An attacker targeted a CircleCI engineer’s laptop, causing a recent security incident
On Friday, DevOps platform CircleCI announced that it had experienced a data breach as a result of a “sophisticated attack” on December 16, 2022. The incident involved an employee’s laptop being compromised by unknown actors, who then used malware to steal the employee’s two-factor authentication-backed credentials to gain access to the company’s systems and data.
- Published in News
The majority of Cacti servers fail to patch critical vulnerabilities, leaving them vulnerable to attack
A significant portion of internet-exposed Cacti servers remain unpatched against a recently discovered critical security vulnerability that has been actively exploited in the wild, according to attack surface management platform Censys. Out of a total of 6,427 servers, only 26 were found to be running a patched version of Cacti (1.2.23 and 1.3.0). The vulnerability
- Published in News
Latest Gootkit malware attacks target Australian healthcare sector
A recent surge in attacks utilizing the Gootkit malware loader has targeted the Australian healthcare sector, according to cybersecurity firm Trend Micro. The malware, also known as Gootloader, is known for using search engine optimization (SEO) poisoning tactics to gain initial access. It typically works by compromising legitimate infrastructure and planting malware on those sites
- Published in News
Governments and military in APAC are targeted by a Dark Pink APT Group
A previously unknown actor of an “advanced persistent threat” (APT) is targeting government and military organizations in the Asia-Pacific region, according to a report from Singapore-based cybersecurity firm Group-IB.The group, which is tracking the campaign under the name “Dark Pink,” has attributed seven successful attacks to the adversarial collective between June and December 2022.The majority
- Published in News