Tag: cyber
-
Talent overlooked: embracing neurodiversity in cybersecurity
In cybersecurity, diverse perspectives help in addressing complex, emerging threats. Increasingly, there’s a push to recognize that neurodiversity brings significant value to cybersecurity. However, neurodiverse people frequently face systemic barriers that hinder their success in the field.Neurodiversity refers to the way some people’s brains work differently to the neurotypical brain. This includes autism, ADHD (attention…
-
MobSF XSS Vulnerability Let Attackers Inject Malicious Scripts
A critical vulnerability has been identified in the Mobile Security Framework (MobSF) that allows attackers to inject malicious scripts into the system. This vulnerability, CVE-2024-53999 is a Stored Cross-Site Scripting (XSS) flaw found in the >>Diff or Compare
-
Joint Advisory Warns of PRC-Backed Cyber Espionage Targeting Telecom Networks
A joint advisory issued by Australia, Canada, New Zealand, and the U.S. has warned of a broad cyber espionage campaign undertaken by People’s Republic of China (PRC)-affiliated threat actors targeting telecommunications providers.”Identified exploitations or compromises associated with these threat actors’ activity align with existing weaknesses associated with victim infrastructure; no novel First seen on thehackernews.com…
-
CISA Releases Advisory to Monitor Networks to Detect Malicious Cyber Actors
Tags: advisory, china, cisa, cyber, cybersecurity, exploit, infrastructure, malicious, network, threatThe National Security Agency (NSA) has partnered with the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and other entities to release a critical advisory. This initiative comes in response to the exploitation of major global telecommunications providers by a threat actor affiliated with the People’s Republic of China (PRC). The…
-
SafeLine: Open-source web application firewall (WAF)
SafeLine is an open-source and self-hosted Web Application Firewall (WAF) that protects websites from cyber attacks. >>SafeLine WAF was created to protect web … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/12/04/safeline-open-source-web-application-firewall-waf/
-
BlackBerry Highlights Rising Software Supply Chain Risks in Malaysia
Tags: access, ai, attack, breach, ceo, ciso, communications, compliance, cyber, cyberattack, cybersecurity, data, detection, espionage, finance, framework, government, infrastructure, intelligence, international, Internet, iot, malware, mobile, monitoring, phishing, ransomware, regulation, resilience, risk, skills, software, strategy, supply-chain, threat, tool, training, vulnerabilityIn 2024, BlackBerry unveiled new proprietary research, underscoring the vulnerability of software supply chains in Malaysia and around the world.According to the study, 79% of Malaysian organizations reported cyberattacks or vulnerabilities in their software supply chains during the past 12 months, slightly exceeding the global average of 76%. Alarmingly, 81% of respondents revealed they had…
-
Sixgen’s Kyrus Acquisition Boosts National Cybersecurity
Buy of Washington D.C.-Area Firm Adds Reverse Engineering, Data Analytics Expertise. Sixgen will enhance its cybersecurity operations through the purchase of Washington D.C.-area Kyrus. The move introduces reverse engineering and analytics expertise to Sixgen’s portfolio, aligning with its mission to protect critical infrastructure and bolster American cyber defense capabilities. First seen on govinfosecurity.com Jump to…
-
Cyber insurance checklist: 12 must-have security features
First seen on scworld.com Jump to article: www.scworld.com/resource/cyber-insurance-checklist-12-must-have-security-features
-
Cyber-Unsafe Employees Increasingly Put Orgs at Risk
Too much access and privilege, plus a host of unsafe cyber practices, plague most workplaces, and the introduction of tools like GenAI will only make things worse. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/cyber-unsafe-employees-orgs-risk
-
Inside a new initiative to lend cybersecurity volunteers to organizations that need it most
The idea behind the initiative, details of which CyberScoop is first reporting, is that too much cyber expertise doing volunteer work is uncoordinated. First seen on cyberscoop.com Jump to article: cyberscoop.com/cyber-resilience-corps-volunteers-berkeley-cyberpeace/
-
UK cyber chief warns country is at an inflection point as digital threats rise
In his first major speech, NCSC CEO Richard Horne, said state linked and criminal threat groups are working to undermine the nation’s reliance on technology.; First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/uk-cyber-chief-inflection-point-threats/734447/
-
DMM Bitcoin halts operations six months after a $300 million cyber heist
The Japanese cryptocurrency platform DMM Bitcoin is closing its operations just six months after a $300 million cyber heist. DMM Bitcoin is a cryptocurrency exchange based in Japan, operated by DMM Group, a large Japanese e-commerce and entertainment conglomerate. Launched in 2018, the platform allows users to trade various cryptocurrencies, including Bitcoin, Ethereum, and Ripple,…
-
NCSC boss calls for ‘sustained vigilance’ in an aggressive world
NCSC CEO Richard Horne is to echo wider warnings about the growing number and severity of cyber threats facing the UK as he launches the security body’s eighth annual report First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366616635/NCSC-boss-calls-for-sustained-vigilance-in-an-aggressive-world
-
PEFT-As-An-Attack, Jailbreaking Language Models For Malicious Prompts
