Category: Uncategorized
-

A New Way To Manage Your Web Exposure: The Reflectiz Product Explained [email protected] (The Hacker News)
An in-depth look into a proactive website security solution that continuously detects, prioritizes, and validates web threats, helping to mitigate security, privacy, and compliance risks. [Reflectiz shields websites from client-side attacks, supply chain risks, data breaches, privacy violations, and compliance issues] You Can’t Protect What You Can’t See Today’s websites are connectedRead More
-
BlackCat Ransomware Gang Suspected of Pulling Exit Scam Ionut Arghire
The BlackCat ransomware gang announces shutdown as an affiliate accuses theft of $22 million ransom payment. The post BlackCat Ransomware Gang Suspected of Pulling Exit Scam appeared first on SecurityWeek. Read More
-
CISA Warns of Pixel Phone Vulnerability Exploitation Eduard Kovacs
CISA adds Pixel Android phone (CVE-2023-21237) and Sunhillo SureLine (CVE-2021-36380) flaws to its known exploited vulnerabilities catalog. The post CISA Warns of Pixel Phone Vulnerability Exploitation appeared first on SecurityWeek. Read More
-

How to Find and Fix Risky Sharing in Google Drive [email protected] (The Hacker News)
Every Google Workspace administrator knows how quickly Google Drive becomes a messy sprawl of loosely shared confidential information. This isn’t anyone’s fault; it’s inevitable as your productivity suite is purposefully designed to enable real-time collaboration – both internally and externally. For Security & Risk Management teams, the untenable risk of any Google Drive footprintRead More
-
U.S. Cracks Down on Predatory Spyware Firm for Targeting Officials and Journalists [email protected] (The Hacker News)
The U.S. Department of Treasury’s Office of Foreign Assets Control (OFAC) sanctioned two individuals and five entities associated with the Intellexa Alliance for their role in “developing, operating, and distributing” commercial spyware designed to target government officials, journalists, and policy experts in the country. “The proliferation of commercial spyware poses distinct and growingRead More
-

VMware Issues Security Patches for ESXi, Workstation, and Fusion Flaws [email protected] (The Hacker News)
VMware has released patches to address four security flaws impacting ESXi, Workstation, and Fusion, including two critical flaws that could lead to code execution. Tracked as CVE-2024-22252 and CVE-2024-22253, the vulnerabilities have been described as use-after-free bugs in the XHCI USB controller. They carry a CVSS score of 9.3 for Workstation and Fusion, and 8.4 for…
-

Alert: GhostSec and Stormous Launch Joint Ransomware Attacks in Over 15 Countries [email protected] (The Hacker News)
The cybercrime group called GhostSec has been linked to a Golang variant of a ransomware family called GhostLocker. “TheGhostSec and Stormous ransomware groups are jointly conducting double extortion ransomware attacks on various business verticals in multiple countries,” Cisco Talos researcher Chetan Raghuprasad said in a report shared with The Hacker News. “GhostLocker andRead More
-

New APT Group ‘Lotus Bane’ Behind Recent Attacks on Vietnam’s Financial Entities [email protected] (The Hacker News)
A financial entity in Vietnam was the target of a previously undocumented threat actor called Lotus Bane that was first detected in March 2023. Singapore-headquartered Group-IB described the hacking outfit as an advanced persistent threat group that’s believed to have been active since at least 2022. The exact specifics of the infection chain remain unknown as yet,…
-

Urgent: Apple Issues Critical Updates for Actively Exploited Zero-Day Flaws [email protected] (The Hacker News)
Apple has released security updates to address several security flaws, including two vulnerabilities that it said have been actively exploited in the wild. The shortcomings are listed below – CVE-2024-23225 – A memory corruption issue in Kernel that an attacker with arbitrary kernel read and write capability can exploit to bypass kernel memory protections CVE-2024-23296 – A…
-
CrowdStrike to Acquire Flow Security SecurityWeek News
CrowdStrike says the acquisition of Flow Security will expand its cloud security capabilities with Data Security Posture Management. The post CrowdStrike to Acquire Flow Security appeared first on SecurityWeek. Read More
