2024

North Korean ScarCruft Exploits Windows Zero-Day to Spread RokRAT Malware

North Korean ScarCruft Exploits Windows Zero-Day to Spread RokRAT Malware 2024-10-16 at 14:46 By The North Korean threat actor known as ScarCruft has been linked to the zero-day exploitation of a now-patched security flaw in Windows to infect devices with malware known as RokRAT. The vulnerability in question is CVE-2024-38178 (CVSS score: 7.5), a memory […]

North Korean ScarCruft Exploits Windows Zero-Day to Spread RokRAT Malware Read More »

Fake LockBit, Real Damage: Ransomware Samples Abuse AWS S3 to Steal Data

Fake LockBit, Real Damage: Ransomware Samples Abuse AWS S3 to Steal Data 2024-10-16 at 14:35 By This article uncovers a Golang ransomware abusing AWS S3 for data theft, and masking as LockBit to further pressure victims. The discovery of hard-coded AWS credentials in these samples led to AWS account suspensions. This article is an excerpt

Fake LockBit, Real Damage: Ransomware Samples Abuse AWS S3 to Steal Data Read More »

Lookout offers protection against social engineering and executive impersonation attacks

Lookout offers protection against social engineering and executive impersonation attacks 2024-10-16 at 14:35 By Industry News Lookout announced new features for its Mobile Threat Defense (MTD) solution, Lookout Mobile Endpoint Security. These advancements provide comprehensive protection against two fast-growing advanced social engineering tactics: smishing (SMS phishing) and executive impersonation fraud texts. Lookout offers a defense-in-depth

Lookout offers protection against social engineering and executive impersonation attacks Read More »

CISA Issues Urgent Advisory on Vulnerabilities Affecting Multiple Products

CISA Issues Urgent Advisory on Vulnerabilities Affecting Multiple Products 2024-10-16 at 14:14 By daksh sharma Overview The Cybersecurity and Infrastructure Security Agency (CISA) has released a critical advisory report highlighting vulnerabilities recently added to the Known Exploited Vulnerability (KEV) catalog. These vulnerabilities pose risks to organizations and require immediate attention. CISA categorizes vulnerabilities based on

CISA Issues Urgent Advisory on Vulnerabilities Affecting Multiple Products Read More »

‘Newport would look like Dubai’ if guy could dumpster dive for lost Bitcoin hard drive

‘Newport would look like Dubai’ if guy could dumpster dive for lost Bitcoin hard drive 2024-10-16 at 13:31 By Richard Currie To Wales now, where crypto bro sues to be allowed to excavate landfill site Last time we met 39-year-old James Howells from Newport, Wales, he was petitioning his local council to let him excavate

‘Newport would look like Dubai’ if guy could dumpster dive for lost Bitcoin hard drive Read More »

5 Techniques for Collecting Cyber Threat Intelligence

5 Techniques for Collecting Cyber Threat Intelligence 2024-10-16 at 13:31 By To defend your organization against cyber threats, you need a clear picture of the current threat landscape. This means constantly expanding your knowledge about new and ongoing threats. There are many techniques analysts can use to collect crucial cyber threat intelligence. Let’s consider five

5 Techniques for Collecting Cyber Threat Intelligence Read More »

Swift launches AI-powered fraud detection service

Swift launches AI-powered fraud detection service 2024-10-16 at 13:20 By Industry News Swift announced that it is rolling out new AI-enhanced fraud detection to help the global payments industry step up its defence as bad actors grow increasingly sophisticated. Available from January 2025, the service is the result of extensive collaboration with banks from around

Swift launches AI-powered fraud detection service Read More »

Android 15 unveils new security features to protect sensitive data

Android 15 unveils new security features to protect sensitive data 2024-10-16 at 13:20 By Help Net Security Android 15 brings enhanced security features to protect your sensitive health, financial, and personal data from theft and fraud. It also introduces productivity improvements for large-screen devices and updates to apps like the camera, messaging, and passkeys. Android

Android 15 unveils new security features to protect sensitive data Read More »

NHS England warned about plans to extend Covid-era rules for patient data access

NHS England warned about plans to extend Covid-era rules for patient data access 2024-10-16 at 12:31 By Lindsay Clark Governance and public consultation need work before rule change goes ahead A group overseeing UK health data sharing has advised the government not to expand legal rules allowing access to patient information introduced during the Covid

NHS England warned about plans to extend Covid-era rules for patient data access Read More »

Netskope extends data security with DSPM capabilities

Netskope extends data security with DSPM capabilities 2024-10-16 at 12:31 By Industry News Netskope announced new enhancements to the Netskope One platform, extending the company’s data protection solutions to include integrated data security posture management (DSPM) capabilities.  Modern data protection continues to be a top priority for organizations as they optimize hybrid work environments, adopt

