Does Your Help Desk Know Who’s Calling?

09/03/2023 0 Comments 0 tags

Phishing, the theft of users’ credentials or sensitive data using social engineering, has been a significant threat since the early days of the internet – and continues to plague organizations

Iranian Hackers Target Women Involved in Human Rights and Middle East Politics

09/03/2023 0 Comments 0 tags

Iranian state-sponsored actors are continuing to engage in social engineering campaigns targeting researchers by impersonating a U.S. think tank. “Notably the targets in this instance were all women who are

New Critical Flaw in FortiOS and FortiProxy Could Give Hackers Remote Access

09/03/2023 0 Comments 0 tags

Fortinet has released fixes to address 15 security flaws, including one critical vulnerability impacting FortiOS and FortiProxy that could enable a threat actor to take control of affected systems. The issue,

New ScrubCrypt Crypter Used in Cryptojacking Attacks Targeting Oracle WebLogic

09/03/2023 0 Comments 0 tags

The infamous cryptocurrency miner group called 8220 Gang has been observed using a new crypter called ScrubCrypt to carry out cryptojacking operations. According to Fortinet FortiGuard Labs, the attack chain

Jenkins Security Alert: New Security Flaws Could Allow Code Execution Attacks

09/03/2023 0 Comments 0 tags

A pair of severe security vulnerabilities have been disclosed in the Jenkins open source automation server that could lead to code execution on targeted systems. The flaws, tracked as CVE-2023-27898 and CVE-2023-27905, impact

Lazarus Group Exploits Zero-Day Vulnerability to Hack South Korean Financial Entity

08/03/2023 0 Comments 0 tags

The North Korea-linked Lazarus Group has been observed weaponizing flaws in an undisclosed software to breach a financial business entity in South Korea twice within a span of a year. While the

Sharp Panda Using New Soul Framework Version to Target Southeast Asian Governments

08/03/2023 0 Comments 0 tags

High-profile government entities in Southeast Asia are the target of a cyber espionage campaign undertaken by a Chinese threat actor known as Sharp Panda since late last year. The intrusions

Syxsense Platform: Unified Security and Endpoint Management

08/03/2023 0 Comments 0 tags

As threats grow and attack surfaces get more complex, companies continue to struggle with the multitude of tools they utilize to handle endpoint security and management. This can leave gaps

CISA’s KEV Catalog Updated with 3 New Flaws Threatening IT Management Systems

08/03/2023 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The list of vulnerabilities is below –

SYS01stealer: New Threat Using Facebook Ads to Target Critical Infrastructure Firms

07/03/2023 0 Comments 0 tags

Cybersecurity researchers have discovered a new information stealer dubbed SYS01stealer targeting critical government infrastructure employees, manufacturing companies, and other sectors. “The threat actors behind the campaign are targeting Facebook business