Jen Easterly, former director of CISA, discussed the first 100 days of the second Trump administration and criticized the president's "mandate for loyalty" during a panel at RSAC 2025.
0
Former CISA Head Slams Trump Admin Over 'Loyalty Mandate'
Thứ Tư, 30 tháng 4, 2025
Việt Nam Hacker
0
TheWizards APT Casts a Spell on Asian Gamblers With Novel Attack
Việt Nam Hacker
A SLAAC-spoofing, adversary-in-the-middle campaign is hiding the WizardNet backdoor malware inside updates for legitimate software and popular applications.
0
NVIDIA's AI Security Offering Protects From Software Landmines
Việt Nam Hacker
0
Many Fuel Tank Monitoring Systems Vulnerable to Disruption
Thứ Ba, 29 tháng 4, 2025
Việt Nam Hacker
Thousands of automatic tank gauge (ATG) devices are accessible over the Internet and are just "a packet away" from compromise, security researcher warns at 2025 RSAC Conference.
0
From Mission-Centric to People-Centric: Competitive Leadership in Cyber
Việt Nam Hacker
0
Hacking in Space: Not as Tough as You Might Think
Việt Nam Hacker
Barbara Grofe, space asset security architect at Spartan Corp, discussed the realities of hacking in space, and the outlook is not pie-in-the-sky.
0
Risks of Using AI Models Developed by Competing Nations
Việt Nam Hacker
The current offline/open source model boom is unstoppable. Its impact depends on how well the risks are managed today.
0
Windows Backdoor Targets Members of Exiled Uyghur Community
Việt Nam Hacker
A spear-phishing campaign sent Trojanized versions of legitimate word-processing software to members of the World Uyghur Congress as part of China's continued cyber-espionage activity against the ethnic minority.
0
Vulnerability Exploitation Is Shifting in 2024-25
Việt Nam Hacker
The number of vulnerabilities exploited by attacks may not be growing these days, but they are increasingly affecting enterprise technologies.
0
SAP NetWeaver Visual Composer Flaw Under Active Exploitation
Thứ Hai, 28 tháng 4, 2025
Việt Nam Hacker
CVE-2025-31324 is a maximum severity bug that attackers exploited weeks before SAP released a patch for it.
0
AI, Automation, and Dark Web Fuel Evolving Threat Landscape
Việt Nam Hacker
Attackers are leveraging the benefits of new technology and the availability of commodity tools, credentials, and other resources to develop sophisticated attacks more quickly than ever, putting defenders on their heels.
0
Forget the Stack; Focus on Control
Việt Nam Hacker
Security teams are under more pressure than ever — and cybersecurity debt is adding fuel to the fire. While it can't be eliminated overnight, it can be managed.
0
DoJ Data Security Program Highlights Data Sharing Challenges
Việt Nam Hacker
The Department of Justice announced compliance rules for the Data Security Program that will require organizations to reexamine how they do business and with whom.
0
Digital Twins Bring Simulated Security to the Real World
Thứ Sáu, 25 tháng 4, 2025
Việt Nam Hacker
By simulating business environments or running software, while incorporating real-time data from production systems, companies can model the impact of software updates, exploits, or disruptions.
0
'SessionShark' ToolKit Evades Microsoft Office 365 MFA
Thứ Năm, 24 tháng 4, 2025
Việt Nam Hacker
The creators of the toolkit are advertising it as an educational and ethical resource, but what it promises to provide users if purchased indicates it's anything but.
0
Max-Severity Commvault Bug Alarms Researchers
Việt Nam Hacker
Though already patched, the vulnerability is especially problematic because of the highly privileged access it offers to business-critical systems, sensitive data, and backups for attackers.
0
NFC-Powered Android Malware Enables Instant Cash-Outs
Việt Nam Hacker
Researchers at security vendor Cleafy detailed a malware known as "SuperCard X" that uses the NFC reader on a victim's own phone to steal credit card funds instantly.
