15,000 Go Module Repositories on GitHub Vulnerable to Repojacking Attack

05/12/2023 0 Comments 0 tags

New research has found that over 15,000 Go module repositories on GitHub are vulnerable to an attack called repojacking. “More than 9,000 repositories are vulnerable to repojacking due to GitHub

New Threat Actor ‘AeroBlade’ Emerges in Espionage Attack on U.S. Aerospace

05/12/2023 0 Comments 0 tags

A previously undocumented threat actor has been linked to a cyber attack targeting an aerospace organization in the U.S. as part of what’s suspected to be a cyber espionage mission.

Microsoft Warns of Kremlin-Backed APT28 Exploiting Critical Outlook Vulnerability

05/12/2023 0 Comments 0 tags

Microsoft on Monday said it detected Kremlin-backed nation-state activity exploiting a now-patched critical security flaw in its Outlook email service to gain unauthorized access to victims’ accounts within Exchange servers.

New BLUFFS Bluetooth Attack Expose Devices to Adversary-in-the-Middle Attacks

04/12/2023 0 Comments 0 tags

New research has unearthed multiple novel attacks that break Bluetooth Classic’s forward secrecy and future secrecy guarantees, resulting in adversary-in-the-middle (AitM) scenarios between two already connected peers. The issues, collectively

Make a Fresh Start for 2024: Clean Out Your User Inventory to Reduce SaaS Risk

04/12/2023 0 Comments 0 tags

As work ebbs with the typical end-of-year slowdown, now is a good time to review user roles and privileges and remove anyone who shouldn’t have access as well as trim

New P2PInfect Botnet MIPS Variant Targeting Routers and IoT Devices

04/12/2023 0 Comments 0 tags

Cybersecurity researchers have discovered a new variant of an emerging botnet called P2PInfect that’s capable of targeting routers and IoT devices. The latest version, per Cado Security Labs, is compiled for Microprocessor

LogoFAIL: UEFI Vulnerabilities Expose Devices to Stealth Malware Attacks

04/12/2023 0 Comments 0 tags

The Unified Extensible Firmware Interface (UEFI) code from various independent firmware/BIOS vendors (IBVs) has been found vulnerable to potential attacks through high-impact flaws in image parsing libraries embedded into the

Microsoft Warns of Malvertising Scheme Spreading CACTUS Ransomware

04/12/2023 0 Comments 0 tags

Microsoft has warned of a new wave of CACTUS ransomware attacks that leverage malvertising lures to deploy DanaBot as an initial access vector. The DanaBot infections led to “hands-on-keyboard activity

Russian Hacker Vladimir Dunaev Convicted for Creating TrickBot Malware

04/12/2023 0 Comments 0 tags

A Russian national has been found guilty in connection with his role in developing and deploying a malware known as TrickBot, the U.S. Department of Justice (DoJ) announced. Vladimir Dunaev,

Agent Racoon Backdoor Targets Organizations in Middle East, Africa, and U.S.

04/12/2023 0 Comments 0 tags

Organizations in the Middle East, Africa, and the U.S. have been targeted by an unknown threat actor to distribute a new backdoor called Agent Racoon. “This malware family is written using