DTCC cuts breach risks by 11% with Automated Security Validation. Using Pentera, they boosted security, reduced costs, and freed up expert resourcesβwithout adding staff.
Is your team ahead, or falling behind? π€
Read how DTCC is leading the way: https://thehackernews.com/2024/11/the-roi-of-security-investments-how.html
Is your team ahead, or falling behind? π€
Read how DTCC is leading the way: https://thehackernews.com/2024/11/the-roi-of-security-investments-how.html
β‘5π4
π¨ SEO poisoning attack alert! GootLoader malware spreads by exploiting searches like "Are Bengal Cats legal in Australia?"
Read more: https://thehackernews.com/2024/11/new-gootloader-campaign-targets-users.html
Read more: https://thehackernews.com/2024/11/new-gootloader-campaign-targets-users.html
π₯7π5π3
π Imagine your banking app or car's software secretly turning on you...
This isn't a movie plotβit's the world of cyber in 2024. Dive into this weekβs wildest cyber threats and top defense tips in our latest weekly recap.
Read it here: https://thehackernews.com/2024/11/thn-recap-top-cybersecurity-threats_11.html
This isn't a movie plotβit's the world of cyber in 2024. Dive into this weekβs wildest cyber threats and top defense tips in our latest weekly recap.
Read it here: https://thehackernews.com/2024/11/thn-recap-top-cybersecurity-threats_11.html
π16π₯4π4
A new ransomware, Ymir, uses advanced memory management tactics to execute malicious code stealthily.
It targeted a Colombian organization after credentials were stolen by RustyStealer.
Read: https://thehackernews.com/2024/11/new-ymir-ransomware-exploits-memory-for.html
It targeted a Colombian organization after credentials were stolen by RustyStealer.
Read: https://thehackernews.com/2024/11/new-ymir-ransomware-exploits-memory-for.html
π12π€5π₯4π2
π‘οΈ North Korean hackers are using Flutter apps to target macOS with malware, bypassing traditional Apple security through signed developer IDs. Cryptocurrency companies are at risk.
Learn more: https://thehackernews.com/2024/11/north-korean-hackers-target-macos-using.html
Learn more: https://thehackernews.com/2024/11/north-korean-hackers-target-macos-using.html
π14π€―8π₯3π1
π Revolutionizing SOCs: Behavioral Analytics is BackβBetter than Ever!
Discover how behavioral analytics is transforming SOC incident response, improving speed and accuracy, and reducing resource costs.
Read: https://thehackernews.com/2024/11/5-ways-behavioral-analytics-is.html
Discover how behavioral analytics is transforming SOC incident response, improving speed and accuracy, and reducing resource costs.
Read: https://thehackernews.com/2024/11/5-ways-behavioral-analytics-is.html
π₯8π2π€2
π¨ Cybercriminals have a new weapon: GoIssue, a tool that targets #GitHub developers with bulk phishing emails.
This method can steal credentials and compromise repositories. With prices slashed, attacks are now more scalable.
Read: https://thehackernews.com/2024/11/new-phishing-tool-goissue-targets.html
This method can steal credentials and compromise repositories. With prices slashed, attacks are now more scalable.
Read: https://thehackernews.com/2024/11/new-phishing-tool-goissue-targets.html
π6π₯5π2π±1
Researchers have identified a #vulnerability in Citrix Virtual Apps that allows unauthenticated RCE through improper deserialization.
Read more: https://thehackernews.com/2024/11/new-flaws-in-citrix-virtual-apps-enable.html
Patches are available, but many organizations may still be exposed if not updated.
Read more: https://thehackernews.com/2024/11/new-flaws-in-citrix-virtual-apps-enable.html
Patches are available, but many organizations may still be exposed if not updated.
π₯14π1
Protect your organization with a Georgetown Master's in Cybersecurity Risk Management. Attend a sample class on November 19.
https://thn.news/cyber-risk-sample-class-ig
https://thn.news/cyber-risk-sample-class-ig
π12π₯5β‘3π€3π€―3π2π1π±1
π¨ Microsoft warns of actively exploited flaws in NTLM (CVE-2024-43451) & Task Scheduler (CVE-2024-49039), allowing NTLMv2 hash disclosure and privilege escalation to restricted RPC functions.
Find details on the November Patch Tuesday update: https://thehackernews.com/2024/11/microsoft-fixes-90-new-vulnerabilities.html
Find details on the November Patch Tuesday update: https://thehackernews.com/2024/11/microsoft-fixes-90-new-vulnerabilities.html
π₯14π5π5
The βDream Jobβ campaign isnβt just a scamβitβs a sophisticated cyberattack.
Iranian hacker group TA455 mimics North Korean tactics, using fake job offers to deploy malware in the aerospace sector.
Learn more: https://thehackernews.com/2024/11/iranian-hackers-use-dream-job-lures-to.html
Iranian hacker group TA455 mimics North Korean tactics, using fake job offers to deploy malware in the aerospace sector.