0
FBI: Cybercrime Losses Rocket to $16.6B in 2024
Việt Nam Hacker
The losses are 33% higher than the year before, with phishing leading the way as the most-reported cybercrime last year, and ransomware was the top threat to critical infrastructure, according to the FBI Internet Crime Report.
0
North Korean Operatives Use Deepfakes in IT Job Interviews
Thứ Tư, 23 tháng 4, 2025
Việt Nam Hacker
Use of synthetic identities by malicious employment candidates is yet another way state-sponsored actors are trying to game the hiring process and infiltrate Western organizations.
0
Japan Warns on Unauthorized Stock Trading via Stolen Credentials
Việt Nam Hacker
Attackers are using credentials stolen via phishing websites that purport to be legitimate securities company homepages, duping victims and selling their stocks before they realize they've been hacked.
0
Kubernetes Pods Are Inheriting Too Many Permissions
Việt Nam Hacker
Scalable, effective — and best of all, free — securing Kubernetes workload identity cuts cyber-risk without adding infrastructure, according to new research from SANS.
0
Microsoft Purges Millions of Cloud Tenants in Wake of Storm-0558
Thứ Ba, 22 tháng 4, 2025
Việt Nam Hacker
The tech giant is boosting Entra ID and MSA security as part of the wide-ranging Secure Future Initiative (SFI) that the company launched following a Chinese APT's breach of its Exchange Online environment in 2023.
0
3 More Healthcare Orgs Hit by Ransomware Attacks
Việt Nam Hacker
Dialysis firm DaVita, Wisconsin-based Bell Ambulance, and Alabama Ophthalmology Associates all suffered apparent or confirmed ransomware attacks this month.
0
'Cookie Bite' Entra ID Attack Exposes Microsoft 365
Việt Nam Hacker
A proof-of-concept (PoC) attack vector exploits two Azure authentication tokens from within a browser, giving threat actors persistent access to key cloud services, including Microsoft 365 applications.
0
'Elusive Comet' Attackers Use Zoom to Swindle Victims
Thứ Hai, 21 tháng 4, 2025
Việt Nam Hacker
The threat actor uses sophisticated social engineering techniques to infect a victim's device, either with an infostealer or remote access Trojan (RAT).
0
Nation-State Threats Put SMBs in Their Sights
Việt Nam Hacker
Cyberthreat groups increasingly see small and medium-sized businesses, especially those with links to larger businesses, as the weak link in the supply chain for software and IT services.
0
Can Cybersecurity Weather the Current Economic Chaos?
Việt Nam Hacker
Cybersecurity firms tend to be more software- and service-oriented than their peers, and threats tend to increase during a downturn, leaving analysts hopeful that the industry will buck a recession.
0
Nation-State Threats Put SMBs in Their Sights
Việt Nam Hacker
Cyberthreat groups increasingly see small and medium businesses, especially those with links to larger businesses, as the weak link in the supply chain for software and IT services.
0
ASUS Urges Users to Patch AiCloud Router Vuln Immediately
Việt Nam Hacker
The vulnerability is only found in the vendor's router series and can be triggered by an attacker using a crafted request — all of which helps make it a highly critical vulnerability with a 9.2 CVSS score.
0
The Global AI Race: Balancing Innovation and Security
Việt Nam Hacker
The AI security race is on — and it will be won where defenders come together with developers and researchers to do things right.
0
Organizations Fix Less Than Half of All Exploitable Vulnerabilities, With Just 21% of GenAI App Flaws Resolved
Thứ Sáu, 18 tháng 4, 2025
Việt Nam Hacker
0
Attackers and Defenders Lean on AI in Identity Fraud Battle
Việt Nam Hacker
Identity verification, insurance claims, and financial services are all seeing surges in AI-enabled fraud, but organizations are taking advantage of AI systems to fight fire with fire.
0
Chinese APT Mustang Panda Debuts 4 New Attack Tools
Việt Nam Hacker
The notorious nation-state-backed threat actor has added two new keyloggers, a lateral movement tool, and an endpoint detection and response (EDR) evasion driver to its arsenal.
