Cybercriminals Weaponizing Legitimate Advanced Installer Tool in Crypto-Mining Attacks

10/09/2023 0 Comments 0 tags

A legitimate Windows tool used for creating software packages called Advanced Installer is being abused by threat actors to drop cryptocurrency-mining malware on infected machines since at least November 2021.

U.K. and U.S. Sanction 11 Russia-based Trickbot Cybercrime Gang Members

08/09/2023 0 Comments 0 tags

The U.K. and U.S. governments on Thursday sanctioned 11 individuals who are alleged to be part of the notorious Russia-based TrickBot cybercrime gang. “Russia has long been a safe haven

Cisco Issues Urgent Fix for Authentication Bypass Bug Affecting BroadWorks Platform

08/09/2023 0 Comments 0 tags

Cisco has released security fixes to address multiple security flaws, including a critical bug, that could be exploited by a threat actor to take control of an affected system or

Protecting Your Microsoft IIS Servers Against Malware Attacks

08/09/2023 0 Comments 0 tags

Microsoft Internet Information Services (IIS) is a web server software package designed for Windows Server. Organizations commonly use Microsoft IIS servers to host websites, files, and other content on the

North Korean Hackers Exploit Zero-Day Bug to Target Cybersecurity Researchers

08/09/2023 0 Comments 0 tags

Threat actors associated with North Korea are continuing to target the cybersecurity community using a zero-day bug in an unspecified software over the past several weeks to infiltrate their machines. The findings come from

CISA Warning: Nation-State Hackers Exploit Fortinet and Zoho Vulnerabilities

08/09/2023 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday warned that multiple nation-state actors are exploiting security flaws in Fortinet FortiOS SSL-VPN and Zoho ManageEngine ServiceDesk Plus to gain

Apple Rushes to Patch Zero-Day Flaws Exploited for Pegasus Spyware on iPhones

08/09/2023 0 Comments 0 tags

Apple on Thursday released emergency security updates for iOS, iPadOS, macOS, and watchOS to address two zero-day flaws that have been exploited in the wild to deliver NSO Group’s Pegasus

The State of the Virtual CISO Report: MSP/MSSP Security Strategies for 2024

08/09/2023 0 Comments 0 tags

By the end of 2024, the number of MSPs and MSSPs offering vCISO services is expected to grow by almost 5 fold, as can be seen in figure 1. This

Alert: Apache Superset Vulnerabilities Expose Servers to Remote Code Execution Attacks

08/09/2023 0 Comments 0 tags

Patches have been released to address two new security vulnerabilities in Apache Superset that could be exploited by an attacker to gain remote code execution on affected systems. The update (version 2.1.1)

Mirai Botnet Variant ‘Pandora’ Hijacks Android TVs for Cyberattacks

08/09/2023 0 Comments 0 tags

A Mirai botnet variant called Pandora has been observed infiltrating inexpensive Android-based TV sets and TV boxes and using them as part of a botnet to perform distributed denial-of-service (DDoS) attacks. Doctor Web said