Windows Downgrade Attack Risks Exposing Patched Systems to Old Vulnerabilities

08/08/2024 0 Comments 0 tags

Microsoft said it is developing security updates to address two loopholes that it said could be abused to stage downgrade attacks against the Windows update architecture and replace current versions

Roundcube Webmail Flaws Allow Hackers to Steal Emails and Passwords

07/08/2024 0 Comments 0 tags

Cybersecurity researchers have disclosed details of security flaws in the Roundcube webmail software that could be exploited to execute malicious JavaScript in a victim’s web browser and steal sensitive information

New Linux Kernel Exploit Technique ‘SLUBStick’ Discovered by Researchers

07/08/2024 0 Comments 0 tags

Cybersecurity researchers have shed light on a novel Linux kernel exploitation technique dubbed SLUBStick that could be exploited to elevate a limited heap vulnerability to an arbitrary memory read-and-write primitive.

Apple’s New macOS Sequoia Tightens Gatekeeper Controls to Block Unauthorized Software

07/08/2024 0 Comments 0 tags

Apple on Tuesday announced an update to its next-generation macOS version that makes it a little more difficult for users to override Gatekeeper protections. Gatekeeper is a crucial line of

Chameleon Android Banking Trojan Targets Users Through Fake CRM App

07/08/2024 0 Comments 0 tags

Cybersecurity researchers have lifted the lid on a new technique adopted by threat actors behind the Chameleon Android banking trojan targeting users in Canada by masquerading as a Customer Relationship

CrowdStrike Reveals Root Cause of Global System Outages

07/08/2024 0 Comments 0 tags

Cybersecurity company CrowdStrike has published its root cause analysis detailing the Falcon Sensor software update crash that crippled millions of Windows devices globally. The “Channel File 291” incident, as originally

New Go-based Backdoor GoGra Targets South Asian Media Organization

07/08/2024 0 Comments 0 tags

An unnamed media organization in South Asia was targeted in November 20233 using a previously undocumented Go-based backdoor called GoGra. “GoGra is written in Go and uses the Microsoft Graph

INTERPOL Recovers $41 Million in Largest Ever BEC Scam in Singapore

06/08/2024 0 Comments 0 tags

INTERPOL said it devised a “global stop-payment mechanism” that helped facilitate the largest-ever recovery of funds defrauded in a business email compromise (BEC) scam.  The development comes after an unnamed

North Korean Hackers Moonstone Sleet Push Malicious JS Packages to npm Registry

06/08/2024 0 Comments 0 tags

The North Korea-linked threat actor known as Moonstone Sleet has continued to push malicious npm packages to the JavaScript package registry with the aim of infecting Windows systems, underscoring the

Suspicious Minds: Insider Threats in The SaaS World

06/08/2024 0 Comments 0 tags

Everyone loves the double-agent plot twist in a spy movie, but it’s a different story when it comes to securing company data. Whether intentional or unintentional, insider threats are a