Cybersecurity News
-
Report Shows Over Half of Enterprise Web Assets Lack WAF Protection
A new report from CyCognito, a cybersecurity exposure platform, has uncovered a significant blind spot in enterprise web security: more than half of internet-facing enterprise assets are not protected by Web Application…
-
Plex Confirms Security Incident Involving User Account Data
Plex, a popular personal media server and streaming platform, has disclosed a recent security incident that exposed limited user account data. In an official announcement, the company stated that an unauthorized third…
-
Wiz Discovers Nx Supply Chain Attack Involving AI Malware
Researchers at Wiz, a cloud security software company, have released new findings on the recent compromise of the Nx JavaScript framework, revealing a multi-phase supply chain attack that affected thousands of users…
-
VirusTotal’s AI Code Insight Finds Hidden Malware Campaign in SVG Files
A recent cybersecurity report from VirusTotal, a leading online malware detection and analysis platform, reveals a sophisticated malware campaign delivered through seemingly harmless SVG files. These malicious files utilized advanced phishing techniques…
-
Shadowserver Highlights Elevated Activity in HTTP-Based Network Scans
The Shadowserver Foundation, a non-profit security organization, has identified a significant uptick in high-severity activities involving hosts performing HTTP-based scans across diverse networks worldwide. These activities often include attempts to detect and…
-
Unauthorized TLS Certificates Issued for Cloudflare’s 1.1.1.1 DNS Resolver
Recently, a security incident involving the unauthorized issuance of TLS certificates for 1.1.1.1, a widely used public DNS resolver, has come to light. Over nearly a year and a half, a Certificate…
-
Cloudflare Successfully Blocks Massive 11tb DDoS Attacks
In recent weeks, Cloudflare has been actively protecting its network from a surge of large-scale Distributed Denial of Service (DDoS) attacks. Security systems have autonomously identified and blocked hundreds of these malicious…
-
Jaguar Land Rover Posts Notice on Cybersecurity Incident Impacting Operations
Jaguar Land Rover (JLR), the British automotive manufacturer known for its luxury vehicles including Range Rover, Discovery, and Jaguar’s line of elegant vehicles, recently disclosed a significant cyber incident affecting its global…
-
Critical SQL Injection Vulnerability Patched in WordPress Membership Plugin
A critical security vulnerability discovered by Patchstack cybersecurity researchers within the widely-used Paid Membership Subscriptions WordPress plugin has recently been patched. This flaw could have allowed cybercriminals to access sensitive website databases…
