Word Fence Intelligence’s security professionals found a malicious activity that intends to take advantage of a critical severity vulnerability in the WordPress plugin “Better Search Replace.” More than one million popular WordPress plugins and Better Search Replace installations have been installed globally. WordPress could replace databases and do more thorough…
An SBOM – abbreviated as software bill of materials, is a list of all the software components that collectively make up a particular software product. OS’s, libraries, firmware, drivers, licenses, and other things are listed in an SBOM. An SBOM is often referred to as a software’s “ingredients list” or…
From Google to JP Morgan, every brand is now using a Verified Mark Certificate. With the other advancements and trends in the digital ecosystem, VMC is now becoming a new requirement for brands to establish their legitimacy. But, still, some numerous organizations and professionals need clarification about what precisely a…
A WordPress Google Fonts Plugin vulnerability lets unauthorized users create and remove directories and launch cross-site scripting attacks. Millions of websites all around the world utilize WordPress as their content management system (CMS). It offers a wide range of plugins to expand its functionality and customize the user experience. Nevertheless,…
The year 2023 has been incredibly busy, and the year 2024 does not seem any better. These worries include the security flaws presented by artificial intelligence (AI) as well as the expanding regulatory obligations placed on chief information security officers (CISOs). Our security experts at Certera anticipate that the cybersecurity…
Maintaining the confidentiality and authenticity of online communication has become essential in today’s connected digital environment, as information moves freely over enormous networks. The Internet is not exempt from challenges; nothing extraordinary comes without difficulty. People unintentionally and intentionally post a lot of sensitive data online these days. But staying…
The final standards for quantum-safe algorithms were made available early in 2019. NIST has posted draft standards for the public to comment on. Draft standards for CRYSTALS-KYBER, CRYSTALS-DILITHIUM, and SPHINCS+ have been made available to the public by the National Institute of Standards and Technology of the United States. A…
14.7 million people are getting notice letters from mortgage giant Mr. Cooper informing them that a recent cyberattack resulted in the theft of their confidential information. Mr. Cooper checked and confirmed that the recent unexpected event has led to the compromise of both personal and financial information. According to the…
Over the past year, several developments in the cybersecurity and Public Key Infrastructure (PKI) sectors have forced organizations to assess and revise their security posture. Discussions on certificate validity periods, new laws, growing cyber threats facilitated by artificial intelligence, and actual instances of the catastrophic consequences that security incidents may…
As 2024 draws near, the cybersecurity sector is poised for profound changes. Cyberattacks are not only becoming more common but also more sophisticated, which is challenging long-held security beliefs. Staying ahead of the curve and prepared requires recognizing the following significant developments in our ever-changing digital environment. By researching the top 10…
The holiday season is around the corner, and so the attackers are ready with their tools to leverage vulnerabilities. In recent years, some of the most impactful cyberattacks have also been discovered during Christmas and New Year. If you are a CISO or a senior security professional, then you don’t…
Crypto agility can be defined as a system’s capacity and willingness to quickly switch from its present cryptographic primitives and algorithms to the latest and most advanced ones. RSA-based public-key systems that rely upon discrete logarithm issues and large integer factorization are vulnerable to hacking with the introduction of quantum…
Threat-hunting professionals at Hunters’ Team Axon have found a severe design issue in Google Workspace’s domain-wide delegation capability. This weakness might enable attackers to abuse current delegations, enabling privilege escalation and unauthorized access to Workspace APIs without Super Admin abilities. November 28, 2023, in Tel Aviv, Israel, and Boston, Massachusetts,…
In the intricate game of cybersecurity threats, loader malware is a cunning actor that slips into unwary systems and sets the stage for more advanced cyberattacks. This hostile thing is relatively modest but can prevent detection and cause devastation. Hidden behind the curtain, Loader malware is the first activator in…
Cybersecurity specialists at Securelist found that the DLL file known as hrserv.dll, a previously unidentified web shell, displays advanced capabilities, including unique encoding techniques for client connection and in-memory execution. Following the data analysis, comparable variations created in 2021 were found, suggesting a possible connection between these disparate instances of…