Recent Security News

  • Ivanti Pulse Secure Found Using 11-Year-Old Linux Version and Outdated Libraries

    February 15, 2024 at 10:18AM A firmware reverse engineering of Ivanti Pulse Secure revealed outdated, vulnerable software components in the Utah-based company’s appliance. Active exploitation of security flaws in related gateways has been observed. Eclypsium found outdated packages and vulnerable libraries, emphasizing the need for visibility into digital supply chains. Concerns about security holes in…

    Read More

  • Cybersecurity’s Transformative Shift

    February 15, 2024 at 10:04AM The traditional model of cybersecurity, focused on reactive threat detection, is no longer sufficient due to the complexity of modern cyber threats. A shift is occurring towards proactive strategies such as User and Entity Behavior Analytics (UEBA) and a focus on data flow to identify anomalies and potential security risks.…

    Read More

  • Turla hackers backdoor NGOs with new TinyTurla-NG malware

    February 15, 2024 at 10:03AM Security researchers discovered new malware known as TinyTurla-NG and TurlaPower-NG, being used by the Russian hacker group Turla. The group exploits vulnerable WordPress websites for command and control purposes. Targeting organizations across various sectors, they aim to steal sensitive data using custom tools and malware. The malware’s purpose is to…

    Read More

  • Turla hackers target NGOs with new TinyTurla-NG ‘secret backdoor’

    February 15, 2024 at 09:56AM Security researchers have discovered new malware called TinyTurla-NG and TurlaPower-NG, utilized by the Russian hacker group Turla for network access and data theft. Turla exploits vulnerable WordPress websites for command and control, targeting organizations across various sectors. The malware’s backdoor functionality and data exfiltration methods were detailed in a report…

    Read More

  • ESET Patches High-Severity Privilege Escalation Vulnerability

    February 15, 2024 at 09:51AM ESET announced patches for a high-severity vulnerability in its consumer, business, and server security products for Windows, tracked as CVE-2024-0353. The flaw could allow an attacker to delete files with System privileges. Researchers with Trend Micro’s ZDI reported the security defect, and patches were released for affected products, with customers…

    Read More