How to Keep Your Business Running in a Contested Environment

27/10/2023 0 Comments 0 tags

When organizations start incorporating cybersecurity regulations and cyber incident reporting requirements into their security protocols, it’s essential for them to establish comprehensive plans for preparation, mitigation, and response to potential

Google Expands Its Bug Bounty Program to Tackle Artificial Intelligence Threats

27/10/2023 0 Comments 0 tags

Google has announced that it’s expanding its Vulnerability Rewards Program (VRP) to reward researchers for finding attack scenarios tailored to generative artificial intelligence (AI) systems in an effort to bolster AI

F5 Issues Warning: BIG-IP Vulnerability Allows Remote Code Execution

27/10/2023 0 Comments 0 tags

F5 has alerted customers of a critical security vulnerability impacting BIG-IP that could result in unauthenticated remote code execution. The issue, rooted in the configuration utility component, has been assigned

Record-Breaking 100 Million RPS DDoS Attack Exploits HTTP/2 Rapid Reset Flaw

26/10/2023 0 Comments 0 tags

Cloudflare on Thursday said it mitigated thousands of hyper-volumetric HTTP distributed denial-of-service (DDoS) attacks that exploited a recently disclosed flaw called HTTP/2 Rapid Reset, 89 of which exceeded 100 million requests

The Danger of Forgotten Pixels on Websites: A New Case Study

26/10/2023 0 Comments 0 tags

While cyberattacks on websites receive much attention, there are often unaddressed risks that can lead to businesses facing lawsuits and privacy violations even in the absence of hacking incidents. A

Iranian Group Tortoiseshell Launches New Wave of IMAPLoader Malware Attacks

26/10/2023 0 Comments 0 tags

The Iranian threat actor known as Tortoiseshell has been attributed to a new wave of watering hole attacks that are designed to deploy a malware dubbed IMAPLoader. “IMAPLoader is a .NET malware

Critical Flaw in NextGen’s Mirth Connect Could Expose Healthcare Data

26/10/2023 0 Comments 0 tags

Users of Mirth Connect, an open-source data integration platform from NextGen HealthCare, are being urged to update to the latest version following the discovery of an unauthenticated remote code execution vulnerability.

YoroTrooper: Researchers Warn of Kazakhstan’s Stealthy Cyber Espionage Group

26/10/2023 0 Comments 0 tags

A relatively new threat actor known as YoroTrooper is likely made up of operators originating from Kazakhstan. The assessment, which comes from Cisco Talos, is based on their fluency in Kazakh and

Nation State Hackers Exploiting Zero-Day in Roundcube Webmail Software

26/10/2023 0 Comments 0 tags

The threat actor known as Winter Vivern has been observed exploiting a zero-day flaw in Roundcube webmail software on October 11, 2023, to harvest email messages from victims’ accounts. “Winter Vivern has

Critical OAuth Flaws Uncovered in Grammarly, Vidio, and Bukalapak Platforms

26/10/2023 0 Comments 0 tags

Critical security flaws have been disclosed in the Open Authorization (OAuth) implementation of popular online services such as Grammarly, Vidio, and Bukalapak, building upon previous shortcomings uncovered in Booking[.]com and Expo.