Security News

New York man defrauded thousands using credit cards sold on dark web
2023-01-18 17:06

A New York resident has pleaded guilty to charges of conspiracy to commit bank fraud using stolen credit cards purchased on dark web cybercrime marketplaces. According to the indictment shared in the U.S. Department of Justice announcement, Osagie purchased thousands of credit and debit card data from dark web markets.

Hackers exploit Control Web Panel flaw to open reverse shells
2023-01-13 00:23

Hackers are actively exploiting a critical vulnerability patched recently in Control Web Panel, a tool for managing servers formerly known as CentOS Web Panel. On January 3, researcher Numan Türle at Gais Cyber Security, who had reported the issue around October last year, published a proof-of-concept exploit and a video showing how it works.

Alert: Hackers Actively Exploiting Critical "Control Web Panel" RCE Vulnerability
2023-01-12 06:48

Malicious actors are actively attempting to exploit a recently patched critical vulnerability in Control Web Panel that enables elevated privileges and unauthenticated remote code execution on susceptible servers. Control Web Panel, formerly known as CentOS Web Panel, is a popular server administration tool for enterprise-based Linux systems.

Pakistan’s government to agencies: Dark web is dangerous, please don’t go there
2023-01-10 02:29

Pakistan's government has warned its agencies that the dark web exists, is home to all sorts of unpleasant people, and should be avoided. Linking the dark web to terrorism therefore associates the networks with threats to national security.

Google introduces end-to-end encryption for Gmail on the web
2022-12-17 14:15

Google announced on Friday that it's adding end-to-end encryption to Gmail on the web, allowing enrolled Google Workspace users to send and receive encrypted emails within and outside their domain.The company says that the feature is not yet available to users with personal Google Accounts or Google Workspace Essentials, Business Starter, Business Standard, Business Plus, Enterprise Essentials, Education Fundamentals, Frontline, and Nonprofits, as well as legacy G Suite Basic and Business customers.

Top 5 Web App Vulnerabilities and How to Find Them
2022-12-15 10:00

Most startup CTOs have an excellent understanding of how to build highly functional SaaS businesses but need to gain more knowledge of how to secure the web application that underpins it. According to recent research from Verizon, web application attacks are involved in 26% of all breaches, and app security is a concern for of enterprises.

The Dark Web is Getting Darker - Ransomware Thrives on Illegal Markets
2022-12-14 15:33

The dark web is getting darker as cybercrime gangs increasingly shop their malware, phishing, and ransomware tools on illegal cybercrime markets. In 2022, threat actors preferred joining a RaaS for ransomware attacks as they tend to have more freedom and can deploy faster than private ransomware.

Researchers Detail New Attack Method to Bypass Popular Web Application Firewalls
2022-12-10 06:18

A new attack method can be used to circumvent web application firewalls of various vendors and infiltrate systems, potentially enabling attackers to gain access to sensitive business and customer information. Web application firewalls are a key line of defense to help filter, monitor, and block HTTP(S) traffic to and from a web application, and safeguard against attacks such as cross-site forgery, cross-site-scripting, file inclusion, and SQL injection.

Automated dark web markets sell corporate email accounts for $2
2022-12-08 16:22

Cybercrime marketplaces are increasingly selling stolen corporate email addresses for as low as $2 to fill a growing demand by hackers who use them for business email compromise and phishing attacks or initial access to networks. Analysts at Israeli cyber-intelligence firm KELA have closely followed this trend, reporting at least 225,000 email accounts for sale on underground markets.

Attackers take over expired domain to deliver web skimming scripts
2022-12-06 14:57

Attackers have taken over at least one expired domain that used to host a popular JavaScript library and used it to deliver web skimming scripts to a number of e-commerce sites. "The victim websites had years to remove the dead link that was leveraged by attackers but didn't - likely due to a lack of visibility about third-party scripts running on their websites and poor security hygiene," Jscrambler researchers noted.