<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>CISO Times</title><description>Practical tools, tested workflows and independent judgment for security leaders working under European regulatory requirements.</description><link>https://cisotimes.com/</link><language>en-gb</language><item><title>Security Policies Nobody Reads: Are We Just Writing PDFs for Auditors?</title><link>https://cisotimes.com/security-policies-nobody-reads-are-we-just-writing-pdfs-for-auditors/</link><guid isPermaLink="true">https://cisotimes.com/security-policies-nobody-reads-are-we-just-writing-pdfs-for-auditors/</guid><description>Have you lost the count of the security policies you have written, reviewed or &quot;inherited&quot; over the years?</description><pubDate>Fri, 12 Dec 2025 00:00:00 GMT</pubDate><category>information security policy</category><category>policies</category><author>Dimitris Gkoutzamanis</author></item><item><title>2026 National Security Predictions</title><link>https://cisotimes.com/2026-national-security-predictions/</link><guid isPermaLink="true">https://cisotimes.com/2026-national-security-predictions/</guid><description>As borders become irrelevant through remotely-launched attacks, the geopolitical landscape is rapidly growing in complexity and changing how countries define</description><pubDate>Mon, 08 Dec 2025 00:00:00 GMT</pubDate><author>Anthony J. Ferrante</author></item><item><title>Threat Actors See Bigger Return for Smaller Devices: The Growing Threat of Mobile Malware</title><link>https://cisotimes.com/threat-actors-see-bigger-return-for-smaller-devices-the-growing-threat-of-mobile-malware/</link><guid isPermaLink="true">https://cisotimes.com/threat-actors-see-bigger-return-for-smaller-devices-the-growing-threat-of-mobile-malware/</guid><description>Mobile devices have become indispensable to modern life, supporting both personal connectivity and professional operations. This ubiquity has made them</description><pubDate>Wed, 05 Nov 2025 00:00:00 GMT</pubDate><category>Malware</category><category>Mobile</category><author>David Youssef</author></item><item><title>While You’re Hunting Phish, Someone’s Bugging the Boardroom</title><link>https://cisotimes.com/while-youre-hunting-phish-someones-bugging-the-boardroom/</link><guid isPermaLink="true">https://cisotimes.com/while-youre-hunting-phish-someones-bugging-the-boardroom/</guid><description>There is a quiet war happening behind the noise of cybersecurity. Firewalls are roaring, alerts are pinging, dashboards are glowing red, and somewhere in the</description><pubDate>Mon, 20 Oct 2025 00:00:00 GMT</pubDate><category>espionage</category><category>Physical Security</category><author>Active Counter Measures</author></item><item><title>Insider Threat – From Detection to Prevention</title><link>https://cisotimes.com/insider-threat-from-detection-to-prevention/</link><guid isPermaLink="true">https://cisotimes.com/insider-threat-from-detection-to-prevention/</guid><description>From data leaks and cybersecurity incidents enabled by careless users to the malicious theft of intellectual property (IP) or even workplace violence, insider</description><pubDate>Wed, 23 Apr 2025 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>Insider Threats</category><author>Jenn Christian</author></item><item><title>Cryptocurrency Cybersecurity Threats: How Hacks, Exploits, and Scams Undermine the Future of Blockchain and DeFi</title><link>https://cisotimes.com/cryptocurrency-cybersecurity-threats-how-hacks-exploits-and-scams-undermine-the-future-of-blockchain-and-defi/</link><guid isPermaLink="true">https://cisotimes.com/cryptocurrency-cybersecurity-threats-how-hacks-exploits-and-scams-undermine-the-future-of-blockchain-and-defi/</guid><description>In recent years, we&apos;ve all seen cryptocurrencies grow from what felt like a niche, tech-lover experiment into a massive, complex financial system. It&apos;s been</description><pubDate>Sun, 12 Jan 2025 00:00:00 GMT</pubDate><category>Cryptocurrency</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>BayMark Health Services Data Breach: RansomHub Ransomware Group Claims Responsibility for Massive 1.5TB Data Theft</title><link>https://cisotimes.com/baymark-health-services-data-breach-ransomhub-ransomware-group-claims-responsibility-for-massive-1-5tb-data-theft/</link><guid isPermaLink="true">https://cisotimes.com/baymark-health-services-data-breach-ransomhub-ransomware-group-claims-responsibility-for-massive-1-5tb-data-theft/</guid><description>BayMark Health Services, Inc. (BayMark), the largest provider of medication-assisted treatment (MAT) for substance use disorders in North America, has</description><pubDate>Sat, 11 Jan 2025 00:00:00 GMT</pubDate><category>Data Breach</category><category>Healthcare</category><author>Dimitris Gkoutzamanis</author></item><item><title>Best Cybersecurity Certifications for Penetration Testing</title><link>https://cisotimes.com/best-cybersecurity-certifications-for-penetration-testing/</link><guid isPermaLink="true">https://cisotimes.com/best-cybersecurity-certifications-for-penetration-testing/</guid><description>A master list of penetration testing certifications. From beginner, to intermediate to advanced level.</description><pubDate>Sat, 11 Jan 2025 00:00:00 GMT</pubDate><category>Certifications</category><category>Cybersecurity</category><category>Hacking</category><category>Learning</category><category>Penetration Testing</category><author>Dimitris Gkoutzamanis</author></item><item><title>Critical Vulnerability on Samsung Devices Could Enable Remote Exploitation</title><link>https://cisotimes.com/critical-vulnerability-on-samsung-devices-could-enable-remote-exploitation/</link><guid isPermaLink="true">https://cisotimes.com/critical-vulnerability-on-samsung-devices-could-enable-remote-exploitation/</guid><description>A significant vulnerability has been uncovered in Samsung smartphones, linked to the Monkey&apos;s Audio (APE) decoder. The flaw, now resolved, was identified as</description><pubDate>Sat, 11 Jan 2025 00:00:00 GMT</pubDate><category>mobile devices</category><category>Samsung</category><category>Vulnerability</category><category>Zero-Day</category><author>Dimitris Gkoutzamanis</author></item><item><title>Darktrace to Acquire Cado Security, Strengthening Cloud Forensics and Cybersecurity Capabilities</title><link>https://cisotimes.com/darktrace-to-acquire-cado-security-strengthening-cloud-forensics-and-cybersecurity-capabilities/</link><guid isPermaLink="true">https://cisotimes.com/darktrace-to-acquire-cado-security-strengthening-cloud-forensics-and-cybersecurity-capabilities/</guid><description>Darktrace, a prominent leader in AI-driven cybersecurity solutions, has announced its intent to acquire Cado Security, a UK-based provider specializing in</description><pubDate>Sat, 11 Jan 2025 00:00:00 GMT</pubDate><category>Cado Security</category><category>Cloud Security</category><category>Darktrace</category><author>Dimitris Gkoutzamanis</author></item><item><title>The Overlooked Foundations of Cybersecurity Programs: Why Small Details Determine Strategic Success</title><link>https://cisotimes.com/the-overlooked-foundations-of-cybersecurity-programs-why-small-details-determine-strategic-success/</link><guid isPermaLink="true">https://cisotimes.com/the-overlooked-foundations-of-cybersecurity-programs-why-small-details-determine-strategic-success/</guid><description>When you think about information security strategies, what comes to mind? If you&apos;re like most cybersecurity professionals, you probably envision bold</description><pubDate>Mon, 06 Jan 2025 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>Strategy</category><author>Dimitris Gkoutzamanis</author></item><item><title>The Future of Technology: Microsoft CEO Satya Nadella’s Vision of a World Without Software Applications</title><link>https://cisotimes.com/the-future-of-technology-microsoft-ceo-satya-nadellas-vision-of-a-world-without-software-applications/</link><guid isPermaLink="true">https://cisotimes.com/the-future-of-technology-microsoft-ceo-satya-nadellas-vision-of-a-world-without-software-applications/</guid><description>Microsoft CEO Satya Nadella recently made waves in the tech industry with groundbreaking predictions about the future of software. His bold statements have</description><pubDate>Wed, 01 Jan 2025 00:00:00 GMT</pubDate><category>AI</category><category>Artifical Intelligence</category><category>Microsoft</category><category>Satya Nadella</category><author>Dimitris Gkoutzamanis</author></item><item><title>Ethical Hacking: From Misconceptions to Modern-Day Superheroes of Cybersecurity</title><link>https://cisotimes.com/ethical-hacking-from-misconceptions-to-modern-day-superheroes-of-cybersecurity/</link><guid isPermaLink="true">https://cisotimes.com/ethical-hacking-from-misconceptions-to-modern-day-superheroes-of-cybersecurity/</guid><description>Most people envision hacking as the dark arts of cybercrime, conjuring images of masked individuals exploiting others. However, within this stereotype lies a</description><pubDate>Wed, 30 Oct 2024 00:00:00 GMT</pubDate><category>Hacking</category><author>Louis Martin</author></item><item><title>Microsoft Faces Intense Scrutiny Over Cybersecurity Practices</title><link>https://cisotimes.com/microsoft-faces-intense-scrutiny-over-cybersecurity-practices/</link><guid isPermaLink="true">https://cisotimes.com/microsoft-faces-intense-scrutiny-over-cybersecurity-practices/</guid><description>In a pivotal hearing before the House Homeland Security Committee, Microsoft President Brad Smith faced rigorous questioning regarding the company&apos;s</description><pubDate>Sun, 16 Jun 2024 00:00:00 GMT</pubDate><category>DHS</category><category>Microsoft</category><author>Dimitris Gkoutzamanis</author></item><item><title>Micro-Segmentation: Balancing Security Benefits with Implementation Challenges</title><link>https://cisotimes.com/micro-segmentation-balancing-security-benefits-with-implementation-challenges/</link><guid isPermaLink="true">https://cisotimes.com/micro-segmentation-balancing-security-benefits-with-implementation-challenges/</guid><description>Micro-segmentation is a buzzword in the IT world, promising enhanced security and streamlined network management. It&apos;s a cutting-edge technique designed to</description><pubDate>Thu, 13 Jun 2024 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>IT Security</category><category>Micro-Segmentation</category><category>Network Segmentation</category><author>Dimitris Gkoutzamanis</author></item><item><title>The Rise of Autonomous GPT-4 Bots: Revolutionizing Cybersecurity with AI-Driven Exploits</title><link>https://cisotimes.com/the-rise-of-autonomous-gpt-4-bots-revolutionizing-cybersecurity-with-ai-driven-exploits/</link><guid isPermaLink="true">https://cisotimes.com/the-rise-of-autonomous-gpt-4-bots-revolutionizing-cybersecurity-with-ai-driven-exploits/</guid><description>In a demonstration of artificial intelligence capabilities, researchers have successfully infiltrated over half of their test websites using autonomous teams</description><pubDate>Mon, 10 Jun 2024 00:00:00 GMT</pubDate><category>AI</category><category>CVEs</category><category>Hacking</category><category>LLM</category><author>TheCISO</author></item><item><title>Free Microsoft Azure Courses to Boost Your IT Skills</title><link>https://cisotimes.com/free-microsoft-azure-courses-to-boost-your-it-skills/</link><guid isPermaLink="true">https://cisotimes.com/free-microsoft-azure-courses-to-boost-your-it-skills/</guid><description>Microsoft is providing a fantastic opportunity to expand your knowledge with a suite of free courses centered on Microsoft Azure and related technologies. By</description><pubDate>Mon, 06 May 2024 00:00:00 GMT</pubDate><category>Azure</category><category>Certification</category><category>Courses</category><category>Learning</category><category>Microsoft</category><author>Dimitris Gkoutzamanis</author></item><item><title>FTI Consulting Study Reveals Significant Communications Gaps Between CISOs and C-Suites Despite Increased Focus on Cybersecurity</title><link>https://cisotimes.com/fti-consulting-study-reveals-significant-communications-gaps-between-cisos-and-c-suites-despite-increased-focus-on-cybersecurity/</link><guid isPermaLink="true">https://cisotimes.com/fti-consulting-study-reveals-significant-communications-gaps-between-cisos-and-c-suites-despite-increased-focus-on-cybersecurity/</guid><description>FTI Consulting, Inc.&apos;s (NYSE: FCN) Cybersecurity &amp; Data Privacy Communications practice today released the second installment of its &quot;CISO Redefined&quot;</description><pubDate>Wed, 03 Apr 2024 00:00:00 GMT</pubDate><category>C-Suite</category><category>FTI Consulting</category><category>Survey</category><author>TheCISO</author></item><item><title>The “World’s Most Harmful Cyber Crime Group” Taken Down</title><link>https://cisotimes.com/the-worlds-most-harmful-cyber-crime-group-taken-down/</link><guid isPermaLink="true">https://cisotimes.com/the-worlds-most-harmful-cyber-crime-group-taken-down/</guid><description>The United Kingdom&apos;s National Crime Agency (NCA) unveiled that an initiative dubbed Operation Cronos has led to the acquisition of the LockBit ransomware&apos;s</description><pubDate>Tue, 20 Feb 2024 00:00:00 GMT</pubDate><category>Cybercrime</category><category>LockBit</category><category>National Crime Agency</category><category>NCA</category><category>Operation Cronos</category><category>Ransomware</category><category>StealBit</category><author>Dimitris Gkoutzamanis</author></item><item><title>CISA Warns on Known Exploited Vulnerability ‘Roundcube’</title><link>https://cisotimes.com/cisa-warns-on-known-exploited-vulnerability-roundcube/</link><guid isPermaLink="true">https://cisotimes.com/cisa-warns-on-known-exploited-vulnerability-roundcube/</guid><description>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) included a well-known vulnerability in its Known Exploited Vulnerabilities (KEV) catalog,</description><pubDate>Tue, 13 Feb 2024 00:00:00 GMT</pubDate><category>CISA</category><category>CVE-2023-43770</category><category>Roundcube</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>The Canadian Clampdown on Flipper Zero: A Move Against Auto Theft</title><link>https://cisotimes.com/the-canadian-clampdown-on-flipper-zero-a-move-against-auto-theft/</link><guid isPermaLink="true">https://cisotimes.com/the-canadian-clampdown-on-flipper-zero-a-move-against-auto-theft/</guid><description>In a decisive step aimed at curbing the escalating wave of car thefts, the Canadian government has set its sights on banning Flipper Zero, a device</description><pubDate>Tue, 13 Feb 2024 00:00:00 GMT</pubDate><category>Auto Theft</category><category>Flipper Zero</category><author>Dimitris Gkoutzamanis</author></item><item><title>HPE Hacked by Russian Group Following Microsoft Email Breach</title><link>https://cisotimes.com/hpe-hacked-by-russian-group-following-microsoft-email-breach/</link><guid isPermaLink="true">https://cisotimes.com/hpe-hacked-by-russian-group-following-microsoft-email-breach/</guid><description>Hewlett Packard Enterprise (HPE), a titan in the realm of enterprise technology, encountered a formidable cyber threat when its cloud-based email service fell</description><pubDate>Fri, 26 Jan 2024 00:00:00 GMT</pubDate><category>APT29</category><category>Cozy Bear</category><category>Hewlett Packard Enterprise</category><category>HPE</category><category>Midnight Blizzard</category><author>Dimitris Gkoutzamanis</author></item><item><title>SEC Blames SIM Swapping and Lack of MFA for X Account Hijacking</title><link>https://cisotimes.com/sec-blames-sim-swapping-and-lack-of-mfa-for-x-account-hijacking/</link><guid isPermaLink="true">https://cisotimes.com/sec-blames-sim-swapping-and-lack-of-mfa-for-x-account-hijacking/</guid><description>On a seemingly regular day in early January, the U.S. Securities and Exchange Commission (SEC), a bastion of financial regulation, faced an unforeseen digital</description><pubDate>Tue, 23 Jan 2024 00:00:00 GMT</pubDate><category>SEC</category><category>SIM Swapping</category><category>Twitter</category><category>X</category><author>TheCISO</author></item><item><title>CISA’s Pre-Ransomware Alerts Saved Organizations Millions in Damages</title><link>https://cisotimes.com/cisas-pre-ransomware-alerts-saved-organizations-millions-in-damages/</link><guid isPermaLink="true">https://cisotimes.com/cisas-pre-ransomware-alerts-saved-organizations-millions-in-damages/</guid><description>In recent years, ransomware attacks have become a critical threat to American organizations, causing significant disruptions across various sectors. These</description><pubDate>Sun, 21 Jan 2024 00:00:00 GMT</pubDate><category>CERT</category><category>CISA</category><category>JCDC</category><category>Joint Cyber Defense Collaborative</category><category>Ransomware</category><author>Dimitris Gkoutzamanis</author></item><item><title>FCC Expands Data Breach Notification Requirements</title><link>https://cisotimes.com/fcc-expands-data-breach-notification-requirements/</link><guid isPermaLink="true">https://cisotimes.com/fcc-expands-data-breach-notification-requirements/</guid><description>The Federal Communications Commission (FCC) has significantly bolstered the data breach notification and reporting requirements for telecommunications</description><pubDate>Sun, 21 Jan 2024 00:00:00 GMT</pubDate><category>Data Breach</category><category>FCC</category><author>TheCISO</author></item><item><title>Microsoft Executive Emails Hacked by Russian Intelligence Group</title><link>https://cisotimes.com/microsoft-executive-emails-hacked-by-russian-intelligence-group/</link><guid isPermaLink="true">https://cisotimes.com/microsoft-executive-emails-hacked-by-russian-intelligence-group/</guid><description>Microsoft disclosed a significant breach in its email system. This incident, orchestrated by Nobelium, a Russian intelligence group, targeted the software</description><pubDate>Sun, 21 Jan 2024 00:00:00 GMT</pubDate><category>APT29</category><category>Cozy Bear</category><category>Microsoft</category><category>Midnight Blizzard</category><category>Nobelium</category><author>Dimitris Gkoutzamanis</author></item><item><title>Top Impersonated Brands in Phishing</title><link>https://cisotimes.com/top-impersonated-brands-in-phishing/</link><guid isPermaLink="true">https://cisotimes.com/top-impersonated-brands-in-phishing/</guid><description>The final quarter of 2023 has unveiled a striking trend in the realm of digital deception. The latest CheckPoint Brand Phishing Report, meticulously compiled</description><pubDate>Sat, 20 Jan 2024 00:00:00 GMT</pubDate><category>Amazon</category><category>Apple</category><category>Google</category><category>Microsoft</category><category>Phishing</category><category>Study</category><author>Dimitris Gkoutzamanis</author></item><item><title>FBI and CISA Issue Warning on AndroxGh0st Malware</title><link>https://cisotimes.com/fbi-and-cisa-issue-warning-on-androxgh0st-malware/</link><guid isPermaLink="true">https://cisotimes.com/fbi-and-cisa-issue-warning-on-androxgh0st-malware/</guid><description>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have issued warnings about the proliferation of</description><pubDate>Fri, 19 Jan 2024 00:00:00 GMT</pubDate><category>Advisory</category><category>AndroxGh0st</category><category>AWS Security</category><category>CISA</category><category>FBI</category><category>Lacework</category><category>Malware</category><author>Dimitris Gkoutzamanis</author></item><item><title>Sophisticated Email Spoofing Attack Results in Multi-Million Dollar Theft from US Health Department</title><link>https://cisotimes.com/sophisticated-email-spoofing-attack-results-in-multi-million-dollar-theft-from-us-health-department/</link><guid isPermaLink="true">https://cisotimes.com/sophisticated-email-spoofing-attack-results-in-multi-million-dollar-theft-from-us-health-department/</guid><description>In a notable cybersecurity breach, hackers executed a complex spoofing attack on the US Department of Health and Human Services, defrauding the agency of</description><pubDate>Fri, 19 Jan 2024 00:00:00 GMT</pubDate><category>Data Breach</category><category>Email Spoofing</category><category>US Health Department</category><author>Dimitris Gkoutzamanis</author></item><item><title>Over 178,000 SonicWall Firewalls Vulnerable to Exploits</title><link>https://cisotimes.com/over-178000-sonicwall-firewalls-vulnerable-to-exploits/</link><guid isPermaLink="true">https://cisotimes.com/over-178000-sonicwall-firewalls-vulnerable-to-exploits/</guid><description>A recent investigation by cybersecurity experts at Bishop Fox has uncovered a significant vulnerability in SonicWall&apos;s next-generation firewalls (NGFW). This</description><pubDate>Tue, 16 Jan 2024 00:00:00 GMT</pubDate><category>Bishop Fox</category><category>Firewall</category><category>SonicWall</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>Ransomware Attacks in 2023: A Startling Surge and the Ongoing Battle</title><link>https://cisotimes.com/ransomware-attacks-in-2023-a-startling-surge-and-the-ongoing-battle/</link><guid isPermaLink="true">https://cisotimes.com/ransomware-attacks-in-2023-a-startling-surge-and-the-ongoing-battle/</guid><description>Cyberint, a forerunner in threat intelligence services, disclosed a staggering 55% increase in ransomware attacks compared to the previous year. This meteoric</description><pubDate>Tue, 16 Jan 2024 00:00:00 GMT</pubDate><category>ALPHV</category><category>Clop</category><category>Cyberint</category><category>LockBit</category><category>Ransomware</category><author>Dimitris Gkoutzamanis</author></item><item><title>Hacker Group Actively Exploiting a Critical Exchange Server Vulnerability</title><link>https://cisotimes.com/hacker-group-actively-exploiting-a-critical-exchange-server-vulnerability/</link><guid isPermaLink="true">https://cisotimes.com/hacker-group-actively-exploiting-a-critical-exchange-server-vulnerability/</guid><description>A significant threat has emerged from an activity group known as Forest Blizzard (STRONTIUM), originating from Russia. This group has been actively exploiting</description><pubDate>Wed, 06 Dec 2023 00:00:00 GMT</pubDate><category>CVE-2023-23397</category><category>DKWOC</category><category>Exchange Server</category><category>Forest Blizzard</category><category>Microsoft</category><category>Microsoft Incident Response</category><category>Polish Cyber Command</category><category>Russia</category><author>Dimitris Gkoutzamanis</author></item><item><title>How the LockBit Ransomware Compromised the World’s Largest Financial Institution</title><link>https://cisotimes.com/how-the-lockbit-ransomware-compromised-the-worlds-largest-financial-institution/</link><guid isPermaLink="true">https://cisotimes.com/how-the-lockbit-ransomware-compromised-the-worlds-largest-financial-institution/</guid><description>The recent LockBit ransomware attack on the Industrial &amp; Commercial Bank of China (ICBC) marks a significant escalation in cyber vulnerabilities within</description><pubDate>Wed, 06 Dec 2023 00:00:00 GMT</pubDate><category>ICBC</category><category>LockBit</category><category>Ransomware</category><category>U.S. Treasury</category><author>Dimitris Gkoutzamanis</author></item><item><title>Understanding the Escalating Threat of DoS Attacks: Insights from the ENISA Threat Landscape Report</title><link>https://cisotimes.com/understanding-the-escalating-threat-of-dos-attacks-insights-from-the-enisa-threat-landscape-report/</link><guid isPermaLink="true">https://cisotimes.com/understanding-the-escalating-threat-of-dos-attacks-insights-from-the-enisa-threat-landscape-report/</guid><description>In the ever-evolving world of cyber security, Denial-of-Service (DoS) attacks have emerged as a formidable threat to organizations across the globe. The</description><pubDate>Wed, 