Advertisement
Top

Category: Security


Cybersecurity, Security

The Fast Evolution of SaaS Security from 2020 to 2024 (Told Through Video)

October 16, 2023

Via: The Hacker News

SaaS Security’s roots are in configuration management. An astounding 35% of all security breaches begin with security settings that were misconfigured. In the past 3 years, the initial access vectors to SaaS data have widened beyond misconfiguration management. “SaaS Security […]


Hacking, Security

Pro-Russian Hackers Exploiting Recent WinRAR Vulnerability in New Campaign

October 16, 2023

Via: The Hacker News

Pro-Russian hacking groups have exploited a recently disclosed security vulnerability in the WinRAR archiving utility as part of a phishing campaign designed to harvest credentials from compromised systems. “The attack involves the use of malicious archive files that exploit the […]


Hacking, Security

Researchers Uncover Malware Posing as WordPress Caching Plugin

October 12, 2023

Via: The Hacker News

Cybersecurity researchers have shed light on a new sophisticated strain of malware that masquerades a WordPress plugin to stealthily create administrator accounts and remotely control a compromised site. “Complete with a professional looking opening comment implying it is a caching […]


Privacy, Security

Take an Offensive Approach to Password Security by Continuously Monitoring for Breached Passwords

October 11, 2023

Via: The Hacker News

Passwords are at the core of securing access to an organization’s data. However, they also come with security vulnerabilities that stem from their inconvenience. With a growing list of credentials to keep track of, the average end-user can default to […]


Cybersecurity, Security

U.S. Cybersecurity Agency Warns of Actively Exploited Adobe Acrobat Reader Vulnerability

October 11, 2023

Via: The Hacker News

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a high-severity flaw in Adobe Acrobat Reader to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. Tracked as CVE-2023-21608 (CVSS score: 7.8), the vulnerability has been […]


Cybersecurity, Security

HTTP/2 Rapid Reset Zero-Day Vulnerability Exploited to Launch Record DDoS Attacks

October 10, 2023

Via: The Hacker News

Amazon Web Services (AWS), Cloudflare, and Google on Tuesday said they took steps to mitigate record-breaking distributed denial-of-service (DDoS) attacks that relied on a novel technique called HTTP/2 Rapid Reset. The layer 7 attacks were detected in late August 2023, […]


Hacking, Security

Cybercriminals Using EvilProxy Phishing Kit to Target Senior Executives in U.S. Firms

October 9, 2023

Via: The Hacker News

Senior executives working in U.S.-based organizations are being targeted by a new phishing campaign that leverages a popular adversary-in-the-middle (AiTM) phishing toolkit named EvilProxy to conduct credential harvesting and account takeover attacks. Menlo Security said the activity started in July […]


Hacking, Security

Microsoft Warns of Cyber Attacks Attempting to Breach Cloud via SQL Server Instance

October 4, 2023

Via: The Hacker News

Microsoft has detailed a new campaign in which attackers unsuccessfully attempted to move laterally to a cloud environment through an SQL Server instance. “The attackers initially exploited a SQL injection vulnerability in an application within the target’s environment,” security researchers […]


Cybersecurity, Security

Wing Disrupts the Market by Introducing Affordable SaaS Security

October 4, 2023

Via: The Hacker News

Today, mid-sized companies and their CISOs are struggling to handle the growing threat of SaaS security with limited manpower and tight budgets. Now, this may be changing. By focusing on the critical SaaS security needs of these companies, a new […]


Cybersecurity, Security

Researcher Reveals New Techniques to Bypass Cloudflare’s Firewall and DDoS Protection

October 3, 2023

Via: TheHackersNews

Firewall and distributed denial-of-service (DDoS) attack prevention mechanisms in Cloudflare can be circumvented by exploiting gaps in cross-tenant security controls, defeating the very purpose of these safeguards, it has emerged. “Attackers can utilize their own Cloudflare accounts to abuse the […]


Cybersecurity, Security

API Security Trends 2023 – Have Organizations Improved their Security Posture?

October 3, 2023

Via: TheHackersNews

APIs, also known as application programming interfaces, serve as the backbone of modern software applications, enabling seamless communication and data exchange between different systems and platforms. They provide developers with an interface to interact with external services, allowing them to […]


Cybersecurity, Security

Update Chrome Now: Google Releases Patch for Actively Exploited Zero-Day Vulnerability

September 28, 2023

Via: TheHackersNews

Google on Wednesday rolled out fixes to address a new actively exploited zero-day in the Chrome browser. Tracked as CVE-2023-5217, the high-severity vulnerability has been described as a heap-based buffer overflow in the VP8 compression format in libvpx, a free […]


Cybersecurity, Security

Critical libwebp Vulnerability Under Active Exploitation – Gets Maximum CVSS Score

September 27, 2023

Via: TheHackersNews

Google has assigned a new CVE identifier for a critical security flaw in the libwebp image library for rendering images in the WebP format that has come under active exploitation in the wild. Tracked as CVE-2023-5129, the issue has been […]


Hacking, Security

New ZenRAT Malware Targeting Windows Users via Fake Password Manager Software

September 27, 2023

Via: TheHackersNews

A new malware strain called ZenRAT has emerged in the wild that’s distributed via bogus installation packages of the Bitwarden password manager. “The malware is specifically targeting Windows users and will redirect people using other hosts to a benign web […]


Cybersecurity, Security

LibreOffice 7.6.2 fixes a critical WebP vulnerability

September 26, 2023

Via: TechSpot

LibreOffice is a powerful and free office suite, a successor to OpenOffice, used by millions of people around the world. Its clean interface and feature-rich tools help you unleash your creativity and enhance your productivity. LibreOffice includes several applications that […]


Cybersecurity, Security

How to get a handle on shadow AI

September 5, 2023

Via: InfoWorld

CIOs and CISOs have long grappled with the challenge of shadow IT—technology that is being used within an enterprise but that is not officially sanctioned by the IT or security department. According to Gartner research, 41% of employees acquired, modified, […]


Hacking, Security

Discord.io suffers massive data breach, announces closure

August 15, 2023

Via: Mashable

Discord.io, a service that allowed users to create custom links for their Discord channels, is closing down following a large data breach. A hacker stole the data of 760,000 users, per TechRadar, and has posted a sample on Breached Forums […]


Privacy, Security

AMD Zen 1 Vulnerability Not Properly Fixed, Second Pass Issued

August 14, 2023

Via: Tom's Hardware

It seems that AMD’s issued patch for its Zen 1 “Division by zero” bug wasn’t the end-all, be-all the company wanted it to be. While the company was fast in issuing a patch, there’s now the suspicion that they might’ve […]


Hacking, Security

AI cyberattack could figure out your password from keyboard acoustics

August 8, 2023

Via: Mashable

Hacking passwords by recording the sound of your keystrokes is nothing new, but researchers using AI have been able to do this with much more accuracy. Computer scientists from Durham University, University of Surrey, and Royal Holloway University of London, […]


Hacking, Security

Malicious npm Packages Found Exfiltrating Sensitive Data from Developers

August 4, 2023

Via: The Hacker News

Cybersecurity researchers have discovered a new bunch of malicious packages on the npm package registry that are designed to exfiltrate sensitive developer information. Software supply chain firm Phylum, which first identified the “test” packages on July 31, 2023, said they […]