[ad_1] Sep 27, 2023NewsroomVulnerability / Endpoint Security A novel side-channel attack called GPU.zip renders virtually all modern graphics processing units (GPU) vulnerable to information leakage. “This channel exploits an optimization that is data dependent, software transparent, and present in nearly all modern GPUs: graphical data compression,” a group of academics from the University of Texas…
Month: October 2023
Red Cross-Themed Phishing Attacks Distributing DangerAds and AtlasAgent Backdoors
[ad_1] Sep 27, 2023NewsroomMalware / Cyber Attack A new threat actor known as AtlasCross has been observed leveraging Red Cross-themed phishing lures to deliver two previously undocumented backdoors named DangerAds and AtlasAgent. NSFOCUS Security Labs described the adversary as having a “high technical level and cautious attack attitude,” adding that “the phishing attack activity captured…
China-Linked Budworm Targeting Middle Eastern Telco and Asian Government Agencies
[ad_1] Sep 28, 2023NewsroomMalware / Cyber Threat Government and telecom entities have been subjected to a new wave of attacks by a China-linked threat actor tracked as Budworm using an updated malware toolset. The intrusions, targeting a Middle Eastern telecommunications organization and an Asian government, took place in August 2023, with the adversary deploying an…
The Dark Side of Browser Isolation – and the Next Generation Browser Security Technologies
[ad_1] Sep 28, 2023The Hacker NewsBrowser Security / Cybersecurity The landscape of browser security has undergone significant changes over the past decade. While Browser Isolation was once considered the gold standard for protecting against browser exploits and malware downloads, it has become increasingly inadequate and insecure in today’s SaaS-centric world. The limitations of Browser Isolation,…
China’s BlackTech Hacking Group Exploited Routers to Target U.S. and Japanese Companies
[ad_1] Cybersecurity agencies from Japan and the U.S. have warned of attacks mounted by a state-backed hacking group from China to stealthily tamper with branch routers and use them as jumping-off points to access the networks of various companies in the two countries. The attacks have been tied to a malicious cyber actor dubbed BlackTech…
GitHub Repositories Hit by Password-Stealing Commits Disguised as Dependabot Contributions
[ad_1] Sep 28, 2023NewsroomSupply Chain / Malware A new deceptive campaign has been observed hijacking GitHub accounts and committing malicious code disguised as Dependabot contributions with an aim to steal passwords from developers. “The malicious code exfiltrates the GitHub project’s defined secrets to a malicious C2 server and modify any existing javascript files in the…
Cisco Warns of Vulnerability in IOS and IOS XE Software After Exploitation Attempts
[ad_1] Sep 29, 2023NewsroomVulnerability / Network Security Cisco is warning of attempted exploitation of a security flaw in its IOS Software and IOS XE Software that could permit an authenticated remote attacker to achieve remote code execution on affected systems. The medium-severity vulnerability is tracked as CVE-2023-20109, and has a CVSS score of 6.6. It…
Microsoft’s AI-Powered Bing Chat Ads May Lead Users to Malware-Distributing Sites
[ad_1] Malicious ads served inside Microsoft Bing’s artificial intelligence (AI) chatbot are being used to distribute malware when searching for popular tools. The findings come from Malwarebytes, which revealed that unsuspecting users can be tricked into visiting booby-trapped sites and installing malware directly from Bing Chat conversations. Introduced by Microsoft in February 2023, Bing Chat…
Finally Real in Consumer Apps?
[ad_1] Sep 29, 2023The Hacker NewsQuantum Computing / Network Security Most people are barely thinking about basic cybersecurity, let alone post-quantum cryptography. But the impact of a post-quantum world is coming for them regardless of whether or not it’s keeping them up tonight. Today, many rely on encryption in their daily lives to protect their…
Lazarus Group Impersonates Recruiter from Meta to Target Spanish Aerospace Firm
[ad_1] Sep 29, 2023NewsroomCyber Espionage / Malware The North Korea-linked Lazarus Group has been linked to a cyber espionage attack targeting an unnamed aerospace company in Spain in which employees of the firm were approached by the threat actor posing as a recruiter for Meta. “Employees of the targeted company were contacted by a fake…