06 Dec 2023 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>DDoS</category><category>DoS</category><category>ENISA</category><category>Report</category><author>Dimitris Gkoutzamanis</author></item><item><title>Okta Security Breach More Serious Than Initially Estimated</title><link>https://cisotimes.com/okta-security-breach-more-serious-than-initially-estimated/</link><guid isPermaLink="true">https://cisotimes.com/okta-security-breach-more-serious-than-initially-estimated/</guid><description>The recent security breach at Okta, a leading identity-management software company, has revealed more extensive damage than initially reported. This</description><pubDate>Sat, 02 Dec 2023 00:00:00 GMT</pubDate><category>Data Breach</category><category>Identity Management</category><category>Okta</category><category>Supply Chain</category><author>Dimitris Gkoutzamanis</author></item><item><title>Exposed: How Romance Scams Steal Millions in Crypto</title><link>https://cisotimes.com/exposed-how-romance-scams-steal-millions-in-crypto/</link><guid isPermaLink="true">https://cisotimes.com/exposed-how-romance-scams-steal-millions-in-crypto/</guid><description>In an era where digital finance and online interactions intertwine, the phenomenon of &quot;pig butchering&quot; scams has emerged as a sinister evolution of</description><pubDate>Sat, 25 Nov 2023 00:00:00 GMT</pubDate><category>Pig Butchering</category><category>Scams</category><category>US Department of Justice</category><author>Dimitris Gkoutzamanis</author></item><item><title>Exposed Kubernetes Secrets Can Lead to Supply Chain Attacks</title><link>https://cisotimes.com/exposed-kubernetes-secrets-can-lead-to-supply-chain-attacks/</link><guid isPermaLink="true">https://cisotimes.com/exposed-kubernetes-secrets-can-lead-to-supply-chain-attacks/</guid><description>In the ever-evolving landscape of cybersecurity, a new concern has emerged that could jeopardize the safety of numerous organizations. This issue revolves</description><pubDate>Sat, 25 Nov 2023 00:00:00 GMT</pubDate><category>Github</category><category>Kubernetes</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>Hamas-linked APT Group Targeting Israeli Entities</title><link>https://cisotimes.com/hamas-linked-apt-group-targeting-israeli-entities/</link><guid isPermaLink="true">https://cisotimes.com/hamas-linked-apt-group-targeting-israeli-entities/</guid><description>In the ever-evolving landscape of cyber threats, a new player has emerged, signaling a significant shift in the tactics of Advanced Persistent Threat (APT)</description><pubDate>Sat, 25 Nov 2023 00:00:00 GMT</pubDate><category>Hamas</category><category>Israel</category><category>Malware</category><category>SysJoker</category><author>Dimitris Gkoutzamanis</author></item><item><title>Australia’s Proactive Stance Against State-Sponsored Cyber Threats</title><link>https://cisotimes.com/australias-proactive-stance-against-state-sponsored-cyber-threats/</link><guid isPermaLink="true">https://cisotimes.com/australias-proactive-stance-against-state-sponsored-cyber-threats/</guid><description>In an era where digital security is paramount, the Australian government has taken a proactive approach to fortify its IT infrastructure against</description><pubDate>Fri, 24 Nov 2023 00:00:00 GMT</pubDate><category>ASD</category><category>Australia</category><category>Australian Signals Directorate</category><category>Cybersecurity</category><category>Ransomware</category><author>Dimitris Gkoutzamanis</author></item><item><title>Botnet Spreads Mirai Malware via Zero-Day Vulnerabilities</title><link>https://cisotimes.com/botnet-spreads-mirai-malware-via-zero-day-vulnerabilities/</link><guid isPermaLink="true">https://cisotimes.com/botnet-spreads-mirai-malware-via-zero-day-vulnerabilities/</guid><description>In the ever-evolving landscape of cybersecurity threats, a new and active malware campaign has emerged, employing not one but two zero-day vulnerabilities.</description><pubDate>Fri, 24 Nov 2023 00:00:00 GMT</pubDate><category>Akamai</category><category>Malware</category><category>Mirai</category><category>Mirai-based botnets</category><category>Remote Code Execution</category><category>Zero-Day</category><author>Dimitris Gkoutzamanis</author></item><item><title>Breaking: Major Firms Hit by Alarming Ransomware Blitz!</title><link>https://cisotimes.com/breaking-major-firms-hit-by-alarming-ransomware-blitz/</link><guid isPermaLink="true">https://cisotimes.com/breaking-major-firms-hit-by-alarming-ransomware-blitz/</guid><description>In an era where digital data is as valuable as physical assets, the specter of cyber threats looms large. Two recent incidents at Sabre Insurance and Fidelity</description><pubDate>Fri, 24 Nov 2023 00:00:00 GMT</pubDate><category>ALPHV</category><category>BlackCat</category><category>Fidelity National Finance</category><category>LockBit</category><category>Ransomware</category><category>Sabre Insurance</category><author>TheCISO</author></item><item><title>Diamond Sleet: A Deep Dive into the Latest Supply Chain Cyberattack</title><link>https://cisotimes.com/diamond-sleet-a-deep-dive-into-the-latest-supply-chain-cyberattack/</link><guid isPermaLink="true">https://cisotimes.com/diamond-sleet-a-deep-dive-into-the-latest-supply-chain-cyberattack/</guid><description>Microsoft Threat Intelligence has exposed a sophisticated supply chain attack. Orchestrated by the North Korea-based cyber group, Diamond Sleet (formerly</description><pubDate>Fri, 24 Nov 2023 00:00:00 GMT</pubDate><category>Cyberlink</category><category>Diamond Sleet</category><category>North Korea</category><category>ZINC</category><author>Dimitris Gkoutzamanis</author></item><item><title>The Rising Menace of Scattered Spider Cyber-Attacks: A Comprehensive Analysis</title><link>https://cisotimes.com/the-rising-menace-of-scattered-spider-cyber-attacks-a-comprehensive-analysis/</link><guid isPermaLink="true">https://cisotimes.com/the-rising-menace-of-scattered-spider-cyber-attacks-a-comprehensive-analysis/</guid><description>In the ever-evolving world of cybercrime, law enforcement agencies in North America have recently raised alarms over a new and dangerous player: the Scattered</description><pubDate>Fri, 24 Nov 2023 00:00:00 GMT</pubDate><category>0ktapus</category><category>Octo Tempest</category><category>Scatter Swine</category><category>Scattered Spider</category><category>Scattered Spider group</category><category>UNC3944</category><author>Dimitris Gkoutzamanis</author></item><item><title>Urgent Alert: LockBit Ransomware Targets Citrix Users – Protect Your Network Now!</title><link>https://cisotimes.com/urgent-alert-lockbit-ransomware-targets-citrix-users-protect-your-network-now/</link><guid isPermaLink="true">https://cisotimes.com/urgent-alert-lockbit-ransomware-targets-citrix-users-protect-your-network-now/</guid><description>The recent discovery and exploitation of CVE-2023-4966, a significant vulnerability in Citrix NetScaler Gateway and ADC devices, underscores the critical</description><pubDate>Fri, 24 Nov 2023 00:00:00 GMT</pubDate><category>Citrix</category><category>CVE-2023-4966</category><category>Netscaler</category><category>Patching</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>New PoC for Apache ActiveMQ’s Critical Flaw Unleashes a Wave of Cyber Mayhem</title><link>https://cisotimes.com/new-poc-for-apache-activemqs-critical-flaw-unleashes-a-wave-of-cyber-mayhem/</link><guid isPermaLink="true">https://cisotimes.com/new-poc-for-apache-activemqs-critical-flaw-unleashes-a-wave-of-cyber-mayhem/</guid><description>The exploitation of a critical security flaw in Apache ActiveMQ, identified as CVE-2023-46604 with a CVSS score of 10.0, has raised significant concerns in</description><pubDate>Wed, 15 Nov 2023 00:00:00 GMT</pubDate><category>ActiveMQ</category><category>Apache</category><category>CVE-2023-46604</category><category>Malware</category><category>VulnCheck</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>Cybersecurity Incident Reports Reach All-Time High</title><link>https://cisotimes.com/cybersecurity-incident-reports-reach-all-time-high/</link><guid isPermaLink="true">https://cisotimes.com/cybersecurity-incident-reports-reach-all-time-high/</guid><description>The surge in reported cyber incidents to the UK&apos;s National Cyber Security Centre (NCSC), reaching an &quot;all-time high&quot; with a 64% increase in voluntary reports,</description><pubDate>Tue, 14 Nov 2023 00:00:00 GMT</pubDate><category>CVE-2023-3519</category><category>National Cyber Security Centre</category><category>NCSC</category><category>NCSC-UK</category><author>Dimitris Gkoutzamanis</author></item><item><title>LockBit Ransomware Group Leaks Alleged Boeing Files After Cyberattack</title><link>https://cisotimes.com/lockbit-ransomware-group-leaks-alleged-boeing-files-after-cyberattack/</link><guid isPermaLink="true">https://cisotimes.com/lockbit-ransomware-group-leaks-alleged-boeing-files-after-cyberattack/</guid><description>The LockBit ransomware group has reportedly leaked gigabytes of files claimed to be stolen from aerospace giant Boeing.</description><pubDate>Tue, 14 Nov 2023 00:00:00 GMT</pubDate><category>Boeing</category><category>Data Breach</category><category>Data Leak</category><category>LockBit</category><author>TheCISO</author></item><item><title>Report: Nuclear and Oil &amp;#038; Gas are Major Targets in 2024</title><link>https://cisotimes.com/report-nuclear-and-oil-gas-are-major-targets-in-2024/</link><guid isPermaLink="true">https://cisotimes.com/report-nuclear-and-oil-gas-are-major-targets-in-2024/</guid><description>The surge in ransomware operations targeting the energy sector, including nuclear facilities, is indeed alarming and underscores the evolving threat landscape</description><pubDate>Tue, 14 Nov 2023 00:00:00 GMT</pubDate><category>BlackCat</category><category>Critical Infrastructure</category><category>LockBit</category><category>Ransomware</category><author>Dimitris Gkoutzamanis</author></item><item><title>Chess.com Faces Data Breach: Over 800,000 User Records Leaked</title><link>https://cisotimes.com/chess-com-faces-data-breach-over-800000-user-records-leaked/</link><guid isPermaLink="true">https://cisotimes.com/chess-com-faces-data-breach-over-800000-user-records-leaked/</guid><description>A threat actor known as &apos;DrOne&apos; has claimed responsibility for leaking a scraped database from Chess.com, a popular online platform for chess enthusiasts,</description><pubDate>Sat, 11 Nov 2023 00:00:00 GMT</pubDate><category>Chess</category><category>Data Breach</category><category>Personal Data</category><author>Dimitris Gkoutzamanis</author></item><item><title>Class Action Lawsuit Targets Intel Over Handling of Downfall Vulnerability</title><link>https://cisotimes.com/class-action-lawsuit-targets-intel-over-handling-of-downfall-vulnerability/</link><guid isPermaLink="true">https://cisotimes.com/class-action-lawsuit-targets-intel-over-handling-of-downfall-vulnerability/</guid><description>Intel is facing a class-action lawsuit over its management of speculative execution vulnerabilities, specifically the recently disclosed Downfall attack</description><pubDate>Sat, 11 Nov 2023 00:00:00 GMT</pubDate><category>Intel</category><category>Meltdown</category><category>Spectre</category><category>Vulnerability</category><author>TheCISO</author></item><item><title>Over 69 Million Individuals Affected from MOVEit Cyberattack in the State of Maine</title><link>https://cisotimes.com/over-69-million-individuals-affected-from-moveit-cyberattack-in-the-state-of-maine/</link><guid isPermaLink="true">https://cisotimes.com/over-69-million-individuals-affected-from-moveit-cyberattack-in-the-state-of-maine/</guid><description>The State of Maine has become the latest victim to reveal the significant impact of a cyberattack targeting a zero-day vulnerability in Progress Software&apos;s</description><pubDate>Sat, 11 Nov 2023 00:00:00 GMT</pubDate><category>Data Breach</category><category>MOVEit</category><category>State of Maine</category><category>Vulnerability</category><category>zero day</category><author>Dimitris Gkoutzamanis</author></item><item><title>Ransomware Attack on China’s Biggest Bank Disrupts Treasury Market Trades</title><link>https://cisotimes.com/ransomware-attack-on-chinas-biggest-bank-disrupts-treasury-market-trades/</link><guid isPermaLink="true">https://cisotimes.com/ransomware-attack-on-chinas-biggest-bank-disrupts-treasury-market-trades/</guid><description>Wall Street is grappling with the repercussions of a ransomware attack on China&apos;s Industrial and Commercial Bank of China (ICBC), the nation&apos;s largest bank.</description><pubDate>Sat, 11 Nov 2023 00:00:00 GMT</pubDate><category>Commercial Bank of China</category><category>ICBC</category><category>Ransomware</category><category>Treasury Market</category><author>Dimitris Gkoutzamanis</author></item><item><title>New ‘Digital Risk Protection’ Report from BrandShield Reveals Companies Lose $2.1M on Average to Each Online Attack</title><link>https://cisotimes.com/new-digital-risk-protection-report-from-brandshield-reveals-companies-lose-2-1m-on-average-to-each-online-attack/</link><guid isPermaLink="true">https://cisotimes.com/new-digital-risk-protection-report-from-brandshield-reveals-companies-lose-2-1m-on-average-to-each-online-attack/</guid><description>(New York, NY) – BrandShield, a leader in global digital risk protection, today announced its Digital Risk Protection Report. In a survey of 200</description><pubDate>Fri, 10 Nov 2023 00:00:00 GMT</pubDate><category>BrandShield</category><category>Cyber Attacks</category><category>Digital Risk</category><category>Survey</category><author>TheCISO</author></item><item><title>Millenium RAT: Malware Sold on Github</title><link>https://cisotimes.com/millenium-rat-malware-sold-on-github/</link><guid isPermaLink="true">https://cisotimes.com/millenium-rat-malware-sold-on-github/</guid><description>Millenium-RAT, a sophisticated Remote Access Tool (RAT) for Windows systems is now available for purchase on GitHub. This sophisticated Remote Access Tool, or</description><pubDate>Thu, 09 Nov 2023 00:00:00 GMT</pubDate><category>Github</category><category>Malware</category><category>Millenium RAT</category><category>RAT</category><author>Dimitris Gkoutzamanis</author></item><item><title>Confluence Vulnerabilities Under Active Ransomware Exploitation</title><link>https://cisotimes.com/confluence-vulnerabilities-under-active-ransomware-exploitation/</link><guid isPermaLink="true">https://cisotimes.com/confluence-vulnerabilities-under-active-ransomware-exploitation/</guid><description>The findings from Rapid7&apos;s recent study regarding the targeting of vulnerabilities in Atlassian Confluence Servers by multiple ransomware groups are</description><pubDate>Wed, 08 Nov 2023 00:00:00 GMT</pubDate><category>Atlassian</category><category>Cerber Ransomware</category><category>Confluence</category><category>Ransomware</category><category>Rapid 7</category><author>TheCISO</author></item><item><title>Marina Bay Sands Casino Resort Confirms Data Security Breach</title><link>https://cisotimes.com/marina-bay-sands-casino-resort-confirms-data-security-breach/</link><guid isPermaLink="true">https://cisotimes.com/marina-bay-sands-casino-resort-confirms-data-security-breach/</guid><description>Singapore&apos;s Marina Bay Sands, a renowned casino resort, has unfortunately fallen victim to a data security breach, impacting an estimated 665,000 non-casino</description><pubDate>Wed, 08 Nov 2023 00:00:00 GMT</pubDate><category>Data Breach</category><category>Marina Bay Sands</category><category>Singapore</category><author>TheCISO</author></item><item><title>North Korea-Linked Lazarus Group Deploys New Malware Targeting Blockchain Engineers</title><link>https://cisotimes.com/north-korea-linked-lazarus-group-deploys-new-malware-targeting-blockchain-engineers/</link><guid isPermaLink="true">https://cisotimes.com/north-korea-linked-lazarus-group-deploys-new-malware-targeting-blockchain-engineers/</guid><description>The North Korea-linked Lazarus APT group has been observed employing a novel weapon in their arsenal - the KandyKorn macOS malware. This insidious tool has</description><pubDate>Sun, 05 Nov 2023 00:00:00 GMT</pubDate><category>blockchain</category><category>KandyKorn</category><category>Lazarus</category><category>Lazarus Group</category><category>Threat Actors</category><author>Dimitris Gkoutzamanis</author></item><item><title>Study Reveals: People, Process and Technology Challenges Limit Organizations’ Ability to Prevent Attacks</title><link>https://cisotimes.com/study-reveals-people-process-and-technology-challenges-limit-organizations-ability-to-prevent-attacks/</link><guid isPermaLink="true">https://cisotimes.com/study-reveals-people-process-and-technology-challenges-limit-organizations-ability-to-prevent-attacks/</guid><description>Tenable, the Exposure Management company, recently unveiled a comprehensive study that unveils the obstacles faced by cybersecurity and IT leaders as they</description><pubDate>Mon, 30 Oct 2023 00:00:00 GMT</pubDate><category>Cloud Security</category><category>Cybersecurity</category><category>Security Controls</category><category>Tenable</category><author>Dimitris Gkoutzamanis</author></item><item><title>Ukrainian Hackers Disrupt Russian Internet Services</title><link>https://cisotimes.com/ukrainian-hackers-disrupt-russian-internet-services/</link><guid isPermaLink="true">https://cisotimes.com/ukrainian-hackers-disrupt-russian-internet-services/</guid><description>Ukrainian hackers, known as the IT Army, executed a significant DDoS attack, disrupting Russian internet services in occupied territories. This article explores the attack&apos;s impact, recovery efforts, and the broader implications.</description><pubDate>Sun, 29 Oct 2023 00:00:00 GMT</pubDate><category>Crimea</category><category>DDoS</category><category>IT Army</category><category>KrimTelekom</category><category>Miranda-Media</category><category>MirTelekom</category><author>TheCISO</author></item><item><title>Why NIST included “Governance” in its CSF 2.0</title><link>https://cisotimes.com/why-nist-included-governance-in-its-csf-2-0/</link><guid isPermaLink="true">https://cisotimes.com/why-nist-included-governance-in-its-csf-2-0/</guid><description>The National Institute of Standards and Technology (NIST) has been at the forefront of promoting cybersecurity best practices and standards. One of its most</description><pubDate>Sun, 29 Oct 2023 00:00:00 GMT</pubDate><category>NIST</category><category>NIST CSF</category><category>Risk Management</category><category>Security Frameworks</category><author>Dimitris Gkoutzamanis</author></item><item><title>Understanding Privilege Escalation in Information Security</title><link>https://cisotimes.com/understanding-privilege-escalation-in-information-security/</link><guid isPermaLink="true">https://cisotimes.com/understanding-privilege-escalation-in-information-security/</guid><description>Privilege escalation is one of the core concepts of information security. It refers to the type of attack where a user gains higher levels of access over</description><pubDate>Sat, 28 Oct 2023 00:00:00 GMT</pubDate><category>access control</category><category>credential</category><category>privilege escalation</category><category>Social Engineering</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>Microsoft Sheds Light On The “Octo Tempest” Threat Actor</title><link>https://cisotimes.com/microsoft-sheds-light-on-the-octo-tempest-threat-actor/</link><guid isPermaLink="true">https://cisotimes.com/microsoft-sheds-light-on-the-octo-tempest-threat-actor/</guid><description>In a recent release, Microsoft has provided an extensive analysis of a relatively obscure yet highly dangerous threat actor.</description><pubDate>Fri, 27 Oct 2023 00:00:00 GMT</pubDate><category>ALPHV</category><category>BlackCat</category><category>Microsoft</category><category>MSP</category><category>Octo Tempest</category><category>Phishing</category><category>SIM Swaps</category><category>Social Engineering</category><author>Dimitris Gkoutzamanis</author></item><item><title>Experts released PoC exploit code for VMware Aria Operations for Logs flaw</title><link>https://cisotimes.com/experts-released-poc-exploit-code-for-vmware-aria-operations-for-logs-flaw/</link><guid isPermaLink="true">https://cisotimes.com/experts-released-poc-exploit-code-for-vmware-aria-operations-for-logs-flaw/</guid><description>VMware has become aware of a potentially critical security concern surrounding VMware Aria Operations for Logs, formerly known as vRealize Log Insight. A</description><pubDate>Wed, 25 Oct 2023 00:00:00 GMT</pubDate><category>Aria</category><category>Exploit</category><category>PoC</category><category>VMware</category><category>Vulnerability</category><author>TheCISO</author></item><item><title>Norway on High Alert as Cisco Zero-Days Compromise ‘Important Businesses’</title><link>https://cisotimes.com/norway-on-high-alert-as-cisco-zero-days-compromise-important-businesses/</link><guid isPermaLink="true">https://cisotimes.com/norway-on-high-alert-as-cisco-zero-days-compromise-important-businesses/</guid><description>In a recent security development, Norway&apos;s National Security Authority (NSM) issued a stark warning regarding the exploitation of two Cisco vulnerabilities,</description><pubDate>Wed, 25 Oct 2023 00:00:00 GMT</pubDate><category>Cisco</category><category>Cisco IOS XE</category><category>CVE</category><category>CVE-2023-20198</category><category>Exploit</category><category>Norway</category><category>Norway NSM</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>University of Michigan Data Breach: An In-Depth Analysis</title><link>https://cisotimes.com/university-of-michigan-data-breach-an-in-depth-analysis/</link><guid isPermaLink="true">https://cisotimes.com/university-of-michigan-data-breach-an-in-depth-analysis/</guid><description>The University of Michigan has recently confirmed a significant data breach that came to light in August 2023. This breach had far-reaching consequences and</description><pubDate>Wed, 25 Oct 2023 00:00:00 GMT</pubDate><category>Data Breach</category><category>Michigan</category><category>Personal Data</category><category>University</category><author>TheCISO</author></item><item><title>1Password’s Response to the Okta Breach</title><link>https://cisotimes.com/1passwords-response-to-the-okta-breach/</link><guid isPermaLink="true">https://cisotimes.com/1passwords-response-to-the-okta-breach/</guid><description>Recently, 1Password, a popular password management solution detected suspicious activity on its Okta instance on September 29. This event followed a support</description><pubDate>Tue, 24 Oct 2023 00:00:00 GMT</pubDate><category>0ktapus</category><category>1Password</category><category>Okta</category><category>Scatter Swine</category><category>Scattered Spider</category><category>UNC3944</category><author>TheCISO</author></item><item><title>Cybercriminals From Vietnam Exploiting Stolen Credentials</title><link>https://cisotimes.com/cybercriminals-from-vietnam-exploiting-stolen-credentials/</link><guid isPermaLink="true">https://cisotimes.com/cybercriminals-from-vietnam-exploiting-stolen-credentials/</guid><description>Facebook, the global social networking giant led by Mark Zuckerberg, has found itself in the midst of an alarming challenge. Recent headlines have shed light</description><pubDate>Tue, 24 Oct 2023 00:00:00 GMT</pubDate><category>Cookies</category><category>Cybercriminals</category><category>Facebook</category><category>Vietnam</category><author>TheCISO</author></item><item><title>A Quarter of Americans Have Had Their Health Data Compromised</title><link>https://cisotimes.com/a-quarter-of-americans-have-had-their-health-data-compromised/</link><guid isPermaLink="true">https://cisotimes.com/a-quarter-of-americans-have-had-their-health-data-compromised/</guid><description>Data breaches within the healthcare sector in the United States are becoming an alarmingly frequent occurrence, and it&apos;s a trend that demands our attention.