Chinese State Hackers Target Tibetans with Supply Chain, Watering Hole Attacks

07/03/2024 0 Comments 0 tags

The China-linked threat actor known as Evasive Panda orchestrated both watering hole and supply chain attacks targeting Tibetan users at least since September 2023. The end of the attacks is to deliver

Hacked WordPress Sites Abusing Visitors’ Browsers for Distributed Brute-Force Attacks

07/03/2024 0 Comments 0 tags

Threat actors are conducting brute-force attacks against WordPress sites by leveraging malicious JavaScript injections, new findings from Sucuri reveal. The attacks, which take the form of distributed brute-force attacks, “target

Exit Scam: BlackCat Ransomware Group Vanishes After $22 Million Payout

06/03/2024 0 Comments 0 tags

The threat actors behind the BlackCat ransomware have shut down their darknet website and likely pulled an exit scam after uploading a bogus law enforcement seizure banner. “ALPHV/BlackCat did not get seized.

Hackers Exploit Misconfigured YARN, Docker, Confluence, Redis Servers for Crypto Mining

06/03/2024 0 Comments 0 tags

Threat actors are targeting misconfigured and vulnerable servers running Apache Hadoop YARN, Docker, Atlassian Confluence, and Redis services as part of an emerging malware campaign designed to deliver a cryptocurrency

How to Find and Fix Risky Sharing in Google Drive

06/03/2024 0 Comments 0 tags

Every Google Workspace administrator knows how quickly Google Drive becomes a messy sprawl of loosely shared confidential information. This isn’t anyone’s fault; it’s inevitable as your productivity suite is purposefully

A New Way To Manage Your Web Exposure: The Reflectiz Product Explained

06/03/2024 0 Comments 0 tags

An in-depth look into a proactive website security solution that continuously detects, prioritizes, and validates web threats, helping to mitigate security, privacy, and compliance risks.  [Reflectiz shields websites from client-side attacks,

VMware Issues Security Patches for ESXi, Workstation, and Fusion Flaws

06/03/2024 0 Comments 0 tags

VMware has released patches to address four security flaws impacting ESXi, Workstation, and Fusion, including two critical flaws that could lead to code execution. Tracked as CVE-2024-22252 and CVE-2024-22253, the vulnerabilities

U.S. Cracks Down on Predatory Spyware Firm for Targeting Officials and Journalists

06/03/2024 0 Comments 0 tags

The U.S. Department of Treasury’s Office of Foreign Assets Control (OFAC) sanctioned two individuals and five entities associated with the Intellexa Alliance for their role in “developing, operating, and distributing”

Urgent: Apple Issues Critical Updates for Actively Exploited Zero-Day Flaws

06/03/2024 0 Comments 0 tags

Apple has released security updates to address several security flaws, including two vulnerabilities that it said have been actively exploited in the wild. The shortcomings are listed below – CVE-2024-23225 –

New APT Group ‘Lotus Bane’ Behind Recent Attacks on Vietnam’s Financial Entities

06/03/2024 0 Comments 0 tags

A financial entity in Vietnam was the target of a previously undocumented threat actor called Lotus Bane that was first detected in March 2023. Singapore-headquartered Group-IB described the hacking outfit as an