News
  • "Complex M&A Deals Pave Way for Security Gaps"

    IronNet researchers discovered a likely China-based threat actor that had infiltrated a US software company using legacy infrastructure from a previous company acquisition. Before deploying the Shack2 and China Chopper web shells, the threat actor used…

  • "Over 1,500 Apps Found Leaking API Keys and Potentially Exposing User Data"

    More than 1,500 apps have been discovered to be leaking the Algolia Application Programming Interface (API) key and application ID, potentially exposing user data. Researchers at CloudSEK discovered 32 applications with hard-coded critical admin secrets…

  • "Leaked Algolia API Keys Exposed Data of Millions of Users"

    Security researchers at CloudSEK have recently identified thousands of applications leaking Algolia API keys and tens of applications with hardcoded admin secrets, which could allow attackers to steal the data of millions of users.  The researchers…

  • "BMC Firmware Vulnerabilities Expose OT, IoT Devices to Remote Attacks"

    Security researchers at Nozomi Networks have discovered more than a dozen vulnerabilities in baseboard management controller (BMC) firmware.  BMC is a specialized processor that allows administrators to remotely control and monitor a device without…

  • "Cyberattacks Cost Enterprises $1,200 per Employee per Year"

    Every year, organizations pay $1,197 per employee to address successful cyber incidents involving email services, cloud collaboration apps or services, and web browsers. According to a new Osterman Research survey for Perception Point, a 500-employee…

  • "DOJ Shuts Down 'Pig Butchering' Domains Responsible for $10 Million in Victim Losses"

    The Department of Justice (DOJ) announced the seizure of seven domain names used in "pig butchering" schemes, in which cybercriminals develop relationships with victims before exploiting them. According to the US Attorney's Office for the Eastern…

  • "Cybersecurity Speaker Series: 5G Security Impacts National Security"

    The National Security Agency's (NSA) Cybersecurity Collaboration Center has released a video as part of its Cybersecurity Speaker Series on how 5G security relates to national security. Through the Speaker Series, NSA shares insights, lessons, and…

  • "FBI Arrests Two Estonian Men in $575M Crypto Fraud, Money Laundering Scheme"

    The FBI and Estonian police recently arrested two Estonian citizens for their alleged involvement in a $575 million cryptocurrency fraud scheme.  Sergei Potapenko and Ivan Turõgin, both 37, are charged with conspiracy to commit wire fraud, 16 counts…

  • "Emotet Is Back and Delivers Payloads Like IcedID and Bumblebee"

    Proofpoint researchers have warned of the return of the Emotet malware, observing a high-volume malspam campaign delivering payloads such as IcedID and Bumblebee in early November. The Emotet banking Trojan has been around since at least 2014, and the…

  • "DUCKTAIL Attacks Costing Victims Hundreds of Thousands of Dollars"

    According to a new analysis, DUCKTAIL, a Vietnam-based cybercrime operation discovered by WithSecure earlier this year, has continued to evolve its operations. DUCKTAIL has been using LinkedIn to target individuals and organizations using Facebook's Ads…

  • "CISA Seeks Information for Potential Cyber Threat Intelligence Platform"

    On behalf of the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency (CISA), the General Services Administration (GSA) requested information on the availability of Threat Intelligence Enterprise Services (TIES) to the…

  • "Microsoft Warns of Rise in Stolen Cloud Tokens Used to Bypass MFA"

    Threat actors are stealing authentication tokens that have already been verified by multi-factor authentication (MFA) in order to compromise organizations' systems. According to a new alert from Microsoft's Detection and Response Team (DART), token theft…