Security News

How to Analyze Malware’s Network Traffic in A Sandbox
2023-12-13 12:02

Malware analysis encompasses a broad range of activities, including examining the malware's network traffic. To be effective at it, it's crucial to understand the common challenges and how to...

New cybercrime market 'OLVX' gains popularity among hackers
2023-12-13 12:00

A new cybercrime marketplace, OLVX, has emerged and is quickly gaining new customers looking to purchase tools to conduct online fraud and cyberattacks. OLVX follows a recent trend where cybercrime marketplaces are increasingly hosted on the clearnet instead of the dark web, making them more accessible to a broader range of users and possible to promote through search engine optimization.

EOL Sophos firewalls get hotfix for old but still exploited vulnerability (CVE-2022-3236)
2023-12-13 11:03

Over a year has passed since Sophos delivered patches for a vulnerability affecting Sophos Firewalls that was being actively exploited by attackers, and now they have pushed additional ones to protect vulnerable EOL devices. "In December 2023, we delivered an updated fix after identifying new exploit attempts against this same vulnerability in older, unsupported versions of the Sophos Firewall," the company shared on Monday by updating of the original security advisory.

Microsoft Warns of Hackers Exploiting OAuth for Cryptocurrency Mining and Phishing
2023-12-13 10:55

Microsoft has warned that adversaries are using OAuth applications as an automation tool to deploy virtual machines (VMs) for cryptocurrency mining and launch phishing attacks. "Threat actors...

Nearly a million non-profit donors' details left exposed in unsecured database
2023-12-13 10:30

Close to a million records containing personally identifiable information belonging to donors that sent money to non-profits were found exposed in an online database. Infosec researcher Jeremiah Fowler found 948,029 records exposed online including donor names, addresses, phone numbers, emails, payment methods, and more.

Major Cyber Attack Paralyzes Kyivstar - Ukraine's Largest Telecom Operator
2023-12-13 10:18

Ukraine's biggest telecom operator Kyivstar has become the victim of a cyber attack, disrupting customer access to mobile and internet services. "The cyberattack on Ukraine's #Kyivstar telecoms...

Which cybersecurity controls are organizations struggling with?
2023-12-13 09:50

How are organizations performing across cybersecurity controls in the Minimum Viable Secure Product framework? A recent analysis by Bitsight and Google reveals some good and some bad results - and room for improvement. The study analyzed the cybersecurity performance of nearly 100,000 organizations around the world across nine industries.

Cyber security isn’t simple, but it could be
2023-12-13 08:59

Sponsored Feature Most experts agree cybersecurity is now so complex that managing it has become a security problem in itself. Growing complexity, skills shortages, and rising costs have resulted in huge growth in the managed security service provider sector over the last decade.

Think tank report labels NSO, Lazarus, as 'cyber mercenaries'
2023-12-13 06:05

Cybercrime gangs like the notorious Lazarus group and spyware vendors like Israel's NSO should be considered cyber mercenaries - and become the subject of a concerted international response - according to a Monday report from Delhi-based think tank Observer Research Foundation. Author Fitri Bintang Timur argued the term mercenary applies because, as amendments to the Geneva Convention put it, mercenaries are "An entity having the motivation to gain financial or material compensation in return for their willingness to fight for the recruiter's country."

Microsoft's Final 2023 Patch Tuesday: 33 Flaws Fixed, Including 4 Critical
2023-12-13 05:50

Microsoft released its final set of Patch Tuesday updates for 2023, closing out 33 flaws in its software, making it one of the lightest releases in recent years. Of the 33 shortcomings, four are...