Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Security

CyberTalk with Bill and Robin: 22nd March 2023

1.Hold your horses: Ferrari extorted by RansomEXX The italian sportscar manufacturer carmaker was contacted by a threat actor (RansomEXX) with a demand related to certain client contact details. Upon receipt of the ransom demand, Ferrari immediately started an investigation, however extortion is underway and 7GB of sensitive data has been allegedly leaked. How could this have been prevented?

CyberTalk with Bill and Robin - 29th March 2023

The US Military Cyber Professional Association urged lawmakers this week to establish a U.S Cyber Force in this year's annual defence policy bill. It has been alleged that the current approach to Cybersecurity across the current 6 military branches has been divided, inconsistent, and inefficient, and that a dedicated security branch is needed. The Government is converging, why should you?

Killnet and AnonymousSudan DDoS attack Australian university websites, and threaten more attacks - here's what to do about it

Over the past 24 hours, Cloudflare has observed HTTP DDoS attacks targeting university websites in Australia. Universities were the first of several groups publicly targeted by the pro-Russian hacker group Killnet and their affiliate AnonymousSudan, as revealed in a recent Telegram post. The threat actors called for additional attacks against 8 universities, 10 airports, and 8 hospital websites in Australia beginning on Tuesday, March 28.

Sponsored Post

What is Application Security Orchestration and Correlation?

Gartner just released the Hype Cycle for Application Security 2022, and the main topic was the rise of application security orchestration and correlation (ASOC) tools. As Kondukto, we have been in "this neighbourhood" for more than 3 years; we want to take the chance to say something about "why you need an ASOC platform". As multiple security technologies need to be used at different stages of the modern software development lifecycle, the findings from various tools are creating an immense complexity for understaffed security teams.

Dridex malware, the banking trojan

Dridex, also known as Cridex or Bugat, is a banking Trojan that has been active since 2011. The malware is primarily used to steal sensitive information, such as login credentials and financial information, from victims. Dridex is known for its ability to evade detection by using dynamic configuration files and hiding its servers behind proxy layers.

Traffers and the growing threat against credentials

The Rising Threat of Traffers report, compiled by Outpost24’s Threat Intelligence team, KrakenLabs, provides a deep dive into the credential theft ecosystem, and encourages organizations to evaluate their security measures against these evolving threats. In recent years, the theft of credentials has evolved into a highly professionalized cybercriminal activity.