Tag: cyber
-
Trump Fires Cyber Safety Board Investigating Salt Typhoon Hackers
In a letter sent today, the acting DHS secretary terminated membership to all advisory boards, including the Cyber Safety Review Board (CSRB) tasked with investigating state-sponsored cyber threats against the US. First seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/trump-fires-cyber-safety-board-salt-typhoon-hackers
-
Security chiefs whose companies operate in the EU should be exploring DORA now
Tags: attack, business, ciso, compliance, conference, corporate, cyber, cybersecurity, data, detection, dora, finance, framework, GDPR, incident, network, regulation, resilience, risk, service, technology, threat, vulnerabilityIf your enterprise operates in Europe, you should care about the Digital Operational Resilience Act (DORA), which took effect on January 17. DORA, also known as Directive (EU) 2022/2555 of the European Parliament, aims to enhance and build the EU’s cybersecurity capabilities and it has been hanging like the Sword of Damocles over the heads…
-
Security Researchers Discover Critical RCE Vulnerability, Earn $40,000 Bounty
Cybersecurity researchers Abdullah Nawaf and Orwa Atyat, successfully escalated a limited path traversal vulnerability into a full-blown remote code execution (RCE). Their discovery earned a massive $40,000 bounty from the targeted organization’s bug bounty program. The team documented their step-by-step approach, leaving the cybersecurity community with valuable lessons on persistence, creativity, and methodical bug hunting.…
-
IBM i Access Client Solutions Might Be Leaking Your Passwords
A potential security flaw in IBM i Access Client Solutions (ACS) has raised serious concerns about password leakage, leaving users vulnerable to exploitation. Research published yesterday by a vulnerability assessment team revealed that the *WINLOGON authentication feature in IBM ACS is questionably storing Windows credentials, potentially exposing plaintext passwords. This alarming discovery has prompted immediate…
-
Weaponized VS Code Impersonate Zoom App Steals Cookies From Chrome
A newly identified extension for Visual Studio Code (VS Code) has been found to impersonate a legitimate Zoom application, enabling cybercriminals to steal sensitive cookies from Google Chrome. This incident marks a significant escalation in the tactics employed by malicious actors to exploit trusted software ecosystems. The Discovery The nefarious extension, uploaded to the VS…
-
Die Entwicklung des Cyber-Untergrunds
Tags: cyberTrend Micro hat eine neue Studie mit dem Titel Bridging Divides, Transcending Borders: The Current State of the English Underground veröffentlicht. Der Bericht untersucht aktuelle Entwicklungen im englischsprachigen Cyberkriminalitätsmilieu und dessen weltweite Auswirkungen. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/die-entwicklung-des-cyber-untergrunds
-
DLL Sideloading Proxying: New Campaign Delivers Sliver Implants to German Targets
Cyble Research and Intelligence Labs (CRIL) has uncovered an ongoing cyber campaign targeting German organizations using sophisticated tactics First seen on securityonline.info Jump to article: securityonline.info/dll-sideloading-proxying-new-campaign-delivers-sliver-implants-to-german-targets/
-
Healthcare Cybersecurity: The Chronic Condition We Can’t Ignore
Cyber breaches in healthcare are chronic conditions that can linger for years, quietly draining resources and eroding trust. Imagine a chronic disease. There’s the immediate crisis phase that demands urgent attention”, medication, hospital stays, or even surgery. But long after those acute symptoms subside, the condition requires ongoing care and monitoring. Cyberattacks follow a similar…
-
EU Commission Calls for Health Sector Cyber ‘Action Plan’
Initiative Aims to Bolster Security of EU Member Hospitals, Healthcare Providers. The European Commission has a new action plan to strengthen cybersecurity of the hospitals and other healthcare providers in the European Union from rising cyberthreats and attacks. The plan includes a cybersecurity support center to offer guidance and other resources to the EU’s health…
