Every SaaS account created by your employees represents a new βidentityβ with unique permissions, security settings & risks and many app owners sit outside of IT, meaning security controls could be overlooked.
Learn how Nudge Security can help: https://thn.news/saas-identity-governance
Learn how Nudge Security can help: https://thn.news/saas-identity-governance
Nudgesecurity
Product Demo - Whose app is it anyway? How to regain control of SaaS identity governance
Learn how Nudge Security can help you manage SaaS identities and governance at scale.
π₯10π4π€2
β οΈ North Korea-linked Kimsuky hacking group has launched a new social engineering attack using fake Facebook accounts to target individuals via Messenger.
Learn more: https://thehackernews.com/2024/05/north-korean-hackers-exploit-facebook.html
Learn more: https://thehackernews.com/2024/05/north-korean-hackers-exploit-facebook.html
π₯15π9β‘3π€―2
At Georgetown, gain the tactical skills to plan for and respond to information security threats. Attend this June 7 webinar.
Save your seat: https://thn.news/georgetown-cybersec-webinar-li
Save your seat: https://thn.news/georgetown-cybersec-webinar-li
π11π5β‘3π€―3
π¨ New Wi-Fi #vulnerability discovered!
CVE-2023-52424, dubbed "SSID Confusion attack," affects all operating systems & Wi-Fi clients.
Learn how attackers can trick you into connecting to a less secure network & eavesdrop on your traffic.
https://thehackernews.com/2024/05/new-wi-fi-vulnerability-enabling.html
CVE-2023-52424, dubbed "SSID Confusion attack," affects all operating systems & Wi-Fi clients.
Learn how attackers can trick you into connecting to a less secure network & eavesdrop on your traffic.
https://thehackernews.com/2024/05/new-wi-fi-vulnerability-enabling.html
π20π±12π6π₯5β‘4π€3
π¨ Attention D-Link users - CISA warns of actively exploited vulnerabilities, CVE-2014-100005 and CVE-2021-40655, that attackers could exploit to change your router settings or steal your credentials.
Learn more: https://thehackernews.com/2024/05/cisa-warns-of-actively-exploited-d-link.html
Learn more: https://thehackernews.com/2024/05/cisa-warns-of-actively-exploited-d-link.html
π12π₯6β‘5π±2
β οΈ North Korean APT group Kimsuky deploys Linux version of GoBear backdoor, targeting South Korean organizations.
Learn more about the Gomir backdoor and its capabilities: https://thehackernews.com/2024/05/kimsuky-apt-deploying-linux-backdoor.html
Learn more about the Gomir backdoor and its capabilities: https://thehackernews.com/2024/05/kimsuky-apt-deploying-linux-backdoor.html
π₯15β‘6π4π4π€―1π±1
π¨ Alert: China-linked BlackTech group using advanced Deuterbear RAT in Asia-Pacific cyber espionage campaign.
Learn more about the improved capabilities and infection pathway of this evolving threat: https://thehackernews.com/2024/05/china-linked-hackers-adopt-two-stage.html#hacking #cybersecurity
Learn more about the improved capabilities and infection pathway of this evolving threat: https://thehackernews.com/2024/05/china-linked-hackers-adopt-two-stage.html#hacking #cybersecurity
π8π8β‘7π₯1π€―1
π Attention cybersecurity professionals!
A new report reveals that CVE-based vulnerabilities account for less than 1% of the average organization's on-prem exposure landscape.
It's time to shift our focus to the real threats.
Learn how: https://thehackernews.com/2024/05/new-xm-cyber-research-80-of-exposures.html
A new report reveals that CVE-based vulnerabilities account for less than 1% of the average organization's on-prem exposure landscape.
It's time to shift our focus to the real threats.
Learn how: https://thehackernews.com/2024/05/new-xm-cyber-research-80-of-exposures.html
π25π₯8π3β‘2
Kinsing cryptojacking hacker group continuously expanding its exploitation arsenal, which now includes various flaws in Apache ActiveMQ, Log4j, NiFi, Atlassian Confluence, Citrix, Linux, Openfire, WebLogic Server, and SaltStack.
Read: https://thehackernews.com/2024/05/kinsing-hacker-group-exploits-more.html
Read: https://thehackernews.com/2024/05/kinsing-hacker-group-exploits-more.html
π₯17π13π±5π3β‘1π€―1
β οΈ Grandoreiro banking trojan is back, targeting 1,500+ banks in 60+ countries. It now uses infected Outlook to spread phishing emails, with updated domain-generating algorithm and anti-malware evasion capability.
Learn more: https://thehackernews.com/2024/05/grandoreiro-banking-trojan-resurfaces.html
Learn more: https://thehackernews.com/2024/05/grandoreiro-banking-trojan-resurfaces.html
π₯16π12β‘3π€―3π1
π¨ Two Chinese nationals arrested for laundering $73 million in a massive pig butchering scam. The DoJ charges them with managing an international syndicate that tricked victims into crypto investment scams.
