Chinese Hackers Spotted Using Linux Variant of PingPull in Targeted Cyberattacks

26/04/2023 0 Comments 0 tags

The Chinese nation-state group dubbed Alloy Taurus is using a Linux variant of a backdoor called PingPull as well as a new undocumented tool codenamed Sword2033. That’s according to findings from Palo

Charming Kitten’s New BellaCiao Malware Discovered in Multi-Country Attacks

26/04/2023 0 Comments 0 tags

The prolific Iranian nation-state group known as Charming Kitten targeted multiple victims in the U.S., Europe, the Middle East and India with a novel malware dubbed BellaCiao, adding to its ever-expanding list of

Chinese Hackers Using MgBot Malware to Target International NGOs in Mainland China

26/04/2023 0 Comments 0 tags

The advanced persistent threat (APT) group referred to as Evasive Panda has been observed targeting an international non-governmental organization (NGO) in Mainland China with malware delivered via update channels of legitimate applications

Browser Security Survey: 87% of SaaS Adopters Exposed to Browser-borne Attacks

26/04/2023 0 Comments 0 tags

The browser serves as the primary interface between the on-premises environment, the cloud, and the web in the modern enterprise. Therefore, the browser is also exposed to multiple types of

Apache Superset Vulnerability: Insecure Default Configuration Exposes Servers to RCE Attacks

26/04/2023 0 Comments 0 tags

The maintainers of the Apache Superset open source data visualization software have released fixes to plug an insecure default configuration that could lead to remote code execution. The vulnerability, tracked as CVE-2023-27524 (CVSS score:

VMware Releases Critical Patches for Workstation and Fusion Software

26/04/2023 0 Comments 0 tags

VMware has released updates to resolve multiple security flaws impacting its Workstation and Fusion software, the most critical of which could allow a local attacker to achieve code execution. The

Iranian Hackers Launch Sophisticated Attacks Targeting Israel with PowerLess Backdoor

25/04/2023 0 Comments 0 tags

An Iranian nation-state threat actor has been linked to a new wave of phishing attacks targeting Israel that’s designed to deploy an updated version of a backdoor called PowerLess. Cybersecurity

Modernizing Vulnerability Management: The Move Toward Exposure Management

25/04/2023 0 Comments 0 tags

Managing vulnerabilities in the constantly evolving technological landscape is a difficult task. Although vulnerabilities emerge regularly, not all vulnerabilities present the same level of risk. Traditional metrics such as CVSS

Lazarus Subgroup Targeting Apple Devices with New RustBucket macOS Malware

25/04/2023 0 Comments 0 tags

A financially-motivated North Korean threat actor is suspected to be behind a new Apple macOS malware strain called RustBucket. “[RustBucket] communicates with command and control (C2) servers to download and execute

Google Cloud Introduces Security AI Workbench for Faster Threat Detection and Analysis

25/04/2023 0 Comments 0 tags

Google’s cloud division is following in the footsteps of Microsoft with the launch of Security AI Workbench that leverages generative AI models to gain better visibility into the threat landscape.  Powering the cybersecurity suite