Malicious Android Apps Pose as Google, Instagram, WhatsApp to Steal Credentials

10/05/2024 0 Comments 0 tags

Malicious Android apps masquerading as Google, Instagram, Snapchat, WhatsApp, and X (formerly Twitter) have been observed to steal users’ credentials from compromised devices. “This malware uses famous Android app icons

Researchers Uncover ‘LLMjacking’ Scheme Targeting Cloud-Hosted AI Models

10/05/2024 0 Comments 0 tags

Cybersecurity researchers have discovered a novel attack that employs stolen cloud credentials to target cloud-hosted large language model (LLM) services with the goal of selling access to other threat actors. The attack

North Korean Hackers Deploy New Golang Malware ‘Durian’ Against Crypto Firms

10/05/2024 0 Comments 0 tags

The North Korean threat actor tracked as Kimsuky has been observed deploying a previously undocumented Golang-based malware dubbed Durian as part of highly-targeted cyber attacks aimed at two South Korean cryptocurrency firms.

New TunnelVision Attack Allows Hijacking of VPN Traffic via DHCP Manipulation

09/05/2024 0 Comments 0 tags

Researchers have detailed a Virtual Private Network (VPN) bypass technique dubbed TunnelVision that allows threat actors to snoop on victim’s network traffic by just being on the same local network. The “decloaking” method has

New Guide: How to Scale Your vCISO Services Profitably

09/05/2024 0 Comments 0 tags

Cybersecurity and compliance guidance are in high demand among SMEs. However, many of them cannot afford to hire a full-time CISO. A vCISO can answer this need by offering on-demand access

Mirai Botnet Exploits Ivanti Connect Secure Flaws for Malicious Payload Delivery

09/05/2024 0 Comments 0 tags

Two recently disclosed security flaws in Ivanti Connect Secure (ICS) devices are being exploited to deploy the infamous Mirai botnet. That’s according to findings from Juniper Threat Labs, which said the vulnerabilities CVE-2023-46805 and

Kremlin-Backed APT28 Targets Polish Institutions in Large-Scale Malware Campaign

09/05/2024 0 Comments 0 tags

Polish government institutions have been targeted as part of a large-scale malware campaign orchestrated by a Russia-linked nation-state actor called APT28. “The campaign sent emails with content intended to arouse the

Critical F5 Central Manager Vulnerabilities Allow Enable Full Device Takeover

09/05/2024 0 Comments 0 tags

Two security vulnerabilities have been discovered in F5 Next Central Manager that could be exploited by a threat actor to seize control of the devices and create hidden rogue administrator

A SaaS Security Challenge: Getting Permissions All in One Place 

08/05/2024 0 Comments 0 tags

Permissions in SaaS platforms like Salesforce, Workday, and Microsoft 365 are remarkably precise. They spell out exactly which users have access to which data sets. The terminology differs between apps, but each

New Spectre-Style ‘Pathfinder’ Attack Targets Intel CPU, Leak Encryption Keys and Data

08/05/2024 0 Comments 0 tags

Researchers have discovered two novel attack methods targeting high-performance Intel CPUs that could be exploited to stage a key recovery attack against the Advanced Encryption Standard (AES) algorithm. The techniques have been collectively dubbed Pathfinder by a