Uncategorized

Multiple Cross-Site Scripting (XSS) Vulnerabilities in REDCap (CVE-2024-37394, CVE-2024-37395, and CVE-2024-37396)

Multiple Cross-Site Scripting (XSS) Vulnerabilities in REDCap (CVE-2024-37394, CVE-2024-37395, and CVE-2024-37396) 2024-07-30 at 19:31 By Hamza Hussain Trustwave SpiderLabs uncovered multiple stored cross-site scripting (XSS) vulnerabilities (CVE-2024-37394, CVE-2024-37395, and CVE-2024-37396) in REDCap (Research Electronic Data Capture), a widely used web application for building and managing online surveys and databases in research environments. These vulnerabilities, if exploited, […]

Multiple Cross-Site Scripting (XSS) Vulnerabilities in REDCap (CVE-2024-37394, CVE-2024-37395, and CVE-2024-37396) Read More »

Rising costs biggest issue for datacenter operators as demand grows

Rising costs biggest issue for datacenter operators as demand grows 2024-07-30 at 18:32 By Dan Robinson Not to mention the skills gap, AI skepticism, and the unrelenting quest for power Datacenter operators face multiple challenges such as power and cooling requirements, while staffing issues persist and many are not tracking the right sustainability metrics. On

Rising costs biggest issue for datacenter operators as demand grows Read More »

‘LockBit of phishing’ EvilProxy used in more than a million attacks every month

‘LockBit of phishing’ EvilProxy used in more than a million attacks every month 2024-07-30 at 17:46 By Jessica Lyons Leaves a trail of ransomware infections, data theft, business email compromise in its wake Insight  The developers of EvilProxy – a phishing kit dubbed the “LockBit of phishing” – have produced guides on using legitimate Cloudflare

‘LockBit of phishing’ EvilProxy used in more than a million attacks every month Read More »

New Mandrake Spyware Found in Google Play Store Apps After Two Years

New Mandrake Spyware Found in Google Play Store Apps After Two Years 2024-07-30 at 17:01 By A new iteration of a sophisticated Android spyware called Mandrake has been discovered in five applications that were available for download from the Google Play Store and remained undetected for two years. The applications attracted a total of more

New Mandrake Spyware Found in Google Play Store Apps After Two Years Read More »

WhatsApp Vulnerability Allows Python, PHP Script Execution

WhatsApp Vulnerability Allows Python, PHP Script Execution 2024-07-30 at 16:22 A security flaw in WhatsApp for Windows allows Python and PHP scripts to execute without warning when opened by recipients. This vulnerability, affecting users with Python installed on their systems, could pose a risk to software developers, researchers, and power users. The flaw enables the

WhatsApp Vulnerability Allows Python, PHP Script Execution Read More »

W3C says Google’s cookie climbdown ‘undermines’ a lot of work

W3C says Google’s cookie climbdown ‘undermines’ a lot of work 2024-07-30 at 16:16 By Richard Speed While some celebrate, the World Wide Web Consortium Technical Architecture Group is not happy The World Wide Web Consortium (W3C) has published a blog criticizing Google’s climbdown over the deprecation of third-party cookies, declaring that the move “undermines a

W3C says Google’s cookie climbdown ‘undermines’ a lot of work Read More »

How deliciously binary: AI has yet to pay off – or is transforming business

How deliciously binary: AI has yet to pay off – or is transforming business 2024-07-30 at 15:31 By Thomas Claburn Calculating ROI of neural networks turns out to be rather complicated Feature  The tech industry’s enthusiasm for artificial intelligence software – a conveniently amorphous term – has yet to generate much of an economic windfall.…

How deliciously binary: AI has yet to pay off – or is transforming business Read More »

Ransomware gangs are loving this dumb but deadly make-me-admin ESXi vulnerability

Ransomware gangs are loving this dumb but deadly make-me-admin ESXi vulnerability 2024-07-30 at 14:31 By Connor Jones Get those patches applied – all the big dogs are abusing it Do you have your VMware ESXi hypervisor joined to Active Directory? Well, the latest news from Microsoft serves as a reminder that you might not want

