Critical Zero-Day in Apache OfBiz ERP System Exposes Businesses to Attack

27/12/2023 0 Comments 0 tags

A new zero-day security flaw has been discovered in the Apache OfBiz, an open-source Enterprise Resource Planning (ERP) system that could be exploited to bypass authentication protections. The vulnerability, tracked

Carbanak Banking Malware Resurfaces with New Ransomware Tactics

26/12/2023 0 Comments 0 tags

The banking malware known as Carbanak has been observed being used in ransomware attacks with updated tactics. “The malware has adapted to incorporate attack vendors and techniques to diversify its effectiveness,” cybersecurity firm NCC

Cloud Atlas’ Spear-Phishing Attacks Target Russian Agro and Research Companies

25/12/2023 0 Comments 0 tags

The threat actor referred to as Cloud Atlas has been linked to a set of spear-phishing attacks on Russian enterprises. Targets included a Russian agro-industrial enterprise and a state-owned research company, according

British LAPSUS$ Teen Members Sentenced for High-Profile Attacks

24/12/2023 0 Comments 0 tags

Two British teens part of the LAPSUS$ cyber crime and extortion gang have been sentenced for their roles in orchestrating a string of high-profile attacks against a number of companies.

Rogue WordPress Plugin Exposes E-Commerce Sites to Credit Card Theft

22/12/2023 0 Comments 0 tags

Threat hunters have discovered a rogue WordPress plugin that’s capable of creating bogus administrator users and injecting malicious JavaScript code to steal credit card information. The skimming activity is part

Decoy Microsoft Word Documents Used to Deliver Nim-Based Malware

22/12/2023 0 Comments 0 tags

A new phishing campaign is leveraging decoy Microsoft Word documents as bait to deliver a backdoor written in the Nim programming language. “Malware written in uncommon programming languages puts the security

Operation RusticWeb: Rust-Based Malware Targets Indian Government Entities

22/12/2023 0 Comments 0 tags

Indian government entities and the defense sector have been targeted by a phishing campaign that’s engineered to drop Rust-based malware for intelligence gathering. The activity, first detected in October 2023,

UAC-0099 Using WinRAR Exploit to Target Ukrainian Firms with LONEPAGE Malware

22/12/2023 0 Comments 0 tags

The threat actor known as UAC-0099 has been linked to continued attacks aimed at Ukraine, some of which leverage a high-severity flaw in the WinRAR software to deliver a malware strain called

Microsoft Warns of New ‘FalseFont’ Backdoor Targeting the Defense Sector

22/12/2023 0 Comments 0 tags

Organizations in the Defense Industrial Base (DIB) sector are in the crosshairs of an Iranian threat actor as part of a campaign designed to deliver a never-before-seen backdoor called FalseFont.

Cost of a Data Breach Report 2023: Insights, Mitigators and Best Practices

21/12/2023 0 Comments 0 tags

John Hanley of IBM Security shares 4 key findings from the highly acclaimed annual Cost of a Data Breach Report 2023 What is the IBM Cost of a Data Breach