Cybersecurity

Regulatory activity forces compliance leaders to spend more on GRC tools – Help Net Security

Legal and compliance department investment in GRC (governance, risk, and compliance) tools will increase 50% by 2026, according to Gartner. Assurance leaders are seeking out technology solutions to help them address increasing regulatory attention on executive risk oversight and monitoring. “Recent actions ranging from the U.S. Securities and Exchange Commission (SEC) to the U.S. Department […]

Cybersecurity

Do You Really Trust Your Web Application Supply Chain?

Sep 20, 2023The Hacker NewsWeb Application Security Well, you shouldn’t. It may already be hiding vulnerabilities. It’s the modular nature of modern web applications that has made them so effective. They can call on dozens of third-party web components, JS frameworks, and open-source tools to deliver all the different functionalities that keep their customers happy, […]

Cybersecurity

Fresh Wave of Malicious npm Packages Threaten Kubernetes Configs and SSH Keys

Sep 20, 2023THNKubernetes / Supply Chain Attack Cybersecurity researchers have discovered a fresh batch of malicious packages in the npm package registry that are designed to exfiltrate Kubernetes configurations and SSH keys from compromised machines to a remote server. Sonatype said it has discovered 14 different npm packages so far: @am-fe/hooks, @am-fe/provider, @am-fe/request, @am-fe/utils, @am-fe/watermark, […]

Cybersecurity

Sophisticated Phishing Campaign Targeting Chinese Users with ValleyRAT and Gh0st RAT

Sep 20, 2023THNMalware Attack / Cyber Threat Chinese-language speakers have been increasingly targeted as part of multiple email phishing campaigns that aim to distribute various malware families such as Sainbox RAT, Purple Fox, and a new trojan called ValleyRAT. “Campaigns include Chinese-language lures and malware typically associated with Chinese cybercrime activity,” enterprise security firm Proofpoint […]

Cybersecurity

Araújo e Policastro Advogados Breach Claimed by 8BASE Ransomware Group

The 8BASE ransomware group has claimed Araújo e Policastro Advogados breach following a cyber attack on the organization. Known for its sophisticated cyber-attacks on large-scale organizations, 8BASE ransomware group announced the data breach on their dark web channel.  The threat actors have boldly announced their intention to publish the compromised data on September 25, 2023. […]

Cybersecurity

Signal Messenger Introduces PQXDH Quantum-Resistant Encryption

Sep 20, 2023THNEncryption / Privacy Encrypted messaging app Signal has announced an update to the Signal Protocol to add support for quantum resistance by upgrading the Extended Triple Diffie-Hellman (X3DH) specification to Post-Quantum Extended Diffie-Hellman (PQXDH). “With this upgrade, we are adding a layer of protection against the threat of a quantum computer being built […]

Cybersecurity

Critical business app outages cost $500,000 per hour of downtime – Help Net Security

Observability’s adoption is on the rise and full-stack observability leads to better service-level metrics, such as fewer, shorter outages and lower outage costs, according to New Relic. Respondents receive a median $2 return per $1 of investment in observability, with 41% receiving more than $1 million total annual value. According to the research, organizations are […]