Hackers Found Using A New Code Injection Technique to Evade Detection

While performing in-depth analysis of various malware samples, security researchers at Cyberbit found a new code injection technique, dubbed Early Bird, being used by at least three different sophisticated malware that helped attackers evade detection. As its name suggests, Early Bird Read More …

Cisco mess from 2017 becomes tool for state-sponsored infrastructure attacks and defacements

Cisco’s Smart Install software has become the vector for a series of infrastructure attacks and politically-motivated defacements. Cisco’s own Talos security limb reports that bad actors, some likely state-supported, have been scanning Switchzilla devices to see if they run Smart Read More …

Cyber Dam Busters could give Australia’s military an asymmetric edge

The Australian Defence Force (ADF) has a “distinct battlefield edge” because it has fully integrated its military offensive capability into ADF operations. But a “modest” additional investment would give it “an asymmetric capability against future adversaries”, according to the International Read More …

Critical Code Execution Flaw Found in CyberArk Enterprise Password Vault

A critical remote code execution vulnerability has been discovered in CyberArk Enterprise Password Vault application that could allow an attacker to gain unauthorized access to the system with the privileges of the web application. Enterprise password manager (EPV) solutions help organizations securely manage Read More …

1.5 billion sensitive files exposed by misconfigured servers, storage and cloud services

Researchers have discovered over 1.5 billion sensitive files including payroll information, credit card details, medical data, and patents for intellectual property are exposed online, putting consumers and businesses at risk of theft, cybercrime, and espionage. But the information exposed online Read More …