CISA Adds Citrix ShareFile Flaw to KEV Catalog Due to In-the-Wild Attacks

17/08/2023 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical security flaw in Citrix ShareFile storage zones controller to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence

What’s the State of Credential theft in 2023?

17/08/2023 0 Comments 0 tags

At a little overt halfway through 2023, credential theft is still a major thorn in the side of IT teams. The heart of the problem is the value of data

Experts Uncover Weaknesses in PowerShell Gallery Enabling Supply Chain Attacks

17/08/2023 0 Comments 0 tags

Active flaws in the PowerShell Gallery could be weaponized by threat actors to pull off supply chain attacks against the registry’s users. “These flaws make typosquatting attacks inevitable in this

Guide: How Google Workspace-based Organizations can leverage Chrome to improve Security

17/08/2023 0 Comments 0 tags

More and more organizations are choosing Google Workspace as their default employee toolset of choice. But despite the productivity advantages, this organizational action also incurs a new security debt. Security

Google Introduces First Quantum Resilient FIDO2 Security Key Implementation

17/08/2023 0 Comments 0 tags

Google on Tuesday announced the first quantum resilient FIDO2 security key implementation as part of its OpenSK security keys initiative. “This open-source hardware optimized implementation uses a novel ECC/Dilithium hybrid

Critical Security Flaws Affect Ivanti Avalanche, Threatening 30,000 Organizations

17/08/2023 0 Comments 0 tags

Multiple critical security flaws have been reported in Ivanti Avalanche, an enterprise mobile device management solution that’s used by 30,000 organizations. The vulnerabilities, collectively tracked as CVE-2023-32560 (CVSS score: 9.8), are stack-based buffer

Nearly 2,000 Citrix NetScaler Instances Hacked via Critical Vulnerability

16/08/2023 0 Comments 0 tags

Nearly 2,000 Citrix NetScaler instances have been compromised with a backdoor by weaponizing a recently disclosed critical security vulnerability as part of a large-scale attack. “An adversary appears to have

Cybercriminals Abusing Cloudflare R2 for Hosting Phishing Pages, Experts Warn

15/08/2023 0 Comments 0 tags

Threat actors’ use of Cloudflare R2 to host phishing pages has witnessed a 61-fold increase over the past six months. “The majority of the phishing campaigns target Microsoft login credentials,

Multiple Flaws Found in ScrutisWeb Software Exposes ATMs to Remote Hacking

15/08/2023 0 Comments 0 tags

Four security vulnerabilities in the ScrutisWeb ATM fleet monitoring software made by Iagona could be exploited to remotely break into ATMs, upload arbitrary files, and even reboot the terminals. The

Monti Ransomware Returns with New Linux Variant and Enhanced Evasion Tactics

15/08/2023 0 Comments 0 tags

The threat actors behind the Monti ransomware have resurfaced after a two-month break with a new Linux version of the encryptor in its attacks targeting government and legal sectors. Monti emerged in