2024

Critical Exim vulnerability facilitates malware delivery (CVE-2024-39929)

Critical Exim vulnerability facilitates malware delivery (CVE-2024-39929) 2024-07-15 at 14:20 By Zeljka Zorz The maintainers of the Exim mail transfer agent (MTA) have fixed a critical vulnerability (CVE-2024-39929) that currently affects around 1.5 million public-facing servers and can help attackers deliver malware to users. About CVE-2024-39929 The vulnerability stems from a bug in RFC 2231 […]

Critical Exim vulnerability facilitates malware delivery (CVE-2024-39929) Read More »

10,000 Victims a Day: Infostealer Garden of Low-Hanging Fruit

10,000 Victims a Day: Infostealer Garden of Low-Hanging Fruit 2024-07-15 at 14:20 By Imagine you could gain access to any Fortune 100 company for $10 or less, or even for free. Terrifying thought, isn’t it? Or exciting, depending on which side of the cybersecurity barricade you are on. Well, that’s basically the state of things

10,000 Victims a Day: Infostealer Garden of Low-Hanging Fruit Read More »

CRYSTALRAY Hackers Infect Over 1,500 Victims Using Network Mapping Tool

CRYSTALRAY Hackers Infect Over 1,500 Victims Using Network Mapping Tool 2024-07-15 at 14:20 By A threat actor that was previously observed using an open-source network mapping tool has greatly expanded their operations to infect over 1,500 victims. Sysdig, which is tracking the cluster under the name CRYSTALRAY, said the activities have witnessed a 10x surge,

CRYSTALRAY Hackers Infect Over 1,500 Victims Using Network Mapping Tool Read More »

BlueVoyant Cyber Defense Platform helps organizations reduce cyber risk

BlueVoyant Cyber Defense Platform helps organizations reduce cyber risk 2024-07-15 at 14:01 By Industry News BlueVoyant unveiled its innovative Cyber Defense Platform. The platform integrates internal, external, and supply chain defense solutions into a single, cloud-native platform designed to measure and strengthen cyber defense posture in a cost-effective manner. The mission of security operations teams

BlueVoyant Cyber Defense Platform helps organizations reduce cyber risk Read More »

Hey Microsoft – what ever happened to ‘Developers, developers, developers’?

Hey Microsoft – what ever happened to ‘Developers, developers, developers’? 2024-07-15 at 11:46 By Rupert Goodwins Hey, here’s an idea… create a point system for every time Microsoft hurts us Opinion  As Microsoft approaches its 50th birthday next year, it can look back with satisfaction at having created the first era of universal corporate computing,

Hey Microsoft – what ever happened to ‘Developers, developers, developers’? Read More »

Singapore Banks to Phase Out OTPs for Online Logins Within 3 Months

Singapore Banks to Phase Out OTPs for Online Logins Within 3 Months 2024-07-15 at 11:31 By Retail banking institutions in Singapore have three months to phase out the use of one-time passwords (OTPs) for authentication purposes when signing into online accounts to mitigate the risk of phishing attacks. The decision was announced by the Monetary

Singapore Banks to Phase Out OTPs for Online Logins Within 3 Months Read More »

China’s internet cleanup campaigns are going so well it needs a new one to protect kids

China’s internet cleanup campaigns are going so well it needs a new one to protect kids 2024-07-15 at 08:46 By Laura Dobberstein Years of crackdowns haven’t stopped some revolting stuff China’s many attempts to clean up its internet appear not to have prevented the proliferation of revolting material and products that abuse or target children.…

China’s internet cleanup campaigns are going so well it needs a new one to protect kids Read More »

New HardBit Ransomware 4.0 Uses Passphrase Protection to Evade Detection

New HardBit Ransomware 4.0 Uses Passphrase Protection to Evade Detection 2024-07-15 at 08:46 By Cybersecurity researchers have shed light on a new version of a ransomware strain called HardBit that comes packaged with new obfuscation techniques to deter analysis efforts. “Unlike previous versions, HardBit Ransomware group enhanced the version 4.0 with passphrase protection,” Cybereason researchers

New HardBit Ransomware 4.0 Uses Passphrase Protection to Evade Detection Read More »

Risk related to non-human identities: Believe the hype, reject the FUD

Risk related to non-human identities: Believe the hype, reject the FUD 2024-07-15 at 08:01 By Help Net Security The hype surrounding unmanaged and exposed non-human identities (NHIs), or machine-to-machine credentials – such as service accounts, system accounts, certificates and API keys – has recently skyrocketed. A steady stream of NHI-related breaches is causing some of

Risk related to non-human identities: Believe the hype, reject the FUD Read More »

Realm: Open-source adversary emulation framework

Realm: Open-source adversary emulation framework 2024-07-15 at 07:32 By Mirko Zorz Realm is an open-source adversary emulation framework emphasizing scalability, reliability, and automation. It’s designed to handle engagements of any size. “Realm is unique in its custom interpreter written in Rust. This allows us to write complex TTPs as code. With these actions as code,

Realm: Open-source adversary emulation framework Read More »

Discover the growing threats to data security

Discover the growing threats to data security 2024-07-15 at 07:01 By Mirko Zorz In this Help Net Security interview, Pranava Adduri, CEO at Bedrock Security, discusses how businesses can identify and prioritize their data security risks. Adduri emphasizes the necessity of ongoing monitoring and automation to keep up with evolving threats and maintain the shortest

Discover the growing threats to data security Read More »

Encrypted traffic: A double-edged sword for network defenders

Encrypted traffic: A double-edged sword for network defenders 2024-07-15 at 06:31 By Help Net Security Organizations are ramping up their use of encrypted traffic to lock down data. Could they be making it easier to hide threats in the process? On one hand, encryption means enhanced privacy, but it can also make the job of

Encrypted traffic: A double-edged sword for network defenders Read More »

Pressure mounts for C-Suite executives to implement GenAI solutions

Pressure mounts for C-Suite executives to implement GenAI solutions 2024-07-15 at 06:01 By Help Net Security 87% of C-Suite executives feel under pressure to implement GenAI solutions at speed and scale, according to RWS. Despite these pressures, 76% expressed an overwhelming excitement across their organization for the potential benefits of GenAI. However, this excitement is

Pressure mounts for C-Suite executives to implement GenAI solutions Read More »

UK cyber-boss slams China’s bug-hoarding laws

UK cyber-boss slams China’s bug-hoarding laws 2024-07-15 at 03:21 By Laura Dobberstein Plus: Japanese scientists ID ancient supernova; AWS dismisses China trouble rumor; and more ASIA IN BRIEF  The interim CEO of the UK’s National Cyber Security Centre (NCSC) has criticized China’s approach to bug reporting.… This article is an excerpt from The Register View

UK cyber-boss slams China’s bug-hoarding laws Read More »

Scroll to Top