Category: Uncategorized
-

Google Adds 24-Hour Wait for Unverified App Sideloading to Reduce Malware and Scams [email protected] (The Hacker News)
Google on Thursday announced a new “advanced flow” for Android sideloading that requires a mandatory 24-hour wait period to install apps from unverified developers in an attempt to balance openness with safety. The new changes come against the backdrop of a developer verification mandate the tech giant announced last year that requires all Android apps…
-

The Importance of Behavioral Analytics in AI-Enabled Cyber Attacks [email protected] (The Hacker News)
Artificial Intelligence (AI) is changing how individuals and organizations conduct many activities, including how cybercriminals carry out phishing attacks and iterate on malware. Now, cybercriminals are using AI to generate personalized phishing emails, deepfakes and malware that evade traditional detection by impersonating normal user activity and bypassing legacy security models. As a result,Read More
-

Magento PolyShell Flaw Enables Unauthenticated Uploads, RCE and Account Takeover [email protected] (The Hacker News)
Sansec is warning of a critical security flaw in Magento’s REST API that could allow unauthenticated attackers to upload arbitrary executables and achieve code execution and account takeover. The vulnerability has been codenamed PolyShell by Sansec owing to the fact that the attack hinges on disguising malicious code as an image. There is no evidence…
-
News brief: Stryker recovering after large-scale cyberattack
Check out the latest security news from the Informa TechTarget team.Read More
-

DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks [email protected] (The Hacker News)
The U.S. Department of Justice (DoJ) on Thursday announced the disruption of command-and-control (C2) infrastructure used by several Internet of Things (IoT) botnets like AISURU, Kimwolf, JackSkid, and Mossad as part of a court-authorized law enforcement operation. The effort also saw authorities from Canada and Germany targeting the operators behind these botnets, with a number…
-

Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks [email protected] (The Hacker News)
Apple is urging users who are still running an outdated version of iOS to update their iPhones to secure against web-based attacks carried out via powerful exploit kits like Coruna and DarkSword. These attacks employ malicious web content to target out-of-date versions of iOS, triggering an infection chain that leads to the theft of sensitive…
-
Handala Wiper Attack
What is the Attack? A large-scale cyberattack against medical technology company Stryker resulted in widespread system outages. The attack was driven by a destructive wiper campaign attributed to Iran-linked threat actors, including the hacktivist group Handala. Following the incident, CISA issued an alert highlighting the compromise of endpoint management infrastructure- specifically platforms such as Microsoft…
-

Speagle Malware Hijacks Cobra DocGuard to Steal Data via Compromised Servers [email protected] (The Hacker News)
Cybersecurity researchers have flagged a new malware dubbed Speagle that hijacks the functionality and infrastructure of a legitimate program called Cobra DocGuard. “Speagle is designed to surreptitiously harvest sensitive information from infected computers and transmit it to a Cobra DocGuard server that has been compromised by the attackers, masking the data exfiltration process as legitimateRead…
-
What AI zero days mean for enterprise cybersecurity
AI’s ability to find and exploit high-severity zero days at speed and scale presents both attackers and defenders with game-changing opportunity. Here’s what CISOs should know.Read More
-

54 EDR Killers Use BYOVD to Exploit 34 Signed Vulnerable Drivers and Disable Security [email protected] (The Hacker News)
A new analysis of endpoint detection and response (EDR) killers has revealed that 54 of them leverage a technique known as bring your own vulnerable driver (BYOVD) by abusing a total of 34 vulnerable drivers. EDR killer programs have been a common presence in ransomware intrusions as they offer a way for affiliates to neutralize…