Learn more: https://thehackernews.com/2024/11/iranian-hackers-use-dream-job-lures-to.html
π11π10π₯6
π¨ OvrC cloud platformβs critical security flaws (CVE up to 9.2) allow attackers to bypass firewalls, hijack devices, and execute arbitrary code on IoT systems, threatening critical infrastructure.
Learn more: https://thehackernews.com/2024/11/ovrc-platform-vulnerabilities-expose.html
Learn more: https://thehackernews.com/2024/11/ovrc-platform-vulnerabilities-expose.html
π11β‘3π3π3
Bitdefender has released a free decryptor for ShrinkLocker, a #ransomware that uses BitLocker to lock files, and can compromise entire networks in under 10 minutes.
Read: https://thehackernews.com/2024/11/free-decryptor-released-for-bitlocker.html
Read: https://thehackernews.com/2024/11/free-decryptor-released-for-bitlocker.html
π14β‘4π3π€―3
π¨ 90% of network traffic flows through browsers. This makes them a prime target for cybercriminals. Phishing, data leakage & credential theft are increasing threats.
Check out LayerXβs guide for CISOs on protecting your teams and data.
Read: https://thehackernews.com/2024/11/comprehensive-guide-to-building-strong.html
Check out LayerXβs guide for CISOs on protecting your teams and data.
Read: https://thehackernews.com/2024/11/comprehensive-guide-to-building-strong.html
π13β‘5π1
On November 19, GigaOm Analyst, Paul Stringfellow and Sentra's Director of Product Marketing, David S., will share the latest insights from Gigaomβs recent DSPM report.
This session will spotlight critical factors in choosing a DSPM provider and reveal why DSPM is emerging as a distinct and essential component of modern data security.
Donβt miss this opportunity to learn directly from the experts!
Reserve your spot here π https://thn.news/dspm-webinar
This session will spotlight critical factors in choosing a DSPM provider and reveal why DSPM is emerging as a distinct and essential component of modern data security.
Donβt miss this opportunity to learn directly from the experts!
Reserve your spot here π https://thn.news/dspm-webinar
www.sentra.io
Webinar: Securing Data Everywhere and Always with DSPM
How Data Security Posture Management (DSPM) is - finally- giving organizations a way to automatically discover, classify, and secure all their data.
π13β‘2π€2π€―2π1
A threat group aligned with Hamas has expanded its cyber warfare beyond espionage, deploying new disruptive wipers and phishing campaigns targeting Israel.
Learn more: https://thehackernews.com/2024/11/hamas-affiliated-wirte-employs-samecoin.html
Learn more: https://thehackernews.com/2024/11/hamas-affiliated-wirte-employs-samecoin.html
π26π€―5π€4β‘3π3π₯1
π Internal vs. External PenTesting: What IT Pros Need to Know!
Cyber threats are up 180% β is your network ready? Regular network pentesting is more important than ever, but do you know the difference between internal vs external pentesting? π€
β’ Internal: Tests from the inside, catching insider threats.
β’ External: Protects your public-facing assets from outside attacks.
Finding weaknesses first = saving $$$, staying compliant, and peace of mind. And with vPenTest, network pen testing is easier and more affordable than ever!
π Read more: https://thn.news/network-penetration-testing
Cyber threats are up 180% β is your network ready? Regular network pentesting is more important than ever, but do you know the difference between internal vs external pentesting? π€
β’ Internal: Tests from the inside, catching insider threats.
β’ External: Protects your public-facing assets from outside attacks.
Finding weaknesses first = saving $$$, staying compliant, and peace of mind. And with vPenTest, network pen testing is easier and more affordable than ever!
π Read more: https://thn.news/network-penetration-testing
Vonahi Security's Blog
Internal vs. External Network Penetration Testing: What IT Professionals Need to Know
Stay secure with regular network penetration testing. Learn about internal vs. external tests and how vPenTest makes frequent testing easy and affordable.
π8π7β‘5π₯2π2π€1
Exploit alert: Russia-linked threat actors have actively exploited the CVE-2024-43451 #vulnerability to deploy Spark RAT, with the potential for significant damage through credential theft.
Read: https://thehackernews.com/2024/11/russian-hackers-exploit-new-ntlm-flaw.html
Read: https://thehackernews.com/2024/11/russian-hackers-exploit-new-ntlm-flaw.html
π12π₯6π3β‘2
π North Korean hackers are back with a new malware campaign targeting macOS. "RustyAttr" leverages extended file attributes to stealthily deliver malicious payloads.
Learn more: https://thehackernews.com/2024/11/new-rustyattr-malware-targets-macos.html
Learn more: https://thehackernews.com/2024/11/new-rustyattr-malware-targets-macos.html
π19β‘4π2π€2π1
A misconfigured TikTok pixel nearly caused a costly GDPR violation for a global travel company, showing how simple oversights can lead to significant fines and reputational damage.
Learn more: https://thehackernews.com/2024/11/tiktok-pixel-privacy-nightmare-new-case.html
Learn more: https://thehackernews.com/2024/11/tiktok-pixel-privacy-nightmare-new-case.html
π7β‘2π2π€2π±1