Are Your APIs Leaking Sensitive Data?

22/05/2023 0 Comments 0 tags

It’s no secret that data leaks have become a major concern for both citizens and institutions across the globe. They can cause serious damage to an organization’s reputation, induce considerable

KeePass Exploit Allows Attackers to Recover Master Passwords from Memory

22/05/2023 0 Comments 0 tags

A proof-of-concept (PoC) has been made available for a security flaw impacting the KeePass password manager that could be exploited to recover a victim’s master password in cleartext under specific

PyPI Repository Under Attack: User Sign-Ups and Package Uploads Temporarily Halted

21/05/2023 0 Comments 0 tags

The maintainers of Python Package Index (PyPI), the official third-party software repository for the Python programming language, have temporarily disabled the ability for users to sign up and upload new

Meet ‘Jack’ from Romania! Mastermind Behind Golden Chickens Malware

21/05/2023 0 Comments 0 tags

The identity of the second threat actor behind the Golden Chickens malware has been uncovered courtesy of a “fatal” operational security blunder, cybersecurity firm eSentire said. The individual in question,

Notorious Cyber Gang FIN7 Returns With Cl0p Ransomware in New Wave of Attacks

21/05/2023 0 Comments 0 tags

The notorious cybercrime group known as FIN7 has been observed deploying Cl0p (aka Clop) ransomware, marking the threat actor’s first ransomware campaign since late 2021. Microsoft, which detected the activity in April

Warning: Samsung Devices Under Attack! New Security Flaw Exposed

21/05/2023 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned of active exploitation of a medium-severity flaw affecting Samsung devices. The issue, tracked as CVE-2023-21492 (CVSS score: 4.4), impacts select Samsung devices

Dr. Active Directory vs. Mr. Exposed Attack Surface: Who’ll Win This Fight?

20/05/2023 0 Comments 0 tags

Active Directory (AD) is among the oldest pieces of software still used in the production environment and can be found in most organizations today. This is despite the fact that

Developer Alert: NPM Packages for Node.js Hiding Dangerous TurkoRat Malware

20/05/2023 0 Comments 0 tags

Two malicious packages discovered in the npm package repository have been found to conceal an open source information stealer malware called TurkoRat. The packages – named nodejs-encrypt-agent and nodejs-cookie-proxy-agent – were

Searching for AI Tools? Watch Out for Rogue Sites Distributing RedLine Malware

20/05/2023 0 Comments 0 tags

Malicious Google Search ads for generative AI services like OpenAI ChatGPT and Midjourney are being used to direct users to sketchy websites as part of a BATLOADER campaign designed to

WebKit Under Attack: Apple Issues Emergency Patches for 3 New Zero-Day Vulnerabilities

20/05/2023 0 Comments 0 tags

Apple on Thursday rolled out security updates to iOS, iPadOS, macOS, tvOS, watchOS, and the Safari web browser to address three new zero-day flaws that it said are being actively exploited in