that leverages a legitimate and open source command-line file transfer service to implement its attack. “Underpinning this campaign

2023 Browser Security Report Uncovers Major Browsing Risks and Blind Spots

06/03/2023 0 Comments 0 tags

As a primary working interface, the browser plays a significant role in today’s corporate environment. The browser is constantly used by employees to access websites, SaaS applications and internal applications,

Experts Identify Fully-Featured Info Stealer and Trojan in Python Package on PyPI

06/03/2023 0 Comments 0 tags

A malicious Python package uploaded to the Python Package Index (PyPI) has been found to contain a fully-featured information stealer and remote access trojan. The package, named colourfool, was identified by