Ransomware Gangs Use LockBit’s Fame to Intimidate Victims in Latest Attacks

23/10/2024 0 Comments 0 tags

Threat actors have been observed abusing Amazon S3 (Simple Storage Service) Transfer Acceleration feature as part of ransomware attacks designed to exfiltrate victim data and upload them to S3 buckets

Think You’re Secure? 49% of Enterprises Underestimate SaaS Risks

23/10/2024 0 Comments 0 tags

It may come as a surprise to learn that 34% of security practitioners are in the dark about how many SaaS applications are deployed in their organizations. And it’s no

Researchers Reveal ‘Deceptive Delight’ Method to Jailbreak AI Models

23/10/2024 0 Comments 0 tags

Cybersecurity researchers have shed light on a new adversarial technique that could be used to jailbreak large language models (LLMs) during the course of an interactive conversation by sneaking in

Gophish Framework Used in Phishing Campaigns to Deploy Remote Access Trojans

22/10/2024 0 Comments 0 tags

Russian-speaking users have become the target of a new phishing campaign that leverages an open-source phishing toolkit called Gophish to deliver DarkCrystal RAT (aka DCRat) and a previously undocumented remote

Cybercriminals Exploiting Docker API Servers for SRBMiner Crypto Mining Attacks

22/10/2024 0 Comments 0 tags

Bad actors have been observed targeting Docker remote API servers to deploy the SRBMiner crypto miner on compromised instances, according to new findings from Trend Micro. “In this attack, the

Security Flaw in Styra’s OPA Exposes NTLM Hashes to Remote Attackers

22/10/2024 0 Comments 0 tags

Details have emerged about a now-patched security flaw in Styra’s Open Policy Agent (OPA) that, if successfully exploited, could have led to leakage of New Technology LAN Manager (NTLM) hashes.

A Comprehensive Guide to Finding Service Accounts in Active Directory

22/10/2024 0 Comments 0 tags

Service accounts are vital in any enterprise, running automated processes like managing applications or scripts. However, without proper monitoring, they can pose a significant security risk due to their elevated

Malicious npm Packages Target Developers’ Ethereum Wallets with SSH Backdoor

22/10/2024 0 Comments 0 tags

Cybersecurity researchers have discovered a number of suspicious packages published to the npm registry that are designed to harvest Ethereum private keys and gain remote access to the machine via

Bumblebee and Latrodectus Malware Return with Sophisticated Phishing Strategies

22/10/2024 0 Comments 0 tags

Two malware families that suffered setbacks in the aftermath of a coordinated law enforcement operation called Endgame have resurfaced as part of new phishing campaigns. Bumblebee and Latrodectus, which are

VMware Releases vCenter Server Update to Fix Critical RCE Vulnerability

22/10/2024 0 Comments 0 tags

VMware has released software updates to address an already patched security flaw in vCenter Server that could pave the way for remote code execution. The vulnerability, tracked as CVE-2024-38812 (CVSS