Balada Injector Infects Over 7,100 WordPress Sites Using Plugin Vulnerability

16/01/2024 0 Comments 0 tags

Thousands of WordPress sites using a vulnerable version of the Popup Builder plugin have been compromised with a malware called Balada Injector. First documented by Doctor Web in January 2023, the campaign takes

DDoS Attacks on the Environmental Services Industry Surge by 61,839% in 2023

16/01/2024 0 Comments 0 tags

The environmental services industry witnessed an “unprecedented surge” in HTTP-based distributed denial-of-service (DDoS) attacks, accounting for half of all its HTTP traffic. This marks a 61,839% increase in DDoS attack

New Findings Challenge Attribution in Denmark’s Energy Sector Cyberattacks

14/01/2024 0 Comments 0 tags

The cyber attacks targeting the energy sector in Denmark last year may not have had the involvement of the Russia-linked Sandworm hacking group, new findings from Forescout show. The intrusions, which targeted around

29-Year-Old Ukrainian Cryptojacking Kingpin Arrested for Exploiting Cloud Services

14/01/2024 0 Comments 0 tags

A 29-year-old Ukrainian national has been arrested in connection with running a “sophisticated cryptojacking scheme,” netting them over $2 million (€1.8 million) in illicit profits. The person was apprehended in

Critical RCE Vulnerability Uncovered in Juniper SRX Firewalls and EX Switches

14/01/2024 0 Comments 0 tags

Juniper Networks has released updates to fix a critical remote code execution (RCE) vulnerability in its SRX Series firewalls and EX Series switches. The issue, tracked as CVE-2024-21591, is rated 9.8

Medusa Ransomware on the Rise: From Data Leaks to Multi-Extortion

12/01/2024 0 Comments 0 tags

The threat actors associated with the Medusa ransomware have ramped up their activities following the debut of a dedicated data leak site on the dark web in February 2023 to publish sensitive

Applying the Tyson Principle to Cybersecurity: Why Attack Simulation is Key to Avoiding a KO

12/01/2024 0 Comments 0 tags

Picture a cybersecurity landscape where defenses are impenetrable, and threats are nothing more than mere disturbances deflected by a strong shield. Sadly, this image of fortitude remains a pipe dream

Urgent: GitLab Releases Patch for Critical Vulnerabilities – Update ASAP

12/01/2024 0 Comments 0 tags

GitLab has released security updates to address two critical vulnerabilities, including one that could be exploited to take over accounts without requiring any user interaction. Tracked as CVE-2023-7028, the flaw has

Cryptominers Targeting Misconfigured Apache Hadoop and Flink with Rootkit in New Attacks

12/01/2024 0 Comments 0 tags

Cybersecurity researchers have identified a new attack that exploits misconfigurations in Apache Hadoop and Flink to deploy cryptocurrency miners within targeted environments. “This attack is particularly intriguing due to the

Nation-State Actors Weaponize Ivanti VPN Zero-Days, Deploying 5 Malware Families

12/01/2024 0 Comments 0 tags

As many as five different malware families were deployed by suspected nation-state actors as part of post-exploitation activities leveraging two zero-day vulnerabilities in Ivanti Connect Secure (ICS) VPN appliances since early December