Have some tips? Write it down and share it to your friends!
Click Login Now button to start!
News
Cyber Security Related News
Since April 2022, the Black Basta ransomware group has attacked over 500 organizations in North America, Europe, and Australia. A report from CISA, FBI, HHS, and MS-ISAC shows that they have targeted 12 of the 16 main critical infrastructure sectors, encrypting and stealing data. Black Basta commonly uses phishing and known software flaws to break in, then demands money by threatening to publish stolen data if not paid. Instead of giving a ransom amount u
Source:
Dropbox, the cloud storage services provider, disclosed a significant breach affecting its digital signature service, Dropbox Sign (formerly known as HelloSign). This breach, discovered on April 24, 2024, resulted in unauthorized access by unidentified threat actors to user emails, usernames, and general account settings associated with all users of the digital signature product. Additionally, for certain subsets of users, the attackers accessed...
May 9, 2024 13:52 (on 5/9/24) | 0 |
2 minutes read
Google has delayed its plan to remove third-party tracking cookies from its Chrome browser amid ongoing concerns from U.K. regulators about its Privacy Sandbox initiative. The company is working closely with the U.K. Competition and Markets Authority (CMA) to address these issues and hopes to reach an agreement by the end of the year.
The new timeline involves beginning the phase-out of...
April 26, 2024 12:39 (on 4/26/24) | 0 |
2 minutes read
Binarly's recent findings reveal a security loophole in the Lighttpd web server utilized within baseboard management controllers (BMCs), left unaddressed by major device manufacturers like Intel and Lenovo. Originally discovered and patched by Lighttpd maintainers in August 2018, the absence of a CVE identifier or advisory led to its oversight by developers of AMI MegaRAC BMC, thus integrating it into Intel and Lenovo products.
Google has unveiled support for the V8 Sandbox in its Chrome web browser, aiming to combat memory corruption issues. According to Samuel Groß, the V8 Security technical lead, the sandbox prevents the spread of memory corruption within the host process.
Described as a lightweight, in-process sandbox for the JavaScript and WebAssembly engine, the V8 Sandbox mitigates common vulnerabilities....
April 9, 2024 08:26 (on 4/9/24) | 0 |
2 minutes read
Malicious advertisements and counterfeit websites have become conduits for disseminating two distinct types of stealer malware, notably Atomic Stealer, targeting users of Apple's macOS operating system. Jamf Threat Labs has released a report highlighting ongoing attacks aimed at extracting sensitive data from macOS users. The attackers behind these campaigns employ diverse methods to compromise victims' Macs, stealing valuable...
April 2, 2024 09:39 (on 4/2/24) | 0 |
2 minutes read
A recent phishing campaign targets U.S. organizations, aiming to deploy the NetSupport RAT, a remote access trojan. Tracked by Israeli cybersecurity firm Perception Point as Operation PhantomBlu, this campaign employs a sophisticated method by exploiting Microsoft Office's Object Linking and Embedding (OLE) template manipulation to execute malicious code, avoiding detection. NetSupport RAT, derived from the legitimate tool NetSupport Manager,...
March 26, 2024 13:49 (on 3/26/24) | 0 |
2 minutes read
Cybersecurity researchers have identified critical vulnerabilities within the third-party plugin ecosystem for OpenAI ChatGPT, shedding light on potential avenues for threat actors to exploit and gain unauthorized access to sensitive data. Recent findings from Salt Labs highlight security flaws within the ChatGPT platform itself and its accompanying plugin infrastructure, posing significant risks to user privacy and data...
March 19, 2024 10:17 (on 3/19/24) | 0 |
2 minutes read
The U.S. Department of Justice (DoJ) has unveiled charges against Linwei Ding, a 38-year-old Chinese national, and a California resident, for their alleged involvement in stealing proprietary information from Google while clandestinely collaborating with two Chinese tech firms. The indictment alleges that Ding, a former Google engineer, clandestinely siphoned off sensitive trade secrets to his account, facilitating the Chinese companies'...
March 13, 2024 13:25 (on 3/13/24) | 0 |
2 minutes read
A U.S. judge has mandated that NSO Group relinquish its source code for Pegasus and other remote access trojans to Meta as part of Meta's ongoing legal dispute with the Israeli spyware vendor.
This decision represents a significant legal triumph for Meta, which initiated the lawsuit in October 2019, accusing NSO Group of exploiting its infrastructure to distribute spyware to roughly 1,400...
March 5, 2024 11:13 (on 3/5/24) | 0 |
2 minutes read