Researchers uncovered new worming second-stage tools used to locally exfiltrate data from air gapped ICS environments, putting threat actors one step away from transmission of the info to a C2.
0
Air-Gapped ICS Systems Targeted by Sophisticated Malware
Thứ Hai, 31 tháng 7, 2023
Việt Nam Hacker
0
Abyss Locker Ransomware Looks to Drown VMware's ESXi Servers
Việt Nam Hacker
The 4-month-old ransomware gang is now actively targeting VMware's virtual environments with a second variant of its custom malware.
0
Call of Duty Self-Spreading Worm Takes Aim at Player Lobbies
Việt Nam Hacker
The revival of the beloved online multiplayer video game was short-lived once players detected unusual activity and behavior that portended malware.
0
Israeli Oil Refinery Taken Offline by Pro-Iranian Attackers
Việt Nam Hacker
The apparent pro-Iranian Cyber Avengers posted images of BAZAN Groups's SCADA systems, diagrams, and programmable logic controller (PLC) code.
0
Best Practices for Enterprise Private 5G Security
Việt Nam Hacker
Omdia's latest research with Trend Micro and CTOne sheds light on 5G security challenges and ways to effectively extend enterprise-grade security to 5G networks
0
Summer Documentary Watch Party: 8 Sizzling Cybersecurity Tales
Việt Nam Hacker
From the upcoming Billion Dollar Heist to docs on the Ashley Madison breach and Stuxnet, here are a bevy of films that can scratch that wanna-be hacker itch.
0
Healthcare Innovation: A Safe and Secure Approach
Việt Nam Hacker
0
Hack Crew Responsible for Stolen Data, NATO Investigates Claims
Thứ Sáu, 28 tháng 7, 2023
Việt Nam Hacker
NATO asserts that their cyber experts continue to look into the claims and that its classified networks remain secure.
0
CherryBlos Malware Uses OCR to Pluck Android Users' Cryptocurrency
Việt Nam Hacker
0
Choose the Best Biometrics Authentication for Your Use Case
Việt Nam Hacker
0
Senator Blasts Microsoft for Negligence in 365 Email Breach
Việt Nam Hacker
In a letter to the DoJ, FTC and CISA, Oregon's Wyden also called for Microsoft to be held accountable in the sprawling SolarWinds breach.
0
Another AI Pitfall: Digital Mirroring Opens New Cyberattack Vector
Việt Nam Hacker
The more artificial intelligence builds out our digital personas, the easier it will become for bad actors to target us with more convincing attacks.
0
Despite Post-Log4J Security Gains, Developers Can Still Improve
Thứ Năm, 27 tháng 7, 2023
Việt Nam Hacker
Developers need more software security safeguards earlier in the process, especially as AI becomes more common.
0
CompTIA ChannelCon Technology Vendor Fair Highlights Tech Solutions
Việt Nam Hacker
0
Ryanair Hit With Lawsuit Over Use of Facial Recognition Technology
Việt Nam Hacker
Airline violates privacy protections of the EU's General Data Protection Regulation, plaintiff says, seeking a $210 million fine.
0
Millions of People Affected in MOVEit Attack on US Gov't Vendor
Việt Nam Hacker
Living up to its name, Maximus sees a whale of a breach that affects millions of people's sensitive government records, including health data.
0
TSA Updates Pipeline Cybersecurity Requirements
Việt Nam Hacker
The updates will require pipeline owners and operators to do more than just plan for potential cyberattacks; now, those plans will need to be tested.
0
Group-IB Co-Founder Sentenced to 14 Years in Russian Penal Colony
Việt Nam Hacker
Ilya Sachkov, convicted of treason by the Kremlin, will serve time in one of Russia's prison camps, which feature rigid schedules and isolation from the outside world, critics say.
0
Israeli-Trained Azerbaijan Cyber Students Mark Inaugural Graduation
Việt Nam Hacker
Azerbaijan minister pledges to train many more cyber specialists in the coming years to improve regional cyber-readiness.
0
What Will CISA's Secure Software Development Attestation Form Mean?
Việt Nam Hacker
The proposed attestation form is meant to help secure the software chain and formalizes the role of the SBOM as the first line of defense.