-
Three Keys to Modernizing Data Security: DSPM, AI, and Encryption
Tags: access, ai, automation, best-practice, business, cloud, compliance, container, control, cyber, cybercrime, data, data-breach, detection, encryption, GDPR, incident response, infrastructure, privacy, regulation, risk, saas, security-incident, skills, software, strategy, threat, tool, vulnerabilityThree Keys to Modernizing Data Security: DSPM, AI, and Encryption andrew.gertz@t“¦ Tue, 01/21/2025 – 14:56 Organizations worldwide face a “perfect storm” of increasing and ever-evolving cyber threats. Internal and external factors are at play, elevating cyber risks and their consequences and mandating new approaches to safeguard data. A recent study based on responses from over…
-
TSA chief behind cyber directives for aviation, pipelines and rail ousted by Trump team
TSA administrator David Pekoske, who was appointed during President Donald Trump’s first term and led the way in issuing cybersecurity directives governing the airline, pipeline and rail industries, sent a farewell memo to the agency’s staff Monday.]]> First seen on therecord.media Jump to article: therecord.media/tsa-chief-behind-cyber-directives-ousted-trump-administration
-
Call to action: Sen. Hickenlooper highlights urgency of strengthening federal cyber resilience
First seen on scworld.com Jump to article: www.scworld.com/resource/call-to-action-sen-hickenlooper-highlights-urgency-of-strengthening-federal-cyber-resilience
-
Guilty plea entered by cyber fraudster
Tags: cyberFirst seen on scworld.com Jump to article: www.scworld.com/brief/guilty-plea-entered-by-cyber-fraudster
-
Will the last-minute Biden EO on cyber see the light of day?
Tags: cyberFirst seen on scworld.com Jump to article: www.scworld.com/perspective/will-the-last-minute-biden-eo-on-cyber-see-the-light-of-day
-
Treasury Department issues sanctions linked to cyber intrusions, telecom attacks
The Office of Foreign Assets Control took measures against a state-linked hacker and a Shanghai-based cybersecurity firm in response to the recent attacks against critical infrastructure in the U.S. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/treasury-sanctions-linked-cyber-telecom-china/737842/
-
Europas neue Cyber-Sicherheitsverordnung stellt nicht nur den Finanzsektor vor Herausforderungen
First seen on datensicherheit.de Jump to article: www.datensicherheit.de/dora-europas-neuheit-cyber-sicherheitsverordnung-finanzsektor-herausforderungen
-
PoC Exploit Released for TP-Link Code Execution Vulnerability(CVE-2024-54887)
A security researcher, exploring reverse engineering and exploit development, has successfully identified a critical vulnerability in the TP-Link TL-WR940N router, specifically affecting hardware versions 3 and 4 with all firmware up to the latest version. This vulnerability, which has been documented as CVE-2024-54887, allows for potential arbitrary remote code execution (RCE) through stack buffer overflow…
-
2025 Prediction 4: Cyber Attacks Targeting HighWorth Individuals Will Increase, Targeting Not Only Their Financial Lives but also Their Brands And Reputations
On January 7, we published a press release to share our five predictions for cybersecurity in 2025. Over the next few weeks, we’ll publish a blog series that provides additional commentary on each prediction. This is the second blog in the series. Check out the first, second, and third blogs here. Prediction Key Takeaways:……
-
From qualitative to quantifiable: Transforming cyber risk management for critical infrastructure
TSA’s new incident disclosure rules are a good fit for cyber risk quantification. First seen on cyberscoop.com Jump to article: cyberscoop.com/from-qualitative-to-quantifiable-transforming-cyber-risk-management-for-critical-infrastructure/
-
Cyber Insights 2025: Attack Surface Management
SecurityWeek’s Cyber Insights 2025 examines expert opinions to gain their opinions on what to expect in Attack Surface Management in 2025. The post Cyber Insights 2025: Attack Surface Management appeared first on SecurityWeek. First seen on securityweek.com Jump to article: www.securityweek.com/cyber-insights-2025-attack-surface-management/
