Cybersecurity

Vulnerability Exploitation on the Rise as Attackers Ditch Phishing

In a move away from traditional phishing scams, attackers are increasingly exploiting vulnerabilities in computer systems to gain initial network access, according to Mandiant’s M-Trends 2024 Report. In 2023, attackers gained initial access through exploiting vulnerabilities in 38% of intrusions, a 6% increase from the previous year. Mandiant also found phishing’s prevalence declined from 22% […]

Cybersecurity

CISA to issue list of software products critical to agency security by end of September

The Cybersecurity and Infrastructure Security Agency is targeting a Sept. 30 deadline to give federal agencies a list of example software products deemed critical for the federal government’s cyber posture. The target date comes from the agency’s responses to a Thursday Government Accountability Office oversight report that examines implementation of a major 2021 cybersecurity executive […]

Cybersecurity

GuptiMiner: Hijacking Antivirus Updates for Distributing Backdoors and Casual Mining – Avast Threat Labs

Key Points Avast discovered and analyzed a malware campaign hijacking an eScan antivirus update mechanism to distribute backdoors and coinminers Avast disclosed the vulnerability to both eScan antivirus and India CERT. On 2023-07-31, eScan confirmed that the issue was fixed and successfully resolved The campaign was orchestrated by a threat actor with possible ties to […]

DJing

Peter Doherty’s Strap Originals label celebrates fifth birthday with Manchester and London shows | Juno Daily

Juno Daily favourites PREGOBLIN and more to play Strap Originals shows Peter Doherty is hosting three special celebratory nights in Manchester and London in May to mark his Strap Originals label’s fifth anniversary. Each night will feature Strap Originals artists live in concert on all three nights and Doherty will do a Q&A with a journalist about his life, his music […]

Cybersecurity

Apache Cordova App Harness Targeted in Dependency Confusion Attack

Apr 23, 2024NewsroomSupply Chain Attack / Application Security Researchers have identified a dependency confusion vulnerability impacting an archived Apache project called Cordova App Harness. Dependency confusion attacks take place owing to the fact that package managers check the public repositories before private registries, thus allowing a threat actor to publish a malicious package with the […]