Security News

Over 3 million mail servers without encryption exposed to sniffing attacks
2025-01-02 15:54

Over three million POP3 and IMAP mail servers without TLS encryption are currently exposed on the Internet and vulnerable to network sniffing attacks. [...]

Cross-Domain Attacks: A Growing Threat to Modern Security and How to Combat Them
2025-01-02 10:53

In the past year, cross-domain attacks have gained prominence as an emerging tactic among adversaries. These operations exploit weak points across multiple domains – including endpoints, identity...

It's only a matter of time before LLMs jump start supply-chain attacks
2024-12-29 18:20

'The greatest concern is with spear phishing and social engineering' Interview Now that criminals have realized there's no need to train their own LLMs for any nefarious purposes - it's much...

Malware botnets exploit outdated D-Link routers in recent attacks
2024-12-29 15:09

Two botnets tracked as 'Ficora' and 'Capsaicin' have recorded increased activity in targeting D-Link routers that have reached end of life or are running outdated firmware versions. [...]

FICORA and Kaiten Botnets Exploit Old D-Link Vulnerabilities for Global Attacks
2024-12-27 07:11

Cybersecurity researchers are warning about a spike in malicious activity that involves roping vulnerable D-Link routers into two different botnets, a Mirai variant dubbed FICORA and a Kaiten (aka...

Ruijie Networks' Cloud Platform Flaws Could've Exposed 50,000 Devices to Remote Attacks
2024-12-25 13:45

Cybersecurity researchers have discovered several security flaws in the cloud management platform developed by Ruijie Networks that could permit an attacker to take control of the network...

Clop ransomware threatens 66 Cleo attack victims with data leak
2024-12-24 13:02

The Clop ransomware gang started to extort victims of its Cleo data theft attacks and announced on its dark web portal that 66 companies have 48 hours to respond to the demands. [...]

Apache Tomcat Vulnerability CVE-2024-56337 Exposes Servers to RCE Attacks
2024-12-24 06:06

The Apache Software Foundation (ASF) has released a security update to address an important vulnerability in its Tomcat server software that could result in remote code execution (RCE) under...

Evilginx: Open-source man-in-the-middle attack framework
2024-12-23 05:30

Evilginx is an open-source man-in-the-middle attack framework designed to phish login credentials and session cookies, enabling attackers to bypass 2FA safeguards. “Back in 2017, I was...

Ascension: Health data of 5.6 million stolen in ransomware attack
2024-12-20 12:05

​Ascension, one of the largest private U.S. healthcare systems, is notifying over 5.6 million patients and employees that their personal and health data was stolen in a May cyberattack linked to...