CanesSpy Spyware Discovered in Modified WhatsApp Versions

November 4, 2023 Cybersecurity researchers have unearthed a number of WhatsApp mods for Android that come fitted with a spyware module dubbed CanesSpy. These modified versions of the instant messaging app have been observed propagated via sketchy websites advertising such software as well as Telegram channels used primarily by Arabic and Azerbaijani speakers, one of which …

CanesSpy Spyware Discovered in Modified WhatsApp Versions Read More »

48 Malicious npm Packages Found Deploying Reverse Shells on Developer Systems

November 4, 2023 A new set of 48 malicious npm packages have been discovered in the npm repository with capabilities to deploy a reverse shell on compromised systems. “These packages, deceptively named to appear legitimate, contained obfuscated JavaScript designed to initiate a reverse shell on package install,” software supply chain security firm Phylum said. All the …

48 Malicious npm Packages Found Deploying Reverse Shells on Developer Systems Read More »

Unveiling the Power of Nmap: Dive into Network Scanning Techniques

November 4, 2023 Welcome to our video on network scanning techniques using Nmap! Continue reading on Medium » Article posted by: https://medium.com/@pentesterclubpvtltd/unveiling-the-power-of-nmap-dive-into-network-scanning-techniques-0687fe32a93b?source=rss——cehv12-5 ——————————————————————————————————————– Infocerts, 5B 306 Riverside Greens, Panvel, Raigad 410206 Maharashtra, India Contact us – https://www.infocerts.com

SaaS Security is Now Accessible and Affordable to All

November 3, 2023 This new product offers SaaS discovery and risk assessment coupled with a free user access review in a unique “freemium” model Securing employees’ SaaS usage is becoming increasingly crucial for most cloud-based organizations. While numerous tools are available to address this need, they often employ different approaches and technologies, leading to unnecessary …

SaaS Security is Now Accessible and Affordable to All Read More »

Iran’s MuddyWater Targets Israel in New Spear-Phishing Cyber Campaign

November 3, 2023 The Iranian nation-state actor known as MuddyWater has been linked to a new spear-phishing campaign targeting two Israeli entities to ultimately deploy a legitimate remote administration tool from N-able called Advanced Monitoring Agent. Cybersecurity firm Deep Instinct, which disclosed details of the attacks, said the campaign “exhibits updated TTPs to previously reported MuddyWater activity,” Article posted by: …

Iran’s MuddyWater Targets Israel in New Spear-Phishing Cyber Campaign Read More »

Researchers Find 34 Windows Drivers Vulnerable to Full Device Takeover

November 3, 2023 As many as 34 unique vulnerable Windows Driver Model (WDM) and Windows Driver Frameworks (WDF) drivers could be exploited by non-privileged threat actors to gain full control of the devices and execute arbitrary code on the underlying systems. “By exploiting the drivers, an attacker without privilege may erase/alter firmware, and/or elevate [operating …

Researchers Find 34 Windows Drivers Vulnerable to Full Device Takeover Read More »

FIRST Announces CVSS 4.0 – New Vulnerability Scoring System

November 3, 2023 The Forum of Incident Response and Security Teams (FIRST) has officially announced CVSS v4.0, the next generation of the Common Vulnerability Scoring System standard, more than eight years after the release of CVSS v3.0 in June 2015. “This latest version of CVSS 4.0 seeks to provide the highest fidelity of vulnerability assessment for both industry …

FIRST Announces CVSS 4.0 – New Vulnerability Scoring System Read More »

HelloKitty Ransomware Group Exploiting Apache ActiveMQ Vulnerability

November 3, 2023 Cybersecurity researchers are warning of suspected exploitation of a recently disclosed critical security flaw in the Apache ActiveMQ open-source message broker service that could result in remote code execution. “In both instances, the adversary attempted to deploy ransomware binaries on target systems in an effort to ransom the victim organizations,” cybersecurity firm …

HelloKitty Ransomware Group Exploiting Apache ActiveMQ Vulnerability Read More »

5 New Cybersecurity Challenges Chief Security Officers (CSOs) Should Be Aware of in 2023 

If you’re a chief security officer (CSO), chief information security officer (CISO), or other cybersecurity leader, your job is never dull. Technology is constantly evolving, as are the threats to an organization’s data and intellectual property. No chief security officer can rest on their laurels because each year brings new challenges. And 2023 is shaping…

The post 5 New Cybersecurity Challenges Chief Security Officers (CSOs) Should Be Aware of in 2023  appeared first on Cybersecurity Exchange.

Open Whatsapp chat
Whatsapp Us
Chat with us for faster replies.