2024

New Backdoor Targeting European Officials Linked to Indian Diplomatic Events

New Backdoor Targeting European Officials Linked to Indian Diplomatic Events 2024-02-29 at 10:32 By A previously undocumented threat actor dubbed SPIKEDWINE has been observed targeting officials in European countries with Indian diplomatic missions using a new backdoor called WINELOADER. The adversary, according to a report from Zscaler ThreatLabz, used a PDF file in emails that purported to come from […]

New Backdoor Targeting European Officials Linked to Indian Diplomatic Events Read More »

Lazarus Exploits Typos to Sneak PyPI Malware into Dev Systems

Lazarus Exploits Typos to Sneak PyPI Malware into Dev Systems 2024-02-29 at 10:32 By The notorious North Korean state-backed hacking group Lazarus uploaded four packages to the Python Package Index (PyPI) repository with the goal of infecting developer systems with malware. The packages, now taken down, are pycryptoenv, pycryptoconf, quasarlib, and swapmempool. They have been collectively downloaded 3,269 times,

Lazarus Exploits Typos to Sneak PyPI Malware into Dev Systems Read More »

Nutanix doesn’t expect a rush of VMware refugees – maybe for years

Nutanix doesn’t expect a rush of VMware refugees – maybe for years 2024-02-29 at 09:03 By Simon Sharwood Beats guidance as renewals grow and waits for Broadcom and Cisco to bring more bucks Nutanix doesn’t expect a rush of VMware users to adopt its platform, because many signed up for long-term deals before Broadcom acquired

Nutanix doesn’t expect a rush of VMware refugees – maybe for years Read More »

Alibaba Cloud cuts prices – hard – for multi-year commitments in mainland China

Alibaba Cloud cuts prices – hard – for multi-year commitments in mainland China 2024-02-29 at 08:31 By Simon Sharwood This might solve its twin problems of low growth and short-term customers Alibaba Cloud has made significant price cuts for those willing to use its datacenters in mainland China and commit to multi-year deals.… This article

Alibaba Cloud cuts prices – hard – for multi-year commitments in mainland China Read More »

Chinese Hackers Exploiting Ivanti VPN Flaws to Deploy New Malware

Chinese Hackers Exploiting Ivanti VPN Flaws to Deploy New Malware 2024-02-29 at 08:31 By At least two different suspected China-linked cyber espionage clusters, tracked as UNC5325 and UNC3886, have been attributed to the exploitation of security flaws in Ivanti Connect Secure VPN appliances. UNC5325 abused CVE-2024-21893 to deliver a wide range of new malware called LITTLELAMB.WOOLTEA, PITSTOP, PITDOG, PITJET, and

Chinese Hackers Exploiting Ivanti VPN Flaws to Deploy New Malware Read More »

BobTheSmuggler: Open-source tool for undetectable payload delivery

BobTheSmuggler: Open-source tool for undetectable payload delivery 2024-02-29 at 08:03 By Mirko Zorz BobTheSmuggler is an open-source tool designed to easily compress, encrypt, and securely transport your payload. It basically enables you to hide a payload in plain sight. BobTheSmuggler is helpful in phishing campaign assessments, data exfiltration exercises, and assumed breach scenarios. Features Hiding

BobTheSmuggler: Open-source tool for undetectable payload delivery Read More »

How organizations can navigate identity security risks in 2024

How organizations can navigate identity security risks in 2024 2024-02-29 at 07:34 By Mirko Zorz Managing IAM challenges in hybrid IT environments requires a holistic approach, integrating solutions and automating processes to ensure effective access controls and operational efficiency. In this Help Net Security interview, Deepak Taneja, CEO of Zilla Security, discusses identity security risks

How organizations can navigate identity security risks in 2024 Read More »

President Biden Blocks Mass Transfer of Personal Data to High-Risk Nations

President Biden Blocks Mass Transfer of Personal Data to High-Risk Nations 2024-02-29 at 07:17 By U.S. President Joe Biden has issued an Executive Order that prohibits the mass transfer of citizens’ personal data to countries of concern. The Executive Order also “provides safeguards around other activities that can give those countries access to Americans’ sensitive data,” the

President Biden Blocks Mass Transfer of Personal Data to High-Risk Nations Read More »

Chinese PC-maker Acemagic customized its own machines to get infected with malware

Chinese PC-maker Acemagic customized its own machines to get infected with malware 2024-02-29 at 07:04 By Simon Sharwood Tried to speed boot times, maybe by messing with ‘Windows source code’, ended up building a viral on-ramp Chinese PC maker Acemagic has admitted some of its products shipped with pre-installed malware.… This article is an excerpt

