Category: Uncategorized
-
Lottie Player NPM package compromised in supply chain attack
Post ContentRead More
-
Enterprise Identity Threat Report 2024: Unveiling Hidden Threats to Corporate Identities [email protected] (The Hacker News)
In the modern, browser-centric workplace, the corporate identity acts as the frontline defense for organizations. Often referred to as “the new perimeter”, the identity stands between safe data management and potential breaches. However, a new report reveals how enterprises are often unaware of how their identities are being used across various platforms. This leaves them…
-
LiteSpeed Cache Plugin Vulnerability Poses Significant Risk to WordPress Websites [email protected] (The Hacker News)
A high-severity security flaw has been disclosed in the LiteSpeed Cache plugin for WordPress that could allow an unauthenticated threat actor to elevate their privileges and perform malicious actions. The vulnerability, tracked as CVE-2024-50550 (CVSS score: 8.1), has been addressed in version 6.5.2 of the plugin. “The plugin suffers from an unauthenticated privilege escalation vulnerabilityRead…
-
North Korean Group Collaborates with Play Ransomware in Significant Cyber Attack [email protected] (The Hacker News)
Threat actors in North Korea have been implicated in a recent incident that deployed a known ransomware family called Play, underscoring their financial motivations. The activity, observed between May and September 2024, has been attributed to a threat actor tracked as Jumpy Pisces, which is also known as Andariel, APT45, DarkSeoul, Nickel Hyatt, Onyx Sleet…
-
Play ransomware attack tied to North Korean nation-state actor
Post ContentRead More
-
Opera Browser Fixes Big Security Hole That Could Have Exposed Your Information [email protected] (The Hacker News)
A now-patched security flaw in the Opera web browser could have enabled a malicious extension to gain unauthorized, full access to private APIs. The attack, codenamed CrossBarking, could have made it possible to conduct actions such as capturing screenshots, modifying browser settings, and account hijacking, Guardio Labs said. To demonstrate the issue, the company said…
-
Malvertising Campaign Hijacks Facebook Accounts to Spread SYS01stealer Malware [email protected] (The Hacker News)
Cybersecurity researchers have uncovered an ongoing malvertising campaign that abuses Meta’s advertising platform and hijacked Facebook accounts to distribute information known as SYS01stealer. “The hackers behind the campaign use trusted brands to expand their reach,” Bitdefender Labs said in a report shared with The Hacker News. “The malvertising campaign leverages nearly a hundred maliciousRead More
-
Top AI security certifications to consider
Post ContentRead More
-
Researchers Uncover Python Package Targeting Crypto Wallets with Malicious Code [email protected] (The Hacker News)
Cybersecurity researchers have discovered a new malicious Python package that masquerades as a cryptocurrency trading tool but harbors functionality designed to steal sensitive data and drain assets from victims’ crypto wallets. The package, named “CryptoAITools,” is said to have been distributed via both Python Package Index (PyPI) and bogus GitHub repositories. It was downloaded over…
-
Embarking on a Compliance Journey? Here’s How Intruder Can Help [email protected] (The Hacker News)
Navigating the complexities of compliance frameworks like ISO 27001, SOC 2, or GDPR can be daunting. Luckily, Intruder simplifies the process by helping you address the key vulnerability management criteria these frameworks demand, making your compliance journey much smoother. Read on to understand how to meet the requirements of each framework to keep your customer…