Recent Security News

  • How to Identify a Cyber Adversary: What to Look For

    March 13, 2024 at 02:41PM Attribution of cyber incidents is vital for legal and security actions, but it’s becoming more challenging. A framework for attribution includes victimology analysis, categorizing adversary tools, understanding time implications, investigating malicious infrastructure, reviewing implementation techniques, and assessing collected intelligence for accuracy and exclusivity. Rushing attribution can lead to disastrous consequences,…

    Read More

  • PixPirate Android malware uses new tactic to hide on phones

    March 13, 2024 at 02:19PM The latest PixPirate banking trojan for Android conceals itself on phones even after its dropper app is removed. It avoids using a launcher icon and is designed to remain hidden on recent Android versions. Employing two apps, it steals information and targets the Brazilian instant payment platform Pix to initiate…

    Read More

  • Poking holes in Google tech bagged bug hunters $10M

    March 13, 2024 at 02:10PM Google awarded $10 million to 632 bug hunters in 2023, slightly less than the previous year. The company introduced new reward categories and a Bonus Awards program. High-paying categories included Android VRP, and Wear OS was added to the bounty program. However, the effectiveness of bug bounties in making software…

    Read More

  • Patch Now: Kubernetes RCE Flaw Allows Full Takeover of Windows Nodes

    March 13, 2024 at 01:21PM A security bug in Kubernetes allows attackers to remotely execute code with System privileges on Windows endpoints, potentially leading to full takeover of all Windows nodes in a cluster. Tracked as CVE-2023-5528 with a CVSS score of 7.2, the vulnerability can be exploited by manipulating Kubernetes volumes. The flaw affects…

    Read More

  • LockBit Ransomware Affiliate Sentenced to Prison in Canada

    March 13, 2024 at 12:51PM Russian-Canadian national Mikhail Vasiliev, 34, sentenced to nearly four years in prison in Canada for his role in LockBit ransomware operation. He targeted at least three organizations in Canada, seeking ransom payments. The US is also pursuing charges against him. LockBit, operating under ransomware-as-a-service model, was a prolific operation until…

    Read More