The New Effective Way to Prevent Account Takeovers

04/09/2024 0 Comments 0 tags

Account takeover attacks have emerged as one of the most persistent and damaging threats to cloud-based SaaS environments. Yet despite significant investments in traditional security measures, many organizations continue to

Hackers Hijack 22,000 Removed PyPI Packages, Spreading Malicious Code to Developers

04/09/2024 0 Comments 0 tags

A new supply chain attack technique targeting the Python Package Index (PyPI) registry has been exploited in the wild in an attempt to infiltrate downstream organizations. It has been codenamed

Clearview AI Faces €30.5M Fine for Building Illegal Facial Recognition Database

04/09/2024 0 Comments 0 tags

The Dutch Data Protection Authority (Dutch DPA) has imposed a fine of €30.5 million ($33.7 million) against facial recognition firm Clearview AI for violating the General Data Protection Regulation (GDPR)

Hackers Use Fake GlobalProtect VPN Software in New WikiLoader Malware Attack

04/09/2024 0 Comments 0 tags

A new malware campaign is spoofing Palo Alto Networks’ GlobalProtect VPN software to deliver a variant of the WikiLoader (aka WailingCrab) loader by means of a search engine optimization (SEO)

New Rust-Based Ransomware Cicada3301 Targets Windows and Linux Systems

03/09/2024 0 Comments 0 tags

Cybersecurity researchers have unpacked the inner workings of a new ransomware variant called Cicada3301 that shares similarities with the now-defunct BlackCat (aka ALPHV) operation. “It appears that Cicada3301 ransomware primarily

Hacktivists Exploits WinRAR Vulnerability in Attacks Against Russia and Belarus

03/09/2024 0 Comments 0 tags

A hacktivist group known as Head Mare has been linked to cyber attacks that exclusively target organizations located in Russia and Belarus. “Head Mare uses more up-to-date methods for obtaining

Rocinante Trojan Poses as Banking Apps to Steal Sensitive Data from Brazilian Android Users

03/09/2024 0 Comments 0 tags

Mobile users in Brazil are the target of a new malware campaign that delivers a new Android banking trojan named Rocinante. “This malware family is capable of performing keylogging using

Secrets Exposed: Why Your CISO Should Worry About Slack

03/09/2024 0 Comments 0 tags

In the digital realm, secrets (API keys, private keys, username and password combos, etc.) are the keys to the kingdom. But what if those keys were accidentally left out in

New Flaws in Microsoft macOS Apps Could Allow Hackers to Gain Unrestricted Access

03/09/2024 0 Comments 0 tags

Eight vulnerabilities have been uncovered in Microsoft applications for macOS that an adversary could exploit to gain elevated privileges or access sensitive data by circumventing the operating system’s permissions-based model,

Ex-Engineer Charged in Missouri for Failed $750,000 Bitcoin Extortion Attempt

03/09/2024 0 Comments 0 tags

A 57-year-old man from the U.S. state of Missouri has been arrested in connection with a failed data extortion campaign that targeted his former employer. Daniel Rhyne of Kansas City,