Recent Security News

  • MTTR: The Most Important Security Metric

    February 29, 2024 at 10:01AM Security teams face increasing challenges with managing risk as code and cloud assets continue to sprawl, leading to a surge in vulnerabilities and longer remediation times. Mean time to remediate (MTTR) emerges as a crucial metric for gauging security success, requiring organizations to streamline vulnerability management and prioritize high-risk issues…

    Read More

  • Ransomware-as-a-Service Spawns Wave of Cyberattacks in Middle East & Africa

    February 29, 2024 at 09:32AM Ransomware-as-a-service (RaaS) affiliates are driving a surge in ransomware attacks in the Middle East and Africa. Group-IB’s report shows a 68% increase in data leaks from 205 companies, with financial services as the primary target. Organizations in the region, particularly those with less mature security controls, are vulnerable to operational…

    Read More

  • Iranian Hackers Target Aviation and Defense Sectors in Middle East

    February 29, 2024 at 09:27AM Iranian hackers have been utilizing Microsoft Azure cloud infrastructure in attacks on aerospace, aviation, and defense organizations in the Middle East, particularly in Israel and the UAE. The hacking group, UNC1549, has deployed two backdoors named MiniBike and MiniBus. These activities are linked to Iran’s Islamic Revolutionary Guard Corps. Mandiant…

    Read More

  • Meta Patches Facebook Account Takeover Vulnerability

    February 29, 2024 at 09:27AM Meta recently patched a critical vulnerability affecting the Facebook password reset process, as reported by cybersecurity researcher Samip Aryal. The flaw allowed an attacker to exploit a two-hour window to brute-force a unique six-digit code and gain control of an account. Meta’s bug bounty program recognized Aryal’s contribution, but the…

    Read More

  • Meta’s pay-or-consent model hides ‘massive illegal data processing ops’: lawsuit

    February 29, 2024 at 08:05AM Consumer groups in the EU are taking legal action over Meta’s approach to data protection laws, claiming that the company gives users a “fake choice” between paying or consenting to data collection. The complaints focus on Meta’s subscription model and alleged breaches of GDPR principles. Meta disputes the allegations, stating…

    Read More