Technology

Jan 18, 2023Ravie LakshmananCyber Threat / Malware An ongoing campaign dubbed Earth Bogle is leveraging geopolitical-themed lures to deliver the NjRAT remote access trojan to victims across the Middle East and North Africa. “The threat actor uses public cloud storage services such as files[.]fm and failiem[.]lv to host malware, while compromised web servers distribute NjRAT,”
0 Comments
WhatsApp has reportedly begun rolling out a new feature for select Android beta testers that allows them to exchange voice notes as status updates. The feature lets you share voice status updates “with a certain audience configured within your privacy settings,” according to a feature tracker. The new feature is available within the text status
0 Comments
Jan 18, 2023Ravie LakshmananCyber Espionage / Cyber Risk The threat actor known as BackdoorDiplomacy has been linked to a new wave of attacks targeting Iranian government entities between July and late December 2022. Palo Alto Networks Unit 42, which is tracking the activity under its constellation-themed moniker Playful Taurus, said it observed the government domains
0 Comments
Jan 17, 2023Ravie LakshmananThreat Response / Malware New research has found that it is possible for threat actors to abuse a legitimate feature in GitHub Codespaces to deliver malware to victim systems. GitHub Codespaces is a cloud-based configurable development environment that allows users to debug, maintain, and commit changes to a given codebase from a
0 Comments
While the budget smartphone segment today offers phones with a decent mix of good software and hardware features, those seeking better camera performance or want added features will often find themselves looking for smartphones in the mid-range segment. The phones in our sub-Rs. 25,000 price bracket are roughly where the mid-range segment begins and some of them offer impressive performance,
0 Comments
Jan 17, 2023Ravie LakshmananCloud Security / Bug Report Four different Microsoft Azure services have been found vulnerable to server-side request forgery (SSRF) attacks that could be exploited to gain unauthorized access to cloud resources. The security issues, which were discovered by Orca between October 8, 2022 and December 2, 2022 in Azure API Management, Azure
0 Comments
Jan 16, 2023The Hacker NewsIdentity Management / MFA When considering authentication providers, many organizations consider the ease of configuration, ubiquity of usage, and technical stability. Organizations cannot always be judged on those metrics alone. There is an increasing need to evaluate company ownership, policies and the stability, or instability, that it brings. How Leadership Change
0 Comments
Jan 16, 2023Ravie LakshmananData Security / Cyber Threat A “large and resilient infrastructure” comprising over 250 domains is being used to distribute information-stealing malware such as Raccoon and Vidar since early 2020. The infection chain “uses about a hundred of fake cracked software catalogue websites that redirect to several links before downloading the payload hosted
0 Comments
Jan 14, 2023Ravie LakshmananNetwork Security / Bug Report Cisco has warned of two security vulnerabilities affecting end-of-life (EoL) Small Business RV016, RV042, RV042G, and RV082 routers that it said will not be fixed, even as it acknowledged the public availability of proof-of-concept (PoC) exploit. The issues are rooted in the router’s web-based management interface, enabling
0 Comments
Jan 14, 2023Ravie LakshmananPrivacy / Online Safety Popular short-form video hosting service TikTok has been fined €5 million (about $5.4 million) by the French data protection watchdog for breaking cookie consent rules, making it the latest platform to face similar penalties after Amazon, Google, Meta, and Microsoft since 2020. “Users of ‘tiktok[.]com’ could not refuse
0 Comments
Jan 14, 2023Ravie LakshmananServer Security / Patch Management A majority of internet-exposed Cacti servers have not been patched against a recently patched critical security vulnerability that has come under active exploitation in the wild. That’s according to attack surface management platform Censys, which found only 26 out of a total of 6,427 servers to be
0 Comments
Jan 14, 2023Ravie LakshmananDevOps / Data Security DevOps platform CircleCI on Friday disclosed that unidentified threat actors compromised an employee’s laptop and leveraged malware to steal their two-factor authentication-backed credentials to breach the company’s systems and data last month. The CI/CD service CircleCI said the “sophisticated attack” took place on December 16, 2022, and that
0 Comments
Samsung Galaxy S23 series, speculated to launch at the Galaxy Unpacked event scheduled for February 1, is being subjected to numerous tips and rumours. With about two weeks to go for the official launch, the design of the Samsung Galaxy S23 Ultra and Samsung Galaxy S23 Plus models from the South Korean conglomerate’s next-generation flagship
0 Comments