Security News

New Golang-Based Backdoor Uses Telegram Bot API for Evasive C2 Operations
2025-02-17 09:04

Cybersecurity researchers have shed light on a new Golang-based backdoor that uses Telegram as a mechanism for command-and-control (C2) communications. Netskope Threat Labs, which detailed the...

FINALDRAFT Malware Exploits Microsoft Graph API for Espionage on Windows and Linux
2025-02-13 09:11

Threat hunters have shed light on a new campaign targeting the foreign ministry of an unnamed South American nation with bespoke malware capable of granting remote access to infected hosts. The...

The API security crisis and why businesses are at risk
2025-02-05 04:30

In this Help Net Security video, Ivan Novikov, CEO of Wallarm, discusses the 2025 API ThreatStats Report, highlighting how APIs have become the primary attack surface over the past year, mainly...

BeyondTrust Zero-Day Breach Exposed 17 SaaS Customers via Compromised API Key
2025-02-01 06:40

BeyondTrust has revealed it completed an investigation into a recent cybersecurity incident that targeted some of the company's Remote Support SaaS instances by making use of a compromised API...

89% of AI-powered APIs rely on insecure authentication mechanisms
2025-01-30 04:30

APIs have emerged as the predominant attack surface over the past year, with AI being the biggest driver of API security risks, according to Wallarm. “Based on our findings, what is clear is that...

Guess who left a database wide open, exposing chat logs, API keys, and more? Yup, DeepSeek
2025-01-30 00:31

Oh someone's in DeepShi... China-based AI biz DeepSeek may have developed competitive, cost-efficient generative models, but its cybersecurity chops are another story.…

Severe Security Flaws Patched in Microsoft Dynamics 365 and Power Apps Web API
2025-01-02 12:53

Details have emerged about three now-patched security vulnerabilities in Dynamics 365 and Power Apps Web API that could result in data exposure. The flaws, discovered by Melbourne-based...

Chinese APT Exploits BeyondTrust API Key to Access U.S. Treasury Systems and Documents
2024-12-31 05:42

The United States Treasury Department said it suffered a "major cybersecurity incident" that allowed suspected Chinese threat actors to remotely access some computers and unclassified documents. ...

API security blind spots put businesses at risk
2024-12-24 04:00

Many customer-facing APIs remain unprotected, leaving businesses vulnerable to breaches. To address these threats, a comprehensive approach to API security, covering every stage of the lifecycle,...

Over 300K Prometheus Instances Exposed: Credentials and API Keys Leaking Online
2024-12-12 14:24

Cybersecurity researchers are warning that thousands of servers hosting the Prometheus monitoring and alerting toolkit are at risk of information leakage and exposure to denial-of-service (DoS) as...