0
If Boards Don't Fix OT Security, Regulators Will
Việt Nam Hacker
Around the world, governments are setting higher-bar regulations with clear corporate accountability for breaches on the belief organizations won't drive up security maturity for operational technology unless they're made to.
0
PromptArmor Launches to Help Assess, Monitor Third-Party AI Risks
Việt Nam Hacker
The AI security startup has already made waves with critical vulnerability discoveries and seeks to address emerging AI concerns with its PromptArmor platform.
0
Android Phones Pre-Downloaded With Malware Target User Crypto Wallets
Thứ Năm, 17 tháng 4, 2025
Việt Nam Hacker
The threat actors lace pre-downloaded applications with malware to steal cryptocurrency by covertly swapping users' wallet addresses with their own.
0
GPS Spoofing Attacks Spike in Middle East, Southeast Asia
Thứ Tư, 16 tháng 4, 2025
Việt Nam Hacker
An Indian disaster-relief flight delivering aid is the latest air-traffic incident, as attacks increase in the Middle East and Myanmar and along the India-Pakistan border.
0
China-Linked Hackers Lay Brickstorm Backdoors on Euro Networks
Việt Nam Hacker
Researchers discovered new variants of the malware, which is tied to a China-nexus threat group, targeting Windows environments of critical infrastructure networks in Europe.
0
Ransomware gang 'CrazyHunter' Targets Critical Taiwanese Orgs
Việt Nam Hacker
Trend Micro researchers detailed an emerging ransomware campaign by a new group known as "CrazyHunter" that is targeting critical sectors in Taiwan.
0
AI-Powered Presentation Tool Leveraged in Phishing Attacks
Thứ Ba, 15 tháng 4, 2025
Việt Nam Hacker
Researchers at Abnormal Security said threat actors are using a legitimate presentation and graphic design tool named "Gamma" in phishing attacks.
0
Hertz Falls Victim to Cleo Zero-Day Attacks
Việt Nam Hacker
Customer data such as birth dates, credit card numbers and driver's license information were stolen when threat actors exploited zero-day vulnerabilities in Cleo-managed file transfer products.
0
Hertz Falls Victim to Cleo Zero-Day Attacks
Việt Nam Hacker
Customer data such as birth dates, credit card numbers and driver's license information were stolen when threat actors exploited zero-day vulnerabilities in Cleo-managed file transfer products.
0
Are We Prioritizing the Wrong Security Metrics?
Việt Nam Hacker
True security isn't about meeting deadlines — it's about mitigating risk in a way that aligns with business objectives while protecting against real-world threats.
0
Threat Intel Firm Offers Crypto in Exchange for Dark Web Accounts
Thứ Hai, 14 tháng 4, 2025
Việt Nam Hacker
Prodaft is currently buying accounts from five Dark Web forums and offers to pay extra for administrator or moderator accounts. The idea is to infiltrate forums to boost its threat intelligence.
0
Fortinet Zero-Day Bug May Lead to Arbitrary Code Execution
Việt Nam Hacker
A threat actor posted about the zero-day exploit on the same day that Fortinet published a warning about known vulnerabilities under active exploitation.
0
A New 'It RAT': Stealthy 'Resolver' Malware Burrows In
Việt Nam Hacker
A new infostealer on the market is making big waves globally, replacing Lumma et al. in attacks and employing so many stealth, persistence, and anti-analysis tricks that it's downright difficult to count them all.
0
7 RSAC 2025 Cloud Security Sessions You Don't Want to Miss
Việt Nam Hacker
0
How DigitalOcean Moved Away From Manual Identity Management
Việt Nam Hacker
DigitalOcean executives describe how they automated and streamlined many of the identity and access management functions which had been previously handled manually.