0
Rezilion Uncovers High-Risk Vulnerabilities Missing From CISA KEV Catalog
Thứ Tư, 26 tháng 7, 2023
Việt Nam Hacker
0
Massive macOS Campaign Targets Crypto Wallets, Data
Việt Nam Hacker
Threat actors are distributing new "Realst" infostealer via fake blockchain games, researchers warn.
0
SEC Adopts New Rule on Cybersecurity Incident Disclosure Requirements
Việt Nam Hacker
Boards must now file notice of a "material incident" within four business days, although questions remain.
0
Former NSA-er Harry Coker Nominated National Cyber Director
Việt Nam Hacker
The potential nominee is coming in with a model resume and background in cyberspace, as well as strong political support from the Hill.
0
ETSI Dismisses Claims of 'Backdoor' Vulnerabilities in TETRA Standard
Việt Nam Hacker
Nonetheless, European standards body revised the wireless standard and insists its integrity remains sound.
0
Decoy Dog Gets an Upgrade With New Persistence Features
Thứ Ba, 25 tháng 7, 2023
Việt Nam Hacker
At least three actors are using the new, improved version, prompting researchers to conclude it was likely developed by a nation-state.
0
ChatGPT, Other Generative AI Apps Prone to Compromise, Manipulation
Việt Nam Hacker
Researchers find artificial intelligence applications that use large language models could be compromised by attackers using natural language to dupe users.
0
Ivanti Zero-Day Exploit Disrupts Norway's Government Services
Việt Nam Hacker
Cyberattackers have used a zero-day exploit to compromise up to 12 Norwegian government departments.
0
10 Free Purple Team Security Tools to Check Out
Việt Nam Hacker
Check out the curated list of cool tools and platforms for both offensive security experts and defenders which will be released or demoed at Black Hat USA 2023.
0
Zero-Day Vulnerabilities Discovered in Global Emergency Services Communications Protocol
Việt Nam Hacker
0
Atlassian RCE Bugs Plague Confluence, Bamboo
Thứ Hai, 24 tháng 7, 2023
Việt Nam Hacker
The security vulnerabilities allow full takeover of Atlassian instances, so admins should patch now.
0
KillNet's Kremlin Connection Unclear as the Cybercrime Collective Grows
Việt Nam Hacker
KillNet is amassing members, capabilities, and know-how, as it looks to consolidate cybercrime power under its own umbrella.
0
North Korean Cyberspies Target GitHub Developers
Việt Nam Hacker
The North Korean APT is setting up legitimate accounts on GitHub and social media platforms to pose as developers or recruiters — ultimately to fool targets into loading npm repositories with malicious code.
0
Designing a Security Strategy for Defending Multicloud Architectures
Việt Nam Hacker
0
What C-Suite Leaders Need to Know About XDR
Việt Nam Hacker
Considering adopting extended detection and response (XDR) in your cybersecurity defense program? Here's what you need to know about the technology platform.
0
How to Put the Sec in DevSecOps
Việt Nam Hacker
Learn the importance of adding security practices into DevOps life cycles and how to make security stronger.
0
BGP Software Vulnerabilities Under the Microscope in Black Hat Session
Thứ Sáu, 21 tháng 7, 2023
Việt Nam Hacker
In a nod to its centrality in IP networking, a Forescout researcher will parse overlooked vulnerabilities in the Border Gateway Protocol at Black Hat USA.
0
Banks In Attackers' Crosshairs, Via Open Source Software Supply Chain
Việt Nam Hacker
In separate targeted incidents, threat actors tried to upload malware into the Node Package Manager registry to gain access and steal credentials.
0
Rootkit Attack Detections Increase at UAE Businesses
Việt Nam Hacker
Detections of rootkit attacks against businesses in the United Arab Emirates are up 167% in 2023, with an increased view of their use in the Middle East overall.
0
CVSS 4.0 Is Here, But Prioritizing Patches Still a Hard Problem
Việt Nam Hacker
CVSS Version 4 arguably performs better, but companies also need to tailor any measure of threat to their own environment to quickly evaluate new software bugs for patching order.
