Intel and Lenovo BMCs Contain Unpatched Lighttpd Server Flaw

15/04/2024 0 Comments 0 tags

A security flaw impacting the Lighttpd web server used in baseboard management controllers (BMCs) has remained unpatched by device vendors like Intel and Lenovo, new findings from Binarly reveal. While

Palo Alto Networks Releases Urgent Fixes for Exploited PAN-OS Vulnerability

15/04/2024 0 Comments 0 tags

Palo Alto Networks has released hotfixes to address a maximum-severity security flaw impacting PAN-OS software that has come under active exploitation in the wild. Tracked as CVE-2024-3400 (CVSS score: 10.0), the critical

Chinese-Linked LightSpy iOS Spyware Targets South Asian iPhone Users

15/04/2024 0 Comments 0 tags

Cybersecurity researchers have discovered a “renewed” cyber espionage campaign targeting users in South Asia with the aim of delivering an Apple iOS spyware implant called LightSpy. “The latest iteration of LightSpy,

Timing is Everything: The Role of Just-in-Time Privileged Access in Security Evolution

15/04/2024 0 Comments 0 tags

To minimize the risk of privilege misuse, a trend in the privileged access management (PAM) solution market involves implementing just-in-time (JIT) privileged access. This approach to privileged identity management aims to mitigate

U.S. Treasury Hamas Spokesperson for Cyber Influence Operations

13/04/2024 0 Comments 0 tags

The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) on Friday announced sanctions against an official associated with Hamas for his involvement in cyber influence operations. Hudhayfa Samir ‘Abdallah

Ex-Security Engineer Jailed 3 Years for $12.3 Million Crypto Exchange Thefts

13/04/2024 0 Comments 0 tags

A former security engineer has been sentenced to three years in prison in the U.S. for charges relating to hacking two decentralized cryptocurrency exchanges in July 2022 and stealing over $12.3 million.

Hackers Deploy Python Backdoor in Palo Alto Zero-Day Attack

13/04/2024 0 Comments 0 tags

Threat actors have been exploiting the newly disclosed zero-day flaw in Palo Alto Networks PAN-OS software dating back to March 26, 2024, nearly three weeks before it came to light

Popular Rust Crate liblzma-sys Compromised with XZ Utils Backdoor Files

12/04/2024 0 Comments 0 tags

“Test files” associated with the XZ Utils backdoor have made their way to a Rust crate known as liblzma-sys, new findings from Phylum reveal. liblzma-sys, which has been downloaded over 21,000 times to date, provides

Code Keepers: Mastering Non-Human Identity Management

12/04/2024 0 Comments 0 tags

Identities now transcend human boundaries. Within each line of code and every API call lies a non-human identity. These entities act as programmatic access keys, enabling authentication and facilitating interactions

Zero-Day Alert: Critical Palo Alto Networks PAN-OS Flaw Under Active Attack

12/04/2024 0 Comments 0 tags

Palo Alto Networks is warning that a critical flaw impacting its PAN-OS software used in its GlobalProtect gateways is being exploited in the wild. Tracked as CVE-2024-3400, the issue has a