The cornerstone of digital trust in modern enterprise, ET CISO Identity has emerged as the new battleground for cybersecurity in today’s rapidly evolving digital landscape as threat actors are increasingly leveraging identity to compromise enterprises. They are exploiting weaknesses in identity management to gain unauthorized access to data and systems, highlighting the critical importance of securing digital identities. Unlike traditional ...
Read More »Author Archives: firewallfirmadmin
INTERPOL Recovers $41 Million in Largest Ever BEC Scam in Singapore
INTERPOL Recovers $41 Million in Largest Ever BEC Scam in Singapore https://firewall.firm.in/wp-content/uploads/2024/08/bec-scam.png Aug 06, 2024Ravie LakshmananEmail Security / Financial Fraud INTERPOL said it devised a “global stop-payment mechanism” that helped facilitate the largest-ever recovery of funds defrauded in a business email compromise (BEC) scam. The development comes after an unnamed commodity firm based in Singapore fell victim to a BEC ...
Read More »Kazakh Organizations Targeted by ‘Bloody Wolf’ Cyber Attacks
Kazakh Organizations Targeted by ‘Bloody Wolf’ Cyber Attacks https://firewall.firm.in/wp-content/uploads/2024/08/cyberattack.png Aug 05, 2024Ravie LakshmananNetwork Security / Threat Intelligence Organizations in Kazakhstan are the target of a threat activity cluster dubbed Bloody Wolf that delivers a commodity malware called STRRAT (aka Strigoi Master). “The program selling for as little as $80 on underground resources allows the adversaries to take control of corporate ...
Read More »Researchers Uncover Flaws in Windows Smart App Control and SmartScreen
Researchers Uncover Flaws in Windows Smart App Control and SmartScreen https://firewall.firm.in/wp-content/uploads/2024/08/main.gif Aug 05, 2024Ravie LakshmananThreat Intelligence / Vulnerability Cybersecurity researchers have uncovered design weaknesses in Microsoft’s Windows Smart App Control and SmartScreen that could enable threat actors to gain initial access to target environments without raising any warnings. Smart App Control (SAC) is a cloud-powered security feature introduced by Microsoft ...
Read More »CrowdStrike rejects Delta Air Lines claims over flight woes, IT Security News, ET CISO
CrowdStrike rejects Delta Air Lines claims over flight woes, IT Security News, ET CISO CrowdStrike on Sunday rejected a claim by Delta Air Lines that it should be blamed for flight disruptions following a July 19 global outage sparked by a faulty update, and suggested it had minimal potential liability. Delta CEO Ed Bastian said last week the outage had ...
Read More »New Windows Backdoor BITSLOTH Exploits BITS for Stealthy Communication
New Windows Backdoor BITSLOTH Exploits BITS for Stealthy Communication https://firewall.firm.in/wp-content/uploads/2024/08/hacking.png Aug 02, 2024Ravie LakshmananCyber Attack / Windows Security Cybersecurity researchers have discovered a previously undocumented Windows backdoor that leverages a built-in feature called Background Intelligent Transfer Service (BITS) as a command-and-control (C2) mechanism. The newly identified malware strain has been codenamed BITSLOTH by Elastic Security Labs, which made the discovery ...
Read More »Mirai Botnet targeting OFBiz Servers Vulnerable to Directory Traversal
Mirai Botnet targeting OFBiz Servers Vulnerable to Directory Traversal https://firewall.firm.in/wp-content/uploads/2024/08/sans.jpg Aug 02, 2024The Hacker NewsVulnerability / Network Security Enterprise Resource Planning (ERP) Software is at the heart of many enterprising supporting human resources, accounting, shipping, and manufacturing. These systems can become very complex and difficult to maintain. They are often highly customized, which can make patching difficult. However, critical vulnerabilities ...
Read More »DOJ and FTC Sue TikTok for Violating Children’s Privacy Laws
DOJ and FTC Sue TikTok for Violating Children’s Privacy Laws https://firewall.firm.in/wp-content/uploads/2024/08/tiktok.jpg Aug 03, 2024Ravie LakshmananPrivacy / Data Protection The U.S. Department of Justice (DoJ), along with the Federal Trade Commission (FTC), filed a lawsuit against popular video-sharing platform TikTok for “flagrantly violating” children’s privacy laws in the country. The agencies claimed the company knowingly permitted children to create TikTok accounts ...
Read More »OpenAI assigns new project to AI safety leader Madry in revamp, ET CISO
OpenAI assigns new project to AI safety leader Madry in revamp, ET CISO OpenAI Chief Executive Sam Altman said on Tuesday the ChatGPT maker’s AI safety leader Aleksander Madry was working on a new research project, as the startup rejigs the preparedness team. “Aleksander is working on a new and v(very) important research project,” Altman said in a post on ...
Read More »Hackers Exploit Misconfigured Jupyter Notebooks with Repurposed Minecraft DDoS Tool
Hackers Exploit Misconfigured Jupyter Notebooks with Repurposed Minecraft DDoS Tool https://firewall.firm.in/wp-content/uploads/2024/08/ddos.png Aug 03, 2024Ravie LakshmananDDoS Attack / Server Security Cybersecurity researchers have disclosed details of a new distributed denial-of-service (DDoS) attack campaign targeting misconfigured Jupyter Notebooks. The activity, codenamed Panamorfi by cloud security firm Aqua, utilizes a Java-based tool called mineping to launch a TCP flood DDoS attack. Mineping is ...
Read More »