Hacktivist Group Claims Breach of Cybersecurity Firm CrowdStrike
USDoD hacktivist group allegedly exfiltrates sensitive information from CrowdStrike, raising concerns about data security and hacker group credibility.
View full story…
Ongoing Cyberattack Targets Exposed Selenium Grid Services for Unauthorized Cryptocurrency Mining
Security researchers have identified the SeleniumGreed campaign targeting internet-exposed Selenium Grid services for unauthorized cryptocurrency mining, exploiting older versions lacking default security controls.
View full story…
Enterprises Struggle to Govern Use of AI in Application Security
Checkmarx report highlights challenges faced by organizations in utilizing generative AI for application security, emphasizing risks and lack of governance.
View full story…
Global Cybersecurity Advisory Warns of North Korean Espionage Campaign Targeting Critical Infrastructure Organizations
A joint advisory identifies North Korean state-sponsored cyber threat actors targeting defense, aerospace, energy, nuclear, engineering, medical, and telecommunications sectors for espionage and ransomware attacks.
View full story…
New Cybersecurity Threat Targets German Customers with Fake CrowdStrike Crash Reporter
A sophisticated spear-phishing campaign targeting German-speaking CrowdStrike customers involves the distribution of a fake CrowdStrike Crash Reporter, highlighting the threat actor’s use of anti-forensic techniques and the importance of implementing multi-layered security measures.
View full story…
Critical Security Vulnerability Identified in Progress Software’s Telerik Report Server Product
A critical security vulnerability, CVE-2024-6327, has been found in Progress Software’s Telerik Report Server product, posing a risk of remote code execution due to an insecure deserialization issue.
View full story…
Latest Cybernews
Cybercriminals Exploit CrowdStrike Outage with Phishing Attacks
Hackers target CrowdStrike customers with phishing emails disguised as Microsoft recovery guides to steal sensitive information and distribute malware.
View full story…
Ransomware and BEC Attacks Dominate Cyber Threat Landscape in Q2 2024
Ransomware incidents increased by 22% in Q2 2024, with compromised credentials as the most common initial access method, highlighting the need for organizations to strengthen cybersecurity measures.
View full story…
Critical Docker Engine Vulnerability Allows Unauthorized Access
A critical security vulnerability in certain versions of Docker Engine allows attackers to bypass authorization plugins and gain unauthorized access to systems.
View full story…
Meta Platforms Removes 63,000 Instagram Accounts in Nigeria for Financial Sextortion Scams
Meta Platforms takes action against cybercrime in Nigeria by removing accounts involved in financial sextortion scams, primarily targeting American men and minors.
View full story…
Vulnerability ConfusedFunction Identified in Google Cloud Platform’s Cloud Functions and Cloud Build Services
A security risk has been identified in Google Cloud Platform’s Cloud Functions and Cloud Build services, allowing threat actors to escalate privileges and potentially gain unauthorized access to other GCP services.
View full story…
Malware Attacks Surge 30% in First Half of 2024
Malware-based threats increased significantly in the first half of 2024, with a spike in attacks using sophisticated methods like PowerShell and targeting IoT devices.
View full story…
Global IT Outage Caused by CrowdStrike Falcon Sensor Defect
A defect in a content update for CrowdStrike’s Falcon sensor led to a global IT outage impacting over 8.5 million computers running Windows, highlighting the critical need for effective ransomware recovery and response plans.
View full story…
Study Reveals IT Leaders’ Concerns Over Cybersecurity Preparedness
A recent study by Appsbroker CTS found that IT and cybersecurity leaders feel unprepared for emerging technologies and increasing cyber threats, with many turning to Zero Trust controls to address challenges.
View full story…