</description><pubDate>Sat, 21 Oct 2023 00:00:00 GMT</pubDate><category>Data breaches</category><category>Healthcare</category><category>Patient Data</category><author>Dimitris Gkoutzamanis</author></item><item><title>Major Breakthrough: Arrest of Ragnar Locker Ransomware Developer</title><link>https://cisotimes.com/major-breakthrough-arrest-of-ragnar-locker-ransomware-developer/</link><guid isPermaLink="true">https://cisotimes.com/major-breakthrough-arrest-of-ragnar-locker-ransomware-developer/</guid><description>In a significant international law enforcement operation, the authorities managed to apprehend a malware developer linked to the notorious Ragnar Locker</description><pubDate>Sat, 21 Oct 2023 00:00:00 GMT</pubDate><author>Dimitris Gkoutzamanis</author></item><item><title>Malvertisers Use Google Ads to Trap Users Into Installing Malware</title><link>https://cisotimes.com/malvertisers-use-google-ads-to-trap-users-into-installing-malware/</link><guid isPermaLink="true">https://cisotimes.com/malvertisers-use-google-ads-to-trap-users-into-installing-malware/</guid><description>a new and cunning malvertising campaign has surfaced, employing Google Ads to ensnare users searching for popular software. Malwarebytes, the cybersecurity</description><pubDate>Sat, 21 Oct 2023 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>Deceptive Ads</category><category>Google Ads</category><category>malvertising</category><category>Malware</category><category>Punycode</category><category>Security Threats</category><category>Software</category><category>Threat Actors</category><author>TheCISO</author></item><item><title>Munchkin: BlackCat Ransomware’s Latest Tool</title><link>https://cisotimes.com/munchkin-blackcat-ransomwares-latest-tool/</link><guid isPermaLink="true">https://cisotimes.com/munchkin-blackcat-ransomwares-latest-tool/</guid><description>The BlackCat ransomware operators have proven to be a formidable adversary, consistently adapting and innovating their malicious activities. Their relentless</description><pubDate>Sat, 21 Oct 2023 00:00:00 GMT</pubDate><category>BlackCat</category><category>Malware</category><category>Munchkin</category><category>Palo Alto</category><category>Ransomware</category><author>Dimitris Gkoutzamanis</author></item><item><title>Vulnerability in TinyMCE Text Editor Can Allow Attacker Execute XSS Payloads</title><link>https://cisotimes.com/vulnerability-in-tinymce-text-editor-can-allow-attacker-execute-xss-payloads/</link><guid isPermaLink="true">https://cisotimes.com/vulnerability-in-tinymce-text-editor-can-allow-attacker-execute-xss-payloads/</guid><description>In the realm of text editors, TinyMCE has long been a popular choice, and on October 19, 2023, Tiny Technologies unveiled a significant update, version</description><pubDate>Sat, 21 Oct 2023 00:00:00 GMT</pubDate><category>CVE</category><category>CVE-2023-45818</category><category>CVE-2023-45819</category><category>Exploit</category><category>mXSS</category><category>TinyMCE</category><category>Vulnerability</category><category>XSS</category><author>Dimitris Gkoutzamanis</author></item><item><title>Attackers Exploiting Thousands of Cisco Devices</title><link>https://cisotimes.com/attackers-exploiting-thousands-of-cisco-devices/</link><guid isPermaLink="true">https://cisotimes.com/attackers-exploiting-thousands-of-cisco-devices/</guid><description>Tens of thousands of physical and virtual devices running Cisco networking software have been compromised as the result of a yet-unpatched vulnerability,</description><pubDate>Wed, 18 Oct 2023 00:00:00 GMT</pubDate><category>Cisco</category><category>Compromise</category><category>CVE-2023-20198</category><category>Cybersecurity</category><category>Data Breach</category><category>Internet Services</category><category>Networking</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>D-Link Data Breach Uncovered: Insights and Impact</title><link>https://cisotimes.com/d-link-data-breach-uncovered-insights-and-impact/</link><guid isPermaLink="true">https://cisotimes.com/d-link-data-breach-uncovered-insights-and-impact/</guid><description>In a recent development that sent shockwaves through the cybersecurity landscape, global networking equipment and technology powerhouse D-Link has confirmed a</description><pubDate>Wed, 18 Oct 2023 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>cybersecurity response</category><category>D-Link</category><category>Data Breach</category><category>Data Security</category><category>Phishing Attack</category><category>threat actor</category><author>Dimitris Gkoutzamanis</author></item><item><title>Google’s Passwordless Revolution: Passkey Login Security as Default</title><link>https://cisotimes.com/googles-passwordless-revolution-passkey-login-security-as-default/</link><guid isPermaLink="true">https://cisotimes.com/googles-passwordless-revolution-passkey-login-security-as-default/</guid><description>In a groundbreaking move set to commence on January 16, 2024, Google is poised to redefine its online services by adopting passkey login security as the</description><pubDate>Tue, 17 Oct 2023 00:00:00 GMT</pubDate><category>Face Scan</category><category>FIDO Alliance</category><category>Fingerprint Recognition</category><category>Gmail</category><category>Google</category><category>Online Security</category><category>Passkey Login</category><category>Passwordless Login</category><category>phishing attacks</category><category>SendGrid</category><category>Spam Reduction</category><author>TheCISO</author></item><item><title>Microsoft Launches Bug Bounty Program for AI-Powered Bing: Earn up to $15,000 for Reporting Vulnerabilities</title><link>https://cisotimes.com/microsoft-launches-bug-bounty-program-for-ai-powered-bing-earn-up-to-15000-for-reporting-vulnerabilities/</link><guid isPermaLink="true">https://cisotimes.com/microsoft-launches-bug-bounty-program-for-ai-powered-bing-earn-up-to-15000-for-reporting-vulnerabilities/</guid><description>In a proactive move to bolster the security of its innovative AI-powered Bing platform, Microsoft has unveiled a dedicated bug bounty program. This initiative</description><pubDate>Tue, 17 Oct 2023 00:00:00 GMT</pubDate><category>AI Integration</category><category>AI-Powered Bing</category><category>Bing Chat</category><category>Bing Integration</category><category>Bing Search</category><category>Bug Bounty</category><category>ChatGPT</category><category>Cybersecurity</category><category>M365 Bounty Program</category><category>Malware Distribution</category><category>Microsoft</category><category>OpenAI</category><category>Security Researchers</category><category>Vulnerability</category><author>TheCISO</author></item><item><title>Zero-Day Vulnerability in Cisco IOS XE Exploited in the Wild</title><link>https://cisotimes.com/zero-day-vulnerability-in-cisco-ios-xe-exploited-in-the-wild/</link><guid isPermaLink="true">https://cisotimes.com/zero-day-vulnerability-in-cisco-ios-xe-exploited-in-the-wild/</guid><description>On October 16, Cisco&apos;s Talos issued a stern warning about a zero-day vulnerability lurking in the Web User Interface (Web UI) feature of Cisco IOS XE. This</description><pubDate>Tue, 17 Oct 2023 00:00:00 GMT</pubDate><category>Cisco</category><category>Cisco Talos</category><category>CVE-2021-1435</category><category>CVE-2023-20198</category><category>Cybersecurity</category><category>Incident Response</category><category>Network Security</category><category>Security Advisory</category><category>Threat Actors</category><category>Vulnerability</category><category>Zero-Day</category><author>TheCISO</author></item><item><title>Hamas Hacked: IDF Issues Urgent Evacuation Warnings in Gaza</title><link>https://cisotimes.com/hamas-hacked-idf-issues-urgent-evacuation-warnings-in-gaza/</link><guid isPermaLink="true">https://cisotimes.com/hamas-hacked-idf-issues-urgent-evacuation-warnings-in-gaza/</guid><description>Since the outbreak of the conflict, the Israel Defense Forces (IDF) have been actively issuing evacuation warnings to residents of specific Gaza Strip</description><pubDate>Fri, 13 Oct 2023 00:00:00 GMT</pubDate><category>Al-Aqsa TV Channel Hack</category><category>Conflict Coverage</category><category>Cybersecurity</category><category>Evacuation Warnings</category><category>Gaza Strip</category><category>Hamas</category><category>IDF</category><category>Operation Swords of Iron</category><author>TheCISO</author></item><item><title>Unmasking the Vulnerability Exploits Fueling Ransomware Attacks</title><link>https://cisotimes.com/unmasking-the-vulnerability-exploits-fueling-ransomware-attacks/</link><guid isPermaLink="true">https://cisotimes.com/unmasking-the-vulnerability-exploits-fueling-ransomware-attacks/</guid><description>In the ever-evolving landscape of cyber threats, threat actors have an arsenal of methods to infiltrate an organization&apos;s infrastructure. While the tactics</description><pubDate>Fri, 13 Oct 2023 00:00:00 GMT</pubDate><category>CISA</category><category>CVEs</category><category>Cyber Threats</category><category>Cybersecurity</category><category>digital security</category><category>Microsoft</category><category>Ransomware</category><category>vulnerability exploits</category><author>Dimitris Gkoutzamanis</author></item><item><title>Millions of Data Records Exposure Discovered From Cybersecurity Researcher</title><link>https://cisotimes.com/millions-of-data-records-exposure-discovered-from-cybersecurity-researcher/</link><guid isPermaLink="true">https://cisotimes.com/millions-of-data-records-exposure-discovered-from-cybersecurity-researcher/</guid><description>In a recent cybersecurity discovery, Jeremiah Fowler, a dedicated researcher, came across a significant incident involving a renowned global CRM provider</description><pubDate>Wed, 11 Oct 2023 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>Data Exposure</category><author>TheCISO</author></item><item><title>Study: Key Trends and Challenges in Online Safety</title><link>https://cisotimes.com/study-key-trends-and-challenges-in-online-safety/</link><guid isPermaLink="true">https://cisotimes.com/study-key-trends-and-challenges-in-online-safety/</guid><description>In collaboration with the National Cybersecurity Alliance (NCA), CybSafe has recently conducted comprehensive research to delve into the evolving landscape of</description><pubDate>Fri, 06 Oct 2023 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>Report</category><author>Dimitris Gkoutzamanis</author></item><item><title>Cloud Lateral Movement Via Exploited SQL Servers</title><link>https://cisotimes.com/cloud-lateral-movement-via-exploited-sql-servers/</link><guid isPermaLink="true">https://cisotimes.com/cloud-lateral-movement-via-exploited-sql-servers/</guid><description>Recent findings by Microsoft security researchers have unveiled a concerning cyberattack campaign that involves lateral movement to a cloud environment</description><pubDate>Wed, 04 Oct 2023 00:00:00 GMT</pubDate><category>Best Practices</category><category>Cloud Identity</category><category>Cloud Security</category><category>Cybersecurity</category><category>Data Exfiltration</category><category>lateral movement</category><category>Microsoft Defender</category><category>SQL Server</category><category>Threat Detection</category><category>Vulnerability Mitigation</category><author>Dimitris Gkoutzamanis</author></item><item><title>Cybersecurity Alert: Hacktivist Group Siezes NATO Secrets, Motel One Hit by Ransomware</title><link>https://cisotimes.com/cybersecurity-alert-hacktivist-group-siezes-nato-secrets-motel-one-hit-by-ransomware/</link><guid isPermaLink="true">https://cisotimes.com/cybersecurity-alert-hacktivist-group-siezes-nato-secrets-motel-one-hit-by-ransomware/</guid><description>In a chilling cyber twist, the notorious hacktivist collective known as &quot;Hacktivist,&quot; or SiegedSec, has declared its possession of classified NATO documents.</description><pubDate>Wed, 04 Oct 2023 00:00:00 GMT</pubDate><category>ALPHV</category><category>Cyber Threats</category><category>Cybercrime</category><category>Cybersecurity</category><category>Data Breach</category><category>Encryption</category><category>European Union</category><category>Hacktivist</category><category>Motel One</category><category>NATO</category><category>Ransomware</category><author>Dimitris Gkoutzamanis</author></item><item><title>Data Transformation: Impact of Security Governance and Compliance</title><link>https://cisotimes.com/data-transformation-impact-of-security-governance-and-compliance/</link><guid isPermaLink="true">https://cisotimes.com/data-transformation-impact-of-security-governance-and-compliance/</guid><description>Data transformation occurs when raw data changes format, values, structure, or cleansing for human and computer interpretation to support organizational</description><pubDate>Wed, 20 Sep 2023 00:00:00 GMT</pubDate><category>Compliance</category><category>Data Transformation</category><category>Security Governance</category><author>Dr. Daniel Harrison</author></item><item><title>The Most Common Azure Security Misconfigurations</title><link>https://cisotimes.com/the-most-common-azure-security-misconfigurations/</link><guid isPermaLink="true">https://cisotimes.com/the-most-common-azure-security-misconfigurations/</guid><description>The rise of cloud environment usage especially Microsoft Azure, has also brought new challenges for CISOs and security professionals. Following best practices</description><pubDate>Thu, 14 Sep 2023 00:00:00 GMT</pubDate><category>Azure</category><category>Best Practices</category><category>Cloud</category><category>Cloud Security</category><category>Misconfiguration</category><author>Dimitris Gkoutzamanis</author></item><item><title>Understanding Security Risks in PDF Files</title><link>https://cisotimes.com/understanding-security-risks-in-pdf-files/</link><guid isPermaLink="true">https://cisotimes.com/understanding-security-risks-in-pdf-files/</guid><description>PDFs have become a universal format for sharing documents. However, threat actors have also recognized their potential as a vector for cyberattacks. In this</description><pubDate>Wed, 06 Sep 2023 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>Email Attachments</category><category>Email Security</category><category>Endpoint Security</category><category>Malicious PDFs</category><category>PDF Security</category><category>PDF Threats</category><category>Phishing Protection</category><author>Dimitris Gkoutzamanis</author></item><item><title>Security Does Not Have To Be Expensive: Open-Source Tools for the Security Operation Center (SOC)</title><link>https://cisotimes.com/security-does-not-have-to-be-expensive-open-source-tools-for-the-security-operation-center-soc/</link><guid isPermaLink="true">https://cisotimes.com/security-does-not-have-to-be-expensive-open-source-tools-for-the-security-operation-center-soc/</guid><description>Tools don&apos;t make a good engineer, but a good engineer can become great with the right tools.</description><pubDate>Tue, 05 Sep 2023 00:00:00 GMT</pubDate><category>Automation</category><category>Cybersecurity</category><category>cybersecurity tools</category><category>IDS</category><category>incident management</category><category>malware analysis</category><category>Network Security</category><category>SIEM</category><category>Threat Intelligence</category><author>Dimitris Gkoutzamanis</author></item><item><title>29 Essential Tools Every InfoSec Professional Must Know</title><link>https://cisotimes.com/29-essential-tools-every-infosec-professional-must-know/</link><guid isPermaLink="true">https://cisotimes.com/29-essential-tools-every-infosec-professional-must-know/</guid><description>In the realm of information security and cybersecurity, having the right tools can make all the difference. In this article, we&apos;ll introduce you to 29</description><pubDate>Fri, 01 Sep 2023 00:00:00 GMT</pubDate><category>Cyber Defense</category><category>Cyber Threats</category><category>Cybersecurity</category><category>Data Security</category><category>DNS Analysis</category><category>infosec</category><category>Network Security</category><category>Security Tools</category><category>Threat Intelligence</category><category>Vulnerability Assessment</category><author>Dimitris Gkoutzamanis</author></item><item><title>New Cyber Extortion Approach: “Pay Our Ransom or Your GDPR Fines”</title><link>https://cisotimes.com/new-cyber-extortion-approach-pay-our-ransom-or-your-gdpr-fines/</link><guid isPermaLink="true">https://cisotimes.com/new-cyber-extortion-approach-pay-our-ransom-or-your-gdpr-fines/</guid><description>ransomed</description><pubDate>Wed, 30 Aug 2023 00:00:00 GMT</pubDate><category>GDPR</category><category>Ransomware</category><author>Dimitris Gkoutzamanis</author></item><item><title>NIST Announces First Four Quantum-Resistant Cryptographic Algorithms</title><link>https://cisotimes.com/nist-announces-first-four-quantum-resistant-cryptographic-algorithms/</link><guid isPermaLink="true">https://cisotimes.com/nist-announces-first-four-quantum-resistant-cryptographic-algorithms/</guid><description>In an era where quantum computers loom on the horizon, safeguarding our digital privacy becomes an ever-pressing concern. The U.S. Department of Commerce&apos;s</description><pubDate>Thu, 24 Aug 2023 00:00:00 GMT</pubDate><category>Cryptography</category><category>Data Security</category><category>Encryption</category><category>NIST</category><category>Post-quantum cryptography</category><category>Privacy</category><category>quantum computing</category><category>Quantum-resistant algorithms</category><author>Dimitris Gkoutzamanis</author></item><item><title>Navigating Cloud Security Solutions: Exploring the Differences Between CASB and SASE</title><link>https://cisotimes.com/navigating-cloud-security-solutions-exploring-the-differences-between-casb-and-sase/</link><guid isPermaLink="true">https://cisotimes.com/navigating-cloud-security-solutions-exploring-the-differences-between-casb-and-sase/</guid><description>In an era marked by digital transformation and cloud-first strategies, ensuring the security of sensitive data and maintaining regulatory compliance has</description><pubDate>Tue, 22 Aug 2023 00:00:00 GMT</pubDate><category>CASB</category><category>Cloud Access Security Broker</category><category>Cloud Security</category><category>DLP</category><category>SASE</category><category>Secure Access Service Edge</category><author>Dimitris Gkoutzamanis</author></item><item><title>Android Updates Patching Over 40 Vulnerabilities</title><link>https://cisotimes.com/android-updates-patching-over-40-vulnerabilities/</link><guid isPermaLink="true">https://cisotimes.com/android-updates-patching-over-40-vulnerabilities/</guid><description>Android has released its August Security patches, addressing over 40 vulnerabilities.</description><pubDate>Thu, 10 Aug 2023 00:00:00 GMT</pubDate><category>Android</category><category>Elevation of Privileges</category><category>Information Disclosure</category><category>Kernel</category><category>Mobile Security</category><category>Patching</category><category>Remote Code Execution</category><category>Security Updates</category><author>TheCISO</author></item><item><title>Utilizing AI for Enhanced Cybersecurity: White House Launches Contest to Detect and Resolve Software Vulnerabilities</title><link>https://cisotimes.com/utilizing-ai-for-enhanced-cybersecurity-white-house-launches-contest-to-detect-and-resolve-software-vulnerabilities/</link><guid isPermaLink="true">https://cisotimes.com/utilizing-ai-for-enhanced-cybersecurity-white-house-launches-contest-to-detect-and-resolve-software-vulnerabilities/</guid><description>The White House has introduced a unique competition aimed at encouraging cybersecurity researchers to employ artificial intelligence (AI) in identifying and</description><pubDate>Thu, 10 Aug 2023 00:00:00 GMT</pubDate><category>AI</category><category>Artifical Intelligence</category><category>DARPA</category><category>DEFCON</category><category>Open Source</category><author>TheCISO</author></item><item><title>CrowdStrike Unveils New Counter Adversary Operations Team to Thwart Modern Breaches</title><link>https://cisotimes.com/crowdstrike-unveils-new-counter-adversary-operations-team-to-thwart-modern-breaches/</link><guid isPermaLink="true">https://cisotimes.com/crowdstrike-unveils-new-counter-adversary-operations-team-to-thwart-modern-breaches/</guid><description>On August 8, 2023, CrowdStrike, the renowned American cybersecurity technology company, introduced its latest initiative, the &quot;CrowdStrike Falcon</description><pubDate>Wed, 09 Aug 2023 00:00:00 GMT</pubDate><category>Breach</category><category>crowdstrike</category><category>Falcon</category><category>Threat Hunting</category><category>Threat Intelligence</category><author>Dimitris Gkoutzamanis</author></item><item><title>How to Protect Your Business From a Little Known, Shockingly Simple Hacking Technique</title><link>https://cisotimes.com/how-to-protect-your-business-from-a-little-known-shockingly-simple-hacking-technique/</link><guid isPermaLink="true">https://cisotimes.com/how-to-protect-your-business-from-a-little-known-shockingly-simple-hacking-technique/</guid><description>&quot;Search Engine Hacking,&quot; also called &quot;Google dorking,&quot; has quickly become a favorite technique of hackers to find and expose private or sensitive information</description><pubDate>Wed, 09 Aug 2023 00:00:00 GMT</pubDate><category>Google Dorking</category><category>Google Search</category><category>Hacking</category><category>Open Source Intelligence</category><category>OWLsec</category><author>Star Kashman</author></item><item><title>Microsoft Addresses 74 Software Vulnerabilities in August 2023 Update Cycle</title><link>https://cisotimes.com/microsoft-addresses-74-software-vulnerabilities-in-august-2023-update-cycle/</link><guid isPermaLink="true">https://cisotimes.com/microsoft-addresses-74-software-vulnerabilities-in-august-2023-update-cycle/</guid><description>In its recent effort to enhance digital security, Microsoft has taken action to rectify a total of 74 vulnerabilities present in its software through the</description><pubDate>Wed, 09 Aug 2023 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>Microsoft</category><category>Patching</category><category>Software Patching</category><category>Vulnerability</category><author>TheCISO</author></item><item><title>The Top 10 Countries Facing Data Breaches: A Comprehensive Analysis</title><link>https://cisotimes.com/the-top-10-countries-facing-data-breaches-a-comprehensive-analysis/</link><guid isPermaLink="true">https://cisotimes.com/the-top-10-countries-facing-data-breaches-a-comprehensive-analysis/</guid><description>In recent years, the onslaught of cybersecurity attacks has intensified dramatically, culminating in a staggering 156% surge in security breaches worldwide</description><pubDate>Sun, 06 Aug 2023 00:00:00 GMT</pubDate><category>Data Breach</category><category>Report</category><category>SurfShark</category><category>Threats</category><author>Dimitris Gkoutzamanis</author></item><item><title>Chrome Security Update: 17 New Security Fixes</title><link>https://cisotimes.com/chrome-security-update-17-new-security-fixes/</link><guid isPermaLink="true">https://cisotimes.com/chrome-security-update-17-new-security-fixes/</guid><description>Google has published a security update for Chrome, updating the Stable channel for Mac and Linux to 115.0.5790.170 and 115.0.5790.170/.171 for Windows.