CISA Adds Three Security Flaws with Active Exploitation to KEV Catalog

17/11/2023 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added three security flaws to its Known Exploited Vulnerabilities (KEV) catalog based on evidence of active exploitation in the wild.

Zero-Day Flaw in Zimbra Email Software Exploited by Four Hacker Groups

17/11/2023 0 Comments 0 tags

A zero-day flaw in the Zimbra Collaboration email software was exploited by four different groups in real-world attacks to pilfer email data, user credentials, and authentication tokens. “Most of this

Experts Uncover DarkCasino: New Emerging APT Threat Exploiting WinRAR Flaw

16/11/2023 0 Comments 0 tags

A hacking group that leveraged a recently disclosed security flaw in the WinRAR software as a zero-day has now been categorized as an entirely new advanced persistent threat (APT). Cybersecurity

CISA and FBI Issue Warning About Rhysida Ransomware Double Extortion Attacks

16/11/2023 0 Comments 0 tags

The threat actors behind the Rhysida ransomware engage in opportunistic attacks targeting organizations spanning various industry sectors. The advisory comes courtesy of the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Federal

How to Automate the Hardest Parts of Employee Offboarding

16/11/2023 0 Comments 0 tags

According to recent research on employee offboarding, 70% of IT professionals say they’ve experienced the negative effects of incomplete IT offboarding, whether in the form of a security incident tied to

Hackers Could Exploit Google Workspace and Cloud Platform for Ransomware Attacks

16/11/2023 0 Comments 0 tags

A set of novel attack methods has been demonstrated against Google Workspace and the Google Cloud Platform that could be potentially leveraged by threat actors to conduct ransomware, data exfiltration,

Russian Hackers Linked to ‘Largest Ever Cyber Attack’ on Danish Critical Infrastructure

16/11/2023 0 Comments 0 tags

Russian threat actors have been possibly linked to what’s been described as the “largest cyber attack against Danish critical infrastructure,” in which 22 companies associated with the operation of the

U.S. Takes Down IPStorm Botnet, Russian-Moldovan Mastermind Pleads Guilty

15/11/2023 0 Comments 0 tags

The U.S. government on Tuesday announced the takedown of the IPStorm botnet proxy network and its infrastructure, as the Russian and Moldovan national behind the operation pleaded guilty. “The botnet

New PoC Exploit for Apache ActiveMQ Flaw Could Let Attackers Fly Under the Radar

15/11/2023 0 Comments 0 tags

Cybersecurity researchers have demonstrated a new technique that exploits a critical security flaw in Apache ActiveMQ to achieve arbitrary code execution in memory. Tracked as CVE-2023-46604 (CVSS score: 10.0), the vulnerability is

Three Ways Varonis Helps You Fight Insider Threats

15/11/2023 0 Comments 0 tags

What do basketball teams, government agencies, and car manufacturers have in common? Each one has been breached, having confidential, proprietary, or private information stolen and exposed by insiders. In each