Tag: cyber
-
ANEL Backdoor Reactivated in Earth Kasha Cyber-Espionage Campaign
In June 2024, Trend Micro identified a new spear-phishing campaign targeting political organizations, research institutions, and think tanks in Japan. This operation, attributed to the cyber-espionage group Earth Kasha, marks... First seen on securityonline.info Jump to article: securityonline.info/anel-backdoor-reactivated-in-earth-kasha-cyber-espionage-campaign/
-
Salt Typhoon’s surge extends far beyond US telcos
Plus, a brand-new backdoor, GhostSpider, is linked to the cyber-spy crew’s operations First seen on theregister.com Jump to article: www.theregister.com/2024/11/27/salt_typhoons_us_telcos/
-
Trio of South Dakota politicians set to have bigger roles on cybersecurity
The little-populated state is seeing its governor and two senators move into key positions to influence cyber policy. First seen on cyberscoop.com Jump to article: cyberscoop.com/south-dakota-cybersecurity-leadership-2025/
-
U.K. launches AI security lab to combat nation-state cyber threats
First seen on scworld.com Jump to article: www.scworld.com/brief/u-k-launches-ai-security-lab-to-combat-nation-state-cyber-threats
-
India’s new cyber rules for telecoms come with big privacy risks, experts say
First seen on therecord.media Jump to article: therecord.media/india-telecom-act-cyber-regulations-privacy-concerns
-
Further disruption expected after latest NHS cyber attack
IT and security teams at Wirral University Teaching Hospitals NHS Trust continue to work around the clock following a major cyber incident, with services disrupted and no timeline for resolution First seen on Jump to article: /www.computerweekly.com/news/366616494/Further-disruption-expected-after-latest-NHS-cyber-attack
-
Why the MITRE ATTCK Evaluation Is Essential for Security Leaders
In today’s dynamic threat landscape, security leaders are under constant pressure to make informed choices about which solutions and strategies they employ to protect their organizations. The “MITRE Engenuity ATT&CKEvaluations: Enterprise” stands out as an essential resource for cybersecurity decision-makers to navigate this challenge. Unlike other independent assessments, MITRE ATT&CK Evaluations simulate real-world threats to…
-
New EU Commission to Unveil Healthcare Cybersecurity Plan in First 100 Days
One of the priorities of the newly-approved Von der Leyen Commission II will be to strengthen the healthcare sector’s cyber resilience First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/eu-commission-healthcare-cyber-plan/
-
Lazarus Hackers Exploits macOS Extended Attributes To Evade Detection
The xattr command in Unix-like systems allows for the embedding of hidden metadata within files, similar to Windows ADS, known as Rustyattr, which is being exploited by threat actors like Lazarus Group to stealthily conceal malicious payloads within seemingly benign files. The Lazarus Group is covertly embedding malicious data within system files using xattr, a…
-
The Cybersecurity Risks of Black Friday 2024: What are the Experts Saying? Pt.2
This week marks Black Friday 2024! As the popularity of this event has skyrocketed in recent years, so have the cyber risks involved in buying and selling products. In the second of two articles, we have gathered some insights from cybersecurity experts who have their say on Black Friday, from the threats faced by consumers…
-
The Cybersecurity Risks of Black Friday 2024: What are the Experts Saying?
This week marks Black Friday 2024! As the popularity of this event has skyrocketed in recent years, so have the cyber risks involved in buying and selling products. In the first of two articles, we have gathered some insights from cybersecurity experts who have their say on Black Friday, from the threats faced by consumers…
-
ProjectSend Authentication Vulnerability Exploited in the Wild
ProjectSend, an open-source file-sharing web application, has become a target of active exploitation following the recent assignment of CVE-2024-11680 on November 25, 2024. Despite the availability of a patch for more than a year, adoption rates remain alarmingly low, leaving many instances vulnerable to attack. ProjectSend Authentication Vulnerability ProjectSend is moderately popular, with nearly 1,500…
-
Latest Multi-Stage Attack Scenarios with Real-World Examples
Multi-stage cyber attacks, characterized by their complex execution chains, are designed to avoid detection and trick victims into a false sense of security. Knowing how they operate is the first step to building a solid defense strategy against them. Let’s examine real-world examples of some of the most common multi-stage attack scenarios that are active…
-
APT60 Hackers Exploit StatCounter and Bitbucket in SpyGlace Malware Campaign
The threat actor known as APT-C-60 has been linked to a cyber attack targeting an unnamed organization in Japan that used a job application-themed lure to deliver the SpyGlace backdoor.That’s according to findings from JPCERT/CC, which said the intrusion leveraged legitimate services like Google Drive, Bitbucket, and StatCounter. The attack was carried out around August…
-
Winner’s Spotlight: Security Serious Unsung Heroes Awards 2024 Cyber Writer
This year’s Security Serious Unsung Heroes Awards uncovered and celebrated the individuals and teams that go above and beyond to make the UK a safer place to do business, as well as share and spread their expertise far and wide. The sponsors included KnowBe4, Check Point Software, ThinkCyber, The Zensory, Hornetsecurity and Pulse Conferences. The…