</description><pubDate>Fri, 04 Aug 2023 00:00:00 GMT</pubDate><category>Bug Bounty</category><category>Chrome</category><category>Google</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>Cyber Warfare Escalates as Finland Joins NATO: Insights from Cybersecurity Expert</title><link>https://cisotimes.com/cyber-warfare-escalates-as-finland-joins-nato-insights-from-cybersecurity-expert/</link><guid isPermaLink="true">https://cisotimes.com/cyber-warfare-escalates-as-finland-joins-nato-insights-from-cybersecurity-expert/</guid><description>Since Finland&apos;s decision to join NATO, the country has witnessed an alarming surge in ransomware attacks.</description><pubDate>Fri, 04 Aug 2023 00:00:00 GMT</pubDate><category>Cyber Defense</category><category>Cyber Threats</category><category>Cyber Warfare</category><category>Finland</category><category>Geopolitics</category><category>NATO</category><category>NCSC</category><category>Ransomware</category><category>Russia</category><category>Ukraine</category><author>TheCISO</author></item><item><title>NodeStealer 2.0: Cryptocurrency Wallets and Facebook Business Accounts Under Siege</title><link>https://cisotimes.com/nodestealer-2-0-cryptocurrency-wallets-and-facebook-business-accounts-under-siege/</link><guid isPermaLink="true">https://cisotimes.com/nodestealer-2-0-cryptocurrency-wallets-and-facebook-business-accounts-under-siege/</guid><description>A discovery by Palo Alto Network Unit 42 has brought to light an advanced phishing campaign involving the NodeStealer 2.0, a Python variant of the infamous</description><pubDate>Wed, 02 Aug 2023 00:00:00 GMT</pubDate><category>Cryptocurrency</category><category>Facebook</category><category>Malware</category><category>nodestealer</category><category>Phishing</category><author>TheCISO</author></item><item><title>WikiLoader: New Malware-as-a-Service Targets Italian Organizations</title><link>https://cisotimes.com/wikiloader-new-malware-as-a-service-targets-italian-organizations/</link><guid isPermaLink="true">https://cisotimes.com/wikiloader-new-malware-as-a-service-targets-italian-organizations/</guid><description>Italian organizations are facing a significant threat from a phishing campaign unleashed by threat actors deploying a potent new malware called WikiLoader.</description><pubDate>Wed, 02 Aug 2023 00:00:00 GMT</pubDate><category>Malware</category><category>Phishing</category><category>Ursnif</category><category>WikiLoader</category><author>TheCISO</author></item><item><title>Splunk Vulnerability May Allow Attackers To Execute Malicious Code</title><link>https://cisotimes.com/splunk-vulnerability-may-allow-attackers-to-execute-malicious-code/</link><guid isPermaLink="true">https://cisotimes.com/splunk-vulnerability-may-allow-attackers-to-execute-malicious-code/</guid><description>Splunk, a leading security solution, has recently uncovered a critical vulnerability within its powerful Security Orchestration, Automation, and Response</description><pubDate>Tue, 01 Aug 2023 00:00:00 GMT</pubDate><category>ANSI Escape Codes</category><category>CVE-2023-3997</category><category>CVSS Score</category><category>Malicious Code Execution</category><category>Security Advisory</category><category>Splunk</category><category>Splunk SOAR</category><category>Terminal Application</category><category>Unauthenticated Log Injection</category><category>Vulnerability</category><author>TheCISO</author></item><item><title>Spyware App Compromised Over 60,000 Android Devices to Steal Sensitive Data</title><link>https://cisotimes.com/spyware-app-compromised-over-60000-android-devices-to-steal-sensitive-data/</link><guid isPermaLink="true">https://cisotimes.com/spyware-app-compromised-over-60000-android-devices-to-steal-sensitive-data/</guid><description>A dangerous spyware application called &quot;Spyhide&quot; has targeted and compromised over 60,000 Android devices worldwide, allowing the attackers to steal sensitive</description><pubDate>Tue, 01 Aug 2023 00:00:00 GMT</pubDate><category>Android Devices</category><category>Cybersecurity</category><category>Data Breach</category><category>Data Leak</category><category>Privacy</category><category>German Hosting Provider</category><category>Hacking</category><category>Iranian Developers</category><category>Location History</category><category>Photos</category><category>Sensitive Data</category><category>Spyhide</category><category>Spyware</category><category>Spyware Detection</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>Millions Vanish As Alphapo Hot Wallets Hacked</title><link>https://cisotimes.com/millions-vanish-as-alphapo-hot-wallets-hacked/</link><guid isPermaLink="true">https://cisotimes.com/millions-vanish-as-alphapo-hot-wallets-hacked/</guid><description>On July 22, a staggering $31 million was stealthily siphoned from Alphapo&apos;s hot wallets on the Ethereum blockchain. While the extent of Bitcoin theft remains</description><pubDate>Mon, 24 Jul 2023 00:00:00 GMT</pubDate><category>Alphapo</category><category>Bitcoin</category><category>Conic Finance</category><category>Cryptocurrency</category><category>DeFi</category><category>Ethereum</category><category>Hacking</category><category>hot wallets</category><category>HypeDrop</category><category>Cybersecurity</category><author>TheCISO</author></item><item><title>DDoS Botnets Exploiting Critical Flaw in Zyxel Devices Worldwide</title><link>https://cisotimes.com/ddos-botnets-exploiting-critical-flaw-in-zyxel-devices-worldwide/</link><guid isPermaLink="true">https://cisotimes.com/ddos-botnets-exploiting-critical-flaw-in-zyxel-devices-worldwide/</guid><description>Security researchers at Fortinet FortiGuard Labs have issued a serious warning about the increasing threat posed by various DDoS botnets, all taking advantage</description><pubDate>Sun, 23 Jul 2023 00:00:00 GMT</pubDate><category>Botnet</category><category>Command Injection</category><category>CVE-2023-28771</category><category>Cybersecurity</category><category>DDoS botnets</category><category>Katana botnet</category><category>Mirai-based botnets</category><category>Vulnerability</category><category>Zyxel devices</category><author>TheCISO</author></item><item><title>Google’s VirusTotal Leak Exposes Defense and Intelligence Employees</title><link>https://cisotimes.com/googles-virustotal-leak-exposes-defense-and-intelligence-employees/</link><guid isPermaLink="true">https://cisotimes.com/googles-virustotal-leak-exposes-defense-and-intelligence-employees/</guid><description>In an unintentional breach of cybersecurity, Google&apos;s VirusTotal platform disclosed the identities and email addresses of hundreds of individuals employed in</description><pubDate>Fri, 21 Jul 2023 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>Data Breach</category><category>Data Protection</category><category>Defense Employees</category><category>Google</category><category>Intelligence Agencies</category><category>Phishing Attempts</category><category>VirusTotal</category><author>Dimitris Gkoutzamanis</author></item><item><title>Insights From A CISO 2023 Global Survey</title><link>https://cisotimes.com/insights-from-a-ciso-2023-global-survey/</link><guid isPermaLink="true">https://cisotimes.com/insights-from-a-ciso-2023-global-survey/</guid><description>In today&apos;s rapidly evolving technological landscape, the role of chief information security officers (CISOs) is facing new challenges and opportunities. As</description><pubDate>Sun, 16 Jul 2023 00:00:00 GMT</pubDate><category>CISO</category><category>Cybersecurity</category><category>Management</category><category>Survey</category><author>Dimitris Gkoutzamanis</author></item><item><title>Moveit Data Breach Hits Fidelity: More Than 371,000 Retirement Plan Participants Data Exposed</title><link>https://cisotimes.com/moveit-data-breach-hits-fidelity-more-than-371000-retirement-plan-participants-data-exposed/</link><guid isPermaLink="true">https://cisotimes.com/moveit-data-breach-hits-fidelity-more-than-371000-retirement-plan-participants-data-exposed/</guid><description>Pension Benefit Information LLC, operating as PBI Research Services, has disclosed a serious incident of data breach, leaving the personal information of</description><pubDate>Sun, 16 Jul 2023 00:00:00 GMT</pubDate><category>Data Breach</category><category>Fidelity</category><category>MOVEit</category><category>PBI</category><category>PBI Researchh Services</category><author>TheCISO</author></item><item><title>Russia’s State TV Hacked: Millions Told “The Hour Of Reckoning Has Come” – In Ukrainian</title><link>https://cisotimes.com/russias-state-tv-hacked-millions-told-the-hour-of-reckoning-has-come-in-ukrainian/</link><guid isPermaLink="true">https://cisotimes.com/russias-state-tv-hacked-millions-told-the-hour-of-reckoning-has-come-in-ukrainian/</guid><description>Russian leader Vladimir Putin faced a significant blow as his State TV channel fell victim to a humiliating primetime hack.</description><pubDate>Sun, 16 Jul 2023 00:00:00 GMT</pubDate><category>Deepfake</category><category>Hacking</category><category>Russia</category><category>State TV</category><category>Ukraine</category><author>TheCISO</author></item><item><title>BlackLotus UEFI Bootkit: How a Free UEFI Malware Code Puts Windows Machines at Risk</title><link>https://cisotimes.com/blacklotus-uefi-bootkit-how-a-free-uefi-malware-code-puts-windows-machines-at-risk/</link><guid isPermaLink="true">https://cisotimes.com/blacklotus-uefi-bootkit-how-a-free-uefi-malware-code-puts-windows-machines-at-risk/</guid><description>In October of the previous year, a nefarious bootkit named BlackLotus surfaced on underground hacker forums. Crafted exclusively for Windows systems, this</description><pubDate>Fri, 14 Jul 2023 00:00:00 GMT</pubDate><category>BlackLotus</category><category>bootkit</category><category>Cybersecurity</category><category>Hacking</category><category>Malware</category><category>Microsoft</category><category>NSA</category><category>Source Code</category><category>Threat Actors</category><category>UEFI</category><category>UEFI malware</category><category>Vulnerability</category><category>Windows</category><author>Dimitris Gkoutzamanis</author></item><item><title>Chinese Hackers Target US Federal Agencies: U.S. Government Agency Emails Compromised</title><link>https://cisotimes.com/chinese-hackers-target-us-federal-agencies-u-s-government-agency-emails-compromised/</link><guid isPermaLink="true">https://cisotimes.com/chinese-hackers-target-us-federal-agencies-u-s-government-agency-emails-compromised/</guid><description>Chinese hackers have recently breached the email accounts of a US Federal Civilian Executive Branch (FCEB) agency, as part of a larger cyberespionage campaign</description><pubDate>Thu, 13 Jul 2023 00:00:00 GMT</pubDate><category>authentication tokens</category><category>Chinese Hackers</category><category>CISA</category><category>Cloud Security</category><category>cyberespionage</category><category>Cybersecurity</category><category>FBI</category><category>MFA</category><category>MFA Bypass</category><category>Microsoft</category><category>Threat Actors</category><author>Dimitris Gkoutzamanis</author></item><item><title>Microsoft Patches Zero-Day Vulnerabilities And Addresses Issues With Signed Drivers Being Used Maliciously</title><link>https://cisotimes.com/microsoft-patches-zero-day-vulnerabilities-and-addresses-issues-with-signed-drivers-being-used-maliciously/</link><guid isPermaLink="true">https://cisotimes.com/microsoft-patches-zero-day-vulnerabilities-and-addresses-issues-with-signed-drivers-being-used-maliciously/</guid><description>On this recent Patch Tuesday, Microsoft released a significant number of security patches for July 2023. With more than 100 vulnerabilities addressed,</description><pubDate>Thu, 13 Jul 2023 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>kernel drivers</category><category>malicious software</category><category>Microsoft</category><category>Patch Tuesday</category><category>Vulnerability</category><category>Zero-Day</category><category>zero-day vulnerabilities</category><author>Dimitris Gkoutzamanis</author></item><item><title>Ransomware Gangs Collect $449 Million in Extortion Profits: A Rising Threat to Organizations</title><link>https://cisotimes.com/ransomware-gangs-collect-449-million-in-extortion-profits-a-rising-threat-to-organizations/</link><guid isPermaLink="true">https://cisotimes.com/ransomware-gangs-collect-449-million-in-extortion-profits-a-rising-threat-to-organizations/</guid><description>Ransomware gangs have experienced a surge in profitability during the first half of this year, raking in over $449 million from their victims, as reported by</description><pubDate>Thu, 13 Jul 2023 00:00:00 GMT</pubDate><category>Chainalysis</category><category>Cybercrime</category><category>Cybersecurity</category><category>Ransomware</category><author>Dimitris Gkoutzamanis</author></item><item><title>Beware of “Letscall”: Advanced Vishing Technique</title><link>https://cisotimes.com/beware-of-letscall-advanced-vishing-technique/</link><guid isPermaLink="true">https://cisotimes.com/beware-of-letscall-advanced-vishing-technique/</guid><description>Researchers have recently sounded the alarm about a sophisticated and emerging form of voice phishing (vishing) called &quot;Letscall.&quot; This alarming technique is</description><pubDate>Sun, 09 Jul 2023 00:00:00 GMT</pubDate><category>advanced techniques</category><category>evasion</category><category>financial fraud</category><category>Letscall</category><category>Malware</category><category>Cybersecurity</category><category>South Korea</category><category>Vishing</category><category>voice phishing</category><author>Dimitris Gkoutzamanis</author></item><item><title>CISA Issues Warnings as New Vulnerabilities in MOVEit Software Expose Sensitive Information</title><link>https://cisotimes.com/cisa-issues-warnings-as-new-vulnerabilities-in-moveit-software-expose-sensitive-information/</link><guid isPermaLink="true">https://cisotimes.com/cisa-issues-warnings-as-new-vulnerabilities-in-moveit-software-expose-sensitive-information/</guid><description>The federal government issues a strong warning about three recently discovered vulnerabilities in the popular MOVEit file transfer software. These</description><pubDate>Sun, 09 Jul 2023 00:00:00 GMT</pubDate><category>CISA</category><category>CL0P</category><category>Clop ransomware</category><category>Malware</category><category>MOVEit</category><category>Ransomware</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>Decoding the TA453 Threat: Unleashing Advanced Malware Campaigns Targeting Windows and macOS</title><link>https://cisotimes.com/decoding-the-ta453-threat-unleashing-advanced-malware-campaigns-targeting-windows-and-macos/</link><guid isPermaLink="true">https://cisotimes.com/decoding-the-ta453-threat-unleashing-advanced-malware-campaigns-targeting-windows-and-macos/</guid><description>TA453, a sophisticated nation-state actor, has been identified as an entity closely associated with various other notorious groups such as Charming Kitten,</description><pubDate>Sat, 08 Jul 2023 00:00:00 GMT</pubDate><category>APT</category><category>GorjolEcho</category><category>Iran</category><category>Natio State</category><category>NokNok</category><category>PowerShell</category><category>Proofpoint</category><author>Dimitris Gkoutzamanis</author></item><item><title>The Internet of Medical Things and Cybersecurity Risk</title><link>https://cisotimes.com/the-internet-of-medical-things-and-cybersecurity-risk/</link><guid isPermaLink="true">https://cisotimes.com/the-internet-of-medical-things-and-cybersecurity-risk/</guid><description>The healthcare and life sciences industry continues to be plagued by cybersecurity threats.1 According to FTI Consulting&apos;s U.S. Healthcare &amp; Life Sciences</description><pubDate>Sat, 08 Jul 2023 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>FTI Consulting</category><category>Healthcare</category><category>IoT</category><category>Survey</category><author>Jamie Singer</author></item><item><title>Critical Flaw in Fortinet Firewalls Exposes SSL VPN Interfaces: Over 490,000 Devices Vulnerable</title><link>https://cisotimes.com/critical-flaw-in-fortinet-firewalls-exposes-ssl-vpn-interfaces-over-490000-devices-vulnerable/</link><guid isPermaLink="true">https://cisotimes.com/critical-flaw-in-fortinet-firewalls-exposes-ssl-vpn-interfaces-over-490000-devices-vulnerable/</guid><description>A recent report reveals a critical flaw in Fortinet firewalls, leaving over 490,000 devices at risk of exploitation. This article explores the vulnerability,</description><pubDate>Wed, 05 Jul 2023 00:00:00 GMT</pubDate><category>Fortinet</category><category>FortiOS</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>Unmasking SmugX: Chinese Hackers Deploy Stealthy HTML Smuggling Techniques in Europe</title><link>https://cisotimes.com/unmasking-smugx-chinese-hackers-deploy-stealthy-html-smuggling-techniques-in-europe/</link><guid isPermaLink="true">https://cisotimes.com/unmasking-smugx-chinese-hackers-deploy-stealthy-html-smuggling-techniques-in-europe/</guid><description>A sophisticated Chinese nation-state group has been identified employing HTML smuggling techniques to target Foreign Affairs ministries and embassies in</description><pubDate>Wed, 05 Jul 2023 00:00:00 GMT</pubDate><category>Chinese Hackers</category><category>DLL side-loading</category><category>European Union</category><category>HTML Smuggling</category><category>PlugX</category><category>RAT</category><category>remote access trojan</category><category>smugX</category><author>TheCISO</author></item><item><title>White Snake Stealer: A Formidable Info Stealer Targeting Windows and Linux Platforms</title><link>https://cisotimes.com/white-snake-stealer-a-formidable-info-stealer-targeting-windows-and-linux-platforms/</link><guid isPermaLink="true">https://cisotimes.com/white-snake-stealer-a-formidable-info-stealer-targeting-windows-and-linux-platforms/</guid><description>White Snake Stealer, an advanced information stealer, has recently evolved with enhanced features, making it capable of targeting both Windows and Linux</description><pubDate>Wed, 05 Jul 2023 00:00:00 GMT</pubDate><category>Info Stealer</category><category>Malware</category><category>White Snake</category><author>Dimitris Gkoutzamanis</author></item><item><title>The Pros and Cons of Virtual Chief Information Security Officers (vCISOs)</title><link>https://cisotimes.com/the-pros-and-cons-of-virtual-chief-information-security-officers-vcisos/</link><guid isPermaLink="true">https://cisotimes.com/the-pros-and-cons-of-virtual-chief-information-security-officers-vcisos/</guid><description>An increasing number of modern security-conscious companies have Chief Information Security Officers (CISOs) on their payroll to manage the growing threat of</description><pubDate>Sun, 02 Jul 2023 00:00:00 GMT</pubDate><category>Chief Information Security Officer</category><category>CISO</category><category>Security Leadership</category><category>Security Services</category><category>vCISO</category><author>Dimitris Gkoutzamanis</author></item><item><title>Avast released a free decryptor for the Akira ransomware that can allow victims to recover their data without paying the ransom</title><link>https://cisotimes.com/avast-released-a-free-decryptor-for-the-akira-ransomware-that-can-allow-victims-to-recover-their-data-without-paying-the-ransom/</link><guid isPermaLink="true">https://cisotimes.com/avast-released-a-free-decryptor-for-the-akira-ransomware-that-can-allow-victims-to-recover-their-data-without-paying-the-ransom/</guid><description>Avast, the renowned cybersecurity firm, has released a free decryptor for the Akira ransomware. This decryptor enables victims to recover their encrypted data</description><pubDate>Sat, 01 Jul 2023 00:00:00 GMT</pubDate><category>Akira</category><category>Avast</category><category>Ransomware</category><category>Ransomware decryptor</category><author>Dimitris Gkoutzamanis</author></item><item><title>Half of EDR Tools, Organizations Vulnerable to Clop Ransomware, Research Says</title><link>https://cisotimes.com/half-of-edr-tools-organizations-vulnerable-to-clop-ransomware-research-says/</link><guid isPermaLink="true">https://cisotimes.com/half-of-edr-tools-organizations-vulnerable-to-clop-ransomware-research-says/</guid><description>In recent assessments conducted by cybersecurity company Cymulate, it was revealed that nearly half of the endpoint detection and response (EDR) tools and</description><pubDate>Sat, 01 Jul 2023 00:00:00 GMT</pubDate><category>CL0P</category><category>Cymulate</category><category>EDR</category><category>Malware</category><category>MOVEit</category><category>Ransomware</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>MITRE Releases Annual List of Top 25 Most Dangerous Software Weaknesses for 2023</title><link>https://cisotimes.com/mitre-releases-annual-list-of-top-25-most-dangerous-software-weaknesses-for-2023/</link><guid isPermaLink="true">https://cisotimes.com/mitre-releases-annual-list-of-top-25-most-dangerous-software-weaknesses-for-2023/</guid><description>MITRE has recently released its annual list of the top 25 most dangerous software weaknesses for the year 2023.</description><pubDate>Fri, 30 Jun 2023 00:00:00 GMT</pubDate><category>MITRE</category><category>NVD</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>More Major Corporations Added to the Growing MOVEit Victim List</title><link>https://cisotimes.com/more-major-corporations-added-to-the-growing-moveit-victim-list/</link><guid isPermaLink="true">https://cisotimes.com/more-major-corporations-added-to-the-growing-moveit-victim-list/</guid><description>The recent MOVEit breach that has impacted two major energy corporations and numerous organizations. Discover the details of the hacking campaign, the vulnerability exploited, and the potential consequences for affected entities. Stay informed about the latest developments in cybersecurity and sa…</description><pubDate>Wed, 28 Jun 2023 00:00:00 GMT</pubDate><category>CL0P</category><category>MOVEit</category><category>Ransomware</category><category>Schneider Electric</category><author>Dimitris Gkoutzamanis</author></item><item><title>Nessus Plugin Vulnerability May ALlow Attackers Escalate The Privileges</title><link>https://cisotimes.com/nessus-plugin-vulnerability-may-allow-attackers-escalate-the-privileges/</link><guid isPermaLink="true">https://cisotimes.com/nessus-plugin-vulnerability-may-allow-attackers-escalate-the-privileges/</guid><description>Nessus is a powerful vulnerability scanning tool developed by Tenable. With its comprehensive range of plugins, it provides organizations with the ability to</description><pubDate>Wed, 28 Jun 2023 00:00:00 GMT</pubDate><category>CVE-2023-2005</category><category>Nessus</category><category>plugins</category><category>Cybersecurity</category><category>Security Updates</category><category>Tenable</category><category>vulnerability detection</category><category>Vulnerability Scanning</category><author>Dimitris Gkoutzamanis</author></item><item><title>Cryptojacking Campaign Exploiting Linux and IoT Devices</title><link>https://cisotimes.com/cryptojacking-campaign-exploiting-linux-and-iot-devices/</link><guid isPermaLink="true">https://cisotimes.com/cryptojacking-campaign-exploiting-linux-and-iot-devices/</guid><description>Microsoft researchers have identified a series of attacks that employ brute force techniques to gain unauthorized access to systems, enabling illicit</description><pubDate>Tue, 27 Jun 2023 00:00:00 GMT</pubDate><category>Backdoor</category><category>Botnet</category><category>crypto mining</category><category>Cryptojacking</category><category>Cybersecurity</category><category>DDoS</category><category>IoT devices</category><category>Linux</category><category>malicious attacks</category><category>OpenSSH</category><category>rootkits</category><author>Dimitris Gkoutzamanis</author></item><item><title>Mayor Candidate Sues Latitude for Negligence in Safeguarding Customer Data</title><link>https://cisotimes.com/mayor-candidate-sues-latitude-for-negligence-in-safeguarding-customer-data/</link><guid isPermaLink="true">https://cisotimes.com/mayor-candidate-sues-latitude-for-negligence-in-safeguarding-customer-data/</guid><description>Shahriar Sean Saffari, an unsuccessful mayoral candidate in Australia, has initiated legal proceedings against a prominent financial services firm, accusing</description><pubDate>Tue, 27 Jun 2023 00:00:00 GMT</pubDate><category>compensation</category><category>customer data protection</category><category>Cyber Attacks</category><category>Cybersecurity</category><category>Data Breach</category><category>financial services</category><category>identity theft</category><category>legal proceedings</category><category>privacy breach</category><author>TheCISO</author></item><item><title>Microsoft Exposes Rampant Credential-Stealing Attacks by Russian Hackers</title><link>https://cisotimes.com/microsoft-exposes-rampant-credential-stealing-attacks-by-russian-hackers/</link><guid isPermaLink="true">https://cisotimes.com/microsoft-exposes-rampant-credential-stealing-attacks-by-russian-hackers/</guid><description>Microsoft has recently revealed a significant spike in credential-stealing attacks orchestrated by Midnight Blizzard, a Russian state-affiliated hacker group.