Threat Prevention & Detection in SaaS Environments – 101

16/07/2024 0 Comments 0 tags

Identity-based threats on SaaS applications are a growing concern among security professionals, although few have the capabilities to detect and respond to them.  According to the US Cybersecurity and Infrastructure

Malicious npm Packages Found Using Image Files to Hide Backdoor Code

16/07/2024 0 Comments 0 tags

Cybersecurity researchers have identified two malicious packages on the npm package registry that concealed backdoor code to execute malicious commands sent from a remote server. The packages in question –

Iranian Hackers Deploy New BugSleep Backdoor in Middle East Cyber Attacks

16/07/2024 0 Comments 0 tags

The Iranian nation-state actor known as MuddyWater has been observed using a never-before-seen backdoor as part of a recent attack campaign, shifting away from its well-known tactic of deploying legitimate

Void Banshee APT Exploits Microsoft MHTML Flaw to Spread Atlantida Stealer

16/07/2024 0 Comments 0 tags

An advanced persistent threat (APT) group called Void Banshee has been observed exploiting a recently disclosed security flaw in the Microsoft MHTML browser engine as a zero-day to deliver an

Kaspersky Exits U.S. Market Following Commerce Department Ban

16/07/2024 0 Comments 0 tags

Russian security vendor Kaspersky has said it’s exiting the U.S. market nearly a month after the Commerce Department announced a ban on the sale of its software in the country

CISA Warns of Actively Exploited RCE Flaw in GeoServer GeoTools Software

16/07/2024 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical security flaw impacting OSGeo GeoServer GeoTools to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of

GitHub Token Leak Exposes Python’s Core Repositories to Potential Attacks

15/07/2024 0 Comments 0 tags

Cybersecurity researchers said they discovered an accidentally leaked GitHub token that could have granted elevated access to the GitHub repositories of the Python language, Python Package Index (PyPI), and the

10,000 Victims a Day: Infostealer Garden of Low-Hanging Fruit

15/07/2024 0 Comments 0 tags

Imagine you could gain access to any Fortune 100 company for $10 or less, or even for free. Terrifying thought, isn’t it? Or exciting, depending on which side of the

CRYSTALRAY Hackers Infect Over 1,500 Victims Using Network Mapping Tool

15/07/2024 0 Comments 0 tags

A threat actor that was previously observed using an open-source network mapping tool has greatly expanded their operations to infect over 1,500 victims. Sysdig, which is tracking the cluster under

New HardBit Ransomware 4.0 Uses Passphrase Protection to Evade Detection

15/07/2024 0 Comments 0 tags

Cybersecurity researchers have shed light on a new version of a ransomware strain called HardBit that comes packaged with new obfuscation techniques to deter analysis efforts. “Unlike previous versions, HardBit