Learn more: https://thehackernews.com/2024/05/chinese-nationals-arrested-for.html
Learn more: https://thehackernews.com/2024/05/chinese-nationals-arrested-for.html
π23π10π₯6π3π€3β‘2
Researchers have observed a surge in email phishing campaigns delivering Latrodectus, a new malware loader believed to be the successor to IcedID.
Details here > https://thehackernews.com/2024/05/latrodectus-malware-loader-emerges-as.html
Details here > https://thehackernews.com/2024/05/latrodectus-malware-loader-emerges-as.html
π₯18π6β‘4
A multi-faceted campaign is targeting Android, macOS, and Windows users with various stealer malware and banking trojans.
Find out how they're using fake profiles and repositories to trick users into downloading malicious files.
Read: https://thehackernews.com/2024/05/cyber-criminals-exploit-github-and.html
Find out how they're using fake profiles and repositories to trick users into downloading malicious files.
Read: https://thehackernews.com/2024/05/cyber-criminals-exploit-github-and.html
π12π€―9β‘5π±3
π¨ New vulnerabilities emerge daily, forcing developers to refactor code & update dependencies.
With GitGuardian SCA, you can easily scan for CVEs locally & automatically before making a pull request.
Learn how you can create secure code effortlessly: https://thehackernews.com/2024/05/defending-your-commits-from-known-cves.html
With GitGuardian SCA, you can easily scan for CVEs locally & automatically before making a pull request.
Learn how you can create secure code effortlessly: https://thehackernews.com/2024/05/defending-your-commits-from-known-cves.html
π12π₯6β‘4
Foxit PDF Reader users, beware! A design flaw is being weaponized to deliver malware including Agent Tesla, AsyncRAT, DCRat, NanoCore RAT, NjRAT, Pony, Remcos RAT, and XWorm.
Learn more: https://thehackernews.com/2024/05/foxit-pdf-reader-flaw-exploited-by.html
Learn more: https://thehackernews.com/2024/05/foxit-pdf-reader-flaw-exploited-by.html
π22π€6π€―6β‘3π₯3
Void Manticore, an Iranian threat actor affiliated with the MOIS, has been identified as the culprit behind destructive wiping malware attacks targeting Albania and Israel.
Learn more about their tactics: https://thehackernews.com/2024/05/iranian-mois-linked-hackers-behind.html
Learn more about their tactics: https://thehackernews.com/2024/05/iranian-mois-linked-hackers-behind.html
π₯18π8π€5π3β‘2
π¨ Critical security vulnerability discovered in Fluent Bit, a widely used logging and metrics utility.
Nicknamed "Linguistic Lumberjack," it could lead to DoS, information disclosure, or even RCE attacks.
Learn more about CVE-2024-4323: https://thehackernews.com/2024/05/linguistic-lumberjack-vulnerability.html
Nicknamed "Linguistic Lumberjack," it could lead to DoS, information disclosure, or even RCE attacks.
Learn more about CVE-2024-4323: https://thehackernews.com/2024/05/linguistic-lumberjack-vulnerability.html
π12β‘6π₯4
π΅οΈββοΈ Unpatched Vulnerability Exploited!
CISA has added a critical security flaw (CVE-2023-43208) affecting NextGen Healthcare Mirth Connect to its Known Exploited Vulnerabilities catalog.
Learn more: https://thehackernews.com/2024/05/nextgen-healthcare-mirth-connect-under.html
Update to version 4.4.1 or later ASAP!
CISA has added a critical security flaw (CVE-2023-43208) affecting NextGen Healthcare Mirth Connect to its Known Exploited Vulnerabilities catalog.
Learn more: https://thehackernews.com/2024/05/nextgen-healthcare-mirth-connect-under.html
Update to version 4.4.1 or later ASAP!
π₯12π6π€―2
Microsoft has announced new security measures to strengthen Windows11, including deprecating NTLM in favor of Kerberos for authentication and AI-powered Smart App Control to block malware.
Details here > https://thehackernews.com/2024/05/windows-11-to-deprecate-ntlm-add-ai.html
Details here > https://thehackernews.com/2024/05/windows-11-to-deprecate-ntlm-add-ai.html
π15π₯8π6π€―5π€2
Researchers found security flaws in popular software packages: llama_cpp_python for AI models and PDF.js for the Firefox browser, allowing attackers to execute arbitrary code if exploited.
Details here > https://thehackernews.com/2024/05/researchers-uncover-flaws-in-python.html
Details here > https://thehackernews.com/2024/05/researchers-uncover-flaws-in-python.html
π₯18π6π5π€―4π±3
π SolarMarker malware evolves with a multi-tiered infrastructure, making it harder for law enforcement to take down and evade detection.
Learn about the latest tactics: https://thehackernews.com/2024/05/solarmarker-malware-evolves-to-resist.html
Learn about the latest tactics: https://thehackernews.com/2024/05/solarmarker-malware-evolves-to-resist.html
π₯17π5π€―1