Sneaky Skimmer Malware Targets Magento Sites Ahead of Black Friday

November 27, 2024 at 12:52PM Attackers are exploiting Magento e-commerce sites with new card-skimming malware, identified by Sucuri. The malware dynamically steals payment information via JavaScript injections. Researchers recommend regular security audits, deploying Web application firewalls, maintaining updated software, using strong passwords, and implementing file integrity monitoring to safeguard against such attacks, especially during high-traffic … Read more

CISA Releases Guidance on Network Access, VPNs

June 27, 2024 at 11:50AM The Cybersecurity and Infrastructure Security Agency, in collaboration with the FBI and New Zealand organizations, released guidance on modern network access security, emphasizing modern firewall and network access management technologies. It focuses on three approaches: zero trust, secure service edge, and secure access service edge. Recommended practices include continuous monitoring, … Read more

‘Commando Cat’ Digs Its Claws into Exposed Docker Containers

June 6, 2024 at 04:20PM Cybercriminals are exploiting misconfigured Docker containers for cryptojacking, with the recent “Commando Cat” campaign being a prime example. They utilize Docker capabilities to run malicious containers and establish a command-and-control channel for uploading malware. Organizations can mitigate risk by using certified Docker images, avoiding root privileges, conducting security audits, and … Read more

Kali Linux 2024.1 released with 4 new tools, UI refresh

February 28, 2024 at 02:51PM Kali Linux 2024.1 has been released with new tools, desktop changes, and a theme refresh. Four new tools include blue-hydra, opentaxii, readpe, and snort, while visual updates and two new wallpapers enhance user experience. The release also features desktop improvements and upgrading to Kernel version 6.6. Existing users can upgrade, … Read more

PentestPad: Platform for Pentest Teams

October 31, 2023 at 08:18AM PentestPad is a platform that helps pentest teams collaborate and work more efficiently. It offers automated report generation, real-time collaboration, integrations with leading tools, and client engagement features. The platform also provides powerful project management tools, activity logging to detect pen test activities, performance monitoring, and reporting capabilities. PentestPad is … Read more