ANEL and NOOPDOOR Backdoors Weaponized in New MirrorFace Campaign Against Japan

05/12/2024 0 Comments 0 tags

The China-linked threat actor known as MirrorFace has been attributed to a new spear-phishing campaign mainly targeting individuals and organizations in Japan since June 2024. The aim of the campaign

NCA Busts Russian Crypto Networks Laundering Funds and Evading Sanctions

05/12/2024 0 Comments 0 tags

The U.K. National Crime Agency (NCA) on Wednesday announced that it led an international investigation to disrupt Russian money laundering networks that were found to facilitate serious and organized crime

CISA Warns of Active Exploitation of Flaws in Zyxel, ProjectSend, and CyberPanel

05/12/2024 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added multiple security flaws affecting products from Zyxel, North Grid Proself, ProjectSend, and CyberPanel to its Known Exploited Vulnerabilities (KEV) catalog, citing

Russia-Linked Turla Exploits Pakistani Hackers’ Servers to Target Afghan and Indian Entities

04/12/2024 0 Comments 0 tags

The Russia-linked advanced persistent threat (APT) group known as Turla has been linked to a previously undocumented campaign that involved infiltrating the command-and-control (C2) servers of a Pakistan-based hacking group

Europol Dismantles Criminal Messaging Service MATRIX in Major Global Takedown

04/12/2024 0 Comments 0 tags

Europol on Tuesday announced the takedown of an invite-only encrypted messaging service called MATRIX that’s created by criminals for criminal purposes. The joint operation, conducted by French and Dutch authorities

7 PAM Best Practices to Secure Hybrid and Multi-Cloud Environments

04/12/2024 0 Comments 0 tags

Are you using the cloud or thinking about transitioning? Undoubtedly, multi-cloud and hybrid environments offer numerous benefits for organizations. However, the cloud’s flexibility, scalability, and efficiency come with significant risk

How to Plan a New (and Improved!) Password Policy for Real-World Security Challenges

04/12/2024 0 Comments 0 tags

Many organizations struggle with password policies that look strong on paper but fail in practice because they’re too rigid to follow, too vague to enforce, or disconnected from real security

Researchers Uncover Backdoor in Solana’s Popular Web3.js npm Library

04/12/2024 0 Comments 0 tags

Cybersecurity researchers are alerting to a software supply chain attack targeting the popular @solana/web3.js npm library that involved pushing two malicious versions capable of harvesting users’ private keys with an

Joint Advisory Warns of PRC-Backed Cyber Espionage Targeting Telecom Networks

04/12/2024 0 Comments 0 tags

A joint advisory issued by Australia, Canada, New Zealand, and the U.S. has warned of a broad cyber espionage campaign undertaken by People’s Republic of China (PRC)-affiliated threat actors targeting

Veeam Issues Patch for Critical RCE Vulnerability in Service Provider Console

04/12/2024 0 Comments 0 tags

Veeam has released security updates to address a critical flaw impacting Service Provider Console (VSPC) that could pave the way for remote code execution on susceptible instances. The vulnerability, tracked