</description><pubDate>Tue, 27 Jun 2023 00:00:00 GMT</pubDate><category>APT28</category><category>APT29</category><category>credential-stealing attacks</category><category>Cybersecurity</category><category>espionage</category><category>Midnight Blizzard</category><category>Russian cyberwarfare</category><category>Russian hackers</category><category>spear-phishing</category><category>Threat Actors</category><author>TheCISO</author></item><item><title>One of the Most Popular Open-Source Systems for Analytics and Visualization, Grafana, Faces Security Flaw</title><link>https://cisotimes.com/one-of-the-most-popular-open-source-systems-for-analytics-and-visualization-grafana-faces-security-flaw/</link><guid isPermaLink="true">https://cisotimes.com/one-of-the-most-popular-open-source-systems-for-analytics-and-visualization-grafana-faces-security-flaw/</guid><description>Grafana, a widely used open-source platform for analytics and visualization, has recently been discovered to have a security vulnerability. This system caters</description><pubDate>Tue, 27 Jun 2023 00:00:00 GMT</pubDate><category>authentication protocols</category><category>Azure AD</category><category>CVE-2023-3128</category><category>data analysis</category><category>Grafana</category><category>open-source systems</category><category>security flaw</category><category>visualization</category><author>Dimitris Gkoutzamanis</author></item><item><title>Over 33% of Employees are Clicking Malicious Links According to Phishing Report</title><link>https://cisotimes.com/over-33-of-employees-are-clicking-malicious-links-according-to-phishing-report/</link><guid isPermaLink="true">https://cisotimes.com/over-33-of-employees-are-clicking-malicious-links-according-to-phishing-report/</guid><description>In recent years, the frequency and impact of data breaches have been on the rise. Organizations worldwide have suffered significant losses due to ransomware</description><pubDate>Tue, 27 Jun 2023 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>Data breaches</category><category>email threats</category><category>phishing awareness</category><category>phishing campaigns</category><category>Ransomware</category><category>Social Engineering</category><author>Dimitris Gkoutzamanis</author></item><item><title>The Internet Systems Consortium (ISC) Addressed Three Denial-of-Service (DoS) Vulnerabilities in the DNS Software Suite BIND</title><link>https://cisotimes.com/the-internet-systems-consortium-isc-addressed-three-denial-of-service-dos-vulnerabilities-in-the-dns-software-suite-bind/</link><guid isPermaLink="true">https://cisotimes.com/the-internet-systems-consortium-isc-addressed-three-denial-of-service-dos-vulnerabilities-in-the-dns-software-suite-bind/</guid><description>The Internet Systems Consortium (ISC) recently announced the release of security updates for the DNS software suite BIND, addressing three critical</description><pubDate>Tue, 27 Jun 2023 00:00:00 GMT</pubDate><category>BIND</category><category>CVE-2023-2828</category><category>CVE-2023-2829</category><category>CVE-2023-2911</category><category>Denial-of-Service vulnerabilities</category><category>DNS</category><category>ISC security updates</category><category>named resolver</category><category>remote exploitation</category><author>Dimitris Gkoutzamanis</author></item><item><title>List of MOVEit Victim Organizations</title><link>https://cisotimes.com/list-of-moveit-victim-organizations/</link><guid isPermaLink="true">https://cisotimes.com/list-of-moveit-victim-organizations/</guid><description>The risk analysis firm Kroll discovered a significant Zero Day vulnerability by the end of May 2023. The subsequent attack on MOVEit software, a business unit</description><pubDate>Thu, 22 Jun 2023 00:00:00 GMT</pubDate><category>Clop ransomware</category><category>Cyber Attacks</category><category>Data Breach</category><category>double extortion</category><category>financial institutions</category><category>global impact</category><category>health organizations</category><category>Russian intelligence</category><category>victim organizations</category><category>Zero-Day</category><author>TheCISO</author></item><item><title>Does Your Organization Require A Full-Time CISO?</title><link>https://cisotimes.com/does-your-organization-require-a-full-time-ciso/</link><guid isPermaLink="true">https://cisotimes.com/does-your-organization-require-a-full-time-ciso/</guid><description>In an era of digital advancements and ever-evolving cyber threats, organizations of all sizes and industries must grapple with the critical decision of</description><pubDate>Mon, 12 Jun 2023 00:00:00 GMT</pubDate><category>Chief Information Security Officer</category><category>Cyber Threats</category><category>Cybersecurity</category><category>Cybersecurity Strategy</category><category>Privacy</category><category>Data Protection</category><category>Incident Response</category><category>organizational security</category><category>Regulatory Compliance</category><category>risk mitigation</category><author>Dimitris Gkoutzamanis</author></item><item><title>Massive Ransomware Attack Hits Spanish Bank: Client and Employee Data at Risk</title><link>https://cisotimes.com/massive-ransomware-attack-hits-spanish-bank-client-and-employee-data-at-risk/</link><guid isPermaLink="true">https://cisotimes.com/massive-ransomware-attack-hits-spanish-bank-client-and-employee-data-at-risk/</guid><description>A prominent financial institution in Spain faces the brunt of a severe ransomware attack, impacting multiple branches and raising concerns over compromised</description><pubDate>Mon, 05 Jun 2023 00:00:00 GMT</pubDate><category>confidential information</category><category>Cybersecurity</category><category>Data Breach</category><category>financial sector</category><category>Globalcaja</category><category>Personal Data</category><category>Play ransomware group</category><category>Ransomware Attack</category><category>Spain</category><category>Spanish bank</category><author>Dimitris Gkoutzamanis</author></item><item><title>Amazon Faces $31 Million Penalty for Privacy Violations</title><link>https://cisotimes.com/amazon-faces-31-million-penalty-for-privacy-violations/</link><guid isPermaLink="true">https://cisotimes.com/amazon-faces-31-million-penalty-for-privacy-violations/</guid><description>Amazon recently reached a settlement with the Federal Trade Commission (FTC) after facing two civil complaints. The allegations against the company involved</description><pubDate>Sat, 03 Jun 2023 00:00:00 GMT</pubDate><category>Alexa devices</category><category>Amazon</category><category>compensation</category><category>Federal Trade Commission</category><category>FTC settlement</category><category>privacy breach</category><category>privacy violation</category><category>Ring cameras</category><category>security breaches</category><author>Dimitris Gkoutzamanis</author></item><item><title>Unmasking the Threat: Unveiling the Zero-Click iOS Malware Exploitation</title><link>https://cisotimes.com/unmasking-the-threat-unveiling-the-zero-click-ios-malware-exploitation/</link><guid isPermaLink="true">https://cisotimes.com/unmasking-the-threat-unveiling-the-zero-click-ios-malware-exploitation/</guid><description>Kaspersky, a leading cybersecurity firm, has recently disclosed a disconcerting revelation regarding the compromise of numerous iPhones connected to its</description><pubDate>Sat, 03 Jun 2023 00:00:00 GMT</pubDate><category>C&amp;C domains</category><category>Cybersecurity</category><category>iMessage security</category><category>iOS security</category><category>iPhone vulnerabilities</category><category>Kaspersky</category><category>mobile malware</category><category>Operation Triangulation</category><category>zero-click exploits</category><author>Dimitris Gkoutzamanis</author></item><item><title>US Intelligence Accused of Massive Apple Phone Hacking Campaign by Russian FSB</title><link>https://cisotimes.com/us-intelligence-accused-of-massive-apple-phone-hacking-campaign-by-russian-fsb/</link><guid isPermaLink="true">https://cisotimes.com/us-intelligence-accused-of-massive-apple-phone-hacking-campaign-by-russian-fsb/</guid><description>The Russian Federal Security Service (FSB) has leveled serious accusations against the United States Intelligence Community, alleging a large-scale hacking</description><pubDate>Sat, 03 Jun 2023 00:00:00 GMT</pubDate><category>Apple</category><category>Cybersecurity</category><category>diplomatic missions</category><category>FSB</category><category>Hacking</category><category>intelligence community</category><category>iOS malware</category><category>Kaspersky</category><category>NSA</category><category>privacy breach</category><category>Russia</category><category>Surveillance</category><category>United States</category><author>Dimitris Gkoutzamanis</author></item><item><title>Financially Motivated Actor Targets Unsecured Apache NiFi Instances for Covert Cryptocurrency Mining</title><link>https://cisotimes.com/financially-motivated-actor-targets-unsecured-apache-nifi-instances-for-covert-cryptocurrency-mining/</link><guid isPermaLink="true">https://cisotimes.com/financially-motivated-actor-targets-unsecured-apache-nifi-instances-for-covert-cryptocurrency-mining/</guid><description>Discoveries by the SANS Internet Storm Center (ISC) shed light on an ongoing campaign orchestrated by a financially motivated threat actor. This cyber</description><pubDate>Wed, 31 May 2023 00:00:00 GMT</pubDate><category>Apache NiFi</category><category>cryptocurrency mining</category><category>Kinsing malware</category><category>lateral movement</category><category>persistence</category><category>SANS Internet Storm Center</category><category>threat actor</category><category>vulnerability exploitation</category><author>TheCISO</author></item><item><title>The Alarming Vulnerabilities of Solar Panels: Powering Up Cyber Threats</title><link>https://cisotimes.com/the-alarming-vulnerabilities-of-solar-panels-powering-up-cyber-threats/</link><guid isPermaLink="true">https://cisotimes.com/the-alarming-vulnerabilities-of-solar-panels-powering-up-cyber-threats/</guid><description>Solar panels, once seen as a beacon of clean energy, are now facing a new threat – cyber attacks. Digital Watchdog RDI experts warn that hackers are</description><pubDate>Wed, 31 May 2023 00:00:00 GMT</pubDate><category>Critical Infrastructure</category><category>Cyber Attacks</category><category>Cybersecurity</category><category>distributed denial-of-service attacks</category><category>inverters</category><category>renewable energy</category><category>solar panels</category><author>Dimitris Gkoutzamanis</author></item><item><title>Barracuda Zero-Day Vulnerability Breach Raises Cybersecurity Concerns: Urgent Action Required</title><link>https://cisotimes.com/barracuda-zero-day-vulnerability-breach-raises-cybersecurity-concerns-urgent-action-required/</link><guid isPermaLink="true">https://cisotimes.com/barracuda-zero-day-vulnerability-breach-raises-cybersecurity-concerns-urgent-action-required/</guid><description>The recent discovery of a zero-day vulnerability in Barracuda&apos;s Email Security Gateway (ESG) appliances has raised serious concerns in the cybersecurity</description><pubDate>Mon, 29 May 2023 00:00:00 GMT</pubDate><category>Barracuda</category><category>Breach</category><category>CISA</category><category>Cybersecurity</category><category>Email Security Gateway</category><category>Known Exploited Vulnerabilities Catalog</category><category>Zero-Day</category><author>Dimitris Gkoutzamanis</author></item><item><title>Empowering National Defense: Department of Defense Unveils Cutting-Edge Cyber Strategy</title><link>https://cisotimes.com/empowering-national-defense-department-of-defense-unveils-cutting-edge-cyber-strategy/</link><guid isPermaLink="true">https://cisotimes.com/empowering-national-defense-department-of-defense-unveils-cutting-edge-cyber-strategy/</guid><description>The Department of Defense (DoD) has taken a significant step towards fortifying the nation&apos;s cybersecurity by submitting its groundbreaking classified cyber</description><pubDate>Mon, 29 May 2023 00:00:00 GMT</pubDate><category>cyber operations</category><category>cyber strategy</category><category>Cybersecurity</category><category>defend forward</category><category>Department of Defense</category><category>joint force</category><category>national security</category><author>TheCISO</author></item><item><title>Unveiling Tesla’s Autopilot Challenges: Widespread Complaints and Data Privacy Concerns</title><link>https://cisotimes.com/unveiling-teslas-autopilot-challenges-widespread-complaints-and-data-privacy-concerns/</link><guid isPermaLink="true">https://cisotimes.com/unveiling-teslas-autopilot-challenges-widespread-complaints-and-data-privacy-concerns/</guid><description>A recent report in the esteemed German newspaper Handelsblatt sheds light on an alarming number of complaints regarding Tesla Inc&apos;s vehicles. According to the</description><pubDate>Mon, 29 May 2023 00:00:00 GMT</pubDate><category>Autopilot</category><category>complaints</category><category>Privacy</category><category>regulatory intervention</category><category>safety flaws</category><category>self-driving cars</category><category>Tesla</category><author>Dimitris Gkoutzamanis</author></item><item><title>Unveiling Volt Typhoon: A State-Sponsored Cyber Threat from China</title><link>https://cisotimes.com/unveiling-volt-typhoon-a-state-sponsored-cyber-threat-from-china/</link><guid isPermaLink="true">https://cisotimes.com/unveiling-volt-typhoon-a-state-sponsored-cyber-threat-from-china/</guid><description>US and global cybersecurity agencies issue a joint advisory, shedding light on the activities of a state-sponsored cyber actor called &quot;Volt Typhoon&quot;</description><pubDate>Mon, 29 May 2023 00:00:00 GMT</pubDate><author>Dimitris Gkoutzamanis</author></item><item><title>Apple Restricting AI Tools to Safeguard Confidential Data</title><link>https://cisotimes.com/apple-restricting-ai-tools-to-safeguard-confidential-data/</link><guid isPermaLink="true">https://cisotimes.com/apple-restricting-ai-tools-to-safeguard-confidential-data/</guid><description>Apple, renowned for its commitment to safeguarding sensitive information, has recently taken decisive measures to address concerns about the exposure of its</description><pubDate>Wed, 24 May 2023 00:00:00 GMT</pubDate><category>AI tools</category><category>Alexa</category><category>Apple</category><category>Artificial Intelligence</category><category>bans</category><category>ChatGPT</category><category>ChatGPT incident</category><category>confidential data</category><category>Data Security</category><category>in-house AI bot</category><category>Siri</category><category>user privacy</category><author>TheCISO</author></item><item><title>Former IT Security Analyst Turns Dark: Inside the Shocking Cyber Attack Hijack</title><link>https://cisotimes.com/former-it-security-analyst-turns-dark-inside-the-shocking-cyber-attack-hijack/</link><guid isPermaLink="true">https://cisotimes.com/former-it-security-analyst-turns-dark-inside-the-shocking-cyber-attack-hijack/</guid><description>A former IT security analyst at Oxford Biomedica recently confessed to an astonishing act that took place five years ago. In an unexpected twist, the analyst</description><pubDate>Wed, 24 May 2023 00:00:00 GMT</pubDate><category>Bitcoin</category><category>Cyber Attacks</category><category>Cybersecurity</category><category>digital crime</category><category>Insider Threat</category><category>Ransomware</category><author>Dimitris Gkoutzamanis</author></item><item><title>Unveiling the Reign of GUI-vil: Financially Motivated Cyberthreat Group Targeting AWS Accounts</title><link>https://cisotimes.com/unveiling-the-reign-of-gui-vil-financially-motivated-cyberthreat-group-targeting-aws-accounts/</link><guid isPermaLink="true">https://cisotimes.com/unveiling-the-reign-of-gui-vil-financially-motivated-cyberthreat-group-targeting-aws-accounts/</guid><description>A financially motivated cyberthreat group has been identified, relentlessly attacking organizations&apos; Amazon Web Services (AWS) accounts with the intent to</description><pubDate>Wed, 24 May 2023 00:00:00 GMT</pubDate><category>AWS attacks</category><category>Cloud Security</category><category>Cryptocurrency</category><category>Cryptojacking</category><category>cryptomining</category><category>Cyber Attacks</category><category>cyberthreat group</category><category>GUI-vil</category><category>Hacking</category><category>Threat Actors</category><author>Dimitris Gkoutzamanis</author></item><item><title>Meta Slapped with €1.2 Billion GDPR Penalty</title><link>https://cisotimes.com/meta-slapped-with-e1-2-billion-gdpr-penalty/</link><guid isPermaLink="true">https://cisotimes.com/meta-slapped-with-e1-2-billion-gdpr-penalty/</guid><description>Meta, the parent company of Facebook, has incurred a hefty penalty of €1.2 billion for violating the General Data Protection Regulation (GDPR) rules by</description><pubDate>Tue, 23 May 2023 00:00:00 GMT</pubDate><category>Privacy</category><category>European Union</category><category>GDPR</category><category>Meta</category><author>Dimitris Gkoutzamanis</author></item><item><title>Unveiling the Resilience of Satellite Infrastructure: Ethical Hackers Expose Vulnerabilities</title><link>https://cisotimes.com/unveiling-the-resilience-of-satellite-infrastructure-ethical-hackers-expose-vulnerabilities/</link><guid isPermaLink="true">https://cisotimes.com/unveiling-the-resilience-of-satellite-infrastructure-ethical-hackers-expose-vulnerabilities/</guid><description>In a bid to evaluate the security measures protecting satellite infrastructure, the European Space Agency (ESA) recently challenged a group of ethical hackers</description><pubDate>Tue, 23 May 2023 00:00:00 GMT</pubDate><category>China&apos;s cyber defense infrastructure</category><category>Cyber Resilience</category><category>data manipulation</category><category>ethical hackers</category><category>global perspectives</category><category>satellite imaging</category><category>satellite infrastructure</category><category>satellite security</category><category>security measures</category><category>US Space Force</category><category>Vulnerability</category><category>white hat hackers</category><author>Dimitris Gkoutzamanis</author></item><item><title>Beware of Malicious Packages: TurkoRat Malware Concealed in npm Repository</title><link>https://cisotimes.com/beware-of-malicious-packages-turkorat-malware-concealed-in-npm-repository/</link><guid isPermaLink="true">https://cisotimes.com/beware-of-malicious-packages-turkorat-malware-concealed-in-npm-repository/</guid><description>Recently, two packages named nodejs-encrypt-agent and nodejs-cookie-proxy-agent were detected on the npm package repository. Shockingly, these packages</description><pubDate>Fri, 19 May 2023 00:00:00 GMT</pubDate><category>capitalization deception</category><category>Cybersecurity</category><category>deception</category><category>information stealer</category><category>malicious packages</category><category>npm package repository</category><category>open source software</category><category>Python Package Index</category><category>supply chain attacks</category><category>Threat Actors</category><category>TurkoRat malware</category><category>Typosquatting</category><category>VS Code extensions marketplace</category><author>Dimitris Gkoutzamanis</author></item><item><title>Empowering Gmail Users: Dark Web Monitoring and Exciting Feature Upgrades from Google</title><link>https://cisotimes.com/empowering-gmail-users-dark-web-monitoring-and-exciting-feature-upgrades-from-google/</link><guid isPermaLink="true">https://cisotimes.com/empowering-gmail-users-dark-web-monitoring-and-exciting-feature-upgrades-from-google/</guid><description>Google has recently announced a series of updates aimed at enhancing security and user experience. One of the key highlights is the introduction of dark web</description><pubDate>Fri, 19 May 2023 00:00:00 GMT</pubDate><category>dark web monitoring</category><category>Privacy</category><category>feature upgrades</category><category>Gmail</category><category>Cybersecurity</category><author>Dimitris Gkoutzamanis</author></item><item><title>The Powerful Phishing-as-a-Service Platform Targeting Microsoft 365 Users</title><link>https://cisotimes.com/the-powerful-phishing-as-a-service-platform-targeting-microsoft-365-users/</link><guid isPermaLink="true">https://cisotimes.com/the-powerful-phishing-as-a-service-platform-targeting-microsoft-365-users/</guid><description>In the treacherous world of cybercrime, a formidable adversary has emerged - Greatness, the insidious Phishing-as-a-Service (PhaaS) platform. Since its</description><pubDate>Fri, 19 May 2023 00:00:00 GMT</pubDate><category>API key</category><category>Cybercrime</category><category>deception</category><category>Greatness</category><category>Microsoft 365</category><category>phishing-as-a-service</category><category>Cybersecurity</category><category>Two-Factor Authentication</category><category>webinar</category><category>Zero Trust</category><author>Dimitris Gkoutzamanis</author></item><item><title>Discord Data Breach: Unveiling a Security Incident and Enhancing User Protection</title><link>https://cisotimes.com/discord-data-breach-unveiling-a-security-incident-and-enhancing-user-protection/</link><guid isPermaLink="true">https://cisotimes.com/discord-data-breach-unveiling-a-security-incident-and-enhancing-user-protection/</guid><description>Discord, the popular messaging platform, recently alerted its users about a data breach that occurred when a threat actor gained unauthorized access to a</description><pubDate>Tue, 16 May 2023 00:00:00 GMT</pubDate><category>collaboration</category><category>Data Breach</category><category>Discord</category><category>gaming community</category><category>malicious actors</category><category>personal information compromise</category><category>security measures</category><category>suspicious activities</category><category>third-party suppliers</category><category>user notification</category><category>vigilant</category><category>Zendesk</category><author>TheCISO</author></item><item><title>Unveiling the Power-Packed Merdoor: Lancefly APT Group’s Custom Backdoor Wreaks Havoc in South and Southeast Asia</title><link>https://cisotimes.com/unveiling-the-power-packed-merdoor-lancefly-apt-groups-custom-backdoor-wreaks-havoc-in-south-and-southeast-asia/</link><guid