CISA Adds ScienceLogic SL1 Vulnerability to Exploited Catalog After Active Zero-Day Attack – OfficialSarkar

CISA Adds ScienceLogic SL1 Vulnerability to Exploited Catalog After Active Zero-Day Attack – OfficialSarkar

Oct 22, 2024Ravie LakshmananVulnerability / Cyber Threat The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical security flaw impacting ScienceLogic SL1 to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation as a zero-day. The vulnerability in question, tracked as CVE-2024-9537 (CVSS v4 score: 9.3), refers to a bug…

Chinese Nation-State Hackers APT41 Hit Gambling Sector for Financial Gain – OfficialSarkar

The prolific Chinese nation-state actor known as APT41 (aka Brass Typhoon, Earth Baku, Wicked Panda, or Winnti) has been attributed to a sophisticated cyber attack targeting the gambling and gaming industry. “Over a period of at least six months, the attackers stealthily gathered valuable information from the targeted company including, but not limited to, network…

THN Cybersecurity Recap: Top Threats, Tools and News (Oct 14 – OfficialSarkar

Oct 21, 2024Mohit KumarCybersecurity / Weekly Recap Hi there! Here’s your quick update on the latest in cybersecurity. Hackers are using new tricks to break into systems we thought were secure—like finding hidden doors in locked houses. But the good news? Security experts are fighting back with smarter tools to keep data safe. Some big…

NMDC JOT Recruitment 2024: Apply Online for 81 153 JTO Post. [Career]

NMDC Limited, a Navratna Public Sector Enterprise under the Ministry of Steel, Government of India, has released the notification for the recruitment of 153 Junior Officers (Trainees) in various disciplines through its official website of NTPC. Candidates can also check all the details on the official Sarkari Result website SarkariExam.com All interested and eligible candidates…

Guide:  The Ultimate Pentest Checklist for Full-Stack Security – OfficialSarkar

Oct 21, 2024The Hacker NewsPenetration Testing / API Security Pentest Checklists Are More Important Than Ever Given the expanding attack surface coupled with the increasing sophistication of attacker tactics and techniques, penetration testing checklists have become essential for ensuring thorough assessments across an organization’s attack surface, both internal and external. By providing a structured approach,…

Researchers Discover Severe Security Flaws in Major E2EE Cloud Storage Providers – OfficialSarkar

Oct 21, 2024Ravie LakshmananEncryption / Data Protection Cybersecurity researchers have discovered severe cryptographic issues in various end-to-end encrypted (E2EE) cloud storage platforms that could be exploited to leak sensitive data. “The vulnerabilities range in severity: in many cases a malicious server can inject files, tamper with file data, and even gain direct access to plaintext,”…

NTPC Junior Executive Biomass Sarkari Result Online Form 2024 [Career]

National Thermal Power Corporation Limited (NTPC) has released the notification for the recruitment of 50 Junior Executive Biomass posts through its official website of NTPC. Candidates can also check all the details on the official Sarkari Result website SarkariExam.com All interested and eligible candidates who want to apply for this recruitment can read all the…

Hackers Exploit Roundcube Webmail XSS Vulnerability to Steal Login Credentials – OfficialSarkar

Oct 20, 2024Ravie LakshmananVulnerability / Email Security Unknown threat actors have been observed attempting to exploit a now-patched security flaw in the open-source Roundcube webmail software as part of a phishing attack designed to steal user credentials. Russian cybersecurity company Positive Technologies said it discovered last month that an email was sent to an unspecified…

Acronym Overdose – Navigating the Complex Data Security Landscape – OfficialSarkar

In the modern enterprise, data security is often discussed using a complex lexicon of acronyms—DLP, DDR, DSPM, and many others. While these acronyms represent critical frameworks, architectures, and tools for protecting sensitive information, they can also overwhelm those trying to piece together an effective security strategy. This article aims to demystify some of the most…

Crypt Ghouls Targets Russian Firms with LockBit 3.0 and Babuk Ransomware Attacks – OfficialSarkar

Oct 19, 2024Ravie LakshmananNetwork Security / Data Breach A nascent threat actor known as Crypt Ghouls has been linked to a set of cyber attacks targeting Russian businesses and government agencies with ransomware with the twin goals of disrupting business operations and financial gain. “The group under review has a toolkit that includes utilities such…