-
CERT-UA warned of scammers impersonating the agency using fake AnyDesk requests
CERT-UA warned of scammers impersonating the agency, using fake AnyDesk requests to conduct fraudulent security audits. The Computer Emergency Response Team of Ukraine (CERT-UA) warned of cyber scams involving threat actors impersonating the agency by sending fraudulent AnyDesk connection requests under the guise of security audits. CERT-UA pointed out that it uses the software AnyDesk…
-
Brave Browser Vulnerability Allows Malicious Website Appears as Trusted One
A security vulnerability has been identified in Brave Browser, potentially allowing malicious websites to masquerade as trusted ones during file upload or download operations. The issue, tracked under CVE-2025-23086, affects specific versions of the Brave browser on desktop platforms, creating a risk for unsuspecting users. Brave Browser Vulnerability The vulnerability impacts Brave Browser versions 1.70.x…
-
Beware! Fake SBI Reward APK Attacking Users to Deliver Android Malware
A recent phishing campaign has targeted customers of SBI Bank through a deceptive message circulating in WhatsApp groups. The message falsely claims that the recipient’s SBI reward points, amounting to Rs 9,980, will expire unless they download a purported >>SBI BANK REWARD App.
-
Critical SUSE Linux Distro Injection Vulnerability Allow Attackers Exploits “go-git” Library
A significant security vulnerability, designated CVE-2025-21613, has been discovered in the go-git library, used for Git version control in pure Go applications. This issue affects all versions before 5.13.0 and is characterized by an argument injection vulnerability, enabling potential attackers to modify git-upload-pack flags when utilizing the file transport protocol. This protocol is particularly vulnerable…
-
Cyber-Sicherheit: ein Paradigmenwechsel – Willkommen in der Ära der Cyber-Resilienz
First seen on security-insider.de Jump to article: www.security-insider.de/-cyber-sicherheit-und-resilienz-vorbereitung-auf-cyber-angriffe-a-1de3ecfec17e0d01e550e02f9439692f/
-
7 top cybersecurity projects for 2025
Tags: access, advisory, ai, backup, best-practice, breach, business, cio, ciso, cloud, compliance, control, cyber, cybersecurity, data, data-breach, detection, encryption, framework, google, governance, infrastructure, intelligence, law, mitigation, monitoring, network, resilience, risk, risk-management, service, strategy, technology, threat, tool, vulnerabilityAs 2025 dawns, CISOs face the grim reality that the battle against cyberattackers never ends. Strong and carefully planned cybersecurity projects are the best way to stay a step ahead of attackers and prevent them gaining the upper hand.”Urgency is the mantra for 2025,” says Greg Sullivan, founding partner of cybersecurity services firm CIOSO Global.…
-
Cyber Hygiene: Strengthening Your Digital Immune System Through Routine Maintenance
Good cyber hygiene isn’t a one-time effort; it’s an ongoing process that requires diligence, awareness and consistency. First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/01/cyber-hygiene-strengthening-your-digital-immune-system-through-routine-maintenance/
-
Apache CXF Vulnerability Triggers DoS Attack
Colm O hEigeartaigh announced a critical vulnerability affecting various versions of Apache CXF, a widely-used framework for building web services. This issue, documented as CVE-2025-23184, poses a significant risk as it can lead to a Denial of Service (DoS) attack due to improper handling of temporary files. The vulnerability has been confirmed in specific versions…
-
Microsoft Rolls Out New Administrator Protection Feature Under Windows Security
Microsoft has announced the release of Windows 11 Insider Preview Build 27774 to the Canary Channel. This build comes packed with enhancements, including a significant new feature aimed at bolstering system security”, Administrator Protection. The highlight of this update is the newly integrated Administrator Protection, which can now be activated directly from the Windows Security…

