Category Security

Critical Infrastructure Urged to Scrutinize Product Security

Critical infrastructure organizations have been urged to take action to ensure their operational technology (OT) products are secure by design. Government agencies from the Five Eyes intelligence and security alliance, alongside European partners, issued a joint advisory on January 13…

CISA Adds Second BeyondTrust Flaw to KEV Catalog Amid Active Attacks

Jan 14, 2025Ravie LakshmananVulnerability / Cybersecurity The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a second security flaw impacting BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) products to the Known Exploited Vulnerabilities (KEV) catalog, citing…

The Mechanization of Virtualized Attacks

Jan 13, 2025The Hacker NewsThreat Detection / Network Security In 2024, ransomware attacks targeting VMware ESXi servers reached alarming levels, with the average ransom demand skyrocketing to $5 million. With approximately 8,000 ESXi hosts exposed directly to the internet (according…

Russian Malware Campaign Hits Central Asian Diplomatic Files

A cyber-espionage campaign targeting diplomatic entities in Kazakhstan and Central Asia has been linked to the Russia-aligned intrusion set UAC-0063. According to recent findings by cybersecurity firm Sekoia, the campaign involved weaponized Microsoft Word documents designed to deliver HatVibe and…

Microsoft 365 MFA Outage Fixed

Microsoft has confirmed an outage that affected its multi-factor authentication (MFA) system, causing service disruptions for users attempting to access Microsoft 365 applications. The issue, identified early on January 13, prevented some customers from logging into their accounts due to…