Tag: cyber
-
Building Resilience Into Cyber-Physical Systems Has Never Been This Mission-Critical
Our nation’s critical infrastructure is increasingly brittle and under attack. Take the recent report that the drinking water of millions of Americans is at risk due to technical vulnerabilities. First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/01/building-resilience-into-cyber-physical-systems-has-never-been-this-mission-critical/
-
New PayPal Phishing Abusing Microsoft365 Domains for Sophisticated Attacks
A new and sophisticated phishing scam has been uncovered, leveraging Microsoft 365 domains to trick users into compromising their PayPal accounts. The attack exploits legitimate-looking sender addresses and URLs, making it harder for victims to recognize the phishing attempt. Security experts, including Chief Information Security Officers (CISOs), have raised alarms about the growing menace, urging…
-
Cybersecurity Resolutions for 2025
As we begin the New Year, it offers a chance for reflection on 2024 and to consider what we can do as security professionals and business leaders in 2025 that will keep us relevant and in the best position to counter cyber threats going forward. The IT Security Guru caught up with Darren Guccione, CEO…
-
APT32 Hacker Group Attacking Cybersecurity Professionals Poisoning GitHub
The malicious Southeast Asian APT group known as OceanLotus (APT32) has been implicated in a sophisticated attack that compromises the privacy of cybersecurity professionals. A recent investigation by the ThreatBook Research and Response Team revealed that a popular privilege escalation tool utilized by cybersecurity experts had been backdoored, leading to significant data breaches and identity…
-
New Great Morpheus Hacker Group Claims Hacking Into Arrotex Pharmaceuticals And PUS GmbH
A Data Leak Site (DLS) belonging to a new extortion group named Morpheus, which has stolen data from Arrotex Pharmaceuticals (Australia) on December 12th and PUS GmbH (Germany) on December 20th. Morpheus offers stolen data for sale on the DLS, requiring buyers to create accounts. While a researcher suggests a link to Hellcat ransomware, there…
-
Green Bay Packers Store Hacked Thousands of Credit Cards Data Stolen
The Green Bay Packers, Inc. has confirmed that its online merchandise store was hacked, leading to the theft of credit card data from over 8,500 customers. The incident, which occurred on September 23, 2024, was discovered nearly three months later on December 20, 2024. An official notification was sent to affected individuals on January 6,…
-
Is this Website Safe: How to Check Website Safety 2025
is this website safe? In this digital world, Check a website is safe is the most critical concern since there are countless malicious websites available everywhere over the Internet, and it is tough to find a trustworthy website. We need tobrowse smart and ensure the site is not dangerous by using Multiple approaches. There are…
-
Government Launches £1.9m Initiative to Boost UK’s Cyber Resilience
The UK government has pledged nearly £2m to 30 new Cyber Local projects designed to enhance cyber resilience First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/government-19m-boost-uks-cyber/
-
White House Launches US Cyber Trust Mark for IoT Devices
Biden Administration Hopes Good Cybersecurity Is Also Good Marketing. The Biden administration Tuesday launched a cybersecurity labeling program for IoT devices aimed to help consumers choose smart devices that offer enhanced protections against hacking. Eligible products include wireless IoT devices such as fitness trackers, smart appliances and garage door openers. First seen on govinfosecurity.com Jump…
-
Top Cybersecurity Conferences Events in India 2025
The Indian cybersecurity ecosystem is experiencing significant growth, making it one of the fastest-growing and most important technology spaces globally. As cyber threats increase in scale and sophistication, it’s essential… First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/01/top-cybersecurity-conferences-events-in-india-2025/
-
Gitlab Patches Multiple Vulnerabilities Including Resource Exhaustion User Manipulation
GitLab has announced the release of critical updates to its Community Edition (CE) and Enterprise Edition (EE), specifically versions 17.7.1, 17.6.3, and 17.5.5. These updates are essential for maintaining security and stability across all self-managed GitLab installations and should be implemented immediately. The company has already rolled out the patched version on GitLab.com, and GitLab…
-
Ivanti 0-Day Vulnerability Exploited in Wild-Patch Now
Ivanti released a critical security advisory addressing vulnerabilities in its Connect Secure, Policy Secure, and ZTA Gateways products. This advisory reveals the existence of two significant vulnerabilities, CVE-2025-0282 and CVE-2025-0283, which have been exploited in the wild, necessitating immediate action from users. Critical Vulnerability: CVE-2025-0282 CVE-2025-0282 is a stack-based buffer overflow vulnerability that affects Ivanti…
-
Wireshark 4.4.3 Released: What’s New!