0
Mallox Ransomware Group Activity Shifts Into High Gear
Thứ Năm, 20 tháng 7, 2023
Việt Nam Hacker
Malicious activity targeting vulnerable SQL servers has surged 174% compared to 2022, Palo Alto's Unit 42 says.
0
Docker Leaks API Secrets & Private Keys, as Cybercriminals Pounce
Việt Nam Hacker
Researchers found that the private keys and secrets they discovered being exposed within the Docker framework are already being used in the wild.
0
Google Categorizes 6 Real-World AI Attacks to Prepare for Now
Việt Nam Hacker
The models powering generative AI like ChatGPT are open to several common attack vectors that organizations need to understand and get ready for, according to Google's dedicated AI Red Team.
0
P2P Self-Replicating Cloud Worm Targets Redis
Thứ Tư, 19 tháng 7, 2023
Việt Nam Hacker
Although not all Redis instances are vulnerable to the P2P worm variant, all of them can expect a compromise attempt, researchers warn.
0
China's APT41 Linked to WyrmSpy, DragonEgg Mobile Spyware
Việt Nam Hacker
Nation-states see the opportunity in targeting people directly through their mobile phones, in this case with sophisticated Android surveillanceware.
0
Seed Group Brings Resecurity Options to UAE Region
Việt Nam Hacker
UAE's Seed Group is partnering with Resecurity to expand cybersecurity options in the Middle East and Africa.
0
Microsoft Relents, Offers Free Key Logging to All 365 Customers
Việt Nam Hacker
0
3 Ways AI Could Improve Authentication
Việt Nam Hacker
As companies navigate how to protect themselves from the onslaught of increasingly sophisticated fraud threats, artificial intelligence will be a critical piece of next-gen authentication.
0
Reducing Security Debt in the Cloud
Việt Nam Hacker
Security debt exists in on-premises data centers as well as in cloud platforms — but preventing it from accumulating in the cloud requires different skills, processes, and tools.
0
Hacker Infected & Foiled by Own Infostealer
Thứ Ba, 18 tháng 7, 2023
Việt Nam Hacker
A prolific threat actor has been operating on Russian-language forums since 2020, but then he accidentally infected his own computer and sold off its contents to threat researchers.
0
Microsoft Takes Security Copilot AI Assistant to the Next Level
Việt Nam Hacker
The company's AI for security operations centers is now available for technology integrations, as the industry looks to large language models.
0
Name That Toon: Shark Sighting
Việt Nam Hacker
Feeling creative? Submit your caption and our panel of experts will reward the winner with a $25 Amazon gift card.
0
Attackers Pummel Millions of Websites via Critical WooCommerce Payments Flaw
Việt Nam Hacker
A barrage of targeted attacks against vulnerable installations peaked at 1.3 million against 157,000 sites over the weekend, aimed at unauthenticated code execution.
0
Sogu, SnowyDrive Malware Spreads, USB-Based Cyberattacks Surge
Việt Nam Hacker
Two separate threat actors are using poisoned USB drives to distribute malware in cyber-espionage campaigns targeting organizations across different sectors and geographies.
0
Linux Ransomware Poses Significant Threat to Critical Infrastructure
Việt Nam Hacker
Organizations running Linux distributions need to prepare to defend their systems against ransomware attacks. Steps to ensure resiliency and basics such as access control reduce major disruptions.
0
5 Major Takeaways From Microsoft's July Patch Tuesday
Thứ Hai, 17 tháng 7, 2023
Việt Nam Hacker
July's updates contained 100+ patches and security policy notes, leaving vulnerability management teams stressed and scrambling to prioritize. We're here to help find some zen.
0
AWS Cloud Credential Stealing Campaign Spreads to Azure, Google Cloud
Việt Nam Hacker
The TeamTNT threat actor appears to be setting the stage for broader cloud worm attacks, researchers say.
0
UAE and South African Hospitals Fail on DMARC Implementation
Việt Nam Hacker
Only a quarter of hospitals have implemented the strongest level of DMARC, with a third running any version of the email validation protocol.
0
If George Washington Had a TikTok, What Would His Password Be?
