What secure coding practices mean to modern cyber security
06
Nov
2023

IR plans: The difference between disaster and recovery

The inevitability of an organisation being hit by a cyber attack has shot up in recent years, illustrated with frequent…

06
Nov
2023

Okta breach post mortem reveals weaknesses exploited by attackers

The recent breach of the Okta Support system was carried out via a compromised service account with permissions to view…

Testing with OpenAPI Specifications
06
Nov
2023

Testing with OpenAPI Specifications

The 2023 SANS Survey on API Security (Jun-2023) found that less than 50 percent of respondents have API security testing…

Looney Tunables vulnerability exploited
06
Nov
2023

‘Looney Tunables’ Glibc Vulnerability Exploited in Cloud Attacks 

A serious privilege escalation vulnerability patched recently in the GNU C Library (glibc) has been exploited in cloud attacks by…

Who’s Behind the SWAT USA Reshipping Service? – Krebs on Security
06
Nov
2023

Who’s Behind the SWAT USA Reshipping Service? – Krebs on Security

Last week, KrebsOnSecurity broke the news that one of the largest cybercrime services for laundering stolen merchandise was hacked recently,…

Scammers Use Fake Ledger App on Microsoft Store to Steal $800,000 in Crypto
06
Nov
2023

Fake Ledger App on Microsoft Store Leads to $800,000 Crypto Theft

The fake Ledger Live app on the Microsoft Store deceived users into downloading malware, which stole their Bitcoin and Ethereum…

Clop begins naming alleged MOVEit victims
06
Nov
2023

Shadow IT use at Okta behind series of damaging breaches

An Okta employee who signed into their personal Google account on a company-owned device appears to have been the source…

Canadian Psychological Association Cyberattack
06
Nov
2023

Medusa Claims Canadian Psychological Association Cyberattack

The Canadian Psychological Association (CPA), the primary representative body for psychologists across Canada, has allegedly fallen victim to a cyberattack…

Patch Tuesday: Critical Flaws in Adobe Commerce Software
06
Nov
2023

US Sanctions Russian National for Helping Ransomware Groups Launder Money

The US Department of the Treasury’s Office of Foreign Assets Control (OFAC) on Friday announced sanctions against Ekaterina Zhdanova, a…

QNAP
06
Nov
2023

QNAP warns of critical command injection flaws in QTS OS, apps

QNAP Systems published security advisories for two critical command injection vulnerabilities that impact multiple versions of the QTS operating system…

Patch Tuesday: Critical Flaws in Adobe Commerce Software
06
Nov
2023

Iranian APT Targets Israeli Education, Tech Sectors With New Wipers

Since January 2023, an Iranian advanced persistent threat (APT) actor has been targeting higher education and technology organizations in Israel…

Attackers use Google Calendar RAT to abuse Calendar service as C2 infrastructure
06
Nov
2023

Attackers use Google Calendar RAT to abuse Calendar service as C2 infrastructure

Attackers use Google Calendar RAT to abuse Calendar service as C2 infrastructure Pierluigi Paganini November 06, 2023 Google warns of multiple…