Federated Parameter-Efficient Fine-Tuning (FedPEFT) is a technique that combines parameter-efficient fine-tuning (PEFT) with federated learning (FL) to improve the efficiency and privacy of training large language models (PLMs) on specific tasks. However, this approach introduces a new security risk called >>PEFT-as-an-Attack
-
Hackers Exploited Windows Event Logs Tool log Manipulation, And Data Exfiltration
wevtutil.exe, a Windows Event Log management tool, can be abused for LOLBAS attacks. By manipulating its capabilities, attackers can execute arbitrary commands, download malicious payloads, and establish persistence, all while evading traditional security measures. It is a Windows tool for event log management that can be exploited by attackers to manipulate system logs, potentially concealing…
-
Industrie-Umgebungen: Cyber-Sicherheit trotz OT mit Alt-Systemen
Tags: cyberFirst seen on datensicherheit.de Jump to article: www.datensicherheit.de/industrie-umgebungen-cyber-sicherheit-trotz-ot-mit-alt-systemen
-
Whitepaper: 9 traits of effective cybersecurity leaders of tomorrow
The cyber world needs your expertise. But the security leaders of tomorrow require a broad set of skills that job experience alone does not arm you with. What do today’s … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/12/03/isc2-security-leaders-traits-whitepaper/
-
Cyber Agility Mandate Transforming InfoSec Programs to Meet Evolving Markets
Five steps to take that will allow the infosec team to reduce the risk of trailing the latest transformation changes. First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/12/cyber-agility-mandate-transforming-infosec-programs-to-meet-evolving-markets/
-
KI als zweischneidiges Schwert: Zukunft der Cyber-Bedrohung und -abwehr werden neu definiert
First seen on datensicherheit.de Jump to article: www.datensicherheit.de/ki-zwei-schneiden-schwert-zukunft-cyber-bedrohung-abwehr-neu-definition
-
Security Pros Positive About GenAI in Cyber, Despite Raising Attack Severity
Ivanti research found that security professionals are eight-times more likely to say GenAI is a net positive versus a net negative for cybersecurity First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/security-pros-genai-attack/
-
Severity of the risk facing the UK is widely underestimated, NCSC annual review warns
National cyber emergencies increased threefold this year First seen on theregister.com Jump to article: www.theregister.com/2024/12/03/ncsc_annual_review/
-
Threat Actors Allegedly Claims Breach of EazyDiner Reservation Platform
Reports have emerged of a potential data breach involving EazyDiner, a leading restaurant reservation platform. Alleged by a tweet from DailyDarkWeb, the breach is said to have compromised sensitive user data, including names, email addresses, phone numbers, and reservation details. This incident has raised significant alarm over the security and privacy measures in place to…
-
EU enacts new laws to strengthen cybersecurity defenses and coordination
Tags: ai, compliance, cyber, cybersecurity, data, defense, framework, healthcare, infrastructure, law, network, penetration-testing, privacy, regulation, risk, service, soc, technology, threat, vulnerabilityThe European Union has enacted two new laws to bolster its cybersecurity defenses and coordination mechanisms. The measures, part of the cybersecurity legislative package, include the Cyber Solidarity Act and amendments to the Cybersecurity Act (CSA).These steps aim to improve the EU’s ability to detect, prepare for, and respond to cyber threats while fostering uniformity…
-
Salesforce Applications Vulnerability Could Allow Full Account Takeover
A critical vulnerability has been discovered in Salesforce applications that could potentially allow a full account takeover. The vulnerability, uncovered during a penetration testing exercise, hinges on misconfigurations within Salesforce Communities, particularly exploiting the Salesforce Lightning component framework. The implications of this vulnerability are severe, affecting both data security and privacy. Attackers could gain access…
-
UK Cyber-Attacks Surge as Threats Hit Harder, Warns NCSC
In 2024, the UK National Cyber Security Centre issued over 500 notifications to UK organizations about cyber incidents double the number recorded in 2023 First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/uk-cyberattacks-surge-ncsc/
-
APAC businesses face cyber onslaught
The Asia-Pacific region is a cyber security hotspot, enduring significantly more cyber attacks than the global average, with AI-powered threats and skills shortages exacerbating the problem First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366616636/APAC-businesses-face-cyber-onslaught
-
NCSC boss calls for “sustained vigilance” in an aggressive world
NCSC CEO Richard Horne is to echo wider warnings about the growing number and severity of cyber threats facing the UK as he launches the security body’s eighth annual report First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366616635/NCSC-boss-calls-for-sustained-vigilance-in-an-aggressive-world
-
ElizaRAT Exploits Google, Telegram, Slack Services For C2 Communications
APT36, a Pakistani cyber-espionage group, has recently upgraded its arsenal with ElizaRAT, a sophisticated Windows RAT that, initially detected in 2023, employs advanced evasion tactics and robust C2 capabilities to target Indian government agencies, diplomatic personnel, and military installations. The group leverages multiple platforms, including Windows, Linux, and Android, to broaden its attack surface as…

