The Service Accounts Challenge: Can’t See or Secure Them Until It’s Too Late

12/04/2023 0 Comments 0 tags

Here’s a hard question to answer: ‘How many service accounts do you have in your environment?’. A harder one is: ‘Do you know what these accounts are doing?’. And the

Urgent: Microsoft Issues Patches for 97 Flaws, Including Active Ransomware Exploit

12/04/2023 0 Comments 0 tags

It’s the second Tuesday of the month, and Microsoft has released another set of security updates to fix a total of 97 flaws impacting its software, one of which has been actively

North Korean Hackers Uncovered as Mastermind in 3CX Supply Chain Attack

12/04/2023 0 Comments 0 tags

Enterprise communications service provider 3CX confirmed that the supply chain attack targeting its desktop application for Windows and macOS was the handiwork of a threat actor with North Korean nexus. The findings

Cybercriminals Turn to Android Loaders on Dark Web to Evade Google Play Security

11/04/2023 0 Comments 0 tags

Malicious loader programs capable of trojanizing Android applications are being traded on the criminal underground for up to $20,000 as a way to evade Google Play Store defenses. “The most

[eBook] A Step-by-Step Guide to Cyber Risk Assessment

11/04/2023 0 Comments 0 tags

In today’s perilous cyber risk landscape, CISOs and CIOs must defend their organizations against relentless cyber threats, including ransomware, phishing, attacks on infrastructure, supply chain breaches, malicious insiders, and much

Cryptocurrency Stealer Malware Distributed via 13 NuGet Packages

11/04/2023 0 Comments 0 tags

Cybersecurity researchers have detailed the inner workings of the cryptocurrency stealer malware that was distributed via 13 malicious NuGet packages as part of a supply chain attack targeting .NET developers.

Newly Discovered “By-Design” Flaw in Microsoft Azure Could Expose Storage Accounts to Hackers

11/04/2023 0 Comments 0 tags

A “by-design flaw” uncovered in Microsoft Azure could be exploited by attackers to gain access to storage accounts, move laterally in the environment, and even execute remote code. “It is

CISA Warns of 5 Actively Exploited Security Flaws: Urgent Action Required

11/04/2023 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. This includes three

Estonian National Charged in U.S. for Acquiring Electronics and Metasploit Pro for Russian Military

11/04/2023 0 Comments 0 tags

An Estonian national has been charged in the U.S. for purchasing U.S.-made electronics on behalf of the Russian government and military. The 45-year-old individual, Andrey Shevlyakov, was arrested on March 28, 2023,

Hackers Flood NPM with Bogus Packages Causing a DoS Attack

11/04/2023 0 Comments 0 tags

Threat actors are flooding the npm open source package repository with bogus packages that briefly even resulted in a denial-of-service (DoS) attack. “The threat actors create malicious websites and publish