The Wireshark development team announced the release of Wireshark version 4.4.3, a critical update that brings several bug fixes and enhancements to this widely used network protocol analyzer. Renowned for its ability to troubleshoot, analyze, and educate users about network protocols, Wireshark continues to evolve, making it an indispensable tool for network professionals. Key Bug…
-
Mirai Botnet Variant Exploits Zero-Day Vulnerabilities in Routers
Researchers observed the Gayfemboy botnet in early 2024 as a basic Mirai variant. Still, the botnet rapidly evolved through iterative development, including UPX polymorphic packing, integrating N-day vulnerabilities, and ultimately leveraging a 0-day vulnerability in Four-Faith industrial routers. By November 2024, Gayfemboy had infected over 15,000 devices, utilizing over 40 grouping categories for command and…
-
Fed ‘Cyber Trust’ Label: Good Intentions That Fall Short
The voluntary program is intended to boost consumer confidence in vulnerable IoT devices, but experts want to see vendors held to a higher standard. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/white-house-launches-cyber-trust-mark-label-in-voluntary-cybersecurity-program
-
MirrorFace: Unmasking the Chinese Cyber Espionage Group Targeting Japan
On January 8, 2025, the Japanese National Police Agency (NPA) issued a critical warning regarding ongoing cyberattacks attributed First seen on securityonline.info Jump to article: securityonline.info/mirrorface-unmasking-the-chinese-cyber-espionage-group-targeting-japan/
-
The US has a new cybersecurity safety label for smart devices
The White House this week announced a new label for internet-connected devices, the U.S. Cyber Trust Mark, intended to help consumers make more-informed decisions about the cybersecurity of products they bring into their homes. To earn the U.S. Cyber Trust Mark, which is being administered by the Federal Communications Commission, companies have to test their…
-
I tried hard, but didn’t fix all of cybersecurity, admits outgoing US National Cyber Director
In colossal surprise, ONCD boss Harry Coker says more work is needed First seen on theregister.com Jump to article: www.theregister.com/2025/01/08/oncd_director_harry_coker_exit_remarks/
-
I tried hard, but didn’t fix cybersecurity, admits outgoing US National Cyber Director
In colossal surprise, ONCD boss Harry Coker says more work is needed First seen on theregister.com Jump to article: www.theregister.com/2025/01/08/oncd_director_harry_coker_exit_remarks/
-
White House Launches U.S. Cyber Trust Mark for IoT Devices
Biden Administration Hopes Good Cybersecurity Is Also Good Marketing. The Biden administration Tuesday launched a cybersecurity labelling program for IoT devices aimed to help consumers choose smart devices that offer enhanced protections against hacking. Eligible products include wireless IoT devices such as fitness trackers, smart appliances and garage door openers. First seen on govinfosecurity.com Jump…
-
US to Launch Cyber Trust Mark to Label Secure Smart Devices
The Cyber Trust Mark is designed to help consumers make more informed decisions about the cybersecurity of devices they may purchase. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/us-cyber-trust-mark-iot-security/
-
Cyber Command overhaul gets Austin’s approval, but plan faces uncertain future
Defense Secretary Lloyd Austin approved the plan known as Cyber Command 2.0 in December, sources tell Recorded Future News, but any overhaul of the digital warfighting unit will be subject to an entirely new set of Pentagon leaders soon.]]> First seen on therecord.media Jump to article: therecord.media/cyber-command-overhaul-secdef-approval
-
FCC Unveils Cyber Trust Mark Label for IoT Devices
First seen on scworld.com Jump to article: www.scworld.com/brief/fcc-unveils-cyber-trust-mark-label-for-iot-devices
-
Treasury Secretary calls out China’s malicious cyber activities
First seen on scworld.com Jump to article: www.scworld.com/brief/treasury-secretary-calls-out-chinas-malicious-cyber-activities
-
US unveils Cyber Trust Mark label for IoT devices
First seen on scworld.com Jump to article: www.scworld.com/brief/us-unveils-cyber-trust-mark-label-for-iot-devices