-
APT60 Exploits WPS Office Vulnerability to Deploy SpyGlace Backdoor
The threat actor known as APT-C-60 has been linked to a cyber attack targeting an unnamed organization in Japan that used a job application-themed lure to deliver the SpyGlace backdoor.That’s according to findings from JPCERT/CC, which said the intrusion leveraged legitimate services like Google Drive, Bitbucket, and StatCounter. The attack was carried out around August…
-
Zugbrücke und Wächter für die Security – Hardware für die Cyber-Sicherheit in Rechenzentren
First seen on security-insider.de Jump to article: www.security-insider.de/hardware-fuer-die-cyber-sicherheit-in-rechenzentren-a-cb7ff6adef156975cdb9e6aed71b27db/
-
Nuclear Decommissioning Authority Opens Sellafield Cyber Center
The UK’s Nuclear Decommissioning Authority has opened a new hub dedicated to cybersecurity knowledge sharing First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/nuclear-decommissioning-authority/
-
NVIDIA UFM Vulnerability Leads to Privilege Escalation Data Tampering
NVIDIA has released a critical security update addressing a significant vulnerability in its Unified Fabric Manager (UFM) products. This flaw, identified as CVE-2024-0130, poses a high-severity risk to users, with a CVSS v3.1 base score of 8.8. The vulnerability could allow attackers to escalate privileges, tamper with data, and even compromise system availability. Analyze cyber threats with…
-
Fortify your data
How cyber resilient storage hardware can defeat ransomware First seen on theregister.com Jump to article: www.theregister.com/2024/11/26/fortify_your_data/
-
Cybersecurity’s oversimplification problem: Seeing AI as a replacement for human agency
Tags: access, ai, awareness, business, ciso, computer, cyber, cybersecurity, data, election, infrastructure, intelligence, Internet, jobs, technology, threat, tool, trainingThere’s a philosophical concept called the Great Man Theory that suggests history is all about how significant individuals act as centers of gravity for society as a whole, think Alexander the Great, Napoleon Bonaparte, Queen Elizabeth I, or the founding fathers of the American Revolution.Recent research suggests that cybersecurity and related professions are developing a…
-
Critical Gitlab Vulnerability Let Attackers Escalate Privileges
GitLab, a widely used platform for DevOps lifecycle management, has released critical security updates for its Community Edition (CE) and Enterprise Edition (EE). The updates address multiple vulnerabilities, including a high-severity issue that could allow attackers to escalate privileges via compromised tokens. The company strongly advises all self-managed GitLab installations to upgrade immediately to the…
-
Interpol Operation Serengeti führt zu 1.006 Festnahmen
In der Operation “Serengeti” haben Behörden in Afrika unter Koordination von INTERPOL und AFRIPOL einen Schlag gegen Strukturen von Cyber-Kriminellen geführt. Bei Razzien wurden 1.006 Verdächtige verhaftet und 134 089 bösartige Infrastrukturen und Netzwerke zerschlagen. Die Serengeti kennt man eigentlich … First seen on borncity.com Jump to article: www.borncity.com/blog/2024/11/27/interpol-operation-serengeti-fuehrt-zu-1-006-festnahmen/
-
Firefox 133.0 Released with Multiple Security Updates What’s New!
Mozilla has officially launched Firefox 133.0, offering enhanced features, significant performance improvements, and critical security fixes. This latest release enhances privacy, developer tools, and enterprise functionality while introducing several new features and updates. Here’s everything you need to know! One of the most exciting additions is the new Bounce Tracking Protection, available in Firefox’s Enhanced…
-
‘RomCom’ APT Mounts Zero-Day, Zero-Click Browser Escapes in Firefox, Tor
The innocuously named Russian-sponsored cyber threat actor has combined critical and serious vulnerabilities in Windows and Firefox products in a zero-click code execution exploit. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/romcom-apt-zero-day-zero-click-browser-escapes-firefox-tor
-
Sellafield operator opens dedicated cyber centre
Tags: cyberThe UK’s Nuclear Decommissioning Authority has opened a cyber security centre spanning its activities across the nuclear sector First seen on Jump to article: /www.computerweekly.com/news/366616360/Sellafield-operator-opens-dedicated-cyber-centre
-
Australia Passes Groundbreaking Cyber Security Law to Boost Resilience
Australia’s landmark Cyber Security Act has been passed, setting new standards for incident reporting, ransomware payments, and critical infrastructure protection. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/australia-cyber-security-law-passed/
-
Maryland makes $1.8M cyber education investment
Tags: cyberFirst seen on scworld.com Jump to article: www.scworld.com/brief/maryland-makes-1-8m-cyber-education-investment
-
Automating Data Encryption and Security Audits for Continuous Protection
Protecting sensitive data is critical for businesses facing constant cyber threats. Automating encryption, audits, and access control strengthens security and reduces human error. First seen on hackread.com Jump to article: hackread.com/automating-data-encryption-security-audits-protection/

