Microsoft Warns of New INC Ransomware Targeting U.S. Healthcare Sector – OfficialSarkar

Microsoft Warns of New INC Ransomware Targeting U.S. Healthcare Sector – OfficialSarkar

Sep 19, 2024Ravie LakshmananHealthcare / Malware Microsoft has revealed that a financially motivated threat actor has been observed using a ransomware strain called INC for the first time to target the healthcare sector in the U.S. The tech giant’s threat intelligence team is tracking the activity under the name Vanilla Tempest (formerly DEV-0832). “Vanilla Tempest…

GitLab Patches Critical SAML Authentication Bypass Flaw in CE and EE Editions – OfficialSarkar

GitLab Patches Critical SAML Authentication Bypass Flaw in CE and EE Editions – OfficialSarkar

Sep 19, 2024Ravie LakshmananEnterprise Security / DevOps GitLab has released patches to address a critical flaw impacting Community Edition (CE) and Enterprise Edition (EE) that could result in an authentication bypass. The vulnerability is rooted in the ruby-saml library (CVE-2024-45409, CVSS score: 10.0), which could allow an attacker to log in as an arbitrary user…

New “Raptor Train” IoT Botnet Compromises Over 200,000 Devices Worldwide – OfficialSarkar

New “Raptor Train” IoT Botnet Compromises Over 200,000 Devices Worldwide – OfficialSarkar

Cybersecurity researchers have uncovered a never-before-seen botnet comprising an army of small office/home office (SOHO) and IoT devices that are likely operated by a Chinese nation-state threat actor called Flax Typhoon (aka Ethereal Panda or RedJuliett). The sophisticated botnet, dubbed Raptor Train by Lumen’s Black Lotus Labs, is believed to have been operational since at…

Chinese Engineer Charged in U.S. for Years-Long Cyber Espionage Targeting NASA and Military – OfficialSarkar

Chinese Engineer Charged in U.S. for Years-Long Cyber Espionage Targeting NASA and Military – OfficialSarkar

A Chinese national has been indicted in the U.S. on charges of conducting a “multi-year” spear-phishing campaign to obtain unauthorized access to computer software and source code created by the National Aeronautics and Space Administration (NASA), research universities, and private companies. Song Wu, 39, has been charged with 14 counts of wire fraud and 14…

North Korean Hackers Target Energy and Aerospace Industries with New MISTPEN Malware – OfficialSarkar

North Korean Hackers Target Energy and Aerospace Industries with New MISTPEN Malware – OfficialSarkar

Sep 18, 2024Ravie LakshmananCyber Espionage / Malware A North Korea-linked cyber-espionage group has been observed leveraging job-themed phishing lures to target prospective victims in energy and aerospace verticals and infect them with a previously undocumented backdoor dubbed MISTPEN. The activity cluster is being tracked by Google-owned Mandiant under the moniker UNC2970, which it said overlaps…

Chrome Introduces One-Time Permissions and Enhanced Safety Check for Safer Browsing – OfficialSarkar

Chrome Introduces One-Time Permissions and Enhanced Safety Check for Safer Browsing – OfficialSarkar

Sep 18, 2024Ravie LakshmananBrowser Security / Privacy Google has announced that it’s rolling out a new set of features to its Chrome browser that gives users more control over their data when surfing the internet and protects against online threats. “With the newest version of Chrome, you can take advantage of our upgraded Safety Check,…

GSMA Plans End-to-End Encryption for Cross-Platform RCS Messaging – OfficialSarkar

GSMA Plans End-to-End Encryption for Cross-Platform RCS Messaging – OfficialSarkar

Sep 18, 2024Ravie LakshmananMobile Security / Encryption The GSM Association, the governing body that oversees the development of the Rich Communications Services (RCS) protocol, on Tuesday, said it’s working towards implementing end-to-end encryption (E2EE) to secure messages sent between the Android and iOS ecosystems. “The next major milestone is for the RCS Universal Profile to…

Patch Issued for Critical VMware vCenter Flaw Allowing Remote Code Execution – OfficialSarkar

Patch Issued for Critical VMware vCenter Flaw Allowing Remote Code Execution – OfficialSarkar

Sep 18, 2024Ravie LakshmananVirtualization / Network Security Broadcom on Tuesday released updates to address a critical security flaw impacting VMware vCenter Server that could pave the way for remote code execution. The vulnerability, tracked as CVE-2024-38812 (CVSS score: 9.8), has been described as a heap-overflow vulnerability in the DCE/RPC protocol. “A malicious actor with network…

Meta to Train AI Models Using Public U.K. Facebook and Instagram Posts – OfficialSarkar

Meta to Train AI Models Using Public U.K. Facebook and Instagram Posts – OfficialSarkar

Sep 17, 2024Ravie LakshmananArtificial Intelligence / Regulatory Compliance Meta has announced that it will begin training its artificial intelligence (AI) systems using public content shared by adult users across Facebook and Instagram in the U.K. in the coming months. “This means that our generative AI models will reflect British culture, history, and idiom, and that…