Security News

Europol takes down 593 Cobalt Strike servers used by cybercriminals
2024-07-03 14:46

Europol coordinated a joint law enforcement action known as Operation Morpheus, which led to the takedown of almost 600 Cobalt Strike servers used by cybercriminals to infiltrate victims' networks. "Older, unlicensed versions of the Cobalt Strike red teaming tool were targeted during a week of action coordinated from Europol's headquarters between 24 and 28 June," said Europol.

Millions of Apple Applications Were Vulnerable to CocoaPods Supply Chain Attack
2024-07-03 14:37

The security team says they found vulnerable CocoaPods pods in "The documentation or terms of service documents of applications provided by Meta, Apple, and Microsoft; as well as in TikTok, Snapchat, Amazon, LinkedIn, Netflix, Okta, Yahoo, Zynga, and many more." E.V.A. reported the vulnerability to CocoaPods in October 2023, at which point it was patched.

The Emerging Role of AI in Open-Source Intelligence
2024-07-03 11:00

Recently the Office of the Director of National Intelligence (ODNI) unveiled a new strategy for open-source intelligence (OSINT) and referred to OSINT as the “INT of first resort”. Public and...

Bitwarden vs KeePass (2024): Battle of the Best – Who Wins?
2024-07-03 10:11

The major differences between Bitwarden and KeePass quickly became apparent once I started testing out both password managers. Read on to find out why Bitwarden is probably a better fit for your needs than KeePass - unless you're extremely technical and demand a highly customizable password manager.

Proton launches free, privacy-focused Google Docs alternative
2024-07-03 10:00

Proton has launched 'Docs in Proton Drive,' a free and open-source end-to-end encrypted web-based document editing and collaboration tool. Proton is a Swiss company renowned for its privacy-focused services, including Proton VPN, Proton Mail, Proton Pass, Proton Drive, and now also Proton Docs.

Microsoft MSHTML Flaw Exploited to Deliver MerkSpy Spyware Tool
2024-07-03 09:53

Unknown threat actors have been observed exploiting a now-patched security flaw in Microsoft MSHTML to deliver a surveillance tool called MerkSpy as part of a campaign primarily targeting users in...

FakeBat Loader Malware Spreads Widely Through Drive-by Download Attacks
2024-07-03 07:05

The loader-as-a-service (LaaS) known as FakeBat has become one of the most widespread loader malware families distributed using the drive-by download technique this year, findings from Sekoia...

Maintaining human oversight in AI-enhanced software development
2024-07-03 04:30

In this Help Net Security, Martin Reynolds, Field CTO at Harness, discusses how AI can enhance the security of software development and deployment. Increased reliance on AI-generated code introduces new risks, requiring human oversight and integrated security practices to ensure safe software delivery.

Secator: Open-source pentesting Swiss army knife
2024-07-03 04:00

Please turn on your JavaScript for this page to function normally. Secator is an open-source task and workflow runner tailored for security assessments.

Israeli Entities Targeted by Cyberattack Using Donut and Sliver Frameworks
2024-07-03 03:56

Cybersecurity researchers have discovered an attack campaign that targets various Israeli entities with publicly-available frameworks like Donut and Sliver. The campaign, believed to be highly...