Việt Nam Hacker
0
Why CFOs & CISOs Must Collaborate to Strengthen and Protect Organizations in a Recession
Chủ Nhật, 16 tháng 7, 2023
Việt Nam Hacker
Cyber threats are intensifying even as budgets are being scrutinized. Now, more than ever, security and finance professionals need to align on cybersecurity strategies.
0
Insider Risk Management Starts With SaaS Security
Việt Nam Hacker
SaaS security posture management helps mitigate common threats posed by malicious or negligent insiders.
0
How Hackers Can Hijack a Satellite
Thứ Sáu, 14 tháng 7, 2023
Việt Nam Hacker
We rely on them for communications, military activity, and everyday tasks. How long before attackers really start to look up at the stars?
0
Cisco Flags Critical SD-WAN Vulnerability
Việt Nam Hacker
A flaw in the REST API of Cisco's SD_WAN vManage software could allow remote, unauthenticated attackers to perform data exfiltration.
0
SBOMs Still More Mandate Than Security
Việt Nam Hacker
A software bills of materials standard gets an update, but while half of firms require the manifests, the driver is compliance rather than security.
0
Training's New Understanding
Việt Nam Hacker
0
Brand Impersonation Scams in Middle East & Africa See Massive Growth
Việt Nam Hacker
The Middle East and Africa region saw a whopping 135% increase in scams over the past year, with finance, telecommunications, and logistics the most-targeted sectors.
0
Cybersecurity Leaders Report Reduction in Disruptive Cyber Incidents With MSS/MDR Solutions
Thứ Năm, 13 tháng 7, 2023
Việt Nam Hacker
Optiv survey highlights organizations' need for talent, challenges with sophistication of threat actors and expanding attack surface.
0
Orca Sues Wiz for 'Copying' Its Cloud Security Tech
Việt Nam Hacker
Two fierce cloud security competitors are locked in a legal battle, as Orca accuses Wiz of ripping off its intellectual property.
0
How the EU AI Act Will Affect Businesses, Cybersecurity
Việt Nam Hacker
The draft AI Act represents a significant step in regulating AI technologies, recognizing the need to address the potential risks and ethical concerns.
0
Critical RCE Bug in Rockwell Automation PLCs Zaps Industrial Sites
Việt Nam Hacker
Rockwell Automation and CISA warn of security vulnerabilities that affect power plants, factories, and other critical infrastructure sites.
0
Okta, Ping Identity, CyberArk & Oracle Lead the IDaaS Omdia Universe
Việt Nam Hacker
Omdia has published its Omdia Universe on IDaaS. This vendor comparison study highlights the capabilities of the vendors in the space.
0
Startup Spotlight: Mobb Aims to Be the Fixer
Thứ Tư, 12 tháng 7, 2023
Việt Nam Hacker
The startup, one of four finalists in this year's Black Hat USA Startup Spotlight competition, automates vulnerability remediation using AI.
0
Chinese APT Cracks Microsoft Outlook Emails at 25 Government Agencies
Việt Nam Hacker
Foreign state-sponsored actors likely had access to privileged state emails for weeks, thanks to a token validation vulnerability.
0
Firedome Integrates With Microsoft Defender for IoT to Enhance IoT Device Security, Using Microsoft Sentinel
Việt Nam Hacker
Firedome's on device real-time detection, prevention and response along with Microsoft Defender for IoT cloud-based security provides a holistic view of IoT attacks for the first time.
0
(ISC)² Strengthens DEI Initiatives through Global Partnerships
Việt Nam Hacker
Partnership program empowers underrepresented groups by removing barriers to entering the cybersecurity workforce.
0
Less Than Half of SMBs Deploy Privileged Access Management
Việt Nam Hacker
Keeper Security highlights S&P Market Intelligence's latest research showing that lack of PAM is leaving SMBs vulnerable to attack.
0
QuickBlox API Vulnerabilities Open Video, Chat Users to Data Theft
Việt Nam Hacker
QuickBlox users should update to the latest version of the platform in order to protect against several avenues of exploitation.