0
Morocco Investigates Social Security Agency Data Leak
Chủ Nhật, 13 tháng 4, 2025
Việt Nam Hacker
A threat actor has claimed responsibility for the alleged politically motivated attack and has uploaded the stolen data to a Dark Web forum.
0
Pall Mall Process Progresses but Leads to More Questions
Thứ Sáu, 11 tháng 4, 2025
Việt Nam Hacker
Nations continue to sign the Code of Practice for States in an effort to curb commercial spyware, yet implementation and enforcement concerns have yet to be figured out.
0
Paper Werewolf Threat Actor Targets Flash Drives With New Malware
Việt Nam Hacker
The threat actor, also known as Goffee, has been active since at least 2022 and has changed its tactics and techniques over the years while targeting Russian organizations.
0
Financial Fraud, With a Third-Party Twist, Dominates Cyber Claims
Việt Nam Hacker
The most damaging attacks continue to be ransomware, but financial fraud claims are more numerous — and both are driven by increasing third-party breaches.
0
What Should the US Do About Salt Typhoon?
Thứ Năm, 10 tháng 4, 2025
Việt Nam Hacker
Security experts weigh in on the problem Salt Typhoon and its hacking of telecoms poses against the United States, including what the US should do and how defenders can protect themselves.
0
Open Source Poisoned Patches Infect Local Software
Việt Nam Hacker
Malicious packages lurking on open source repositories like npm have become less effective, so cyberattackers are using a new strategy: offering "patches" for locally installed programs.
0
CrushFTP Exploitation Continues Amid Disclosure Dispute
Thứ Tư, 9 tháng 4, 2025
Việt Nam Hacker
Attacks on a critical authentication bypass flaw in CrushFTP's file transfer product continue this week after duplicate CVEs sparked confusion.
0
Tariffs May Prompt Increase in Global Cyberattacks
Việt Nam Hacker
Cybersecurity and policy experts worry that if tariffs give way to a global recession, organizations will reduce their spending on cybersecurity.
0
Oracle Appears to Admit Breach of 2 'Obsolete' Servers
Việt Nam Hacker
The database company said its Oracle Cloud Infrastructure (OCI) was not involved in the breach. And at least one law firm seeking damages is already on the case.
0
China-Linked Hackers Continue Harassing Ethnic Groups With Spyware
Việt Nam Hacker
Threat actors are trolling online forums and spreading malicious apps to target Uyghurs, Taiwanese, Tibetans, and other individuals aligned with interests that China sees as a threat to its authority.
0
Aurascape Brings Visibility, Security Controls to Manage AI Applications
Việt Nam Hacker
New cybersecurity startup Aurascape emerged from stealth today with an AI-native security platform to automate security policies for AI applications.
0
Microsoft Drops Another Massive Patch Update
Thứ Ba, 8 tháng 4, 2025
Việt Nam Hacker
A threat actor has already exploited one of the flaws in a ransomware campaign with victims in the US and other countries.
0
UK Orgs Pull Back Digital Projects With Looming Threat of Cyberwarfare
Việt Nam Hacker
Artificial intelligence poses a significant concern when it comes to nation-state cyberthreats and AI's ability to supercharge attacks.
0
2 Android Zero-Day Bugs Under Active Exploit
Việt Nam Hacker
Neither security issue requires user interaction; and one of the vulnerabilities was used to unlock a student activist's device in an attempt to install spyware.
0
Palo Alto Networks Begins Unified Security Rollout
Việt Nam Hacker
Cortex Cloud integrates Prisma Cloud with CDR to provide a consolidated security posture management and real-time threat detection and remediation.
0
ToddyCat APT Targets ESET Bug to Load Silent Malware
Thứ Hai, 7 tháng 4, 2025
Việt Nam Hacker
Researchers found the threat actor attempting to use the now-patched flaw to load and execute a malicious dynamic link library on infected systems.
0
NIST to Implement 'Deferred' Status to Dated Vulnerabilities
Việt Nam Hacker
The changes will go into effect over the next several days to reflect which CVEs are being prioritized in the National Vulnerability Database (NVD).
