Cybersecurity

Pegasus Spyware Targeted iPhones of Journalists and Activists in Jordan

Feb 05, 2024NewsroomSpyware / Surveillance The iPhones belonging to nearly three dozen journalists, activists, human rights lawyers, and civil society members in Jordan have been targeted with NSO Group’s Pegasus spyware, according to joint findings from Access Now and the Citizen Lab. Nine of the 35 individuals have been publicly confirmed as targeted, out of […]

Cybersecurity

QNAP Patches High-Severity Flaws in QTS, Video Station, QuMagie, Netatalk Products

Taiwan-based QNAP Systems on Friday announced patches for a dozen vulnerabilities across its product portfolio, including high-severity flaws in its operating system. The first of the high-severity issues is CVE-2023-39296, which is described as a prototype pollution flaw that could allow remote attackers “to override existing attributes with ones that have an incompatible type, which […]

Cybersecurity

Over 3 Dozen Data-Stealing Malicious npm Packages Found Targeting Developers

Oct 03, 2023THNSoftware Security / Hacking Nearly three dozen counterfeit packages have been discovered in the npm package repository that are designed to exfiltrate sensitive data from developer systems, according to findings from Fortinet FortiGuard Labs. One set of packages – named @expue/webpack, @expue/core, @expue/vue3-renderer, @fixedwidthtable/fixedwidthtable, and @virtualsearchtable/virtualsearchtable – harbored an obfuscated JavaScript file that’s […]

Cybersecurity

Balancing budget and system security: Approaches to risk tolerance – Help Net Security

Data breaches are a dime a dozen. Although it’s easy to look at that statement negatively, the positive viewpoint is that, as a result, cybersecurity professionals have plenty of learning moments. Learning what went wrong and why can be a good sanity check for organizations that want to revisit their security readiness and up-level their […]