(10 votes, average: 4.90 out of 5)

WordPress Vulnerability “Replace Better Search” Affects Up to +1 Million Websites

Word Fence Intelligence’s security professionals found a malicious activity that intends to take advantage of a critical severity vulnerability in the WordPress plugin “Better Search Replace.” More than one million popular WordPress plugins and Better Search Replace installations have been installed globally. WordPress could replace databases and do more thorough…
(10 votes, average: 5.00 out of 5)

Ultimate Guide to SBOMs (Software Bill of Materials)

An SBOM – abbreviated as software bill of materials, is a list of all the software components that collectively make up a particular software product. OS’s, libraries, firmware, drivers, licenses, and other things are listed in an SBOM. An SBOM is often referred to as a software’s “ingredients list” or…
(15 votes, average: 5.00 out of 5)

What is a Verified Mark Certificate (VMC)? Everything to Know About

From Google to JP Morgan, every brand is now using a Verified Mark Certificate. With the other advancements and trends in the digital ecosystem, VMC is now becoming a new requirement for brands to establish their legitimacy. But, still, some numerous organizations and professionals need clarification about what precisely a…
(9 votes, average: 5.00 out of 5)

WordPress Google Fonts Plugin Vulnerability: Impacts Up to +300,000 Sites

A WordPress Google Fonts Plugin vulnerability lets unauthorized users create and remove directories and launch cross-site scripting attacks. Millions of websites all around the world utilize WordPress as their content management system (CMS). It offers a wide range of plugins to expand its functionality and customize the user experience. Nevertheless,…
(9 votes, average: 4.89 out of 5)

Essential CISO (Chief Information Security Officer) Checklist for 2024

The year 2023 has been incredibly busy, and the year 2024 does not seem any better. These worries include the security flaws presented by artificial intelligence (AI) as well as the expanding regulatory obligations placed on chief information security officers (CISOs). Our security experts at Certera anticipate that the cybersecurity…
(9 votes, average: 5.00 out of 5)

Revealing Important SSL Statistics 2023 For Secure Browsing in 2024

Maintaining the confidentiality and authenticity of online communication has become essential in today’s connected digital environment, as information moves freely over enormous networks. The Internet is not exempt from challenges; nothing extraordinary comes without difficulty. People unintentionally and intentionally post a lot of sensitive data online these days.  But staying…
(17 votes, average: 5.00 out of 5)

NIST First Standardised Post-Quantum Cryptography Algorithms Timeline for 2024

The final standards for quantum-safe algorithms were made available early in 2019. NIST has posted draft standards for the public to comment on. Draft standards for CRYSTALS-KYBER, CRYSTALS-DILITHIUM, and SPHINCS+ have been made available to the public by the National Institute of Standards and Technology of the United States. A…
(10 votes, average: 5.00 out of 5)

Expired SSL Certificates Are Risky: 14.7 Million People Affected by the Mr. Cooper Data Breach

14.7 million people are getting notice letters from mortgage giant Mr. Cooper informing them that a recent cyberattack resulted in the theft of their confidential information. Mr. Cooper checked and confirmed that the recent unexpected event has led to the compromise of both personal and financial information. According to the…
(11 votes, average: 5.00 out of 5)

Public Key Infrastructure Trends and Predictions for 2024

Over the past year, several developments in the cybersecurity and Public Key Infrastructure (PKI) sectors have forced organizations to assess and revise their security posture. Discussions on certificate validity periods, new laws, growing cyber threats facilitated by artificial intelligence, and actual instances of the catastrophic consequences that security incidents may…
(10 votes, average: 5.00 out of 5)

Top 10 Strategic Cybersecurity Trends & Predictions for 2024

As 2024 draws near, the cybersecurity sector is poised for profound changes. Cyberattacks are not only becoming more common but also more sophisticated, which is challenging long-held security beliefs. Staying ahead of the curve and prepared requires recognizing the following significant developments in our ever-changing digital environment. By researching the top 10…
(12 votes, average: 5.00 out of 5)

Proven Holiday Cybersecurity Tips for Organizations to Safeguard your Digital Presence

The holiday season is around the corner, and so the attackers are ready with their tools to leverage vulnerabilities. In recent years, some of the most impactful cyberattacks have also been discovered during Christmas and New Year. If you are a CISO or a senior security professional, then you don’t…
(13 votes, average: 5.00 out of 5)

What is Crypto-Agility? How do you Achieve it for a Quantum-Safe Business?

Crypto agility can be defined as a system’s capacity and willingness to quickly switch from its present cryptographic primitives and algorithms to the latest and most advanced ones. RSA-based public-key systems that rely upon discrete logarithm issues and large integer factorization are vulnerable to hacking with the introduction of quantum…
(9 votes, average: 5.00 out of 5)

Design Issue in Domain-Wide Delegation Could Make Google Workspace Vulnerable to Takeover

Threat-hunting professionals at Hunters’ Team Axon have found a severe design issue in Google Workspace’s domain-wide delegation capability. This weakness might enable attackers to abuse current delegations, enabling privilege escalation and unauthorized access to Workspace APIs without Super Admin abilities. November 28, 2023, in Tel Aviv, Israel, and Boston, Massachusetts,…
(9 votes, average: 4.89 out of 5)

Loader Malware Misuse Confidential System Data & Installs Additional Malware

In the intricate game of cybersecurity threats, loader malware is a cunning actor that slips into unwary systems and sets the stage for more advanced cyberattacks. This hostile thing is relatively modest but can prevent detection and cause devastation. Hidden behind the curtain, Loader malware is the first activator in…
(9 votes, average: 5.00 out of 5)

Security Alert: HrServ Web Shell is Hacked by APT, Breach of Windows Systems

Cybersecurity specialists at Securelist found that the DLL file known as hrserv.dll, a previously unidentified web shell, displays advanced capabilities, including unique encoding techniques for client connection and in-memory execution.  Following the data analysis, comparable variations created in 2021 were found, suggesting a possible connection between these disparate instances of…