Chinese PC-maker Acemagic customized its own machines to get infected with malware Read More »

Inside the book: Androids – The Team That Built the Android Operating System

Inside the book: Androids – The Team That Built the Android Operating System 2024-02-29 at 07:03 By Help Net Security In 2004, Android was two people who wanted to build camera software but couldn’t get investors interested. Android is a large team at Google today, delivering an OS to over 3 billion devices worldwide. In

Inside the book: Androids – The Team That Built the Android Operating System Read More »

Cryptojacking is no longer the sole focus of cloud attackers

Cryptojacking is no longer the sole focus of cloud attackers 2024-02-29 at 06:31 By Help Net Security As commercial adoption of cloud technologies continues, cloud-focused malware campaigns have increased in sophistication and number – a collective effort to safeguard both large and small enterprises is critical, according to Cado Security. Docker remains the most frequently

Cryptojacking is no longer the sole focus of cloud attackers Read More »

Vishing, smishing, and phishing attacks skyrocket 1,265% post-ChatGPT

Vishing, smishing, and phishing attacks skyrocket 1,265% post-ChatGPT 2024-02-29 at 06:02 By Help Net Security 76% of enterprises lack sufficient voice and messaging fraud protection as AI-powered vishing and smishing skyrocket following the launch of ChatGPT, according to Enea. Enterprises report significant losses from mobile fraud 61% of enterprises still suffer significant losses to mobile

Vishing, smishing, and phishing attacks skyrocket 1,265% post-ChatGPT Read More »

The CISO’s guide to reducing the SaaS attack surface

The CISO’s guide to reducing the SaaS attack surface 2024-02-29 at 06:02 By Help Net Security SaaS sprawl introduces security risks, operational headaches, and eye-popping subscription costs. Download this guide to learn how to implement a strategic approach to reducing your SaaS attack surface without slowing down the business. Inside the guide, you’ll find: Tools

The CISO’s guide to reducing the SaaS attack surface Read More »

Toyota admits its engines are overrated – by its own power testing software

Toyota admits its engines are overrated – by its own power testing software 2024-02-29 at 05:49 By Laura Dobberstein Japan’s government slapped it for using the wrong code to produce too-powerful results Toyota apologized on Wednesday for an incident involving the fraudulent certification of its diesel engines that resulted in a corrective order from Japan’s

Toyota admits its engines are overrated – by its own power testing software Read More »

Infosec products of the month: February 2024

Infosec products of the month: February 2024 2024-02-29 at 05:48 By Help Net Security Here’s a look at the most interesting products from the past month, featuring releases from: Appdome, BackBox, Center for Internet Security, Cisco, CompliancePro Solutions, Cyberhaven, LOKKER, ManageEngine, Metomic, OPSWAT, Pindrop, ProcessUnity, Qualys, SentinelOne, Sumsub,Truffle Security, Vade Secure, and Varonis. CIS ESS

Infosec products of the month: February 2024 Read More »

Australian spy chief fears sabotage of critical infrastructure

Australian spy chief fears sabotage of critical infrastructure 2024-02-29 at 04:02 By Simon Sharwood And accuses a former Australian politician of having ‘sold out their country’ The director general of security at Australia’s Security Intelligence Organisation (ASIO) has delivered his annual threat assessment, revealing ongoing attempts by adversaries to map digital infrastructure with a view

Australian spy chief fears sabotage of critical infrastructure Read More »

ALPHV/BlackCat claims responsibility for Change Healthcare attack

ALPHV/BlackCat claims responsibility for Change Healthcare attack 2024-02-29 at 02:48 By Jessica Lyons Brags it lifted 6TB of data, but let’s remember these people are criminals and not worthy of much trust The ALPHV/BlackCat cybercrime gang has taken credit – if that’s the word – for a ransomware infection at Change Healthcare that has disrupted

ALPHV/BlackCat claims responsibility for Change Healthcare attack Read More »

BEAST AI needs just a minute of GPU time to make an LLM fly off the rails

BEAST AI needs just a minute of GPU time to make an LLM fly off the rails 2024-02-29 at 01:48 By Thomas Claburn Talk about gone in 60 seconds Computer scientists at the University of Maryland have developed an efficient way to craft prompts that elicit harmful responses from large language models (LLMs).… This article

BEAST AI needs just a minute of GPU time to make an LLM fly off the rails Read More »

Scroll to Top