Ransomware gangs are loving this dumb but deadly make-me-admin ESXi vulnerability Read More »

Cyber Threat Intelligence: Illuminating the Deep, Dark Cybercriminal Underground

Cyber Threat Intelligence: Illuminating the Deep, Dark Cybercriminal Underground 2024-07-30 at 14:31 By Learn about critical threats that can impact your organization and the bad actors behind them from Cybersixgill’s threat experts. Each story shines a light on underground activities, the threat actors involved, and why you should care, along with what you can do

Cyber Threat Intelligence: Illuminating the Deep, Dark Cybercriminal Underground Read More »

Cybercriminals Target Polish Businesses with Agent Tesla and Formbook Malware

Cybercriminals Target Polish Businesses with Agent Tesla and Formbook Malware 2024-07-30 at 14:31 By Cybersecurity researchers have detailed widespread phishing campaigns targeting small and medium-sized businesses (SMBs) in Poland during May 2024 that led to the deployment of several malware families like Agent Tesla, Formbook, and Remcos RAT. Some of the other regions targeted by

Cybercriminals Target Polish Businesses with Agent Tesla and Formbook Malware Read More »

Europe launches ‘AI Factories’ initiative in hopes of competing globally

Europe launches ‘AI Factories’ initiative in hopes of competing globally 2024-07-30 at 13:46 By Dan Robinson Yes, you’ve heard the term ‘AI Factories’ before but Europe has its own spin Europe’s supercomputing body has officially added a new pillar to its strategy – to develop and operate AI Factories to drive “a more competitive and

Europe launches ‘AI Factories’ initiative in hopes of competing globally Read More »

Latest update for ‘extremely fast’ compression algorithm LZ4 sprints past old versions

Latest update for ‘extremely fast’ compression algorithm LZ4 sprints past old versions 2024-07-30 at 12:46 By Liam Proven New release does something you might have thought it already did The new version of the high-speed compression algorithm LZ4 gets a big speed boost – nearly an order of magnitude.… This article is an excerpt from

Latest update for ‘extremely fast’ compression algorithm LZ4 sprints past old versions Read More »

Revamped UK cybersecurity bill couldn’t come soon enough, but details are patchy

Revamped UK cybersecurity bill couldn’t come soon enough, but details are patchy 2024-07-30 at 11:46 By Connor Jones Long overdue updates including expanded mandatory security incident reporting seem like a step forward, however they end up looking Analysis  The introduction of fresh UK cybersecurity legislation, though delayed, is timely.… This article is an excerpt from

Revamped UK cybersecurity bill couldn’t come soon enough, but details are patchy Read More »

New SideWinder Cyber Attacks Target Maritime Facilities in Multiple Countries

New SideWinder Cyber Attacks Target Maritime Facilities in Multiple Countries 2024-07-30 at 11:31 By The nation-state threat actor known as SideWinder has been attributed to a new cyber espionage campaign targeting ports and maritime facilities in the Indian Ocean and Mediterranean Sea. The BlackBerry Research and Intelligence Team, which discovered the activity, said targets of

New SideWinder Cyber Attacks Target Maritime Facilities in Multiple Countries Read More »

Automation needed to fight army of AI content harvesters stalking the web

Automation needed to fight army of AI content harvesters stalking the web 2024-07-30 at 10:31 By Thomas Claburn Just when you think you’ve ban-hammered one, it pops up with another name Analysis  This month Anthropic’s ClaudeBot – a web content crawler that scrapes data from pages for training AI models – visited tech advice site

Automation needed to fight army of AI content harvesters stalking the web Read More »

OneDrive Phishing Scam Tricks Users into Running Malicious PowerShell Script

OneDrive Phishing Scam Tricks Users into Running Malicious PowerShell Script 2024-07-30 at 10:31 By Cybersecurity researchers are warning about a new phishing campaign that targets Microsoft OneDrive users with the aim of executing a malicious PowerShell script. “This campaign heavily relies on social engineering tactics to deceive users into executing a PowerShell script, thereby compromising

OneDrive Phishing Scam Tricks Users into Running Malicious PowerShell Script Read More »

Scroll to Top