isPermaLink="true">https://cisotimes.com/unveiling-the-power-packed-merdoor-lancefly-apt-groups-custom-backdoor-wreaks-havoc-in-south-and-southeast-asia/</guid><description>The Lancefly APT group has emerged as a formidable threat, employing a custom-written backdoor known as Merdoor, which is unleashing havoc on organizations</description><pubDate>Tue, 16 May 2023 00:00:00 GMT</pubDate><category>APT groups</category><category>Cyber Attacks</category><category>Cybersecurity</category><category>intelligence gathering</category><category>Lancefly APT</category><category>Merdoor backdoor</category><category>South Asia</category><category>Southeast Asia</category><author>Dimitris Gkoutzamanis</author></item><item><title>Detecting Unquoted Service Paths: An Essential Security Measure for Penetration Testers and Blue Teams</title><link>https://cisotimes.com/detecting-unquoted-service-paths-an-essential-security-measure-for-penetration-testers-and-blue-teams/</link><guid isPermaLink="true">https://cisotimes.com/detecting-unquoted-service-paths-an-essential-security-measure-for-penetration-testers-and-blue-teams/</guid><description>As a cybersecurity professional, it&apos;s essential to understand and address potential security threats that may exist within an organization. One such threat is</description><pubDate>Mon, 01 May 2023 00:00:00 GMT</pubDate><category>Blue Team</category><category>Cybersecurity</category><category>Penetration Testing</category><category>PowerShell</category><category>Python</category><category>Red Team</category><category>security vulnerabilities</category><category>unquoted service paths</category><author>Dimitris Gkoutzamanis</author></item><item><title>LockBit Ransomware Group Issues Unconditional Apology and Promises Free Decryptor for Victims</title><link>https://cisotimes.com/lockbit-ransomware-group-issues-unconditional-apology-and-promises-free-decryptor-for-victims/</link><guid isPermaLink="true">https://cisotimes.com/lockbit-ransomware-group-issues-unconditional-apology-and-promises-free-decryptor-for-victims/</guid><description>In a surprising turn of events, the notorious LockBit ransomware group issued an unconditional apology for its recent attack on the Olympia Community Unit</description><pubDate>Thu, 27 Apr 2023 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>Dark Web</category><category>LockBit</category><category>Ransomware</category><author>TheCISO</author></item><item><title>Securing Cloud Data with a CASB: A Guide to Selection and Implementation</title><link>https://cisotimes.com/securing-cloud-data-with-a-casb-a-guide-to-selection-and-implementation/</link><guid isPermaLink="true">https://cisotimes.com/securing-cloud-data-with-a-casb-a-guide-to-selection-and-implementation/</guid><description>With the rise in cloud adoption, companies are increasingly using cloud-based applications, which present a new set of cybersecurity challenges. One solution</description><pubDate>Thu, 27 Apr 2023 00:00:00 GMT</pubDate><category>CASB</category><category>Cloud</category><author>Dimitris Gkoutzamanis</author></item><item><title>Trigona Ransomware: A Menacing Threat to Windows Users</title><link>https://cisotimes.com/trigona-ransomware-a-menacing-threat-to-windows-users/</link><guid isPermaLink="true">https://cisotimes.com/trigona-ransomware-a-menacing-threat-to-windows-users/</guid><description>Trigona ransomware is a newly discovered malware that poses a serious threat to Windows users. The Unit42 research team at Palo Alto Networks recently</description><pubDate>Sun, 23 Apr 2023 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>Encryption</category><category>Malware</category><category>Mimikatz</category><category>Ransomware</category><category>Trigona ransomware</category><author>Dimitris Gkoutzamanis</author></item><item><title>Breach Alert: Kodi’s User Database Hacked and Stolen</title><link>https://cisotimes.com/breach-alert-kodis-user-database-hacked-and-stolen/</link><guid isPermaLink="true">https://cisotimes.com/breach-alert-kodis-user-database-hacked-and-stolen/</guid><description>Open-source media player software provider, Kodi, has announced a data breach after hackers stole the company&apos;s MyBB forum database, including private</description><pubDate>Sun, 16 Apr 2023 00:00:00 GMT</pubDate><category>Breachforums</category><category>Cyber Attacks</category><category>Cybercrime</category><category>Data Breach</category><category>Kodi</category><category>MyBB forum database</category><category>password reset</category><category>Threat Actors</category><category>user data</category><author>Dimitris Gkoutzamanis</author></item><item><title>Beware of Malicious Loaders: Android Apps Infected with Trojanized Malware</title><link>https://cisotimes.com/beware-of-malicious-loaders-android-apps-infected-with-trojanized-malware/</link><guid isPermaLink="true">https://cisotimes.com/beware-of-malicious-loaders-android-apps-infected-with-trojanized-malware/</guid><description>As the number of mobile phone users is increasing, so is the number of security threats that come along with it. Criminals have found a new way to evade</description><pubDate>Tue, 11 Apr 2023 00:00:00 GMT</pubDate><category>Android Applications</category><category>APK Binding Services</category><category>Dropper Apps</category><category>Google Play Developer Account</category><category>Google Play Store</category><category>Malicious Loaders</category><category>Threat Actors</category><category>Trojanized Malware</category><author>TheCISO</author></item><item><title>Cyber Attack on NATO by KillNet: A Threat to Global Security</title><link>https://cisotimes.com/cyber-attack-on-nato-by-killnet-a-threat-to-global-security/</link><guid isPermaLink="true">https://cisotimes.com/cyber-attack-on-nato-by-killnet-a-threat-to-global-security/</guid><description>Cyber attacks have become a rising threat to global security, and one such group that has gained notoriety is KillNet. Originating during the Russian invasion</description><pubDate>Tue, 11 Apr 2023 00:00:00 GMT</pubDate><category>Cyber Attacks</category><category>Cybersecurity</category><category>Data Leak</category><category>Global Security</category><category>Hacking</category><category>Killnet</category><category>NATO</category><author>TheCISO</author></item><item><title>Unmasking the Cryptocurrency Stealer Malware: A Sophisticated Supply Chain Attack on .NET Developers</title><link>https://cisotimes.com/unmasking-the-cryptocurrency-stealer-malware-a-sophisticated-supply-chain-attack-on-net-developers/</link><guid isPermaLink="true">https://cisotimes.com/unmasking-the-cryptocurrency-stealer-malware-a-sophisticated-supply-chain-attack-on-net-developers/</guid><description>Recently, cybersecurity researchers uncovered the techniques used in a sophisticated supply chain attack aimed at .NET developers.</description><pubDate>Tue, 11 Apr 2023 00:00:00 GMT</pubDate><category>.NET</category><category>Cryptocurrency Stealer Malware</category><category>Cybersecurity</category><category>Impala Stealer</category><category>supply chain attack</category><category>Typosquatting</category><author>TheCISO</author></item><item><title>Amazon Bans Flipper Zero Multi-Tool for Pen-Testing Due to Alleged Card-Skimming Capabilities</title><link>https://cisotimes.com/amazon-bans-flipper-zero-multi-tool-for-pen-testing-due-to-alleged-card-skimming-capabilities/</link><guid isPermaLink="true">https://cisotimes.com/amazon-bans-flipper-zero-multi-tool-for-pen-testing-due-to-alleged-card-skimming-capabilities/</guid><description>Amazon recently banned the sale of the Flipper Zero portable multi-tool for pen-testers, alleging that it has card-skimming capabilities. This move has</description><pubDate>Sun, 09 Apr 2023 00:00:00 GMT</pubDate><category>Amazon</category><category>Flipper Zero</category><author>TheCISO</author></item><item><title>Microsoft and Fortra’s Legal Crackdown on Cobalt Strike: A Significant Blow to Cybercriminals</title><link>https://cisotimes.com/microsoft-and-fortras-legal-crackdown-on-cobalt-strike-a-significant-blow-to-cybercriminals/</link><guid isPermaLink="true">https://cisotimes.com/microsoft-and-fortras-legal-crackdown-on-cobalt-strike-a-significant-blow-to-cybercriminals/</guid><description>A recent joint operation between Microsoft&apos;s Digital Crimes Unit (DCU), Fortra, and the Health-ISAC has resulted in a major legal crackdown against servers</description><pubDate>Sun, 09 Apr 2023 00:00:00 GMT</pubDate><category>Cobalt Strike</category><category>collaboration</category><category>Cybersecurity</category><category>cybersecurity tools</category><category>Fortra</category><category>Hacking</category><category>legal crackdown</category><category>Microsoft</category><category>Ransomware</category><category>Threat Actors</category><author>Dimitris Gkoutzamanis</author></item><item><title>Opt-Out of Facebook’s Targeted Advertising: A Quick and Easy Way to Protect Your Privacy</title><link>https://cisotimes.com/opt-out-of-facebooks-targeted-advertising-a-quick-and-easy-way-to-protect-your-privacy/</link><guid isPermaLink="true">https://cisotimes.com/opt-out-of-facebooks-targeted-advertising-a-quick-and-easy-way-to-protect-your-privacy/</guid><description>Privacy watchdog, noyb, has developed a tool that empowers users to opt-out of targeted advertising and other claims made by Meta, formerly Facebook and</description><pubDate>Sun, 09 Apr 2023 00:00:00 GMT</pubDate><category>Facebook</category><category>GDPR</category><category>Instagram</category><category>legitimate interest</category><category>Meta</category><category>opt-out</category><category>Privacy</category><category>targeted advertising</category><author>TheCISO</author></item><item><title>Protect Your Apple Devices: Two Zero-Day Vulnerabilities Exploited by Hackers</title><link>https://cisotimes.com/protect-your-apple-devices-two-zero-day-vulnerabilities-exploited-by-hackers/</link><guid isPermaLink="true">https://cisotimes.com/protect-your-apple-devices-two-zero-day-vulnerabilities-exploited-by-hackers/</guid><description>Apple has always been known for its state-of-the-art technology, and the brand&apos;s devices have become an integral part of our daily lives. However, with</description><pubDate>Sun, 09 Apr 2023 00:00:00 GMT</pubDate><category>Apple</category><category>Cybersecurity</category><category>IOSurfaceAccelerator</category><category>WebKit</category><category>zero-day vulnerabilities</category><author>TheCISO</author></item><item><title>Protect Your Network Now: US CISA Adds Veritas Backup Exec Vulnerabilities to Its Exploited Vulnerabilities Catalog</title><link>https://cisotimes.com/protect-your-network-now-us-cisa-adds-veritas-backup-exec-vulnerabilities-to-its-exploited-vulnerabilities-catalog/</link><guid isPermaLink="true">https://cisotimes.com/protect-your-network-now-us-cisa-adds-veritas-backup-exec-vulnerabilities-to-its-exploited-vulnerabilities-catalog/</guid><description>The Cybersecurity and Infrastructure Security Agency (CISA) in the US has recently updated its Known Exploited Vulnerabilities Catalog to include five new</description><pubDate>Sun, 09 Apr 2023 00:00:00 GMT</pubDate><author>TheCISO</author></item><item><title>Uber’s Law Firm Suffers Third-Party Data Theft, Exposes Driver Information</title><link>https://cisotimes.com/ubers-law-firm-suffers-third-party-data-theft-exposes-driver-information/</link><guid isPermaLink="true">https://cisotimes.com/ubers-law-firm-suffers-third-party-data-theft-exposes-driver-information/</guid><description>Uber, a leading ride-hailing service, has once again faced a data breach that compromised the information of its drivers. This time, the hack targeted Genova</description><pubDate>Sun, 09 Apr 2023 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>Data Breach</category><category>supply chain attack</category><category>third-party</category><category>Uber</category><author>TheCISO</author></item><item><title>Protect Your Android Device Now: Critical Security Vulnerabilities Discovered</title><link>https://cisotimes.com/protect-your-android-device-now-critical-security-vulnerabilities-discovered/</link><guid isPermaLink="true">https://cisotimes.com/protect-your-android-device-now-critical-security-vulnerabilities-discovered/</guid><description>In the April 2023 Android Security Bulletin, Google announced the discovery of critical security vulnerabilities that can impact Android devices running</description><pubDate>Thu, 06 Apr 2023 00:00:00 GMT</pubDate><category>Android</category><category>CVE</category><category>Exploited</category><category>Remote Code Execution</category><category>Security Bulletin</category><category>Updates</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>Ransomware Analysis: Discovering the Unique Features of Rorschach</title><link>https://cisotimes.com/ransomware-analysis-discovering-the-unique-features-of-rorschach/</link><guid isPermaLink="true">https://cisotimes.com/ransomware-analysis-discovering-the-unique-features-of-rorschach/</guid><description>Rorschach is a newly discovered ransomware strain that has caught the attention of the cybersecurity industry. It was discovered by the Cybersecurity and</description><pubDate>Thu, 06 Apr 2023 00:00:00 GMT</pubDate><category>CISA</category><category>Cybersecurity</category><category>Encryption</category><category>hybrid-cryptography</category><category>Malware</category><category>propagation</category><category>Ransomware</category><category>Rorschach</category><author>Dimitris Gkoutzamanis</author></item><item><title>TikTok Fined $15.6 Million for Misusing Children Data</title><link>https://cisotimes.com/tiktok-fined-15-6-million-for-misusing-children-data/</link><guid isPermaLink="true">https://cisotimes.com/tiktok-fined-15-6-million-for-misusing-children-data/</guid><description>TikTok, the popular social media app, has been fined $15.6 million (£12.7 million) by the UK&apos;s data protection watchdog, the Information Commissioner&apos;s Office</description><pubDate>Thu, 06 Apr 2023 00:00:00 GMT</pubDate><category>child safety</category><category>Data Protection</category><category>fine</category><category>ICO</category><category>Social Media</category><category>TikTok</category><author>Dimitris Gkoutzamanis</author></item><item><title>Massive Cybersecurity Breach at Latitude Financial Services: Over 300,000 Customers Affected</title><link>https://cisotimes.com/massive-cybersecurity-breach-at-latitude-financial-services-over-300000-customers-affected/</link><guid isPermaLink="true">https://cisotimes.com/massive-cybersecurity-breach-at-latitude-financial-services-over-300000-customers-affected/</guid><description>Latitude Financial Services, an Australian finance company, has become the latest victim of a sophisticated cyber attack, which has seen the personal data of</description><pubDate>Mon, 27 Mar 2023 00:00:00 GMT</pubDate><category>Cyber Attacks</category><category>Cybersecurity</category><category>data retention policies</category><category>Fraud</category><category>identity theft</category><category>Latitude Financial Services</category><category>Personal Data</category><author>Dimitris Gkoutzamanis</author></item><item><title>NCA Shuts Down Illegal DDoS-For-Hire Services: Operation Power Off</title><link>https://cisotimes.com/nca-shuts-down-illegal-ddos-for-hire-services-operation-power-off/</link><guid isPermaLink="true">https://cisotimes.com/nca-shuts-down-illegal-ddos-for-hire-services-operation-power-off/</guid><description>The National Crime Agency (NCA) has announced that it has successfully infiltrated several online criminal marketplaces that offer Distributed Denial of</description><pubDate>Mon, 27 Mar 2023 00:00:00 GMT</pubDate><category>Booters</category><category>Cybercrime</category><category>DDoS</category><category>NCA</category><category>Operation Power Off</category><author>TheCISO</author></item><item><title>Redis Bug Exposes Personal Information of ChatGPT Users</title><link>https://cisotimes.com/redis-bug-exposes-personal-information-of-chatgpt-users/</link><guid isPermaLink="true">https://cisotimes.com/redis-bug-exposes-personal-information-of-chatgpt-users/</guid><description>OpenAI&apos;s chatbot service, ChatGPT, recently suffered a data exposure incident, where users&apos; personal information and chat titles were accidentally made</description><pubDate>Mon, 27 Mar 2023 00:00:00 GMT</pubDate><category>ChatGPT</category><category>Cybersecurity</category><category>Data Exposure</category><category>Privacy</category><category>open-source libraries</category><category>OpenAI</category><category>Redis</category><category>Redis bug</category><author>Dimitris Gkoutzamanis</author></item><item><title>Beware of Nexus: A New Android Banking Trojan Targeting Financial Apps</title><link>https://cisotimes.com/beware-of-nexus-a-new-android-banking-trojan-targeting-financial-apps/</link><guid isPermaLink="true">https://cisotimes.com/beware-of-nexus-a-new-android-banking-trojan-targeting-financial-apps/</guid><description>A newly discovered Android banking trojan called Nexus is causing havoc in the financial industry. Cybersecurity analysts at Cleafy detected the malware in</description><pubDate>Sun, 26 Mar 2023 00:00:00 GMT</pubDate><category>2FA</category><category>Android banking trojan</category><category>ATO attacks</category><category>C2</category><category>Cybersecurity</category><category>financial apps</category><category>MaaS</category><category>Nexus</category><category>Ransomware</category><category>Threat Actors</category><author>Dimitris Gkoutzamanis</author></item><item><title>Hacker Site Mastermind Charged by US DOJ for Operating Breachforums</title><link>https://cisotimes.com/hacker-site-mastermind-charged-by-us-doj-for-operating-breachforums/</link><guid isPermaLink="true">https://cisotimes.com/hacker-site-mastermind-charged-by-us-doj-for-operating-breachforums/</guid><description>The United States Department of Justice has made a significant breakthrough in the fight against cybercrime. On Friday, the department announced that a</description><pubDate>Sun, 26 Mar 2023 00:00:00 GMT</pubDate><category>Breachforums</category><category>Cybercrime</category><category>Cybersecurity</category><category>Data breaches</category><category>hacker</category><category>US DOJ</category><author>Dimitris Gkoutzamanis</author></item><item><title>New Malware Used in Cyber Espionage Campaign Targeting Russian-Occupied Regions in Ukraine</title><link>https://cisotimes.com/new-malware-used-in-cyber-espionage-campaign-targeting-russian-occupied-regions-in-ukraine/</link><guid isPermaLink="true">https://cisotimes.com/new-malware-used-in-cyber-espionage-campaign-targeting-russian-occupied-regions-in-ukraine/</guid><description>A recent cyber espionage campaign has been discovered by Russian-based infosec software vendor Kaspersky.</description><pubDate>Sat, 25 Mar 2023 00:00:00 GMT</pubDate><category>cyber espionage</category><category>cyber threat</category><category>Kaspersky</category><category>Malware</category><category>Russia</category><category>Ukraine</category><author>Dimitris Gkoutzamanis</author></item><item><title>Protect Your Microsoft Cloud Environments with CISA’s Open-Source Incident Response Tool: Untitled Goose Tool</title><link>https://cisotimes.com/protect-your-microsoft-cloud-environments-with-cisas-open-source-incident-response-tool-untitled-goose-tool/</link><guid isPermaLink="true">https://cisotimes.com/protect-your-microsoft-cloud-environments-with-cisas-open-source-incident-response-tool-untitled-goose-tool/</guid><description>The Cybersecurity and Infrastructure Security Agency (CISA) has introduced a new open-source incident response tool called the Untitled Goose Tool. This</description><pubDate>Sat, 25 Mar 2023 00:00:00 GMT</pubDate><category>CISA</category><category>Cyber Attacks</category><category>Cyber Security Evaluation Tool</category><category>Cybersecurity</category><category>incident response tool</category><category>Microsoft cloud environments</category><category>MITRE ATT&amp;CK mapping reports</category><category>Ransomware</category><category>Ransomware Readiness Assessment</category><category>Untitled Goose Tool</category><author>Dimitris Gkoutzamanis</author></item><item><title>Massive Bitcoin Theft: General Bytes Suffers $1.5 Million Breach</title><link>https://cisotimes.com/massive-bitcoin-theft-general-bytes-suffers-1-5-million-breach/</link><guid isPermaLink="true">https://cisotimes.com/massive-bitcoin-theft-general-bytes-suffers-1-5-million-breach/</guid><description>General Bytes, a major producer of cryptocurrency automated teller machines (ATMs), was recently hit by a security breach that resulted in the theft of over</description><pubDate>Thu, 23 Mar 2023 00:00:00 GMT</pubDate><category>API keys</category><category>Bitcoin</category><category>CAS</category><category>Cryptocurrency</category><category>exchanges</category><category>Firewall</category><category>General Bytes</category><category>hot wallets</category><category>security breach</category><category>security measures</category><category>theft</category><category>VPN</category><author>Dimitris Gkoutzamanis</author></item><item><title>New PerlBot Malware Targeting Poorly Managed Linux SSH Servers</title><link>https://cisotimes.com/new-perlbot-malware-targeting-poorly-managed-linux-ssh-servers/</link><guid isPermaLink="true">https://cisotimes.com/new-perlbot-malware-targeting-poorly-managed-linux-ssh-servers/</guid><description>AhnLab Security Emergency Response Center (ASEC) has uncovered a new variant of the ShellBot malware, which is also known as PerlBot. This Perl-based DDoS bot</description><pubDate>Thu, 23 Mar 2023 00:00:00 GMT</pubDate><category>AhnLab Security Emergency Response Center</category><category>ASEC</category><category>DDoS attacks</category><category>dictionary attacks</category><category>Linux servers</category><category>PerlBot malware</category><category>ShellBot malware</category><category>SSH bruteforce attacks</category><author>Dimitris Gkoutzamanis</author></item><item><title>Protecting Our Transport: ENISA’s Cyber Threat Landscape Report</title><link>https://cisotimes.com/protecting-our-transport-enisas-cyber-threat-landscape-report/</link><guid isPermaLink="true">https://cisotimes.com/protecting-our-transport-enisas-cyber-threat-landscape-report/</guid><description>ENISA, the European Union Agency for Cybersecurity, has released its first-ever Cyber Threat Landscape Report for the transport sector. The report covers</description><pubDate>Thu, 23 Mar 2023 00:00:00 GMT</pubDate><category>aviation sector</category><category>critical infrastructures</category><category>Cyber Threats</category><category>Cybersecurity</category><category>ENISA</category><category>IT Systems</category><category>OT operations</category><category>Ransomware</category><category>Threat Actors</category><category>transport sector</category><author>Dimitris Gkoutzamanis</author></item><item><title>Uncovering the Menacing Tactics of Mispadu: Protecting Against the Rampant Credential Theft</title><link>https://cisotimes.com/uncovering-the-menacing-tactics-of-mispadu-protecting-against-the-rampant-credential-theft/</link><guid isPermaLink="true">https://cisotimes.com/uncovering-the-menacing-tactics-of-mispadu-protecting-against-the-rampant-credential-theft/</guid><description>A total of twenty spam campaigns were found to have targeted Chile, Mexico, Peru, and Portugal according to Metabaseq researchers&apos; investigation.