Category: Uncategorized
-

Signal Debunks Zero-Day Vulnerability Reports, Finds No Evidence [email protected] (The Hacker News)
Encrypted messaging app Signal has pushed back against “viral reports” of an alleged zero-day flaw in its software, stating it found no evidence to support the claim. “After responsible investigation *we have no evidence that suggests this vulnerability is real* nor has any additional info been shared via our official reporting channels,” it said in a series…
-

Binance’s Smart Chain Exploited in New ‘EtherHiding’ Malware Campaign [email protected] (The Hacker News)
Threat actors have been observed serving malicious code by utilizing Binance’s Smart Chain (BSC) contracts in what has been described as the “next level of bulletproof hosting.” The campaign, detected two months ago, has been codenamed EtherHiding by Guardio Labs. The novel twist marks the latest iteration in an ongoing campaign that leverages compromised WordPress sites to serve unsuspectingRead…
-

Microsoft to Phase Out NTLM in Favor of Kerberos for Stronger Authentication [email protected] (The Hacker News)
Microsoft has announced that it plans to eliminate NT LAN Manager (NTLM) in Windows 11 in the future, as it pivots to alternative methods for authentication and bolster security. “The focus is on strengthening the Kerberos authentication protocol, which has been the default since 2000, and reducing reliance on NT LAN Manager (NTLM),” the tech giant said.…
-
Ransomware gang targets critical Progress WS_FTP Server bug
Post ContentRead More
-

New PEAPOD Cyberattack Campaign Targeting Women Political Leaders [email protected] (The Hacker News)
European Union military personnel and political leaders working on gender equality initiatives have emerged as the target of a new campaign that delivers an updated version of RomCom RAT called PEAPOD. Cybersecurity firm Trend Micro attributed the attacks to a threat actor it tracks under the name Void Rabisu, which is also known as Storm-0978, Tropical Scorpius,…
-
CISA Now Flagging Vulnerabilities, Misconfigurations Exploited by Ransomware Ionut Arghire
CISA is now flagging vulnerabilities and misconfigurations that are known to be exploited in ransomware attacks. The post CISA Now Flagging Vulnerabilities, Misconfigurations Exploited by Ransomware appeared first on SecurityWeek. Read More
-
Juniper Networks Patches Over 30 Vulnerabilities in Junos OS Ionut Arghire
Juniper Networks patches over 30 vulnerabilities in Junos OS and Junos OS Evolved, including nine high-severity bugs. The post Juniper Networks Patches Over 30 Vulnerabilities in Junos OS appeared first on SecurityWeek. Read More
-
In Other News: Ex-Uber Security Chief Appeal, New Offerings From Tech Giants, Crypto Bounty SecurityWeek News
In Other The post In Other News: Ex-Uber Security Chief Appeal, New Offerings From Tech Giants, Crypto Bounty appeared first on SecurityWeek. Read More
-
Why fourth-party risk management is a must-have
Post ContentRead More
-

Researchers Unveil ToddyCat’s New Set of Tools for Data Exfiltration [email protected] (The Hacker News)
The advanced persistent threat (APT) actor known as ToddyCat has been linked to a new set of malicious tools that are designed for data exfiltration, offering a deeper insight into the hacking crew’s tactics and capabilities. The findings come from Kaspersky, which first shed light on the adversary last year, linking it to attacks against high-profile entities in Europe and Asia…
