Alert: Hackers Exploit Barracuda Email Security Gateway 0-Day Flaw for 7 Months

01/06/2023 0 Comments 0 tags

Enterprise security firm Barracuda on Tuesday disclosed that a recently patched zero-day flaw in its Email Security Gateway (ESG) appliances had been abused by threat actors since October 2022 to

RomCom RAT Using Deceptive Web of Rogue Software Sites for Covert Attacks

01/06/2023 0 Comments 0 tags

The threat actors behind RomCom RAT are leveraging a network of fake websites advertising rogue versions of popular software at least since July 2022 to infiltrate targets. Cybersecurity firm Trend Micro is

Dark Pink APT Group Leverages TelePowerBot and KamiKakaBot in Sophisticated Attacks

01/06/2023 0 Comments 0 tags

The threat actor known as Dark Pink has been linked to five new attacks aimed at various entities in Belgium, Brunei, Indonesia, Thailand, and Vietnam between February 2022 and April 2023. This

6 Steps to Effectively Threat Hunting: Safeguard Critical Assets and Fight Cybercrime

01/06/2023 0 Comments 0 tags

Finding threat actors before they find you is key to beefing up your cyber defenses. How to do that efficiently and effectively is no small task – but with a

Microsoft Details Critical Apple macOS Vulnerability Allowing SIP Protection Bypass

01/06/2023 0 Comments 0 tags

Microsoft has shared details of a now-patched flaw in Apple macOS that could be abused by threat actors with root access to bypass security enforcements and perform arbitrary actions on

Beware of Ghost Sites: Silent Threat Lurking in Your Salesforce Communities

01/06/2023 0 Comments 0 tags

Improperly deactivated and abandoned Salesforce Sites and Communities (aka Experience Cloud) could pose severe risks to organizations, leading to unauthorized access to sensitive data. Data security firm Varonis dubbed the abandoned, unprotected, and unmonitored

Critical Firmware Vulnerability in Gigabyte Systems Exposes ~7 Million Devices

01/06/2023 0 Comments 0 tags

Cybersecurity researchers have found “backdoor-like behavior” within Gigabyte systems, which they say enables the UEFI firmware of the devices to drop a Windows executable and retrieve updates in an unsecure format. Firmware

Cybercriminals Targeting Apache NiFi Instances for Cryptocurrency Mining

01/06/2023 0 Comments 0 tags

A financially motivated threat actor is actively scouring the internet for unprotected Apache NiFi instances to covertly install a cryptocurrency miner and facilitate lateral movement. The findings come from the SANS Internet

PyPI Implements Mandatory Two-Factor Authentication for Project Owners

30/05/2023 0 Comments 0 tags

The Python Package Index (PyPI) announced last week that every account that maintains a project on the official third-party software repository will be required to turn on two-factor authentication (2FA)

Don’t Click That ZIP File! Phishers Weaponizing .ZIP Domains to Trick Victims

30/05/2023 0 Comments 0 tags

A new phishing technique called “file archiver in the browser” can be leveraged to “emulate” a file archiver software in a web browser when a victim visits a .ZIP domain.