0
Tracy Resident Charged With Computer Attack On Discovery Bay Water Treatment Facility
Thứ Ba, 11 tháng 7, 2023
Việt Nam Hacker
Former employee of contractor allegedly unleashed computer attack on the town's critical infrastructure — the systems controlling its water treatment facility.
0
11M HCA Healthcare Patients Impacted by Data Breach
Việt Nam Hacker
0
Microsoft Expands Entra Into Secure Service Edge
Việt Nam Hacker
Among the changes are the new offerings Entra Internet Access and Entra Private Access — and Azure AD has been renamed.
0
Bangladesh Government Website Leaks Personal Data
Việt Nam Hacker
Personal details of Bangladeshi citizens found online by researcher included full names, phone numbers, email addresses, and national ID numbers.
0
Mastodon Patches 4 Bugs, but Is the Twitter Killer Safe to Use?
Việt Nam Hacker
Platform's independent server "instances" may have different security levels, creating potential for supply chain-like vulnerabilities.
0
Cyberattacks Are a War We'll Never Win, but We Can Defend Ourselves
Việt Nam Hacker
Giving ourselves a chance in this fight means acknowledging that yesterday's successful defensive tactics may already be obsolete.
0
Analysts: Cybersecurity Funding Set for Rebound
Thứ Hai, 10 tháng 7, 2023
Việt Nam Hacker
Analysts seem bullish about funding and M&A activity for the second half of the year, though transaction volumes and values dipped again in Q2.
0
NIST Launches Generative AI Working Group
Việt Nam Hacker
The public working group will develop guidance around the special risks of AI technologies that generate content.
0
Why Hybrid Work Has Made Secure Access So Complicated
Việt Nam Hacker
Employees now have the freedom to work wherever they want, which brings new challenges for security teams trying to protect data.
0
APT35 Develops Mac Bespoke Malware
Việt Nam Hacker
Iran-linked APT35 group crafted specific Mac malware when targeting a member of the media with new tools to add backdoors.
0
Deepfake Quantum AI Investment Scam Pops Up on Facebook
Việt Nam Hacker
A consumer finance journalist and television personality took to Twitter to warn his followers about advertisements using his name and face to scam victims.
0
Banking Firms Under Attack by Sophisticated 'Toitoin' Campaign
Việt Nam Hacker
An attack involves a multi-stage infection chain with custom malware hosted on Amazon EC2 that ultimately steals critical system and browser data; so far, targets have been located in Latin America.
0
Zero Trust Keeps Digital Attacks From Entering the Real World
Việt Nam Hacker
Amid IT/OT convergence, organizations must adopt an "assume breach" mindset to stop bad actors and limit their impact.
0
How to Use Log Management to Retrace Your Digital Footsteps
Chủ Nhật, 9 tháng 7, 2023
Việt Nam Hacker
Log management tools help IT and security teams monitor and improve a system's performance by identifying bugs, cybersecurity breaches, and other issues that can create outages or compliance problems.
0
Exposure Management Looks to Attack Paths Identity to Better Measure Risk
Thứ Sáu, 7 tháng 7, 2023
Việt Nam Hacker
Security firms analyze attack paths and seek out weak identities to find compromise vectors and critical assets that need better controls.
0
Global Hacking Competition Addresses Critical Increase in Cybersecurity Threats for Businesses
Việt Nam Hacker
Hack The Box launches Capture The Flag competition, including offensive and defensive challenges, to unite teams as cyberattacks increase in 2023 to unprecedented levels.
0
Meta's Rush to Topple Twitter Sets Up Looming Privacy Debate
Việt Nam Hacker
GDPR is halting Meta's new Threads app from entering EU markets, portending a broader struggle over the right ways to collect user data on social apps.
0
Truebot Malware Variants Abound According to CISA Advisory
Việt Nam Hacker
US and Canadian government agencies find that new variants of the malware are increasingly being utilized.
0
MOVEit Transfer Faces Another Critical Data-Theft Bug
Việt Nam Hacker
Users need to patch the latest SQL injection vulnerability as soon as possible. Meanwhile, Cl0p's data extortion rampage gallops on.
0
Can Generative AI Be Trusted to Fix Your Code?
