HTTP/2 Rapid Reset Zero-Day Vulnerability Exploited to Launch Record DDoS Attacks

11/10/2023 0 Comments 0 tags

Amazon Web Services (AWS), Cloudflare, and Google on Tuesday said they took steps to mitigate record-breaking distributed denial-of-service (DDoS) attacks that relied on a novel technique called HTTP/2 Rapid Reset.

Google Adopts Passkeys as Default Sign-in Method for All Users

11/10/2023 0 Comments 0 tags

Google on Tuesday announced the ability for all users to set up passkeys by default, five months after it rolled out support for the FIDO Alliance-backed passwordless standard for Google Accounts on

New Report: Child Sexual Abuse Content and Online Risks to Children on the Rise

11/10/2023 0 Comments 0 tags

Certain online risks to children are on the rise, according to a recent report from Thorn, a technology nonprofit whose mission is to build technology to defend children from sexual

Researchers Uncover Grayling APT’s Ongoing Attack Campaign Across Industries

11/10/2023 0 Comments 0 tags

A previously undocumented threat actor of unknown provenance has been linked to a number of attacks targeting organizations in the manufacturing, IT, and biomedical sectors in Taiwan. The Symantec Threat

New Magecart Campaign Alters 404 Error Pages to Steal Shoppers’ Credit Cards

11/10/2023 0 Comments 0 tags

A sophisticated Magecart campaign has been observed manipulating websites’ default 404 error page to conceal malicious code in what’s been described as the latest evolution of the attacks. The activity, per Akamai,

libcue Library Flaw Opens GNOME Linux Systems Vulnerable to RCE Attacks

11/10/2023 0 Comments 0 tags

A new security flaw has been disclosed in the libcue library impacting GNOME Linux systems that could be exploited to achieve remote code execution (RCE) on affected hosts. Tracked as CVE-2023-43641 (CVSS

Citrix Devices Under Attack: NetScaler Flaw Exploited to Capture User Credentials

11/10/2023 0 Comments 0 tags

A recently disclosed critical flaw in Citrix NetScaler ADC and Gateway devices is being exploited by threat actors to conduct a credential harvesting campaign. IBM X-Force, which uncovered the activity

PEACHPIT: Massive Ad Fraud Botnet Powered by Millions of Hacked Android and iOS

11/10/2023 0 Comments 0 tags

An ad fraud botnet dubbed PEACHPIT leveraged an army of hundreds of thousands of Android and iOS devices to generate illicit profits for the threat actors behind the scheme. The botnet is

Cybercriminals Using EvilProxy Phishing Kit to Target Senior Executives in U.S. Firms

11/10/2023 0 Comments 0 tags

Senior executives working in U.S.-based organizations are being targeted by a new phishing campaign that leverages a popular adversary-in-the-middle (AiTM) phishing toolkit named EvilProxy to conduct credential harvesting and account takeover attacks.

Webinar: How vCISOs Can Navigating the Complex World of AI and LLM Security

11/10/2023 0 Comments 0 tags

In today’s rapidly evolving technological landscape, the integration of Artificial Intelligence (AI) and Large Language Models (LLMs) has become ubiquitous across various industries. This wave of innovation promises improved efficiency