U.S. State Government Network Breached via Former Employee’s Account

16/02/2024 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has revealed that an unnamed state government organization’s network environment was compromised via an administrator account belonging to a former employee. “This

Malicious ‘SNS Sender’ Script Abuses AWS for Bulk Smishing Attacks

16/02/2024 0 Comments 0 tags

A malicious Python script known as SNS Sender is being advertised as a way for threat actors to send bulk smishing messages by abusing Amazon Web Services (AWS) Simple Notification Service (SNS).

Why We Must Democratize Cybersecurity

16/02/2024 0 Comments 0 tags

With breaches making the headlines on an almost weekly basis, the cybersecurity challenges we face are becoming visible not only to large enterprises, who have built security capabilities over the

RustDoor macOS Backdoor Targets Cryptocurrency Firms with Fake Job Offers

16/02/2024 0 Comments 0 tags

Several companies operating in the cryptocurrency sector are the target of a newly discovered Apple macOS backdoor codenamed RustDoor. RustDoor was first documented by Bitdefender last week, describing it as a Rust-based

U.S. Government Disrupts Russian-Linked Botnet Engaged in Cyber Espionage

16/02/2024 0 Comments 0 tags

The U.S. government on Thursday said it disrupted a botnet comprising hundreds of small office and home office (SOHO) routers in the country that was put to use by the

Ivanti Pulse Secure Found Using 11-Year-Old Linux Version and Outdated Libraries

15/02/2024 0 Comments 0 tags

A reverse engineering of the firmware running on Ivanti Pulse Secure appliances has revealed numerous weaknesses, once again underscoring the challenge of securing software supply chains. Eclypsiusm, which acquired firmware

Russian Turla Hackers Target Polish NGOs with New TinyTurla-NG Backdoor

15/02/2024 0 Comments 0 tags

The Russia-linked threat actor known as Turla has been observed using a new backdoor called TinyTurla-NG as part of a three-month-long campaign targeting Polish non-governmental organizations in December 2023. “TinyTurla-NG, just like

Critical Exchange Server Flaw (CVE-2024-21410) Under Active Exploitation

15/02/2024 0 Comments 0 tags

Microsoft on Wednesday acknowledged that a newly disclosed critical security flaw in Exchange Server has been actively exploited in the wild, a day after it released fixes for the vulnerability

Chinese Hackers Using Deepfakes in Advanced Mobile Banking Malware Attacks

15/02/2024 0 Comments 0 tags

A Chinese-speaking threat actor codenamed GoldFactory has been attributed to the development of highly sophisticated banking trojans, including a previously undocumented iOS malware called GoldPickaxe that’s capable of harvesting identity documents, facial

How Nation-State Actors Target Your Business: New Research Exposes Major SaaS Vulnerabilities

15/02/2024 0 Comments 0 tags

With many of the highly publicized 2023 cyber attacks revolving around one or more SaaS applications, SaaS has become a cause for genuine concern in many boardroom discussions. More so