Google Cloud Introduces Security AI Workbench for Faster Threat Detection and Analysis

25/04/2023 0 Comments 0 tags

Google’s cloud division is following in the footsteps of Microsoft with the launch of Security AI Workbench that leverages generative AI models to gain better visibility into the threat landscape.  Powering the cybersecurity suite

Google Authenticator App Gets Cloud Backup Feature for TOTP Codes

25/04/2023 0 Comments 0 tags

Search giant Google on Monday unveiled a major update to its 12-year-old Authenticator app for Android and iOS with an account synchronization option that allows users to back up their time-based one-time

Russian Hackers Tomiris Targeting Central Asia for Intelligence Gathering

25/04/2023 0 Comments 0 tags

The Russian-speaking threat actor behind a backdoor known as Tomiris is primarily focused on gathering intelligence in Central Asia, fresh findings from Kaspersky reveal. “Tomiris’s endgame consistently appears to be

Ransomware Hackers Using AuKill Tool to Disable EDR Software Using BYOVD Attack

25/04/2023 0 Comments 0 tags

Threat actors are employing a previously undocumented “defense evasion tool” dubbed AuKill that’s designed to disable endpoint detection and response (EDR) software by means of a Bring Your Own Vulnerable

Study: 84% of Companies Use Breached SaaS Applications – Here’s How to Fix it for Free!

25/04/2023 0 Comments 0 tags

A recent review by Wing Security, a SaaS security company that analyzed the data of over 500 companies, revealed some worrisome information. According to this review, 84% of the companies had

Hackers Exploit Outdated WordPress Plugin to Backdoor Thousands of WordPress Sites

25/04/2023 0 Comments 0 tags

Threat actors have been observed leveraging a legitimate but outdated WordPress plugin to surreptitiously backdoor websites as part of an ongoing campaign, Sucuri revealed in a report published last week. The plugin

New SLP Vulnerability Could Let Attackers Launch 2200x Powerful DDoS Attacks

25/04/2023 0 Comments 0 tags

Details have emerged about a high-severity security vulnerability impacting Service Location Protocol (SLP) that could be weaponized to launch volumetric denial-of-service attacks against targets. “Attackers exploiting this vulnerability could leverage

Lazarus X_TRADER Hack Impacts Critical Infrastructure Beyond 3CX Breach

22/04/2023 0 Comments 0 tags

Lazarus, the prolific North Korean hacking group behind the cascading supply chain attack targeting 3CX, also breached two critical infrastructure organizations in the power and energy sector and two other businesses

CISA Adds 3 Actively Exploited Flaws to KEV Catalog, including Critical PaperCut Bug

22/04/2023 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The three vulnerabilities are as

Kubernetes RBAC Exploited in Large-Scale Campaign for Cryptocurrency Mining

21/04/2023 0 Comments 0 tags

A large-scale attack campaign discovered in the wild has been exploiting Kubernetes (K8s) Role-Based Access Control (RBAC) to create backdoors and run cryptocurrency miners. “The attackers also deployed DaemonSets to