The European Commission on Wednesday proposed new regulation that would require tech companies to scan for child sexual abuse material (CSAM) and grooming behavior, raising worries that it could undermine end-to-end encryption (E2EE).
To that end, online service providers, including hosting services and communication apps, are expected to proactively scan their platforms for CSAM as well as
https://thehackernews.com/2022/05/eu-proposes-new-rules-for-tech.html?utm_source=dlvr.it&utm_medium=blogger
Thursday, May 12, 2022
CISA Urges Organizations to Patch Actively Exploited F5 BIG-IP Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the recently disclosed F5 BIG-IP flaw to its Known Exploited Vulnerabilities Catalog following reports of active abuse in the wild.
The flaw, assigned the identifier CVE-2022-1388 (CVSS score: 9.8), concerns a critical bug in the BIG-IP iControl REST endpoint that provides an unauthenticated adversary with a method to
https://thehackernews.com/2022/05/cisa-urges-organizations-to-patch.html?utm_source=dlvr.it&utm_medium=blogger
https://thehackernews.com/2022/05/cisa-urges-organizations-to-patch.html?utm_source=dlvr.it&utm_medium=blogger
Hackers Deploy IceApple Exploitation Framework on Hacked MS Exchange Servers
Researchers have detailed a previously undocumented .NET-based post-exploitation framework called IceApple that has been deployed on Microsoft Exchange server instances to facilitate reconnaissance and data exfiltration.
"Suspected to be the work of a state-nexus adversary, IceApple remains under active development, with 18 modules observed in use across a number of enterprise environments, as
https://thehackernews.com/2022/05/hackers-deploy-iceapple-exploitation.html?utm_source=dlvr.it&utm_medium=blogger
https://thehackernews.com/2022/05/hackers-deploy-iceapple-exploitation.html?utm_source=dlvr.it&utm_medium=blogger
Bitter APT Hackers Add Bangladesh to Their List of Targets in South Asia
An espionage-focused threat actor known for targeting China, Pakistan, and Saudi Arabia has expanded to set its sights on Bangladeshi government organizations as part of an ongoing campaign that commenced in August 2021.
Cybersecurity firm Cisco Talos attributed the activity with moderate confidence to a hacking group dubbed the Bitter APT based on overlaps in the command-and-control (C2)
https://thehackernews.com/2022/05/bitter-apt-hackers-add-bangladesh-to.html?utm_source=dlvr.it&utm_medium=blogger
https://thehackernews.com/2022/05/bitter-apt-hackers-add-bangladesh-to.html?utm_source=dlvr.it&utm_medium=blogger
[White Paper] Social Engineering: What You Need to Know to Stay Resilient
Security and IT teams are losing sleep as would-be intruders lay siege to the weakest link in any organization's digital defense: employees. By preying on human emotion, social engineering scams inflict billions of dollars of damage with minimal planning or expertise. Cybercriminals find it easier to manipulate people before resorting to technical "hacking" tactics. Recent research reveals that
https://thehackernews.com/2022/05/white-paper-social-engineering-what-you.html?utm_source=dlvr.it&utm_medium=blogger
https://thehackernews.com/2022/05/white-paper-social-engineering-what-you.html?utm_source=dlvr.it&utm_medium=blogger
Wednesday, May 11, 2022
Critical Gems Takeover Bug Reported in RubyGems Package Manager
The maintainers of the RubyGems package manager have addressed a critical security flaw that could have been abused to remove gems and replace them with rogue versions under specific circumstances.
"Due to a bug in the yank action, it was possible for any RubyGems.org user to remove and replace certain gems even if that user was not authorized to do so," RubyGems said in a security advisory
https://thehackernews.com/2022/05/critical-gems-takeover-bug-reported-in.html?utm_source=dlvr.it&utm_medium=blogger
https://thehackernews.com/2022/05/critical-gems-takeover-bug-reported-in.html?utm_source=dlvr.it&utm_medium=blogger
U.S. Proposes $1 Million Fine on Colonial Pipeline for Safety Violations After Cyberattack
The U.S. Department of Transportation's Pipeline and Hazardous Materials Safety Administration (PHMSA) has proposed a penalty of nearly $1 million to Colonial Pipeline for violating federal safety regulations, worsening the impact of the ransomware attack last year.
The $986,400 penalty is the result of an inspection conducted by the regulator of the pipeline operator's control room management (
https://thehackernews.com/2022/05/us-proposes-1-million-fine-on-colonial.html?utm_source=dlvr.it&utm_medium=blogger
https://thehackernews.com/2022/05/us-proposes-1-million-fine-on-colonial.html?utm_source=dlvr.it&utm_medium=blogger
5 Benefits of Detection-as-Code
TL;DR:
Adopt a modern, test-driven methodology for securing your organization with Detection-as-Code.
Over the past decade, threat detection has become business-critical and even more complicated. As businesses move to the cloud, manual threat detection processes are no longer able to keep up. How can teams automate security analysis at scale and address the challenges that threaten business
https://thehackernews.com/2022/05/5-benefits-of-detection-as-code.html?utm_source=dlvr.it&utm_medium=blogger
https://thehackernews.com/2022/05/5-benefits-of-detection-as-code.html?utm_source=dlvr.it&utm_medium=blogger
Experts Detail Saintstealer and Prynt Stealer Info-Stealing Malware Families
Cybersecurity researchers have dissected the inner workings of an information-stealing malware called Saintstealer that's designed to siphon credentials and system information.
"After execution, the stealer extracts username, passwords, credit card details, etc.," Cyble researchers said in an analysis last week. "The stealer also steals data from various locations across the system and
https://thehackernews.com/2022/05/experts-detail-saintstealer-and-prynt.html?utm_source=dlvr.it&utm_medium=blogger
https://thehackernews.com/2022/05/experts-detail-saintstealer-and-prynt.html?utm_source=dlvr.it&utm_medium=blogger
Another Set of Joker Trojan-Laced Android Apps Resurfaces on Google Play Store
A new set of trojanized apps spread via the Google Play Store has been observed distributing the notorious Joker malware on compromised Android devices.
Joker, a repeat offender, refers to a class of harmful apps that are used for billing and SMS fraud, while also performing a number of actions of a malicious hacker's choice, such as stealing text messages, contact lists, and device information.
https://thehackernews.com/2022/05/another-set-of-joker-trojan-laced.html?utm_source=dlvr.it&utm_medium=blogger
https://thehackernews.com/2022/05/another-set-of-joker-trojan-laced.html?utm_source=dlvr.it&utm_medium=blogger
Subscribe to:
Posts (Atom)

.jpg)







