News

Latest news, analysis, and event reviews in the world of information security.

The Internet archive has been hacked again

News · 22.10.2024 · Information Security

The Internet archive has been hacked again

Internet Archive (Archive.org) faced a second data leak in October 2024, when hackers gained access to service tickets through unsecured Zendesk API tokens.
@CitizenSec
@CitizenSec
CitizenSec
TrickMo Trojan: How Phishing attacks your phones and what you need to know to protect yourself from this threat?

News · 20.10.2024 · Information Security

TrickMo Trojan: How Phishing attacks your phones and what you need to know to protect yourself from this threat?

This malicious software uses clever methods to trick users by showing a fake unlock screen
@CitizenSec
@CitizenSec
CitizenSec
How Windows utilities threaten your security by bypassing the protection

News · 17.10.2024 · Information Security

How Windows utilities threaten your security by bypassing the protection

The attackers launched their attacks in early October, and their goal is to install a data theft program known as Lumma.
@CitizenSec
@CitizenSec
CitizenSec
How GitHub, Telegram bots and QR codes are becoming the tools of a new wave of phishing attacks

News · 14.10.2024 · Information Security

How GitHub, Telegram bots and QR codes are becoming the tools of a new wave of phishing attacks

Attackers use links to GitHub in phishing emails to circumvent security measures and deliver malware called Remcos RAT.
@CitizenSec
@CitizenSec
CitizenSec
Scammers were caught in St. Petersburg: how did they steal accounts and what followed?

News · 14.10.2024 · Information Security

Scammers were caught in St. Petersburg: how did they steal accounts and what followed?

Employees of the criminal investigation department of St. Petersburg detained two intruders who hacked accounts on the portal of Public Services and issued loans to microfinance organizations.
@CitizenSec
@CitizenSec
CitizenSec
22,000 PyPI packages at risk: how the Revival Hijack issue could affect the security of your code

News · 18.09.2024 · Information Security

22,000 PyPI packages at risk: how the Revival Hijack issue could affect the security of your code

Analysts at JFrog have discovered a new threat called Revival Hijack.
@CitizenSec
@CitizenSec
CitizenSec
Kazakhstan is in the top three leaders of the CIS dark web: what lies behind the veil of secrecy, and what goods are sold in the shadows?

News · 16.09.2024 · Information Security

Kazakhstan is in the top three leaders of the CIS dark web: what lies behind the veil of secrecy, and what goods are sold in the shadows?

A recent study showed that the Republic of Kazakhstan ranks second in the number of cyberattacks among CIS countries, accounting for 8% of the total.
@CitizenSec
@CitizenSec
CitizenSec
Microsoft Copilot Studio Vulnerability

News · 09.09.2024 · Critical vulnerability · Information Security

Microsoft Copilot Studio Vulnerability

This vulnerability, known as SSRF (server-side request forgery), could allow attackers to gain access to confidential data.
@CitizenSec
@CitizenSec
CitizenSec
Unpatched vulnerability in AVTECH cameras: hackers are taking over devices to create botnets.

News · 05.09.2024 · Information Security · Critical vulnerability

Unpatched vulnerability in AVTECH cameras: hackers are taking over devices to create botnets.

Serious vulnerabilities have been discovered in AVTECH surveillance cameras, which malicious actors use to infect devices with malware.
@CitizenSec
@CitizenSec
CitizenSec
New phishing campaign with QR codes: how Microsoft Sway became a tool for stealing your credentials

News · 02.09.2024 · Information Security

New phishing campaign with QR codes: how Microsoft Sway became a tool for stealing your credentials

The attacks are primarily aimed at users in Asia and North America, particularly in the technology, manufacturing, and finance sectors.
@CitizenSec
@CitizenSec
CitizenSec
The vulnerability of the LiteSpeed Cache plugin threatens over 5 million WordPress sites

News · 28.08.2024 · Information Security · Critical vulnerability

The vulnerability of the LiteSpeed Cache plugin threatens over 5 million WordPress sites

Recently, security researcher John Blackburn from PatchStack discovered a serious vulnerability in the LiteSpeed Cache plugin, which is used to speed up WordPress sites.
@CitizenSec
@CitizenSec
CitizenSec
Google warns: vulnerability CVE-2024-7965 in Chrome is under active exploitation

News · 27.08.2024 · Information Security · Critical vulnerability

Google warns: vulnerability CVE-2024-7965 in Chrome is under active exploitation

Google has reported a security issue in its Chrome browser that has been fixed in the latest update.
@CitizenSec
@CitizenSec
CitizenSec
New phishing attack on Android and iOS users using PWA and WebAPK: how to protect yourself?

News · 22.08.2024 · Information Security

New phishing attack on Android and iOS users using PWA and WebAPK: how to protect yourself?

This attack uses traditional social engineering techniques along with Progressive Web Applications (PWAs) and WebAPKs.
@CitizenSec
@CitizenSec
CitizenSec
The bug bounty platform for Google Play apps is shutting down

News · 20.08.2024 · Information Security

The bug bounty platform for Google Play apps is shutting down

Google explains the program's closure due to the decrease in the number of identified vulnerabilities and the overall improvement in Android security.
@CitizenSec
@CitizenSec
CitizenSec
Kubernetes Vulnerability: Command Injection Attacks Threaten the Security of Your Clusters

News · 19.08.2024 · Information Security

Kubernetes Vulnerability: Command Injection Attacks Threaten the Security of Your Clusters

A recently discovered vulnerability in Kubernetes has raised serious concerns in the cybersecurity community.
@CitizenSec
@CitizenSec
CitizenSec
Critical Vulnerability in OpenSSH on FreeBSD

News · 14.08.2024 · Information Security · Critical vulnerability

Critical Vulnerability in OpenSSH on FreeBSD

A serious security vulnerability was recently discovered in OpenSSH on FreeBSD systems.
@CitizenSec
@CitizenSec
CitizenSec
Vulnerability in MongoDB Allows Attackers to Gain Full Control of Windows Systems

News · 12.08.2024 · Information Security · Critical vulnerability

Vulnerability in MongoDB Allows Attackers to Gain Full Control of Windows Systems

A critical vulnerability has been discovered in MongoDB, identified as CVE-2024-7553.
@CitizenSec
@CitizenSec
CitizenSec
5G Vulnerabilities: How New Technologies Allow Tracking Every Move of Mobile Device Owners, and What You Can Do to Protect Yourself?

News · 09.08.2024 · Information Security

5G Vulnerabilities: How New Technologies Allow Tracking Every Move of Mobile Device Owners, and What You Can Do to Protect Yourself?

Researchers from the University of Pennsylvania demonstrated at the Black Hat conference in Las Vegas how users can be monitored through vulnerabilities in 5G.
@CitizenSec
@CitizenSec
CitizenSec
Show more