4 Reasons Your SaaS Attack Surface Can No Longer be Ignored
What do identity risks, data security risks and third-party risks all have in common? They are all made much worse by SaaS sprawl. Every new…
What do identity risks, data security risks and third-party risks all have in common? They are all made much worse by SaaS sprawl. Every new…
Thank you for joining! Access your Pro+ Content below. 14 January 2025 Generating customer experience at NatWest Bank Share this item with your network: In…
Threat actors exploit Aviatrix Controller flaw to deploy backdoors and cryptocurrency miners Pierluigi Paganini January 14, 2025 A critical vulnerability in Aviatrix Controller is actively…
Cybersecurity researchers at EXPMON have uncovered an intriguing “zero-day behavior” in PDF samples that could potentially be exploited by attackers to leak sensitive NTLM authentication…
A widespread campaign targeting Fortinet FortiGate firewall devices with exposed management interfaces on the public internet. The attacks, observed by Arctic Wolf between November and…
Jan 14, 2025Ravie LakshmananVulnerability / Network Security Threat hunters are calling attention to a new campaign that has targeted Fortinet FortiGate firewall devices with management…
Debate is raging about whether the UK government’s push to grow the number of homegrown datacentres with capabilities to host compute-intensive artificial intelligence (AI) will…
A critical vulnerability in Google’s “Sign in with Google” authentication flow is putting millions of Americans at risk of data theft, particularly those who have…
A critical flaw in Google’s “Sign in with Google” authentication system has left millions of Americans vulnerable to potential data theft. This vulnerability mainly affects…
Jan 14, 2025Ravie LakshmananCryptocurrency / Online Scam The Telegram-based online marketplace known as HuiOne Guarantee and its vendors have cumulatively received at least $24 billion…
A new smishing (SMS phishing) campaign is making waves, specifically targeting iMessage users by manipulating Apple’s built-in phishing protections. Users have been reporting examples of…
A critical security breach in the software supply chain has been detected. An attacker accessed Kong’s DockerHub account and replaced the legitimate Kong Ingress Controller…