Security News > 2023 > August

Hackers can abuse Microsoft Office executables to download malware
2023-08-03 15:48

The main executable for the Microsoft Publisher application has already been confirmed that it can download payloads from a remote server. According to recent research, even executables that are not signed by Microsoft serve purposes that are useful in attacks, such as reconnaissance.

RFP Template for Browser Security
2023-08-03 15:10

A group of experts have recognized the pressing need for comprehensive browser security solutions and collaborated to develop "The Definitive Browser Security RFP Template." This resource helps streamline the process of evaluating and procuring browser security platforms. The RFP template offers numerous advantages for organizations seeking robust browser security solutions.

FBI, CISA, and NSA reveal top exploited vulnerabilities of 2022
2023-08-03 15:08

In collaboration with CISA, the NSA, and the FBI, Five Eyes cybersecurity authorities have issued today a list of the 12 most exploited vulnerabilities throughout 2022."In 2022, malicious cyber actors exploited older software vulnerabilities more frequently than recently disclosed vulnerabilities and targeted unpatched, internet-facing systems," the joint advisory reads.

Chrome malware Rilide targets enterprise users via PowerPoint guides
2023-08-03 14:36

The malicious Rilide Stealer Chrome browser extension has returned in new campaigns targeting crypto users and enterprise employees to steal credentials and crypto wallets. Rilide is a malicious browser extension for Chromium-based browsers, including Chrome, Edge, Brave, and Opera, that Trustwave SpiderLabs initially discovered in April 2023.

New Version of Rilide Data Theft Malware Adapts to Chrome Extension Manifest V3
2023-08-03 14:33

Cybersecurity researchers have discovered a new version of malware called Rilide that targets Chromium-based web browsers to steal sensitive data and steal cryptocurrency. "It exhibits a higher...

Hundreds of Citrix NetScaler ADC and Gateway Servers Hacked in Major Cyber Attack
2023-08-03 14:20

Hundreds of Citrix NetScaler ADC and Gateway servers have been breached by malicious actors to deploy web shells, according to the Shadowserver Foundation. The non-profit said the attacks take advantage of CVE-2023-3519, a critical code injection vulnerability that could lead to unauthenticated remote code execution.

A Penetration Testing Buyer's Guide for IT Security Teams
2023-08-03 12:47

Pen testing helps to identify security flaws in your IT infrastructure before threat actors can detect and exploit them. Here, we outline key factors to consider before, during, and post the penetration testing process.

Webinar: Riding the vCISO Wave: How to Provide vCISO Services
2023-08-03 12:47

vCISO services also enable upselling of additional products and services the MSP or MSSP specializes in. Not all MSPs and MSSPs fully understand how to provide vCISO services.

Russian APT phished government employees via Microsoft Teams
2023-08-03 12:12

An APT group linked to Russia’s Foreign Intelligence Service has hit employees of several dozen global organizations with phishing attacks via Microsoft Teams, says Microsoft. A social engineering...

The Need for Trustworthy AI
2023-08-03 11:17

If you ask Alexa, Amazon’s voice assistant AI system, whether Amazon is a monopoly, it responds by saying it doesn’t know. It doesn’t take much to make it lambaste the other tech giants, but it’s...

#AI