Security News

Kremlin-Backed APT28 Targets Polish Institutions in Large-Scale Malware Campaign
2024-05-09 15:20

Polish government institutions have been targeted as part of a large-scale malware campaign orchestrated by a Russia-linked nation-state actor called APT28. "The campaign sent emails with content...

F5 fixes BIG-IP Next Central Manager flaws with public PoCs (CVE-2024-21793, CVE-2024-26026)
2024-05-09 13:56

Eclypsium researchers have published details and PoC exploits for two remotely exploitable injection vulnerabilities affecting F5's BIG-IP Next Central Manager. BIG-IP Next Central Manager allows users to centrally control their BIG-IP Next instances and services.

Zscaler swats claims of a significant breach
2024-05-09 13:17

On Wednesday, a threat actor named "InteIBroker" put up for sale "Access to one of the largest cyber security companies" and immediately ignited speculation about which company it might be. Some six hours Zscaler confirmed that they discovered an isolated test environment on a single server that was exposed to the internet, but did not contain customer data.

Upgrade Your Cybersecurity With This VPN That’s Only $70 for Three Years
2024-05-09 13:00

With Windscribe VPN, you can improve your security online by blocking ads, covering your browsing data and blocking your network behind a firewall. Normally, a Windscribe VPN Three-Year Pro Subscription would be $207, but you can get it for the best price online of $69.97 through May 12.

New Guide: How to Scale Your vCISO Services Profitably
2024-05-09 11:05

Cybersecurity and compliance guidance are in high demand among SMEs. However, many of them cannot afford to hire a full-time CISO. A vCISO can answer this need by offering on-demand access to...

Mirai Botnet Exploits Ivanti Connect Secure Flaws for Malicious Payload Delivery
2024-05-09 11:04

Two recently disclosed security flaws in Ivanti Connect Secure (ICS) devices are being exploited to deploy the infamous Mirai botnet. That's according to findings from Juniper Threat Labs, which...

CISA starts CVE “vulnrichment” program
2024-05-09 10:10

The US Cybersecurity and Infrastructure Agency has announced the creation of "Vulnrichment," a new project that aims to fill the CVE enrichment gap created by NIST National Vulnerability Database's recent slowdown. Since 1999, NVD analysts have been adding CVE-numbered vulnerabilities to the database, after analyzing public data about them to "Enrich" each entry with impact metrics, vulnerability types, applicability statements, links to security advisories, and more.

Critical F5 Central Manager Vulnerabilities Allow Enable Full Device Takeover
2024-05-09 06:11

Two security vulnerabilities have been discovered in F5 Next Central Manager that could be exploited by a threat actor to seize control of the devices and create hidden rogue administrator...

Regulators are coming for IoT device security
2024-05-09 05:00

Cybersecurity is a relatively new challenge for many IoT device makers who have traditionally produced non-connected devices. IoT devices are built on a foundation of insecure software-a large portion of the open-source software and the chips used to build devices are poorly secured.

Global ransomware crisis worsens
2024-05-09 04:30

Ransomware and extortion incidents surged by 67% in 2023, according to NTT Security Holdings' 2024 Global Threat Intelligence Report. After a down year in 2022, ransomware and extortion incidents increased in 2023.