Recent Security News

  • Data Leakage Prevention in the Age of Cloud Computing: A New Approach

    March 11, 2024 at 08:21AM The traditional on-premises approach to data security is becoming obsolete as IT infrastructure moves to cloud-based solutions. A new guide by LayerX emphasizes the need for DLP solutions to focus on protecting corporate data in the browser. It outlines three data protection paths forward, with browser DLP being highlighted as…

    Read More

  • Magnet Goblin Delivers Linux Malware Using One-Day Vulnerabilities

    March 11, 2024 at 08:09AM Check Point reports that the financially motivated threat actor, Magnet Goblin, has been exploiting one-day vulnerabilities in public-facing services to deploy Linux backdoors. The actor targeted various vulnerabilities, including in Ivanti VPNs, Magento, and Qlik Sense. Check Point warns of ongoing trends for threat actors to target under-protected areas. Based…

    Read More

  • How do you lot feel about Pay or say OK to ads model, asks ICO

    March 11, 2024 at 07:25AM UK’s ICO is seeking input on “consent or pay” business models, where users can pay to access services without data being used for advertising. The ICO emphasizes the need for users to understand the consent aspect and have the freedom to withdraw it easily. The consultation addresses factors like fee…

    Read More

  • BianLian Threat Actors Exploiting JetBrains TeamCity Flaws in Ransomware Attacks

    March 11, 2024 at 06:51AM Threat actors using BianLian ransomware exploit security flaws in JetBrains TeamCity software for extortion-only attacks. The cyberattack involves exploiting TeamCity vulnerabilities to gain initial access, deploying the BianLian backdoor, and using PowerShell for remote communication. VulnCheck also detailed PoC exploits for a critical flaw in Atlassian Confluence, indicating widespread exploitation.…

    Read More

  • New Open Source Tool Hunts for APT Activity in the Cloud

    March 11, 2024 at 06:51AM Permiso Security has released CloudGrappler, an open source tool to detect cloud environment intrusions by advanced persistent threat (APT) actors. CloudGrappler specializes in querying for activity by known threat actors and provides detailed reports in JSON format. The tool is available on GitHub for users to access and utilize. The…

    Read More