</description><pubDate>Thu, 23 Mar 2023 00:00:00 GMT</pubDate><category>Chile</category><category>credential theft</category><category>Cybercrime</category><category>Cybersecurity</category><category>Latin America</category><category>Malware</category><category>Mexico</category><category>Mispadu</category><category>Peru</category><category>Portugal</category><author>Dimitris Gkoutzamanis</author></item><item><title>Hackers Breach Ferrari and NBA’s Data Systems</title><link>https://cisotimes.com/hackers-breach-ferrari-and-nbas-data-systems/</link><guid isPermaLink="true">https://cisotimes.com/hackers-breach-ferrari-and-nbas-data-systems/</guid><description>Data breaches are becoming increasingly common, with many companies falling victim to the sophisticated tactics of cybercriminals. Recently, Ferrari and the</description><pubDate>Tue, 21 Mar 2023 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>Data breaches</category><category>Ferrari</category><category>Hackers</category><category>NBA</category><category>Ransomware</category><author>TheCISO</author></item><item><title>ZCryptor Ransomware Attacks Targeting VMware Systems</title><link>https://cisotimes.com/zcryptor-ransomware-attacks-targeting-vmware-systems/</link><guid isPermaLink="true">https://cisotimes.com/zcryptor-ransomware-attacks-targeting-vmware-systems/</guid><description>The Italian National Cybersecurity Agency (ACN) has sounded the alarm on a new ransomware threat that is targeting unpatched VMware systems. The ransomware,</description><pubDate>Mon, 20 Mar 2023 00:00:00 GMT</pubDate><category>ACN</category><category>CISA</category><category>Cybersecurity</category><category>ESXiArgs</category><category>Ransomware</category><category>VMware</category><category>ZCryptor</category><author>TheCISO</author></item><item><title>Chinese Hacking Group Linked to Zero-Day Exploitation of Fortinet FortiOS Security Flaw</title><link>https://cisotimes.com/chinese-hacking-group-linked-to-zero-day-exploitation-of-fortinet-fortios-security-flaw/</link><guid isPermaLink="true">https://cisotimes.com/chinese-hacking-group-linked-to-zero-day-exploitation-of-fortinet-fortios-security-flaw/</guid><description>Threat intelligence firm Mandiant has attributed the zero-day exploitation of a medium-severity security flaw in the Fortinet FortiOS operating system to a</description><pubDate>Sun, 19 Mar 2023 00:00:00 GMT</pubDate><category>arbitrary code execution</category><category>Chinese hacking group</category><category>Cybersecurity</category><category>Firewall</category><category>Fortinet FortiOS</category><category>Mandiant</category><category>patch</category><category>Threat Intelligence</category><category>UNC3886</category><category>virtualization technologies</category><category>Vulnerability</category><category>zero-day exploitation</category><author>TheCISO</author></item><item><title>How to Protect Yourself from GPT-4 Scammers: Tips to Avoid Crypto Phishing Scams</title><link>https://cisotimes.com/how-to-protect-yourself-from-gpt-4-scammers-tips-to-avoid-crypto-phishing-scams/</link><guid isPermaLink="true">https://cisotimes.com/how-to-protect-yourself-from-gpt-4-scammers-tips-to-avoid-crypto-phishing-scams/</guid><description>The launch of OpenAI&apos;s GPT-4 has created a buzz among artificial intelligence and cryptocurrency enthusiasts. Unfortunately, scammers have also taken notice</description><pubDate>Sun, 19 Mar 2023 00:00:00 GMT</pubDate><category>Cryptocurrency</category><category>GPT-4</category><category>OpenAI</category><category>Phishing</category><category>scam</category><category>wallet security</category><author>Dimitris Gkoutzamanis</author></item><item><title>The Evolution of Pentest Frameworks: From Past to Present</title><link>https://cisotimes.com/the-evolution-of-pentest-frameworks-from-past-to-present/</link><guid isPermaLink="true">https://cisotimes.com/the-evolution-of-pentest-frameworks-from-past-to-present/</guid><description>Pentest frameworks serve as a foundation for conducting systematic and efficient penetration tests. These tools streamline the testing process by offering a</description><pubDate>Sun, 19 Mar 2023 00:00:00 GMT</pubDate><category>Penetration Testing</category><category>Penetration Testing Frameworks</category><author>Dimitris Gkoutzamanis</author></item><item><title>Free Decryption Tool Helps Hundreds of Victims Recover Files from Modified Conti Ransomware</title><link>https://cisotimes.com/free-decryption-tool-helps-hundreds-of-victims-recover-files-from-modified-conti-ransomware/</link><guid isPermaLink="true">https://cisotimes.com/free-decryption-tool-helps-hundreds-of-victims-recover-files-from-modified-conti-ransomware/</guid><description>Cybersecurity researchers have discovered a decryption tool that could help hundreds of victims who have fallen prey to a modified version of the Conti</description><pubDate>Sat, 18 Mar 2023 00:00:00 GMT</pubDate><category>Conti ransomware</category><category>Cybersecurity</category><category>decryption tool</category><category>Kaspersky</category><category>MeowCorp</category><category>Ransomware</category><category>Ryuk ransomware</category><category>TrickBot</category><author>Dimitris Gkoutzamanis</author></item><item><title>Protecting Your Phone from the Exynos Modem Vulnerabilities: What You Need to Know</title><link>https://cisotimes.com/protecting-your-phone-from-the-exynos-modem-vulnerabilities-what-you-need-to-know/</link><guid isPermaLink="true">https://cisotimes.com/protecting-your-phone-from-the-exynos-modem-vulnerabilities-what-you-need-to-know/</guid><description>In late 2022 and early 2023, Project Zero discovered a series of vulnerabilities in Exynos Modems produced by Samsung Semiconductor. These vulnerabilities</description><pubDate>Sat, 18 Mar 2023 00:00:00 GMT</pubDate><category>0-day vulnerabilities</category><category>baseband remote code execution</category><category>Exynos Auto T5123</category><category>Exynos Modem</category><category>Google</category><category>mobile devices</category><category>patch timelines</category><category>Pixel</category><category>Samsung Semiconductor</category><category>Vivo</category><category>VoLTE</category><category>Wi-Fi calling</category><author>Dimitris Gkoutzamanis</author></item><item><title>Urgent Warning: Act Now to Patch Newly Discovered Zero-Day Vulnerability in Microsoft Outlook</title><link>https://cisotimes.com/urgent-warning-act-now-to-patch-newly-discovered-zero-day-vulnerability-in-microsoft-outlook/</link><guid isPermaLink="true">https://cisotimes.com/urgent-warning-act-now-to-patch-newly-discovered-zero-day-vulnerability-in-microsoft-outlook/</guid><description>Microsoft Outlook, the popular email client, is in the news again, but not for good reasons. Security researchers have identified a zero-day vulnerability in</description><pubDate>Sat, 18 Mar 2023 00:00:00 GMT</pubDate><category>Microsoft</category><category>Outlook</category><category>Patching</category><category>Zero-Day</category><author>Dimitris Gkoutzamanis</author></item><item><title>Top Challenges Financial Services CISOs Will Face This Year</title><link>https://cisotimes.com/top-challenges-financial-services-cisos-will-face-this-year/</link><guid isPermaLink="true">https://cisotimes.com/top-challenges-financial-services-cisos-will-face-this-year/</guid><description>In the current uncertain economic climate, many leaders are being asked to cut costs, and despite rising corporate concerns regarding cybersecurity, Chief</description><pubDate>Fri, 17 Mar 2023 00:00:00 GMT</pubDate><author>TheCISO</author></item><item><title>Beware of DoS Attacks on Cisco Routers: Cisco Releases Critical Security Updates</title><link>https://cisotimes.com/beware-of-dos-attacks-on-cisco-routers-cisco-releases-critical-security-updates/</link><guid isPermaLink="true">https://cisotimes.com/beware-of-dos-attacks-on-cisco-routers-cisco-releases-critical-security-updates/</guid><description>Cisco has released critical security updates to address a high-severity DoS (Denial of Service) vulnerability that affects its IOS XR software. This</description><pubDate>Sun, 12 Mar 2023 00:00:00 GMT</pubDate><category>ASR 9000 Series</category><category>ASR 9902</category><category>ASR 9903</category><category>BFD hardware offload</category><category>Cisco</category><category>Cisco routers</category><category>Denial of Service</category><category>DoS attacks</category><category>IOS XR software</category><category>Security Updates</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>Empowering Cybersecurity: Biden Administration’s National Cybersecurity Strategy</title><link>https://cisotimes.com/empowering-cybersecurity-biden-administrations-national-cybersecurity-strategy/</link><guid isPermaLink="true">https://cisotimes.com/empowering-cybersecurity-biden-administrations-national-cybersecurity-strategy/</guid><description>On March 2, 2023, the Biden Administration released its National Cybersecurity Strategy, which aims to address the growing cybersecurity concerns in the</description><pubDate>Sun, 12 Mar 2023 00:00:00 GMT</pubDate><category>Biden Administration</category><category>Cybersecurity</category><category>federal contractors</category><category>industry</category><category>liability</category><category>National Cybersecurity Strategy</category><category>Personal Data</category><category>regulations</category><category>software producers</category><category>zero trust architecture</category><author>TheCISO</author></item><item><title>Protecting Your Investments: OpenSea NFT Marketplace Vulnerability and the Importance of NFT Security</title><link>https://cisotimes.com/protecting-your-investments-opensea-nft-marketplace-vulnerability-and-the-importance-of-nft-security/</link><guid isPermaLink="true">https://cisotimes.com/protecting-your-investments-opensea-nft-marketplace-vulnerability-and-the-importance-of-nft-security/</guid><description>The OpenSea NFT marketplace is one of the largest platforms for buying and selling non-fungible tokens (NFTs) - unique digital assets that are verified on the</description><pubDate>Sun, 12 Mar 2023 00:00:00 GMT</pubDate><category>blockchain</category><category>Cybersecurity</category><category>Fraud</category><category>NFT</category><category>OpenSea</category><category>security measures</category><author>Dimitris Gkoutzamanis</author></item><item><title>Acronis Suffers Cyber Attack, But Only One Customer Account Affected</title><link>https://cisotimes.com/acronis-suffers-cyber-attack-but-only-one-customer-account-affected/</link><guid isPermaLink="true">https://cisotimes.com/acronis-suffers-cyber-attack-but-only-one-customer-account-affected/</guid><description>Acronis, a leading Swiss data protection firm, recently suffered a cyber attack that caused quite a stir in the tech industry. A hacker claiming to be bored</description><pubDate>Sat, 11 Mar 2023 00:00:00 GMT</pubDate><category>Acronis</category><category>Cyber Attacks</category><category>Cybersecurity</category><category>Data Breach</category><category>Data Protection</category><author>Dimitris Gkoutzamanis</author></item><item><title>Malware Uses AI to Avoid Detection</title><link>https://cisotimes.com/malware-uses-ai-to-avoid-detection/</link><guid isPermaLink="true">https://cisotimes.com/malware-uses-ai-to-avoid-detection/</guid><description>With the rise of artificial intelligence (AI), cybercriminals have been developing new exploits that can evade even the most sophisticated cybersecurity</description><pubDate>Sat, 11 Mar 2023 00:00:00 GMT</pubDate><category>AI</category><category>BlackMamba</category><category>ChatGPT</category><category>Cybersecurity</category><category>Malware</category><category>OpenAI</category><category>polymorphic malware</category><author>Dimitris Gkoutzamanis</author></item><item><title>Massive Data Breach at AT&amp;T: 9 Million Wireless Customers’ Account Details Compromised</title><link>https://cisotimes.com/massive-data-breach-at-att-9-million-wireless-customers-account-details-compromised/</link><guid isPermaLink="true">https://cisotimes.com/massive-data-breach-at-att-9-million-wireless-customers-account-details-compromised/</guid><description>Telecommunications giant AT&amp;T has confirmed that nearly nine million of its wireless customers&apos; account details were accessed by unauthorized individuals</description><pubDate>Sat, 11 Mar 2023 00:00:00 GMT</pubDate><category>AT&amp;T</category><category>Customer Data</category><category>Cybersecurity</category><category>Data Breach</category><category>vendor network breach</category><author>Dimitris Gkoutzamanis</author></item><item><title>Playing with Fire: Why TikTok is a Loaded Gun for America’s Youth</title><link>https://cisotimes.com/playing-with-fire-why-tiktok-is-a-loaded-gun-for-americas-youth/</link><guid isPermaLink="true">https://cisotimes.com/playing-with-fire-why-tiktok-is-a-loaded-gun-for-americas-youth/</guid><description>TikTok is an immensely popular social media platform that allows users to create, share, and discover short video clips. However, General Paul Nakasone,</description><pubDate>Sat, 11 Mar 2023 00:00:00 GMT</pubDate><category>ban</category><category>CCP</category><category>espionage</category><category>federal devices</category><category>influence operations</category><category>national security</category><category>TikTok</category><category>US government</category><category>young Americans</category><author>TheCISO</author></item><item><title>Powerful Prometei Botnet Infects 10,000 Systems Worldwide</title><link>https://cisotimes.com/powerful-prometei-botnet-infects-10000-systems-worldwide/</link><guid isPermaLink="true">https://cisotimes.com/powerful-prometei-botnet-infects-10000-systems-worldwide/</guid><description>The digital world is constantly evolving, and unfortunately, so are the cyber threats that come with it. One such threat is the Prometei botnet malware, which</description><pubDate>Sat, 11 Mar 2023 00:00:00 GMT</pubDate><category>Cryptocurrency</category><category>Cyber Attacks</category><category>Cyber Threats</category><category>Cybersecurity</category><category>Malware</category><category>Prometei botnet</category><author>Dimitris Gkoutzamanis</author></item><item><title>Powering up Cyber Resilience: ECB to Launch Simulated Attacks on Major Banks</title><link>https://cisotimes.com/powering-up-cyber-resilience-ecb-to-launch-simulated-attacks-on-major-banks/</link><guid isPermaLink="true">https://cisotimes.com/powering-up-cyber-resilience-ecb-to-launch-simulated-attacks-on-major-banks/</guid><description>In response to the surge of cyber attacks on banks and financial institutions in Europe, the European Central Bank (ECB) is taking a proactive approach to</description><pubDate>Sat, 11 Mar 2023 00:00:00 GMT</pubDate><category>Banks</category><category>Cyber Resilience</category><category>Cyber War</category><category>Defense Mechanisms</category><category>Digital Attacks</category><category>ECB</category><category>IT Infrastructure</category><category>Russia</category><category>Simulated Attacks</category><category>Thematic Stress Tests</category><category>Ukraine</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>Protect Yourself from Bitwarden’s Risky Autofill Feature</title><link>https://cisotimes.com/protect-yourself-from-bitwardens-risky-autofill-feature/</link><guid isPermaLink="true">https://cisotimes.com/protect-yourself-from-bitwardens-risky-autofill-feature/</guid><description>Bitwarden, a popular open-source password management service, has a potentially dangerous security flaw that could allow threat actors to steal login</description><pubDate>Sat, 11 Mar 2023 00:00:00 GMT</pubDate><category>autofill</category><category>Bitwarden</category><category>iframe</category><category>login credentials</category><category>password management</category><category>security flaw</category><author>Dimitris Gkoutzamanis</author></item><item><title>Update Android: Latest Android Security Updates</title><link>https://cisotimes.com/update-android-latest-android-security-updates/</link><guid isPermaLink="true">https://cisotimes.com/update-android-latest-android-security-updates/</guid><description>If you&apos;re an Android user, there&apos;s some important news you need to be aware of. The March 2023 Android Security Bulletin contains crucial information about</description><pubDate>Sat, 11 Mar 2023 00:00:00 GMT</pubDate><category>Android</category><category>Buffer Overflow</category><category>Kernel</category><category>Memory Corruption</category><category>PPP</category><category>Remote Code Execution</category><category>Cybersecurity</category><category>Updates</category><category>Vulnerability</category><author>TheCISO</author></item><item><title>What’s Lacking in Traditional Vulnerability Management: A Comprehensive Look</title><link>https://cisotimes.com/whats-lacking-in-traditional-vulnerability-management-a-comprehensive-look/</link><guid isPermaLink="true">https://cisotimes.com/whats-lacking-in-traditional-vulnerability-management-a-comprehensive-look/</guid><description>Traditional vulnerability management approaches have limitations that put businesses at risk. Adopting a comprehensive and proactive approach to vulnerability</description><pubDate>Sat, 11 Mar 2023 00:00:00 GMT</pubDate><category>Automation</category><category>continuous monitoring</category><category>Cybersecurity</category><category>Network Security</category><category>risk mitigation</category><category>Threat Detection</category><category>vulnerability management</category><author>Dimitris Gkoutzamanis</author></item><item><title>Crushing the DoppelPaymer Ransomware Gang: Joint Operation Results in Arrests</title><link>https://cisotimes.com/crushing-the-doppelpaymer-ransomware-gang-joint-operation-results-in-arrests/</link><guid isPermaLink="true">https://cisotimes.com/crushing-the-doppelpaymer-ransomware-gang-joint-operation-results-in-arrests/</guid><description>Core members of the DoppelPaymer ransomware gang were apprehended in a joint operation by the Ukrainian National Police and the German Regional Police, with</description><pubDate>Tue, 07 Mar 2023 00:00:00 GMT</pubDate><category>Cybercrime</category><category>Cybersecurity</category><category>DoppelPaymer ransomware</category><category>international law enforcement</category><category>Ransomware</category><category>Ransomware Attack</category><author>TheCISO</author></item><item><title>Firewall Optimization: Enhancing Network Security and Performance</title><link>https://cisotimes.com/firewall-optimization-enhancing-network-security-and-performance/</link><guid isPermaLink="true">https://cisotimes.com/firewall-optimization-enhancing-network-security-and-performance/</guid><description>Firewall optimization is a critical process for organizations seeking to enhance their network security and performance. This article explores the benefits of</description><pubDate>Mon, 06 Mar 2023 00:00:00 GMT</pubDate><category>alerting</category><category>asset discovery</category><category>Compliance</category><category>configuration analysis</category><category>cost savings</category><category>firewall analyzer</category><category>firewall management</category><category>firewall optimization</category><category>intrusion detection systems</category><category>log analysis</category><category>Monitoring</category><category>multi-vendor support</category><category>Network Security</category><category>performance</category><category>policy management</category><category>security analytics</category><category>vulnerability scanners</category><author>Dimitris Gkoutzamanis</author></item><item><title>Vulnerability in U.S. Quantum-Resistant Encryption Algorithm</title><link>https://cisotimes.com/vulnerability-in-u-s-quantum-resistant-encryption-algorithm/</link><guid isPermaLink="true">https://cisotimes.com/vulnerability-in-u-s-quantum-resistant-encryption-algorithm/</guid><description>A team of researchers from the KTH Royal Institute of Technology has uncovered a vulnerability in one of the encryption algorithms selected by the U.S.</description><pubDate>Mon, 06 Mar 2023 00:00:00 GMT</pubDate><category>CRYSTALS-Kyber</category><category>Cybersecurity</category><category>Encryption</category><category>masking</category><category>NIST</category><category>quantum-resistant</category><category>side-channel attack</category><author>Dimitris Gkoutzamanis</author></item><item><title>Why Combining Infosec with IT is a Recipe for Disaster: The Case for Separation</title><link>https://cisotimes.com/why-combining-infosec-with-it-is-a-recipe-for-disaster-the-case-for-separation/</link><guid isPermaLink="true">https://cisotimes.com/why-combining-infosec-with-it-is-a-recipe-for-disaster-the-case-for-separation/</guid><description>Before we delve into why separating infosec from IT is important, it&apos;s essential to understand the difference between the two.