Security Experts Urge IT to Lock Down GitHub Services
Cyber Security BlogsA new Recorded Future report warns of growing abuse of GitHub and recommends blocking risky services Read More
- Published in RSS blog posts
Expert Insight for Securing Your Critical Infrastructure
Cyber Security BlogsAt Tripwire’s recent Energy and NERC Compliance Working Group, we had the opportunity to speak with the Manager of Gas Measurement, Controls, & Cybersecurity at a large energy company. More specifically, we focused on SCADA and field assets of gas Operational Technology. The experience at the management level of such an organization provided
- Published in RSS blog posts
Balada Injector continues to infect thousands of WordPress sites
Cyber Security BlogsBalada Injector malware infected more than 7100 WordPress sites using a vulnerable version of the Popup Builder plugin. In September, Sucuri researchers reported that more than 17,000 WordPress websites had been compromised in September with the Balada Injector. The researchers noticed that the number of Balada Injector infections has doubled compared with August 2023.
- Published in RSS blog posts
Anonymous Collective Launches Cyberattack on Bahrain Over Yemen Airstrikes
Cyber Security Blogs The Anonymous Collective has orchestrated an alleged cyberattack on Bahrain, pointing to the country’s support for the US and UK strikes on Yemen. According to the hacker collective, the distributed denial-of-service (DDoS) attack has affected several websites, including prominent media outlets like Akhbar al-Khaleej, Al-Ayam, Gulf Daily News, and Al-Bilad. As of
- Published in RSS blog posts
Database Sale on Dark Web Puts GEICO in the Attackers Crosshairs Again
Cyber Security Blogs A threat actor identified as ‘wangfei19860902055’ recently advertised the sale of a database related to Government Employees Insurance Company (GEICO) on a popular dark web forum. The alleged GEICO data breach incident came to light on January 14, 2024, when the threat actor posted details on the Nuovo BreachForums. According to the
- Published in RSS blog posts
Trellix XDR Platform for RDR strengthens operational resilience
Cyber Security Blogs Trellix announced Trellix XDR Platform for Ransomware Detection and Response (RDR), available immediately worldwide. Trellix XDR Platform for RDR provides visibility across an organization’s entire security ecosystem and delivers critical coverage for each stage of a ransomware campaign. The solution improves SOC efficiencies and strengthens operational resilience for customers, leveraging AI-guided capabilities
- Published in RSS blog posts
A hacker creates a million virtual servers to mine cryptocurrency illegally
Cyber Security Blogs This week, a 29-year-old man from Ukraine was taken into custody for creating one million virtual servers through the use of compromised accounts, which were then used to mine $2 million in cryptocurrency. According to what Europol announced, the suspect is thought to be the brains behind a massive cryptojacking operation that
- Published in RSS blog posts
A Magic Keyboard Bug That Allowed Bluetooth Traffic Monitoring Was Fixed By Apple
Cyber Security Blogs A recently discovered Bluetooth keyboard injection issue, identified as CVE-2024-0230, was fixed by Apple with the release of Magic Keyboard Firmware Update 2.0.6. An attacker with physical access to the accessory could use this flaw, which is a session management issue, to extract the Bluetooth pairing key and eavesdrop on Bluetooth conversations.
- Published in RSS blog posts
Attackers target Apache Hadoop and Flink to deliver cryptominers
Cyber Security BlogsResearchers devised a new attack that exploits misconfigurations in Apache Hadoop and Flink to deploy cryptocurrency miners. Cybersecurity researchers from cyber security firm Aqua have uncovered a new attack targeting Apache Hadoop and Flink applications. The attacks exploit misconfigurations in Apache Hadoop and Flink to deploy cryptocurrency cryptocurrency miners. The researchers reported that
- Published in RSS blog posts
TCE Exclusive: McDonald’s Data Breach 2024, a Continuation of Cybersecurity Dilemmas
Cyber Security Blogs In a developing story that underscores the persistent challenges of cybersecurity in the corporate world, an alleged new McDonald’s data breach was reported on Sunday, January 13, 2024. The information about this latest McDonald’s data breach surfaced on BreachForums, where a user named ‘euphoria’ claimed to have accessed a significant volume of
- Published in RSS blog posts









