2024

Patchwork Hackers Target Bhutan with Advanced Brute Ratel C4 Tool

Patchwork Hackers Target Bhutan with Advanced Brute Ratel C4 Tool 2024-07-24 at 13:46 By The threat actor known as Patchwork has been linked to a cyber attack targeting entities with ties to Bhutan to deliver the Brute Ratel C4 framework and an updated version of a backdoor called PGoShell. The development marks the first time […]

Patchwork Hackers Target Bhutan with Advanced Brute Ratel C4 Tool Read More »

Apple’s Clamshell iBook G3 at 25 – not just a pretty case

Apple’s Clamshell iBook G3 at 25 – not just a pretty case 2024-07-24 at 12:32 By Richard Speed Remembering when laptops could be fun and fixable It is 25 years since Apple’s Clamshell iBook G3 arrived, replete with iMac styling and an innovation – optional Wi-Fi connectivity via Apple’s AirPort.… This article is an excerpt

Apple’s Clamshell iBook G3 at 25 – not just a pretty case Read More »

Craxel Black Forest Reaper boosts cyber defense for organizations

Craxel Black Forest Reaper boosts cyber defense for organizations 2024-07-24 at 12:31 By Industry News Craxel launched integrated cyber defense platform, Black Forest Reaper. Designed to revolutionize cyber defense capabilities for the world’s largest cyber threat hunting enterprises, including U.S. government federal civilian agencies, the Department of Defense, Homeland Security, and the intelligence community, Black

Craxel Black Forest Reaper boosts cyber defense for organizations Read More »

CrowdStrike Explains Friday Incident Crashing Millions of Windows Devices

CrowdStrike Explains Friday Incident Crashing Millions of Windows Devices 2024-07-24 at 12:31 By Cybersecurity firm CrowdStrike on Wednesday blamed an issue in its validation system for causing millions of Windows devices to crash as part of a widespread outage late last week. “On Friday, July 19, 2024 at 04:09 UTC, as part of regular operations,

CrowdStrike Explains Friday Incident Crashing Millions of Windows Devices Read More »

Permit Share-If enables developers to implement secure collaboration features into their apps

Permit Share-If enables developers to implement secure collaboration features into their apps 2024-07-24 at 12:01 By Industry News Secure collaboration through access-sharing is a must-have feature in almost any modern application, from requesting to edit a document or viewing a widget in a dashboard to submitting wire transfers for approval. With “Permit Share-If,” developers no

Permit Share-If enables developers to implement secure collaboration features into their apps Read More »

School gets an F for using facial recognition on kids in canteen

School gets an F for using facial recognition on kids in canteen 2024-07-24 at 11:46 By Lindsay Clark Watchdog reprimand follows similar cases in 2021 The UK’s data protection watchdog has reprimanded a school in Essex for using facial recognition for canteen payments, nearly three years after other schools were warned about doing the same.…

School gets an F for using facial recognition on kids in canteen Read More »

GitGuardian’s tool helps companies discover developer leaks on GitHub

GitGuardian’s tool helps companies discover developer leaks on GitHub 2024-07-24 at 11:01 By Industry News GitGuardian releases a tool to help companies discover how many secrets their developers have leaked on public GitHub, both company-related and personal. Even if your organization doesn’t engage in open source, your developers or subcontractors may inadvertently leak sensitive information

GitGuardian’s tool helps companies discover developer leaks on GitHub Read More »

‘Data embassies’ promise bubbles of digital sovereignty, but India just cooled on the idea

‘Data embassies’ promise bubbles of digital sovereignty, but India just cooled on the idea 2024-07-24 at 10:47 By Simon Sharwood Scratch the surface and they look more like a sales pitch – or a soft power play Embassies are bubbles of sovereignty that local authorities cannot freely enter and in which certain communications are privileged

‘Data embassies’ promise bubbles of digital sovereignty, but India just cooled on the idea Read More »

Microsoft Defender Flaw Exploited to Deliver ACR, Lumma, and Meduza Stealers

Microsoft Defender Flaw Exploited to Deliver ACR, Lumma, and Meduza Stealers 2024-07-24 at 10:16 By A now-patched security flaw in the Microsoft Defender SmartScreen has been exploited as part of a new campaign designed to deliver information stealers such as ACR Stealer, Lumma, and Meduza. Fortinet FortiGuard Labs said it detected the stealer campaign targeting

