Tag: security

That Google Meet invite could be a fake, hiding some dangerous malware

Hackers are targeting victims with fake broken Google Meet calls in an attempt to infect them with malware and thus grab their sensitive information, experts have warned. A report from cybersecurity researchers Sekoia claim the campaign is a new variant of the previously-observed ClickFix attack. ClickFix victims are shown a…

Read More

Google says it has made big steps in improving memory safety

In a recently published blog post, Google explained how it makes its software less susceptible to flaws and vulnerabilities, and thus less interesting to cybercriminals. Its approach includes two key pillars: hardening super-popular, yet unsafe, programming languages, while slowly (but surely) transitioning towards up-and-coming, memory-safe languages. Earlier this week, Alex…

Read More

CISA issues advisory on Iranian brokers selling access to critical infrastructure

Iranian hackers are acting as Initial Access Brokers (IAB), selling access to critical infrastructure organizations in the West to the highest bidder. A joint security advisory recently published by the US Cybersecurity and Infrastructure Agency (CISA), together with the FBI, NSA, the Communications Security Establishment Canada (CSE), the Australian Federal…

Read More

Hundreds of thousands of CVs leaked – here’s what we know

A Singaporean remote hiring platform left a large database unprotected on the internet, accessible to anyone who knew where to look. Since the database contained plenty of sensitive information, the company has inadvertently placed hundreds of thousands of people at risk of data theft, identity theft, phishing, fraud, and more.…

Read More

Firm hacked after accidentally hiring North Korean cyber criminal

A company was hacked after hiring a fake IT professional from North Korea. It has not been clarified whether this was a deliberate cyberattack against the organization, a disgruntled former employee, or a “simple” scam. The company, which was not named, operates either in the US, UK, or Australia. It…

Read More

Critical severity flaw warning issued by CISA for SolarWinds Web Help Desk

A critical vulnerability in a SolarWinds product is being abused in the wild, and now US government agencies have a deadline to patch it or lose it. The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2024-28987 to its Known Exploited Vulnerabilities (KEV) catalog. When a vulnerability is added…

Read More