News:

Lab - Just Launched!

Main Menu

Recent posts

#81
IT News / U.S. Bans Kaspersky Software, ...
Last post by ixsky -
U.S. Bans Kaspersky Software, Citing National Security Risks

The U.S. Department of Commerce's Bureau of Industry and Security (BIS) on Thursday announced a "first of its kind" ban that prohibits Kaspersky Lab's U.S. subsidiary from directly or indirectly offering its security software in the country.
The blockade also extends to the cybersecurity company's affiliates, subsidiaries and parent companies, the department said, adding the action is based on

Source: U.S. Bans Kaspersky Software, Citing National Security Risks
#82
IT News / "Researchers" exploit Kraken e...
Last post by ixsky -
"Researchers" exploit Kraken exchange bug, steal $3 million in crypto

The Kraken crypto exchange disclosed today that alleged security researchers exploited a zero-day website bug to steal $3 million in cryptocurrency and then refused to return the funds. [...]

Source: "Researchers" exploit Kraken exchange bug, steal $3 million in crypto
#83
IT News / ONNX phishing service targets ...
Last post by ixsky -
ONNX phishing service targets Microsoft 365 accounts at financial firms

A new phishing-as-a-service (PhaaS) platform called ONNX Store is targeting Microsoft 365 accounts for employees at financial firms using QR codes in PDF attachments. [...]

Source: ONNX phishing service targets Microsoft 365 accounts at financial firms
#84
IT News / Researchers Uncover UEFI Vulne...
Last post by ixsky -
Researchers Uncover UEFI Vulnerability Affecting Multiple Intel CPUs

Cybersecurity researchers have disclosed details of a now-patched security flaw in Phoenix SecureCore UEFI firmware that affects multiple families of Intel Core desktop and mobile processors.
Tracked as CVE-2024-0762 (CVSS score: 7.5), the "UEFIcanhazbufferoverflow" vulnerability has been described as a case of a buffer overflow stemming from the use of an unsafe variable in the Trusted Platform

Source: Researchers Uncover UEFI Vulnerability Affecting Multiple Intel CPUs
#85
IT News / French Diplomatic Entities Tar...
Last post by ixsky -
French Diplomatic Entities Targeted in Russian-Linked Cyber Attacks

State-sponsored actors with ties to Russia have been linked to targeted cyber attacks aimed at French diplomatic entities, the country's information security agency ANSSI said in an advisory.
The attacks have been attributed to a cluster tracked by Microsoft under the name Midnight Blizzard (formerly Nobelium), which overlaps with activity tracked as APT29, BlueBravo, Cloaked Ursa, Cozy Bear,

Source: French Diplomatic Entities Targeted in Russian-Linked Cyber Attacks
#86
IT News / Infocon: green
Last post by ixsky -
Infocon: green

No Excuses, Free Tools to Help Secure Authentication in Ubuntu Linux [Guest Diary]

Source: Infocon: green
#87
IT News / Scathing report on Medibank cy...
Last post by ixsky -
Scathing report on Medibank cyberattack highlights unenforced MFA

A scathing report by Australia's Information Commissioner details how misconfigurations and missed alerts allowed a hacker to breach Medibank and steal data from over 9 million people. [...]

Source: Scathing report on Medibank cyberattack highlights unenforced MFA
#88
IT News / Tool Overload: Why MSPs Are St...
Last post by ixsky -
Tool Overload: Why MSPs Are Still Drowning with Countless Cybersecurity Tools in 2024

Highlights
Complex Tool Landscape: Explore the wide array of cybersecurity tools used by MSPs, highlighting the common challenge of managing multiple systems that may overlap in functionality but lack integration.Top Cybersecurity Challenges: Discuss the main challenges MSPs face, including integration issues, limited visibility across systems, and the high cost and complexity of maintaining

Source: Tool Overload: Why MSPs Are Still Drowning with Countless Cybersecurity Tools in 2024
#89
IT News / Chinese Cyber Espionage Target...
Last post by ixsky -
Chinese Cyber Espionage Targets Telecom Operators in Asia Since 2021

Cyber espionage groups associated with China have been linked to a long-running campaign that has infiltrated several telecom operators located in a single Asian country at least since 2021.
"The attackers placed backdoors on the networks of targeted companies and also attempted to steal credentials," the Symantec Threat Hunter Team, part of Broadcom, said in a report shared with The Hacker News

Source: Chinese Cyber Espionage Targets Telecom Operators in Asia Since 2021
#90
IT News / New Rust-based Fickle Malware ...
Last post by ixsky -
New Rust-based Fickle Malware Uses PowerShell for UAC Bypass and Data Exfiltration

A new Rust-based information stealer malware called Fickle Stealer has been observed being delivered via multiple attack chains with the goal of harvesting sensitive information from compromised hosts.
Fortinet FortiGuard Labs said it's aware of four different distribution methods -- namely VBA dropper, VBA downloader, link downloader, and executable downloader -- with some of them using a

Source: New Rust-based Fickle Malware Uses PowerShell for UAC Bypass and Data Exfiltration