From Watering Hole to Spyware: EvilBamboo Targets Tibetans, Uyghurs, and Taiwanese

25/09/2023 0 Comments 0 tags

Tibetan, Uyghur, and Taiwanese individuals and organizations are the targets of a persistent campaign orchestrated by a threat actor codenamed EvilBamboo to gather sensitive information. “The attacker has created fake Tibetan websites,

Are You Willing to Pay the High Cost of Compromised Credentials?

25/09/2023 0 Comments 0 tags

Weak password policies leave organizations vulnerable to attacks. But are the standard password complexity requirements enough to secure them? 83% of compromised passwords would satisfy the password complexity and length requirements of

Webinar — AI vs. AI: Harnessing AI Defenses Against AI-Powered Risks

25/09/2023 0 Comments 0 tags

Generative AI is a double-edged sword, if there ever was one. There is broad agreement that tools like ChatGPT are unleashing waves of productivity across the business, from IT, to

Ukrainian Military Targeted in Phishing Campaign Leveraging Drone Manuals

25/09/2023 0 Comments 0 tags

Ukrainian military entities are the target of a phishing campaign that leverages drone manuals as lures to deliver a Go-based open-source post-exploitation toolkit called Merlin. “Since drones or Unmanned Aerial

New Apple Zero-Days Exploited to Target Egyptian ex-MP with Predator Spyware

24/09/2023 0 Comments 0 tags

The three zero-day flaws addressed by Apple on September 21, 2023, were leveraged as part of an iPhone exploit chain in an attempt to deliver a spyware strain called Predator targeting former Egyptian member

Deadglyph: New Advanced Backdoor with Distinctive Malware Tactics

24/09/2023 0 Comments 0 tags

Cybersecurity researchers have discovered a previously undocumented advanced backdoor dubbed Deadglyph employed by a threat actor known as Stealth Falcon as part of a cyber espionage campaign. “Deadglyph’s architecture is unusual as

Apple Rushes to Patch 3 New Zero-Day Flaws: iOS, macOS, Safari, and More Vulnerable

22/09/2023 0 Comments 0 tags

Apple has released yet another round of security patches to address three actively exploited zero-day flaws impacting iOS, iPadOS, macOS, watchOS, and Safari, taking the total tally of zero-day bugs

High-Severity Flaws Uncovered in Atlassian Products and ISC BIND Server

22/09/2023 0 Comments 0 tags

Atlassian and the Internet Systems Consortium (ISC) have disclosed several security flaws impacting their products that could be exploited to achieve denial-of-service (DoS) and remote code execution. The Australian software

Iranian Nation-State Actor OilRig Targets Israeli Organizations

22/09/2023 0 Comments 0 tags

Israeli organizations were targeted as part of two different campaigns orchestrated by the Iranian nation-state actor known as OilRig in 2021 and 2022. The campaigns, dubbed Outer Space and Juicy Mix, entailed

How to Interpret the 2023 MITRE ATT&CK Evaluation Results

22/09/2023 0 Comments 0 tags

Thorough, independent tests are a vital resource for analyzing provider’s capabilities to guard against increasingly sophisticated threats to their organization. And perhaps no assessment is more widely trusted than the