0
Scattered Spider's 'King Bob' Pleads Guilty to Cyber Charges
Việt Nam Hacker
The 20-year-old was arrested in January 2024 alongside four other group members who carried out related cybercriminal acts, earning them similar charges.
0
Autonomous, GenAI-Driven Attacker Platform Enters the Chat
Việt Nam Hacker
"Xanthorox AI" provides a modular GenAI platform for offensive cyberattacks, which supplies a model-agnostic, one-stop shop for developing a range of cybercriminal operations.
0
Intergenerational Mentoring: Key to Cybersecurity's AI Future
Việt Nam Hacker
As threats evolve and technology changes, our ability to work together across generations will determine our success.
0
CISA Warns: Old DNS Trick 'Fast Flux' Is Still Thriving
Thứ Sáu, 4 tháng 4, 2025
Việt Nam Hacker
An old DNS switcheroo technique is still helping attackers keep their infrastructure alive. But is it really a pressing issue in 2025?
0
Minnesota Tribe Struggles After Ransomware Attack
Việt Nam Hacker
Hotel and casino operations for the Lower Sioux Indians have been canceled or postponed, and the local health center is redirecting those needing medical or dental care.
0
Disclosure Drama Clouds CrushFTP Vulnerability Exploitation
Thứ Năm, 3 tháng 4, 2025
Việt Nam Hacker
CrushFTP CEO Ben Spink slammed several cybersecurity companies for creating confusion around a critical authentication bypass flaw that's currently under attack.
0
Counterfeit Phones Carrying Hidden Revamped Triada Malware
Việt Nam Hacker
The malware, first discovered in 2016, has been updated over the years, and the latest version is now hiding in the firmware of counterfeit mobile phones.
0
Runtime Ventures Launches New Fund for Seed, Pre-Seed Startups
Việt Nam Hacker
Co-founders Michael Sutton and David Endler raised $32 million to invest in early stage cybersecurity startups as well as to provide mentoring support.
0
New PCI DSS Rules Say Merchants on Hook for Compliance, Not Providers
Việt Nam Hacker
Merchants and retailers will now face penalties for not being compliant with PCI DSS 4.0.1, and the increased security standards make it clear they cannot transfer compliance responsibility to third-party service providers.
0
Israel Enters 'Stage 3' of Cyber Wars With Iran Proxies
Thứ Tư, 2 tháng 4, 2025
Việt Nam Hacker
While Israel and Iranian proxies fight it out IRL, their conflict in cyberspace has developed in parallel. These days attacks have decelerated, but advanced in sophistication.
0
DPRK 'IT Workers' Pivot to Europe for Employment Scams
Việt Nam Hacker
By using fake references and building connections with recruiters, some North Korean nationals are landing six-figure jobs that replenish DPRK coffers.
0
In Salt Typhoon's Wake, Congress Mulls Potential Options
Việt Nam Hacker
While the House Committee on Government Reform was looking for retaliatory options, cybersecurity experts pointed them toward building better defenses.
0
Surge in Scans on PAN GlobalProtect VPNs Hints at Attacks
Thứ Ba, 1 tháng 4, 2025
Việt Nam Hacker
Over the past few weeks, bad actors from different regions have been scanning devices with the VPN for potential vulnerabilities.
0
As CISA Downsizes, Where Can Enterprises Get Support?
Việt Nam Hacker
In this roundtable, cybersecurity experts — including two former CISA executives — weigh in on alternate sources for threat intel, incident response, and other essential cybersecurity services.
0
Japan Bolsters Cybersecurity Safeguards With Cyber Defense Bill
Việt Nam Hacker
The bill will allow Japan to implement safeguards and strategies that have been in use by other countries for some time.
0
Check Point Disputes Hacker's Breach Claims
Việt Nam Hacker
The security vendor counters that none of the information came directly from its systems but rather was acquired over a period of time by targeting individuals.
Đăng ký:
Bài đăng (Atom)