Blog
Threat Actors Abuse Google AMP for Evasive Phishing Attacks
The idea behind using Google AMP URLs embedded in phishing emails is to make sure that email protection technology does not flag messages as malicious or suspicious due to Google’s good reputation.
Akira Ransomware Group Claims to Target Parathon
Akira ransomware group added U.S.-based software company Parathon to its victim list. The hackers claimed to have 560 GB of data of employee data and other information, exfiltrated after the Parathon cyber attack. Parathon cyber attack Screenshot of Akira’s message...
Have you Patched this Microsoft OneNote Spoofing Vulnerability Yet?
Microsoft has issued an alert on the OneNote spoofing vulnerability, patched previously. According to the latest update from Microsoft, the possibility of exploitation still exists. The Microsoft OneNote Spoofing Vulnerability, coded CVE-2023-33140, potentially...
Iranian Company Cloudzy Accused of Aiding Cybercriminals and Nation-State Hackers
Services offered by an obscure Iranian company known as Cloudzy are being leveraged by multiple threat actors, including cybercrime groups and nation-state crews. "Although Cloudzy is incorporated in the United States, it almost certainly operates out of Tehran, Iran...
Forgepoint Capital Places $15M Series A Bet on Converge Insurance
“This funding will enable us to expand our outreach and grow our bench of in-house experts while accelerating the availability of the Converge platform worldwide,” the newly appointed CEO, Tom Kang, said.
Norwegian Entities Targeted in Ongoing Attacks Exploiting Ivanti EPMM Vulnerability
Advanced persistent threat (APT) actors exploited a recently disclosed critical flaw impacting Ivanti Endpoint Manager Mobile (EPMM) as a zero-day since at least April 2023 in attacks directed against Norwegian entities, including a government network. The disclosure...
Firefox fixes a flurry of flaws in the first of two releases this month
No zero-days, but some interesting patches with their very own "teachable moments".
Russian Sanctions, London Metal Exchange Cyber Attack, and Teaming of Killnet Hackers and Allies
The pro-Russian group Killnet along with other hacker groups claimed to have targeted the London Metal Exchange (LME) with a cyber attack. The London Metal Exchange cyber attack has not been confirmed by the organization. The website of LME was accessible at the time...
New NodeStealer Targeting Facebook Business Accounts and Crypto Wallets
Cybersecurity researchers have unearthed a Python variant of a stealer malware NodeStealer that's equipped to fully take over Facebook business accounts as well as siphon cryptocurrency. Palo Alto Network Unit 42 said it detected the previously undocumented strain as...
Everything You Need to Know About the National Cyber Workforce and Education Strategy (NCWES)
The US White House has unveiled the National Cyber Workforce and Education Strategy (NCWES), a crucial step towards securing the nation’s digital future. The NCWES focuses on making foundational cyber skill learning accessible to everyone and investing in cyber...
FREE GUIDE