NIST Cybersecurity Framework (CSF) and CTEM – Better Together

05/09/2024 0 Comments 0 tags

It’s been a decade since the National Institute of Standards and Technology (NIST) introduced its Cybersecurity Framework (CSF) 1.0. Created following a 2013 Executive Order, NIST was tasked with designing

Malware Attackers Using MacroPack to Deliver Havoc, Brute Ratel, and PhantomCore

05/09/2024 0 Comments 0 tags

Threat actors are likely employing a tool designated for red teaming exercises to serve malware, according to new findings from Cisco Talos. The program in question is a payload generation

New Cross-Platform Malware KTLVdoor Discovered in Attack on Chinese Trading Firm

05/09/2024 0 Comments 0 tags

The Chinese-speaking threat actor known as Earth Lusca has been observed using a new backdoor dubbed KTLVdoor as part of a cyber attack targeting an unnamed trading company based in

Cisco Fixes Two Critical Flaws in Smart Licensing Utility to Prevent Remote Attacks

05/09/2024 0 Comments 0 tags

Cisco has released security updates for two critical security flaws impacting its Smart Licensing Utility that could allow unauthenticated, remote attackers to elevate their privileges or access sensitive information. A

North Korean Hackers Targets Job Seekers with Fake FreeConference App

04/09/2024 0 Comments 0 tags

North Korean threat actors have leveraged a fake Windows video conferencing application impersonating FreeConference.com to backdoor developer systems as part of an ongoing financially-driven campaign dubbed Contagious Interview. The new

Google Confirms CVE-2024-32896 Exploited in the Wild, Releases Android Security Patch

04/09/2024 0 Comments 0 tags

Google has released its monthly security updates for the Android operating system to address a known security flaw that it said has come under active exploitation in the wild. The

The New Effective Way to Prevent Account Takeovers

04/09/2024 0 Comments 0 tags

Account takeover attacks have emerged as one of the most persistent and damaging threats to cloud-based SaaS environments. Yet despite significant investments in traditional security measures, many organizations continue to

Zyxel Patches Critical OS Command Injection Flaw in Access Points and Routers

04/09/2024 0 Comments 0 tags

Zyxel has released software updates to address a critical security flaw impacting certain access point (AP) and security router versions that could result in the execution of unauthorized commands. Tracked

Hackers Hijack 22,000 Removed PyPI Packages, Spreading Malicious Code to Developers

04/09/2024 0 Comments 0 tags

A new supply chain attack technique targeting the Python Package Index (PyPI) registry has been exploited in the wild in an attempt to infiltrate downstream organizations. It has been codenamed

Clearview AI Faces €30.5M Fine for Building Illegal Facial Recognition Database

04/09/2024 0 Comments 0 tags

The Dutch Data Protection Authority (Dutch DPA) has imposed a fine of €30.5 million ($33.7 million) against facial recognition firm Clearview AI for violating the General Data Protection Regulation (GDPR)