Việt Nam Hacker
0
Startup Spotlight: Endor Labs Focuses on Reachability
Thứ Năm, 6 tháng 7, 2023
Việt Nam Hacker
The company, one of four finalists in Black Hat USA's 2023 startup competition, looks to find the vulnerabilities an attacker could actually access.
0
StackRot Linux Kernel Bug Has Exploit Code on the Way
Việt Nam Hacker
Linus Torvalds led a Linux kernel team in developing a set of patches that should be available by the end of July.
0
Shell Becomes Latest Cl0p MOVEit Victim
Việt Nam Hacker
In another MOVEit attack, oil and gas giant Shell saw the release of the private information of its employees.
0
Privacy Woes Hold Up Global Instagram Threads Launch
Việt Nam Hacker
Meta's answer to Twitter went live and quickly racked up millions of members — but the social media app's privacy practices are under the microscope.
0
Cybersecurity's Future Hinges on Stronger Public-Private Partnerships
Việt Nam Hacker
Public and private sector organizations must collaborate on a shared cybersecurity agenda to protect and benefit society at large.
0
6 Steps To Outsmart Business Email Compromise Scammers
Việt Nam Hacker
Email fraud is a confidence game that costs the economy billions. An effective defense takes technology and vigilance.
0
Microsoft Teams Exploit Tool Auto-Delivers Malware
Thứ Tư, 5 tháng 7, 2023
Việt Nam Hacker
The "TeamsPhisher" cyberattack tool gives pentesters — and adversaries — a way to deliver malicious files directly to a Teams user from an external account, or tenant.
0
OPERA1ER Cybercrime Group's Leader Arrested by Interpol
Việt Nam Hacker
The group's mastermind was nabbed in Côte d'Ivoire for stealing up to $30 million using malware, phishing campaigns, and BEC scams, as part of international law enforcement's Operation Nervone.
0
A Golden Age of AI or Security Threats?
Việt Nam Hacker
0
C10p's MOVEit Campaign Represents a New Era in Cyberattacks
Việt Nam Hacker
The ransomware group shows an evolution of its tactics with MOVEit zero day — potentially ushering in a new normal when it comes to extortion supply chain cyberattacks, experts say.
0
China's Mustang Panda Linked to SmugX Attacks on European Governments
Việt Nam Hacker
Attackers use HTML smuggling to spread the PlugX RAT in the campaign, which has been ongoing since at least December.
0
Microsoft Can Fix Ransomware Tomorrow
Việt Nam Hacker
You can't encrypt a file you can't open — Microsoft could dramatically impact ransomware by slowing it down.
0
Researchers Develop Exploit Code for Critical Fortinet VPN Bug
Thứ Hai, 3 tháng 7, 2023
Việt Nam Hacker
Some 340,000 FortiGate SSL VPN appliances remain exposed to the threat more than three weeks after Fortinet released firmware updates to address the issue.
0
Russian Satellite Internet Downed via Attackers Claiming Ties to Wagner Group
Việt Nam Hacker
Attribution for the cyberattack on Dozor-Teleport remains murky, but the effects are real — downed communications and compromised data.
0
Israel Aided UAE in Defending Against DDoS Attack
Việt Nam Hacker
Israel's cyber head points finger at Iran-backed MuddyWater APT group as the perpetrator of a recent attack against a university.
0
SSH Servers Hit in 'Proxyjacking' Cyberattacks
Việt Nam Hacker
Cybercriminals employ obfuscated script to stealthily hijack victim server bandwidth for use in legitimate proxy networks.
0
Name That Edge Toon: Three-Ring Circus
Việt Nam Hacker
Come up with a clever caption, and our panel of experts will reward the winner with a $25 Amazon gift card.
0
A CISO's Guide to Paying Down Software Supply Chain Security Debt
Việt Nam Hacker
When you just keep filing it away to handle "someday," security debt typically rears its head when you are most vulnerable and can least afford to pay it.
0
Architecting XDR to Save Money and Your SOC's Sanity
Chủ Nhật, 2 tháng 7, 2023
Việt Nam Hacker
XDR can lower platform costs and improve detection, but it requires committing to a few principles that go against the established way of thinking about SOC.
Đăng ký:
Bài đăng (Atom)