Technology

Critical Flaws Reported in Philips Vue PACS Medical Imaging Systems

Multiple security vulnerabilities have been disclosed in Philips Clinical Collaboration Platform Portal (aka Vue PACS), some of which could be exploited by an adversary to take control of an affected system. “Successful exploitation of these vulnerabilities could allow an unauthorized person or process to eavesdrop, view or modify data, gain system access, perform code execution, […]

Critical Flaws Reported in Philips Vue PACS Medical Imaging Systems Read More »

New SaaS Security Report Dives into the Concerns and Plans of CISOs in 2021

For years, security professionals have recognized the need to enhance SaaS security. However, the exponential adoption of Software-as-a-Service (SaaS) applications over 2020 turned slow-burning embers into a raging fire.  Organizations manage anywhere from thirty-five to more than a hundred applications. From collaboration tools like Slack and Microsoft Teams to mission-critical applications

New SaaS Security Report Dives into the Concerns and Plans of CISOs in 2021 Read More »

Hackers Use New Trick to Disable Macro Security Warnings in Malicious Office Files

While it’s a norm for phishing campaigns that distribute weaponized Microsoft Office documents to prompt victims to enable macros in order to trigger the infection chain directly, new findings indicate attackers are using non-malicious documents to disable security warnings prior to executing macro code to infect victims’ computers. In yet another instance of malware authors

Hackers Use New Trick to Disable Macro Security Warnings in Malicious Office Files Read More »

Critical Flaws Reported in Sage X3 Enterprise Management Software

Four security vulnerabilities have been uncovered in the Sage X3 enterprise resource planning (ERP) product, two of which could be chained together as part of an attack sequence to enable adversaries to execute malicious commands and take control of vulnerable systems. These issues were discovered by researchers from Rapid7, who notified Sage Group of their findings on

Critical Flaws Reported in Sage X3 Enterprise Management Software Read More »

Experts Uncover Malware Attacks Targeting Corporate Networks in Latin America

Cybersecurity researchers on Thursday took the wraps off a new, ongoing espionage campaign targeting corporate networks in Spanish-speaking countries, specifically Venezuela, to spy on its victims. Dubbed “Bandidos” by ESET owing to the use of an upgraded variant of Bandook malware, the primary targets of the threat actor are corporate networks in the South American

Experts Uncover Malware Attacks Targeting Corporate Networks in Latin America Read More »

How to Mitigate Microsoft Print Spooler Vulnerability – PrintNightmare

This week, PrintNightmare – Microsoft’s Print Spooler vulnerability (CVE-2021-34527) was upgraded from a ‘Low’ criticality to a ‘Critical’ criticality. This is due to a Proof of Concept published on GitHub, which attackers could potentially leverage for gaining access to Domain Controllers. As we reported earlier, Microsoft already released a patch in June 2021, but it

How to Mitigate Microsoft Print Spooler Vulnerability – PrintNightmare Read More »

Security Awareness Training is Broken. Human Risk Management (HRM) is the Fix

Humans are an organization’s strongest defence against evolving cyber threats, but security awareness training alone often isn’t enough to transform user behaviour. In this guide, usecure looks at why Human Risk Management (HRM) is the new fix for building a security-savvy workforce. Don’t be fooled… Businesses are investing more than ever into strengthening their employee

Security Awareness Training is Broken. Human Risk Management (HRM) is the Fix Read More »

SideCopy Hackers Target Indian Government Officials With New Malware

A cyber-espionage group has been observed increasingly targeting Indian government personnel as part of a broad campaign to infect victims with as many as four new custom remote access trojans (RATs), signaling a “boost in their development operations.” Attributed to a group tracked as SideCopy, the intrusions culminate in the deployment of a variety of

SideCopy Hackers Target Indian Government Officials With New Malware Read More »

WildPressure APT Emerges With New Malware Targeting Windows and macOS

A malicious campaign that has set its sights on industrial-related entities in the Middle East since 2019 has resurfaced with an upgraded malware toolset to strike both Windows and macOS operating systems, symbolizing an expansion in both its targets and its strategy around distributing threats. Russian cybersecurity firm attributed the attacks to an advanced persistent

WildPressure APT Emerges With New Malware Targeting Windows and macOS Read More »

Dozens of Vulnerable NuGet Packages Allow Attackers to Target .NET Platform

An analysis of off-the-shelf packages hosted on the NuGet repository has revealed 51 unique software components to be vulnerable to actively exploited, high-severity vulnerabilities, once again underscoring the threat posed by third-party dependencies to the software development process. In light of the growing number of cyber incidents that target the software supply chain, there is

Dozens of Vulnerable NuGet Packages Allow Attackers to Target .NET Platform Read More »