18 Jul U.S. preparing Cyber Trust Mark for more secure smart devices A new cybersecurity certification and labeling program called U.S. Cyber Trust Mark is being shaped to help U.S. consumers choose connected devices that are more secure and resilient to hacker attacks. […]
18 Jul Cybersecurity firm Sophos impersonated by new SophosEncrypt ransomware Cybersecurity vendor Sophos is being impersonated by a new ransomware-as-a-service called SophosEncrypt, with the threat actors using the company name for their operation. […]
18 Jul New critical Citrix ADC and Gateway flaw exploited as zero-day Citrix today is alerting customers of a critical-severity vulnerability (CVE-2023-3519) in NetScaler ADC and NetScaler Gateway that already has exploits in the wild, and “strongly urges” to install updated versions without delay. […]
18 Jul Strengthening Password Security may Lower Cyber Insurance Premiums When insurers assess an organization’s cybersecurity posture, password security is a key element considered. Learn more from Specops Software on how password security can affect your insurance premiums. […]
18 Jul FIN8 deploys ALPHV ransomware using Sardonic malware variant A financially motivated cybercrime gang has been observed deploying BlackCat ransomware payloads on networks backdoored using a revamped Sardonic malware version. […]
17 Jul Hackers exploiting critical WordPress WooCommerce Payments bug Hackers are conducting widespread exploitation of a critical WooCommerce Payments plugin to gain the privileges of any users, including administrators, on vulnerable WordPress installation. […]
17 Jul CISA shares free tools to help secure data in the cloud The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has shared a factsheet providing details on free tools and guidance for securing digital assets after switching to the cloud from on-premises environments. […]
17 Jul Critical ColdFusion flaws exploited in attacks to drop webshells Hackers are actively exploiting two ColdFusion vulnerabilities to bypass authentication and remotely execute commands to install webshells on vulnerable servers. […]
17 Jul Police arrests Ukrainian scareware developer after 10-year hunt The Spanish National Police has apprehended a Ukrainian national wanted internationally for his involvement in a scareware operation spanning from 2006 to 2011. […]
17 Jul IT worker jailed for impersonating ransomware gang to extort employer 28-year-old Ashley Liles, a former IT employee, has been sentenced to over three years in prison for attempting to blackmail his employer during a ransomware attack. […]