Researchers Warn of CatDDoS Botnet and DNSBomb DDoS Attack Technique

The threat actors behind the CatDDoS malware botnet have exploited over 80 known security flaws in various software over the past three months to infiltrate vulnerable devices and co-opt them into a botnet for conducting distributed denial-of-service (DDoS) attacks.
“CatDDoS-related gangs’ samples have used a large number of known vulnerabilities to deliver samples,” the QiAnXin XLab team 

The Hacker News – ​Read More

What is an Infosec Audit and Why Does Your Company Need One?

By Uzair Amir

Uncover IT security weaknesses and ensure compliance with infosec audits. Regular audits protect your data from breaches &…

This is a post from HackRead.com Read the original post: What is an Infosec Audit and Why Does Your Company Need One?

Hackread – Latest Cybersecurity, Tech, Crypto & Hacking News – ​Read More

Data Stolen From MediSecure for Sale on Dark Web

A threat actor is asking $50,000 for data allegedly stolen from Australian digital prescription services provider MediSecure.

The post Data Stolen From MediSecure for Sale on Dark Web appeared first on SecurityWeek.

SecurityWeek – ​Read More

2.8 Million Impacted by Data Breach at Prescription Services Firm Sav-Rx

Pharmacy prescription services provider Sav-Rx says the personal information of 2.8 million was stolen in a cyberattack.

The post 2.8 Million Impacted by Data Breach at Prescription Services Firm Sav-Rx appeared first on SecurityWeek.

SecurityWeek – ​Read More

Cops Are Just Trolling Cybercriminals Now

Police are using subtle psychological operations against ransomware gangs to sow distrust in their ranks—and trick them into emerging from the shadows.

Security Latest – ​Read More

Digital ID Adoption: Implementation and Security Concerns

As digital transformation accelerates, understanding how businesses are preparing for and implementing digital ID technologies is crucial for staying ahead in security and efficiency, according to Regula.

Cyware News – Latest Cyber News – ​Read More

SingCERT Warns Critical Vulnerabilities Found in Multiple WordPress Plugins

Security updates have been promptly released to address these critical vulnerabilities in multiple WordPress plugins. SingCERT reported 9 critical plugin vulnerabilities and shared the mitigation strategies to avoid exploration by threat actors.

Cyware News – Latest Cyber News – ​Read More

White House Announces Plans to Revamp Data Routing Security by Year-End

The augmentations concern the Border Gateway Protocol, a backbone data transmission algorithm that determines the optimal path for data packets to move across networks, said National Cyber Director Harry Coker

Cyware News – Latest Cyber News – ​Read More

Usage of TLS in DDNS Services leads to Information Disclosure in Multiple Vendors

When DDNS is combined with automatic TLS certificate generation using ACME clients, the public Certificate Transparency logs can be abused by attackers to find vulnerable devices en masse.

Cyware News – Latest Cyber News – ​Read More

Update: Threat Actors Created Rogue VMs to Evade Detection During December 2023 Attack on MITRE

According to the new update, threat actors exploited zero-day flaws in Ivanti Connect Secure (ICS) and created rogue virtual machines (VMs) within the organization’s VMware environment.

Cyware News – Latest Cyber News – ​Read More