7 PAM Best Practices to Secure Hybrid and Multi-Cloud Environments

04/12/2024 0 Comments 0 tags

Are you using the cloud or thinking about transitioning? Undoubtedly, multi-cloud and hybrid environments offer numerous benefits for organizations. However, the cloud’s flexibility, scalability, and efficiency come with significant risk

Europol Dismantles Criminal Messaging Service MATRIX in Major Global Takedown

04/12/2024 0 Comments 0 tags

Europol on Tuesday announced the takedown of an invite-only encrypted messaging service called MATRIX that’s created by criminals for criminal purposes. The joint operation, conducted by French and Dutch authorities

How to Plan a New (and Improved!) Password Policy for Real-World Security Challenges

04/12/2024 0 Comments 0 tags

Many organizations struggle with password policies that look strong on paper but fail in practice because they’re too rigid to follow, too vague to enforce, or disconnected from real security

Researchers Uncover Backdoor in Solana’s Popular Web3.js npm Library

04/12/2024 0 Comments 0 tags

Cybersecurity researchers are alerting to a software supply chain attack targeting the popular @solana/web3.js npm library that involved pushing two malicious versions capable of harvesting users’ private keys with an

Joint Advisory Warns of PRC-Backed Cyber Espionage Targeting Telecom Networks

04/12/2024 0 Comments 0 tags

A joint advisory issued by Australia, Canada, New Zealand, and the U.S. has warned of a broad cyber espionage campaign undertaken by People’s Republic of China (PRC)-affiliated threat actors targeting

Hackers Use Corrupted ZIPs and Office Docs to Evade Antivirus and Email Defenses

04/12/2024 0 Comments 0 tags

Cybersecurity researchers have called attention to a novel phishing campaign that leverages corrupted Microsoft Office documents and ZIP archives as a way to bypass email defenses. “The ongoing attack evades

Critical SailPoint IdentityIQ Vulnerability Exposes Files to Unauthorized Access

04/12/2024 0 Comments 0 tags

A critical security vulnerability has been disclosed in SailPoint’s IdentityIQ identity and access management (IAM) software that allows unauthorized access to content stored within the application directory. The flaw, tracked

Veeam Issues Patch for Critical RCE Vulnerability in Service Provider Console

04/12/2024 0 Comments 0 tags

Veeam has released security updates to address a critical flaw impacting Service Provider Console (VSPC) that could pave the way for remote code execution on susceptible instances. The vulnerability, tracked

Cisco Warns of Exploitation of Decade-Old ASA WebVPN Vulnerability

03/12/2024 0 Comments 0 tags

Cisco on Monday updated an advisory to warn customers of active exploitation of a decade-old security flaw impacting its Adaptive Security Appliance (ASA). The vulnerability, tracked as CVE-2014-2120 (CVSS score:

North Korean Kimsuky Hackers Use Russian Email Addresses for Credential Theft Attacks

03/12/2024 0 Comments 0 tags

The North Korea-aligned threat actor known as Kimsuky has been linked to a series of phishing attacks that involve sending email messages that originate from Russian sender addresses to ultimately