News & Updates

Israel-based Spyware Firm QuaDream Targets High-Risk iPhones with Zero-Click Exploit

Threat actors using hacking tools from an Israeli surveillanceware vendor named QuaDream targeted at least five members of civil society in North America, Central Asia, Southeast Asia, Europe, and the Middle East.
According to findings from a group of researchers from the Citizen Lab, the spyware campaign was directed against journalists, political opposition figures, and an NGO worker in 2021.
News & Updates

The Service Accounts Challenge: Can’t See or Secure Them Until It’s Too Late

Here’s a hard question to answer: ‘How many service accounts do you have in your environment?’. A harder one is: ‘Do you know what these accounts are doing?’. And the hardest is probably: ‘If any of your service account was compromised and used to access resources would you be able to detect and stop that in real-time?’. 
Since most identity and security teams would provide a negative reply,
Threats

Detect CVE-2023-28252 & CVE-2023-21554 Exploitation Attempts: Windows Zero-Day Actively Used in Ransomware Attacks and a Critical RCE Flaw

Detect CVE-2023-28252 & CVE-2023-21554 Exploitation Attempts

With a growing number of zero-day flaws affecting widely used software products, proactive detection of vulnerability exploitation has been among the most prevalent security use cases since 2021.  Microsoft has recently issued a series of security updates relevant to critical flaws affecting its products, including a patch for a zero-day actively exploited in the wild […]

The post Detect CVE-2023-28252 & CVE-2023-21554 Exploitation Attempts: Windows Zero-Day Actively Used in Ransomware Attacks and a Critical RCE Flaw appeared first on SOC Prime.

News & Updates

Attackers Using Public USB Outlets to Spread Malware, FBI Warns

The FBI has warned that charging your phone via a USB cable from a free charging
station could be the worst decision you ever make regarding security.

We often advise people to avoid free Wi-Fi networks or at least use a VPN
solution when connecting to an unknown Wi-Fi, as attackers can control wireless
networks to capture all traffic from the victims’ devices. But connecting your
phone to an unknown outlet that supposedly provides free charging is infinitely
worse.

Some businesses, such as ai

News & Updates

QuaDream ‘Reign’ Spyware Used to Hack iPhones of High-Profile Targets

Security researchers have discovered new evidence of spyware targeting Apple
smartphones during the vulnerable days of iOS 14, dating back to 2021.

In a report published this week, Citizen Labresearchers of the University of
Toronto identified at least five civil society victims infected with ‘Reign’
spyware developed by Israeli firm QuaDream.

Targets included journalists, political opposition figures, and a non-government
organisation worker, in North America, Central Asia, Southeast Asia, Eu

Cybersecurity Tools

Warning: Threat Actors Compromise 3CX Desktop App in a Supply Chain Attack (Updated)

An ongoing supply chain attack allegedly uses a digitally signed and trojanized variant of the 3CX Voice Over Internet Protocol (VoIP) desktop client to target the company’s clients. The 3CX Phone System engineered by the VoIP IPBX software development company 3CX is utilized daily by over 12 million users and over 600,000 companies, including high-profile […]

The post Warning: Threat Actors Compromise 3CX Desktop App in a Supply Chain Attack (Updated) appeared first on Heimdal Security Blog.

News & Updates

OpenAI starts bug bounty program with cash rewards up to $20,000

Microsoft-backed OpenAI has launched a bug bounty program and is inviting the global community of security researchers, ethical hackers, and technology enthusiasts to help the company identify and address vulnerabilities in its artificial intelligent systems. 

“We are excited to build on our coordinated disclosure commitments by offering incentives for qualifying vulnerability information,” OpenAI said in its blog post on Tuesday.

To read this article in full, please click here

Scroll to Top