Netskope extends data security with DSPM capabilities Read More »

Akeyless unveils Unified Secrets and Machine Identity Platform

Akeyless unveils Unified Secrets and Machine Identity Platform 2024-10-16 at 12:01 By Industry News Akeyless announced its Unified Secrets and Machine Identity Platform, designed to address the leading cause of breaches—compromised identity credentials. Organizations are more exposed than ever as machine identities far outnumber human identities. High-profile breaches in 2024 demonstrate the risks of unsecured

Akeyless unveils Unified Secrets and Machine Identity Platform Read More »

Openreach reveals latest locations facing the copper chop

Openreach reveals latest locations facing the copper chop 2024-10-16 at 11:31 By Dan Robinson A reminder to get fiber (eventually) or get left behind BT infrastructure arm Openreach has disclosed the latest exchange locations where it plans to stop selling phone and broadband services that use copper cabling as part of its ambition to get

Openreach reveals latest locations facing the copper chop Read More »

Rubrik DSPM for Microsoft 365 Copilot reduces the risk of sensitive data exposure

Rubrik DSPM for Microsoft 365 Copilot reduces the risk of sensitive data exposure 2024-10-16 at 11:31 By Industry News As organizations and their volume of Microsoft 365 data grow, protecting sensitive data and managing access has become even more important. The need for strong security and governance practices is only intensified as more organizations leverage

Rubrik DSPM for Microsoft 365 Copilot reduces the risk of sensitive data exposure Read More »

Arcserve UDP 10 accelerates disaster recovery processes

Arcserve UDP 10 accelerates disaster recovery processes 2024-10-16 at 11:04 By Industry News Arcserve launched Arcserve UDP 10, providing customers with an intuitive, flexible, and affordable way to address their critical data security and business continuity challenges. Arcserve UDP 10 is a unified data protection solution that offers backup, replication, high availability, and advanced ransomware

Arcserve UDP 10 accelerates disaster recovery processes Read More »

Astaroth Banking Malware Resurfaces in Brazil via Spear-Phishing Attack

Astaroth Banking Malware Resurfaces in Brazil via Spear-Phishing Attack 2024-10-16 at 10:46 By A new spear-phishing campaign targeting Brazil has been found delivering a banking malware called Astaroth (aka Guildma) by making use of obfuscated JavaScript to slip past security guardrails. “The spear-phishing campaign’s impact has targeted various industries, with manufacturing companies, retail firms, and

Astaroth Banking Malware Resurfaces in Brazil via Spear-Phishing Attack Read More »

Internet Archive wobbles back online, with limited functionality

Internet Archive wobbles back online, with limited functionality 2024-10-16 at 10:31 By Simon Sharwood DDoS detectives deduce Mirai used to do the deed, using home entertainment boxes in Korea, China, and Brazil The Internet Archive has come back online, in slightly degraded mode, after repelling an October 9 DDoS attack and then succumbing to a

Internet Archive wobbles back online, with limited functionality Read More »

Google’s memory safety plan includes rehab for unsafe languages

Google’s memory safety plan includes rehab for unsafe languages 2024-10-16 at 09:31 By Thomas Claburn Large C and C++ codebases will be around for the ‘foreseeable future’ Google has revealed that its approach to making programming code more memory safe involves both the adoption of memory safe languages and making unsafe languages more secure –

Google’s memory safety plan includes rehab for unsafe languages Read More »

GitHub Patches Critical Flaw in Enterprise Server Allowing Unauthorized Instance Access

GitHub Patches Critical Flaw in Enterprise Server Allowing Unauthorized Instance Access 2024-10-16 at 08:47 By GitHub has released security updates for Enterprise Server (GHES) to address multiple issues, including a critical bug that could allow unauthorized access to an instance. The vulnerability, tracked as CVE-2024-9487, carries a CVS score of 9.5 out of a maximum

GitHub Patches Critical Flaw in Enterprise Server Allowing Unauthorized Instance Access Read More »

CISA Warns of Active Exploitation in SolarWinds Help Desk Software Vulnerability

CISA Warns of Active Exploitation in SolarWinds Help Desk Software Vulnerability 2024-10-16 at 08:47 By The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a critical security flaw impacting SolarWinds Web Help Desk (WHD) software to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. Tracked as CVE-2024-28987 (CVSS score: 9.1),

CISA Warns of Active Exploitation in SolarWinds Help Desk Software Vulnerability Read More »

Scroll to Top