Microsoft Defender Flaw Exploited to Deliver ACR, Lumma, and Meduza Stealers Read More »

CISA Adds Twilio Authy and IE Flaws to Exploited Vulnerabilities List

CISA Adds Twilio Authy and IE Flaws to Exploited Vulnerabilities List 2024-07-24 at 10:16 By The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two security flaws to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerabilities are listed below – CVE-2012-4792 (CVSS score: 9.3) – Microsoft Internet Explorer

CISA Adds Twilio Authy and IE Flaws to Exploited Vulnerabilities List Read More »

Forget security – Google’s reCAPTCHA v2 is exploiting users for profit

Forget security – Google’s reCAPTCHA v2 is exploiting users for profit 2024-07-24 at 09:48 By Thomas Claburn Web puzzles don’t protect against bots, but humans have spent 819 million unpaid hours solving them Google promotes its reCAPTCHA service as a security mechanism for websites, but researchers affiliated with the University of California, Irvine, argue it’s

Forget security – Google’s reCAPTCHA v2 is exploiting users for profit Read More »

CrowdStrike blames a test software bug for that giant global mess it made

CrowdStrike blames a test software bug for that giant global mess it made 2024-07-24 at 08:31 By Simon Sharwood Something called ‘Content Validator’ did not validate the content, and the rest is history CrowdStrike has blamed a bug in its own test software for the mass-crash-event it caused last week.… This article is an excerpt

CrowdStrike blames a test software bug for that giant global mess it made Read More »

Security biz KnowBe4 hired fake North Korean techie, who got straight to work … on evil

Security biz KnowBe4 hired fake North Korean techie, who got straight to work … on evil 2024-07-24 at 08:01 By Laura Dobberstein If it can happen to folks that run social engineering defence training, what hope for the rest of us? Security awareness and training provider KnowBe4 hired a fake North Korean IT worker for

Security biz KnowBe4 hired fake North Korean techie, who got straight to work … on evil Read More »

Cybersecurity ROI: Top metrics and KPIs

Cybersecurity ROI: Top metrics and KPIs 2024-07-24 at 07:31 By Mirko Zorz In this Help Net Security interview, Karthik Swarnam, Chief Security and Trust Officer at ArmorCode, discusses key metrics and KPIs to measure cybersecurity ROI. Swarnam shares strategies for enhancing ROI through proactive measures and effective communication with executive leadership. What are the primary

Cybersecurity ROI: Top metrics and KPIs Read More »

VMware sends vSphere 7 into extra time by extending support for six months

VMware sends vSphere 7 into extra time by extending support for six months 2024-07-24 at 07:01 By Simon Sharwood A nice surprise, but some other vAdmins have an August 1 deadline to sort out subscriptions VMware users have had a little win, as the Broadcom business unit has extended the supported life of its flagship

VMware sends vSphere 7 into extra time by extending support for six months Read More »

Infisical: Open-source secret management platform

Infisical: Open-source secret management platform 2024-07-24 at 07:01 By Help Net Security Infisical is an open-source secret management platform developers use to centralize application configurations and secrets, such as API keys and database credentials, while also managing their internal PKI. In addition to managing secrets with Infisical, you can scan your files, directories, and Git

Infisical: Open-source secret management platform Read More »

Cybersecurity jobs available right now: July 24, 2024

Cybersecurity jobs available right now: July 24, 2024 2024-07-24 at 06:31 By Anamarija Pogorelec Applied Cryptographer Quantstamp | EMEA | Remote – View job details As an Applied Cryptographer, you will research about various cryptographic protocols and have knowledge of cryptographic primitives or concepts, like elliptic curve cryptography, hash functions, and PCPs. You should have

Cybersecurity jobs available right now: July 24, 2024 Read More »

AI accelerates code development faster than security teams can keep up

AI accelerates code development faster than security teams can keep up 2024-07-24 at 06:01 By Help Net Security 91% of respondents say their security budget is increasing this year, demonstrating a growing recognition of the importance of cybersecurity within organizations, according to Seemplicity. Vendor environments introduce complexity and fragmentation Seemplicity surveyed 300 US cybersecurity professionals

AI accelerates code development faster than security teams can keep up Read More »

Scroll to Top