-
"UNICC and Group-IB Take Down 134 Fake Websites Impersonating WHO"Group-IB and the United Nations International Computing Centre (UNICC) took down a massive spam campaign involving 134 fraudulent websites. The fake websites were discovered impersonating the World Health Organization (WHO) on World Health Day,…
-
"Misconfigs and Unpatched Bugs Top Cloud Native Security Incidents"Researchers from Snyk conducted a new survey and discovered that over half of organizations had suffered a security incident due to misconfiguration or a known vulnerability in their cloud native applications. The adoption of cloud native…
-
"Panda Stealer Targets Crypto Wallets"A new information stealer called Panda Stealer is going after cryptocurrency wallets and credentials for applications including NordVPN, Telegram, Discord, and Steam. Panda Stealer uses spam emails and the same hard-to-detect fileless distribution…
-
"PHP Composer Flaw That Could Affect Millions of Sites Patched"A patch has been released for a critical vulnerability in PHP Composer, a tool used for the management and installment of software dependencies in the PHP ecosystem. According to the security researchers at SonarSource, who discovered the flaw, it could…
-
-
"Zero-Knowledge Proofs in Vulnerability Disclosure"Cybersecurity researchers and software security analysts face several challenges in the disclosure process for software vulnerabilities. They are faced with an ethics versus efficacy dilemma in the realm of security bug reporting and sharing. Publicly…
-
"New Protocol Makes Bitcoin Transactions More Secure and Faster Than Lightning"In collaboration with researchers at the IMDEA Software Institute and the Purdue University, the security and privacy research unit at TU Wien analyzed problems associated with Bitcoin transactions such as possible fraud, users' discovery of each other's…
-
"Algorithms Improve How We Protect Our Data"Scientists at the Daegu Gyeongbuk Institute of Science and Technology (DGIST) in Korea have developed algorithms to more efficiently measure how difficult it would be for an attacker to guess cryptographic systems' secret keys. Their approach could make…
-
"Pulse Secure Patches Critical Zero-Day Flaw"Pulse Secure has patched a critical zero-day vulnerability that multiple APT groups were exploiting to target US defense companies, among other entities. The new security update fixes CVE-2021-22893, a critical authentication bypass vulnerability…
-
"Third Parties Caused Data Breaches at 51% of Organizations"Researchers from Ponemon Institute and third-party remote access provider SecureLink conducted a new study and published their findings in a report titled “A Crisis in Third-party Remote Access Security." The researchers stated that organizations expose…
-
"Computer Scientists Discover New Vulnerability Affecting Computers Globally"Since the discovery of the original Spectre vulnerability, computer scientists from industry and academia have developed software patches and hardware defenses to protect the most vulnerable points in the speculative execution process without sacrificing…
-
"Researchers Find Bugs Using Single-Codebase Inconsistencies"A research team at Northeastern University finds code defects and some vulnerabilities by detecting inconsistent programming in which programmers use different code snippets to implement the same functions. The researchers used Machine Learning (ML) to…
News