Recent Security News

  • Two High-Risk Security Flaws Discovered in Curl Library – New Patches Released

    October 12, 2023 at 01:01AM Patches have been released for two security flaws in the Curl data transfer library. The more severe vulnerability, labeled CVE-2023-38545, allows for code execution and is considered one of the worst security flaws in Curl in a long time. The other vulnerability, CVE-2023-38546, enables cookie injection. Both flaws have been…

    Read More

  • How to Prevent Ransomware as a Service (RaaS) Attacks

    October 11, 2023 at 09:44PM Ransomware as a Service (RaaS) attacks are on the rise, with a significant increase in the number of victim organizations. RaaS operators recruit affiliates to carry out the attacks, split the ransom amounts, and provide sophisticated tools and interfaces. To prevent ransomware attacks, companies should leverage cybersecurity frameworks, use a…

    Read More

  • Chinese ‘Stayin’ Alive’ Attacks Dance onto Targets With Dumb Malware

    October 11, 2023 at 05:23PM Chinese APT group “ToddyCat” is using simple but constantly evolving custom backdoors and loaders to target telecommunications organizations in Central and Southeast Asia. The group, previously linked to Chinese espionage operations, uses spear phishing emails with archive files to exploit a DLL sideloading vulnerability. While the malware used by ToddyCat…

    Read More

  • BianLian extortion group claims recent Air Canada breach

    October 11, 2023 at 05:08PM The BianLian extortion group claims to have stolen 210GB of data from Air Canada, including technical and operational information, employee personal data, vendor and supplier information, and confidential documents. The group has shared screenshots of the stolen data as proof. Air Canada has acknowledged the threats but has not confirmed…

    Read More