True Protection or False Promise? The Ultimate ITDR Shortlisting Guide

10/07/2024 0 Comments 0 tags

It’s the age of identity security. The explosion of driven ransomware attacks has made CISOs and security teams realize that identity protection lags 20 years behind their endpoints and networks.

Microsoft’s July Update Patches 143 Flaws, Including Two Actively Exploited

10/07/2024 0 Comments 0 tags

Microsoft has released patches to address a total of 143 security flaws as part of its monthly security updates, two of which have come under active exploitation in the wild.

Smash-and-Grab Extortion

10/07/2024 0 Comments 0 tags

The Problem The “2024 Attack Intelligence Report” from the staff at Rapid7 [1] is a well-researched, well-written report that is worthy of careful study. Some key takeaways are:  53% of

Google Adds Passkeys to Advanced Protection Program for High-Risk Users

10/07/2024 0 Comments 0 tags

Google on Wednesday announced that it’s making available passkeys for high-risk users to enroll in its Advanced Protection Program (APP). “Users traditionally needed a physical security key for APP —

ViperSoftX Malware Disguises as eBooks on Torrents to Spread Stealthy Attacks

10/07/2024 0 Comments 0 tags

The sophisticated malware known as ViperSoftX has been observed being distributed as eBooks over torrents. “A notable aspect of the current variant of ViperSoftX is that it uses the Common

Crypto Analysts Expose HuiOne Guarantee’s $11 Billion Cybercrime Transactions

10/07/2024 0 Comments 0 tags

Cryptocurrency analysts have shed light on an online marketplace called HuiOne Guarantee that’s widely used by cybercriminals in Southeast Asia, particularly those linked to pig butchering scams. “Merchants on the

New OpenSSH Vulnerability Discovered: Potential Remote Code Execution Risk

10/07/2024 0 Comments 0 tags

Select versions of the OpenSSH secure networking suite are susceptible to a new vulnerability that can trigger remote code execution (RCE). The vulnerability, tracked as CVE-2024-6409 (CVSS score: 7.0), is

Hackers Exploiting Jenkins Script Console for Cryptocurrency Mining Attacks

10/07/2024 0 Comments 0 tags

Cybersecurity researchers have found that it’s possible for attackers to weaponize improperly configured Jenkins Script Console instances to further criminal activities such as cryptocurrency mining. “Misconfigurations such as improperly set

RADIUS Protocol Vulnerability Exposes Networks to MitM Attacks

10/07/2024 0 Comments 0 tags

Cybersecurity researchers have discovered a security vulnerability in the RADIUS network authentication protocol called BlastRADIUS that could be exploited by an attacker to stage Mallory-in-the-middle (MitM) attacks and bypass integrity

GuardZoo Malware Targets Over 450 Middle Eastern Military Personnel

09/07/2024 0 Comments 0 tags

Military personnel from Middle East countries are the target of an ongoing surveillanceware operation that delivers an Android data-gathering tool called GuardZoo. The campaign, believed to have commenced as early