</description><pubDate>Sun, 05 Mar 2023 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>Data Security</category><category>efficiency</category><category>infosec</category><category>IT</category><category>organizational security</category><category>security vulnerabilities</category><category>staff responsibilities</category><category>technology infrastructure</category><author>Dimitris Gkoutzamanis</author></item><item><title>Hatch Bank Suffers Data Breach: Another Supply Chain Attack</title><link>https://cisotimes.com/hatch-bank-suffers-data-breach-another-supply-chain-attack/</link><guid isPermaLink="true">https://cisotimes.com/hatch-bank-suffers-data-breach-another-supply-chain-attack/</guid><description>Hatch Bank has become the latest company to suffer the consequences of a data breach caused by a supply chain attack. The incident was a result of a</description><pubDate>Sat, 04 Mar 2023 00:00:00 GMT</pubDate><category>Clop ransomware</category><category>Customer Data</category><category>Cybersecurity</category><category>Data Breach</category><category>Fortra</category><category>GoAnywhere MFT</category><category>Hatch Bank</category><category>supply chain attack</category><category>Zero-Day</category><author>Dimitris Gkoutzamanis</author></item><item><title>Pierce Transit Falls Victim to LockBit Ransomware Attack</title><link>https://cisotimes.com/pierce-transit-falls-victim-to-lockbit-ransomware-attack/</link><guid isPermaLink="true">https://cisotimes.com/pierce-transit-falls-victim-to-lockbit-ransomware-attack/</guid><description>The Pierce County Public Transportation Benefit Area Corporation (Pierce Transit), a public transit operator in Washington state, has recently become a victim</description><pubDate>Sat, 04 Mar 2023 00:00:00 GMT</pubDate><category>Cyber Attacks</category><category>Cybersecurity</category><category>Data Breach</category><category>LockBit</category><category>Pierce Transit</category><category>Public Transit</category><category>Ransomware</category><category>Ransomware-as-a-Service</category><category>Washington State</category><author>TheCISO</author></item><item><title>ROYAL Ransomware Group: An Overview of Tactics, Techniques, and Procedures</title><link>https://cisotimes.com/royal-ransomware-group-an-overview-of-tactics-techniques-and-procedures/</link><guid isPermaLink="true">https://cisotimes.com/royal-ransomware-group-an-overview-of-tactics-techniques-and-procedures/</guid><description>The Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA) have recently released a cybersecurity advisory as part</description><pubDate>Sat, 04 Mar 2023 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>Cybersecurity and Infrastructure Security Agency</category><category>Federal Bureau of Investigation</category><category>malvertising</category><category>Phishing</category><category>Ransomware</category><category>Royal Ransomware</category><author>Dimitris Gkoutzamanis</author></item><item><title>Dish Network Confirms Ransomware Attack and Data Breach</title><link>https://cisotimes.com/dish-network-confirms-ransomware-attack-and-data-breach/</link><guid isPermaLink="true">https://cisotimes.com/dish-network-confirms-ransomware-attack-and-data-breach/</guid><description>Dish Network, the American satellite broadcast provider, has recently admitted that the outage that occurred on February 24, 2023, was caused by a ransomware</description><pubDate>Wed, 01 Mar 2023 00:00:00 GMT</pubDate><category>Black Basta ransomware</category><category>Cybersecurity</category><category>Data Breach</category><category>Dish Network</category><category>Network infrastructure</category><category>Ransomware Attack</category><author>Dimitris Gkoutzamanis</author></item><item><title>Malware Alert: Law Firms Targeted by GootLoader and SocGholish</title><link>https://cisotimes.com/malware-alert-law-firms-targeted-by-gootloader-and-socgholish/</link><guid isPermaLink="true">https://cisotimes.com/malware-alert-law-firms-targeted-by-gootloader-and-socgholish/</guid><description>In January and February 2023, six different law firms were attacked by two distinct threat campaigns, which unleashed GootLoader and FakeUpdates (aka</description><pubDate>Wed, 01 Mar 2023 00:00:00 GMT</pubDate><category>browser-based attacks</category><category>Cybersecurity</category><category>cybersecurity threats</category><category>espionage operations</category><category>GootLoader</category><category>law firms</category><category>legal professionals</category><category>malware attacks</category><category>Ransomware</category><category>SEO poisoning</category><category>SocGholish</category><category>threat campaigns</category><category>website compromise</category><author>Dimitris Gkoutzamanis</author></item><item><title>Dole Food Company Hit by Ransomware Attack, Temporarily Halts Operations</title><link>https://cisotimes.com/dole-food-company-hit-by-ransomware-attack-temporarily-halts-operations/</link><guid isPermaLink="true">https://cisotimes.com/dole-food-company-hit-by-ransomware-attack-temporarily-halts-operations/</guid><description>Dole Food Company, one of the largest fruit and vegetable producers in the world, has recently disclosed that it was hit by a ransomware attack that caused a</description><pubDate>Mon, 27 Feb 2023 00:00:00 GMT</pubDate><category>Crisis Management</category><category>Cybersecurity</category><category>Data Breach</category><category>Dole Food Company</category><category>Food Production</category><category>Grocery Stores</category><category>New Mexico</category><category>Ransomware Attack</category><category>Supply Chain</category><category>Texas</category><category>Third-Party Cybersecurity Experts</category><author>Dimitris Gkoutzamanis</author></item><item><title>New wave of PlugX RAT attacks masquerading as Windows debugger tool</title><link>https://cisotimes.com/new-wave-of-plugx-rat-attacks-masquerading-as-windows-debugger-tool/</link><guid isPermaLink="true">https://cisotimes.com/new-wave-of-plugx-rat-attacks-masquerading-as-windows-debugger-tool/</guid><description>Cybersecurity experts have identified a new wave of attacks aimed at distributing the PlugX remote access trojan. In this campaign, the trojan is disguised as</description><pubDate>Mon, 27 Feb 2023 00:00:00 GMT</pubDate><category>attack techniques</category><category>cybersecurity threats</category><category>DLL side-loading</category><category>indicators of compromise (IoCs)</category><category>Malware</category><category>persistence</category><category>PlugX RAT</category><category>remote access trojan</category><category>Windows debugger tool</category><category>x32dbg</category><author>Dimitris Gkoutzamanis</author></item><item><title>Rancho Mesquite Casino Data Breach Lawsuit</title><link>https://cisotimes.com/rancho-mesquite-casino-data-breach-lawsuit/</link><guid isPermaLink="true">https://cisotimes.com/rancho-mesquite-casino-data-breach-lawsuit/</guid><description>A class-action lawsuit filed on Wednesday alleges that Rancho Mesquite Casino&apos;s computer systems were left vulnerable to a cyberattack, leaving the personal</description><pubDate>Sat, 25 Feb 2023 00:00:00 GMT</pubDate><author>TheCISO</author></item><item><title>Russian National Accused of Creating NLBrute Hacking Tool Faces Criminal Charges in the US</title><link>https://cisotimes.com/russian-national-accused-of-creating-nlbrute-hacking-tool-faces-criminal-charges-in-the-us/</link><guid isPermaLink="true">https://cisotimes.com/russian-national-accused-of-creating-nlbrute-hacking-tool-faces-criminal-charges-in-the-us/</guid><description>NLBrute, a brute-force hacking tool created by a Russian national, and the criminal charges he faces in the US.</description><pubDate>Sat, 25 Feb 2023 00:00:00 GMT</pubDate><category>brute-force attacks</category><category>criminal charges</category><category>Cybercrime</category><category>Cybersecurity</category><category>Dariy Pankov</category><category>Hacking</category><category>NLBrute</category><category>RDP</category><category>Two-Factor Authentication</category><category>US Department of Justice</category><author>TheCISO</author></item><item><title>Two Radio Stations in Crimea Hacked with a Message from Ukraine</title><link>https://cisotimes.com/two-radio-stations-in-crimea-hacked-with-a-message-from-ukraine/</link><guid isPermaLink="true">https://cisotimes.com/two-radio-stations-in-crimea-hacked-with-a-message-from-ukraine/</guid><description>On the eve of the anniversary of Vladimir Putin&apos;s 2014 invasion, two radio stations in Crimea were hacked with a message from Ukraine. The message included</description><pubDate>Sat, 25 Feb 2023 00:00:00 GMT</pubDate><author>TheCISO</author></item><item><title>Website Spoofing: Understanding the Risks and How to Protect Your Business</title><link>https://cisotimes.com/website-spoofing-understanding-the-risks-and-how-to-protect-your-business/</link><guid isPermaLink="true">https://cisotimes.com/website-spoofing-understanding-the-risks-and-how-to-protect-your-business/</guid><description>Protect your business and customers from the risks of website spoofing. Learn about prevention measures and tools to safeguard against this serious threat.</description><pubDate>Sat, 25 Feb 2023 00:00:00 GMT</pubDate><category>Cyber Attacks</category><category>Cybercrime</category><category>Cybersecurity</category><category>Data Protection</category><category>digital risk protection</category><category>internet security</category><category>Malware</category><category>online fraud</category><category>Phishing</category><category>website spoofing</category><author>Dimitris Gkoutzamanis</author></item><item><title>Lazarus Group Unleashes New Backdoor Malware through Wslink Downloader</title><link>https://cisotimes.com/lazarus-group-unleashes-new-backdoor-malware-through-wslink-downloader/</link><guid isPermaLink="true">https://cisotimes.com/lazarus-group-unleashes-new-backdoor-malware-through-wslink-downloader/</guid><description>A new backdoor linked to the notorious North Korea-aligned Lazarus Group has been discovered by researchers.</description><pubDate>Thu, 23 Feb 2023 00:00:00 GMT</pubDate><category>advanced persistent threat</category><category>Backdoor</category><category>Cyber Attacks</category><category>Cybersecurity</category><category>Hacking Tools</category><category>lateral movement</category><category>Lazarus Group</category><category>Malware</category><category>WinorDLL64</category><category>Wslink malware downloader</category><author>Dimitris Gkoutzamanis</author></item><item><title>New Ransomware Strain “Nevada Group” Targets Thousands of Victims in the US and Europe</title><link>https://cisotimes.com/new-ransomware-strain-nevada-group-targets-thousands-of-victims-in-the-us-and-europe/</link><guid isPermaLink="true">https://cisotimes.com/new-ransomware-strain-nevada-group-targets-thousands-of-victims-in-the-us-and-europe/</guid><description>A new variant of ransomware, known as &quot;Nevada Group,&quot; has recently emerged, targeting over 5,000 victims in the US and Europe. Security researchers have</description><pubDate>Thu, 23 Feb 2023 00:00:00 GMT</pubDate><category>CISA</category><category>Cyber Attacks</category><category>Cybersecurity</category><category>FBI</category><category>IBM</category><category>Malware</category><category>Nevada Group</category><category>Ransomware</category><category>Trend Micro</category><author>Dimitris Gkoutzamanis</author></item><item><title>Major Victory Against Cybercrime: Norwegian Police Seize $5.84 Million Worth of Cryptocurrency Stolen by Lazarus Group</title><link>https://cisotimes.com/major-victory-against-cybercrime-norwegian-police-seize-5-84-million-worth-of-cryptocurrency-stolen-by-lazarus-group/</link><guid isPermaLink="true">https://cisotimes.com/major-victory-against-cybercrime-norwegian-police-seize-5-84-million-worth-of-cryptocurrency-stolen-by-lazarus-group/</guid><description>Norwegian police agency Økokrim has made a major breakthrough in the fight against cybercrime, announcing the seizure of $5.84 million worth of cryptocurrency stolen by the notorious Lazarus Group</description><pubDate>Mon, 20 Feb 2023 00:00:00 GMT</pubDate><category>Blockchain analytics</category><category>Cryptocurrency theft</category><category>Cybercrime</category><category>Cybersecurity</category><category>Lazarus Group</category><category>money laundering</category><category>Økokrim</category><category>Ransomware</category><author>TheCISO</author></item><item><title>Critical Flaw in ClamAV Discovered and Patched</title><link>https://cisotimes.com/critical-flaw-in-clamav-discovered-and-patched/</link><guid isPermaLink="true">https://cisotimes.com/critical-flaw-in-clamav-discovered-and-patched/</guid><description>Cisco has released critical security updates for the critical flaw in ClamAV</description><pubDate>Fri, 17 Feb 2023 00:00:00 GMT</pubDate><category>Cisco</category><category>ClamAV</category><category>CVE</category><category>CVSS</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>Secure Your Web Infrastructure: HAProxy Vulnerability Exposes Your Backend</title><link>https://cisotimes.com/haproxy-vulnerability-exposes-your-backend/</link><guid isPermaLink="true">https://cisotimes.com/haproxy-vulnerability-exposes-your-backend/</guid><description>Protect your web infrastructure from the HAProxy vulnerability and learn how to safeguard your backend servers from attackers.</description><pubDate>Fri, 17 Feb 2023 00:00:00 GMT</pubDate><category>bug fix</category><category>Cyber Attacks</category><category>cyber security</category><category>dropped headers</category><category>HAProxy vulnerability</category><category>HTTP request smuggling</category><category>load balancer</category><category>reverse proxy</category><category>web application security</category><category>web infrastructure</category><author>Dimitris Gkoutzamanis</author></item><item><title>How the Devastating Ransomware Attack in Oakland Brought the City to its Knees</title><link>https://cisotimes.com/how-the-devastating-ransomware-attack-in-oakland-brought-the-city-to-its-knees/</link><guid isPermaLink="true">https://cisotimes.com/how-the-devastating-ransomware-attack-in-oakland-brought-the-city-to-its-knees/</guid><description>The ransomware attack that struck Oakland on February 8, 2023, has had severe consequences for the city&apos;s services. The attack forced the City&apos;s Information</description><pubDate>Fri, 17 Feb 2023 00:00:00 GMT</pubDate><category>alternate reporting</category><category>city services</category><category>Critical Infrastructure</category><category>Cyber Attacks</category><category>cyber security</category><category>emergency workers</category><category>Hackers</category><category>investigation</category><category>IT department</category><category>law enforcement</category><category>non-emergency systems</category><category>Oakland</category><category>procurement</category><category>Ransomware</category><category>response times</category><category>restoration</category><category>state of emergency</category><category>technology</category><author>TheCISO</author></item><item><title>Shocking Statistics: 50 million Americans Impacted by Data Breaches in 2022</title><link>https://cisotimes.com/shocking-statistics-50-million-americans-impacted-by-data-breaches-in-2022/</link><guid isPermaLink="true">https://cisotimes.com/shocking-statistics-50-million-americans-impacted-by-data-breaches-in-2022/</guid><description>Nearly 50 million Americans were impacted by these breaches in 2022 alone.</description><pubDate>Thu, 16 Feb 2023 00:00:00 GMT</pubDate><author>Dimitris Gkoutzamanis</author></item><item><title>Cloudflare Mitigates Largest HTTP DDoS Attack on Record</title><link>https://cisotimes.com/cloudflare-mitigates-largest-http-ddos-attack-on-record/</link><guid isPermaLink="true">https://cisotimes.com/cloudflare-mitigates-largest-http-ddos-attack-on-record/</guid><description>Cloudflare mitigated the largest HTTP DDoS attack on record, originating from over 30,000 IP addresses and targeting various industries. Learn how the threat of DDoS attacks is growing and what businesses can do to protect themselves.</description><pubDate>Wed, 15 Feb 2023 00:00:00 GMT</pubDate><category>Botnet</category><category>Cloudflare</category><category>cyber security</category><category>cyber threat</category><category>DDoS Attack</category><category>distributed denial-of-service attack</category><category>HTTP DDoS attack</category><category>ransom DDoS attack</category><category>volumetric attack</category><author>Dimitris Gkoutzamanis</author></item><item><title>eCommerce Security: Accidental Data Leaks Put Online Stores at Risk</title><link>https://cisotimes.com/ecommerce-security-accidental-data-leaks-put-online-stores-at-risk/</link><guid isPermaLink="true">https://cisotimes.com/ecommerce-security-accidental-data-leaks-put-online-stores-at-risk/</guid><description>Sansec&apos;s study of 2,037 online stores found 12.3% exposing compressed files containing sensitive data. Threat actors exploit this flaw, and Sansec urges store owners to take immediate action to prevent data leaks.</description><pubDate>Wed, 15 Feb 2023 00:00:00 GMT</pubDate><category>Backup Files</category><category>Data Exposure</category><category>Data Leaks</category><category>eCommerce</category><category>Malware Scanner</category><category>Online Stores</category><category>Sansec</category><category>Cybersecurity</category><category>Sensitive Data</category><category>Threat Actors</category><category>Two-Factor Authentication (2FA)</category><author>Dimitris Gkoutzamanis</author></item><item><title>Microsoft Releases Security Updates To Address 75 Vulnerabilities, Including 3 Zero-Days</title><link>https://cisotimes.com/microsoft-releases-security-updates-to-address-75-vulnerabilities-including-3-zero-days/</link><guid isPermaLink="true">https://cisotimes.com/microsoft-releases-security-updates-to-address-75-vulnerabilities-including-3-zero-days/</guid><description>Microsoft has released security updates to address 75 vulnerabilities, including 3 zero-day vulnerabilities actively exploited in the wild.</description><pubDate>Wed, 15 Feb 2023 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>Microsoft</category><category>Remote Code Execution</category><category>Security Updates</category><category>system privileges</category><category>zero-day vulnerabilities</category><author>Dimitris Gkoutzamanis</author></item><item><title>New Variant of ESXiArgs Ransomware Cannot be Decrypted with Recovery Script</title><link>https://cisotimes.com/new-variant-of-esxiargs-ransomware-cannot-be-decrypted-with-recovery-script/</link><guid isPermaLink="true">https://cisotimes.com/new-variant-of-esxiargs-ransomware-cannot-be-decrypted-with-recovery-script/</guid><description>A new variant of ESXiArgs ransomware uses an updated encryption routine that cannot be decrypted with the recovery script released by CISA.</description><pubDate>Wed, 15 Feb 2023 00:00:00 GMT</pubDate><category>CISA</category><category>CVE-2021-21974</category><category>CVE-2022-31696</category><category>CVE-2022-31697</category><category>CVE-2022-31698</category><category>CVE-2022-31699</category><category>Cybersecurity</category><category>encryption routine</category><category>ESXiArgs</category><category>FBI</category><category>Ransomware</category><category>recovery script</category><category>SLP</category><category>TOX</category><author>Dimitris Gkoutzamanis</author></item><item><title>NOC vs. SOC: Understanding the Differences</title><link>https://cisotimes.com/noc-vs-soc-understanding-the-differences/</link><guid isPermaLink="true">https://cisotimes.com/noc-vs-soc-understanding-the-differences/</guid><description>Learn the differences between a Network Operations Center (NOC) and a Security Operations Center (SOC) in the roles, responsibilities, and functions of each center.</description><pubDate>Wed, 15 Feb 2023 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>network performance</category><category>Network Security</category><category>NOC</category><category>security incidents</category><category>SOC</category><author>Dimitris Gkoutzamanis</author></item><item><title>Namecheap Email Account Breached, Leading to Flood of Phishing Emails</title><link>https://cisotimes.com/namecheap-email-account-breached-leading-to-flood-of-phishing-emails/</link><guid isPermaLink="true">https://cisotimes.com/namecheap-email-account-breached-leading-to-flood-of-phishing-emails/</guid><description>Namecheap&apos;s email account was breached, resulting in a flood of phishing emails. The incident underscores the ongoing threat of phishing attacks and the importance of robust security measures.</description><pubDate>Tue, 14 Feb 2023 00:00:00 GMT</pubDate><category>Cyber Threats</category><category>Privacy</category><category>email breach</category><category>Namecheap</category><category>Online Security</category><category>phishing attacks</category><author>Dimitris Gkoutzamanis</author></item><item><title>Russian Hacktivist Group Killnet Targets NATO in DDoS Attacks</title><link>https://cisotimes.com/russian-hacktivist-group-killnet-targets-nato-in-ddos-attacks/</link><guid isPermaLink="true">https://cisotimes.com/russian-hacktivist-group-killnet-targets-nato-in-ddos-attacks/</guid><description>Killnet, a Russian hacktivist group, has targeted NATO in a series of DDoS attacks causing temporary disruption. Learn about the attack and NATO&apos;s response in this article</description><pubDate>Mon, 13 Feb 2023 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>DDoS attacks</category><category>Killnet</category><category>NATO</category><category>Russia</category><author>Dimitris Gkoutzamanis</author></item><item><title>SecurityScorecard Publishes List of Proxy IPs to Block Killnet DDoS Bot</title><link>https://cisotimes.com/securityscorecard-publishes-list-of-proxy-ips-to-block-killnet-ddos-bot/</link><guid isPermaLink="true">https://cisotimes.com/securityscorecard-publishes-list-of-proxy-ips-to-block-killnet-ddos-bot/</guid><description>Pro-Russia hacking group, Killnet, and their recent attacks on hospitals and critical infrastructure. Learn how SecurityScorecard is helping to prevent these attacks.</description><pubDate>Thu, 09 Feb 2023 00:00:00 GMT</pubDate><category>Critical Infrastructure</category><category>DDoS attacks</category><category>Hacking Group</category><category>Hospitals</category><category>Killnet</category><category>Pro-Russia</category><category>SecurityScorecard</category><author>Dimitris Gkoutzamanis</author></item><item><title>Russian Hacker Pleads Guilty to Laundering Over $150 Million in Ryuk Ransomware Attacks</title><link>https://cisotimes.com/russian-hacker-pleads-guilty-to-laundering-over-150-million-in-ryuk-ransomware-attacks/</link><guid isPermaLink="true">https://cisotimes.com/russian-hacker-pleads-guilty-to-laundering-over-150-million-in-ryuk-ransomware-attacks/</guid><description>Denis Mihaqlovic Dubnikov, a Russian national, recently pleaded guilty in a US court to money laundering and concealing the source of funds obtained in connection with Ryuk ransomware attacks. Learn more about his involvement in cryptocurrency and the estimated $150 million in laundered funds.</description><pubDate>Wed, 08 Feb 2023 00:00:00 GMT</pubDate><category>Cryptocurrency</category><category>Eggchange</category><category>Federation Tower East</category><category>Hacking</category><category>money laundering</category><category>Ransomware</category><category>Ryuk ransomware</category><author>TheCISO</author></item><item><title>PixPirate: Malware Stealing Banking Passwords</title><link>https://cisotimes.com/pixpirate-malware-stealing-banking-passwords/</link><guid isPermaLink="true">https://cisotimes.com/pixpirate-malware-stealing-banking-passwords/</guid><description>PixPirate, the new strain of mobile malware targeting the Pix instant payment platform in Brazil. Learn about the dangers and steps you can take to protect yourself</description><pubDate>Tue, 07 Feb 2023 00:00:00 GMT</pubDate><category>Brazil</category><category>Central Bank of Brazil</category><category>instant payment platform</category><category>mobile malware</category><category>PixPirate</category><author>Dimitris Gkoutzamanis</author></item><item><title>Toyota Supplier Management Network Hacked</title><link>https://cisotimes.com/toyota-supplier-management-network-hacked/</link><guid isPermaLink="true">https://cisotimes.com/toyota-supplier-management-network-hacked/</guid><description>A security researcher, Eaton Zveare, discovered a vulnerability in Toyota&apos;s Global Supplier Preparation Information Management System (GSPIMS) and was able to access sensitive data of thousands of suppliers and users worldwide. Toyota quickly addressed the issue and fixed the vulnerability.</description><pubDate>Tue, 07 Feb 2023 00:00:00 GMT</pubDate><category>Data Breach</category><category>Eaton Zveare</category><category>security vulnerability</category><category>supplier management network</category><category>Toyota</category><author>TheCISO</author></item><item><title>MalVirt Loaders and Formbook: A New Threat to Cybersecurity</title><link>https://cisotimes.com/malvirt-loaders-and-formbook-a-new-threat-to-cybersecurity/</link><guid isPermaLink="true">https://cisotimes.com/malvirt-loaders-and-formbook-a-new-threat-to-cybersecurity/</guid><description>Formbook family of malware spread via MalVirt loaders through malvertising attacks.</description><pubDate>Mon, 06 Feb 2023 00:00:00 GMT</pubDate><category>anti-analysis</category><category>anti-detection</category><category>Formbook family</category><category>malvertising</category><category>MalVirt</category><category>Malware</category><category>SentinelLabs</category><category>virtualization</category><author>TheCISO</author></item><item><title>Massive Ransomware Campaign Targeting VMware ESXi Servers Worldwide</title><link>https://cisotimes.com/massive-ransomware-campaign-targeting-vmware-esxi-servers-worldwide/</link><guid isPermaLink="true">https://cisotimes.com/massive-ransomware-campaign-targeting-vmware-esxi-servers-worldwide/</guid><description>The Italian National Cybersecurity Agency and the France CERT have issued an alert about an ongoing ransomware campaign targeting VMware ESXi servers worldwide. Organizations are urged to apply security patches and prevent exploitation of the CVE-2021-21974 vulnerability</description><pubDate>Mon, 06 Feb 2023 00:00:00 GMT</pubDate><category>Cyber Attacks</category><category>Cybersecurity</category><category>ESXi servers</category><category>Ransomware</category><category>VMware</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>OpenAI’s “AI Text Classifier” to Detect AI-Generated Text</title><link>https://cisotimes.com/openais-ai-text-classifier-to-detect-ai-generated-text/</link><guid isPermaLink="true">https://cisotimes.com/openais-ai-text-classifier-to-detect-ai-generated-text/</guid><description>OpenAI has recently announced the release of AI Text Classifier, an AI-text detection tool designed to help users detect AI-generated texts with 26% precision. Read on to know more about the tool and its limitations</description><pubDate>Mon, 06 Feb 2023 00:00:00 GMT</pubDate><category>AI Text Classifier</category><category>AI-generated text</category><category>ChatGPT</category><category>OpenAI</category><category>precision</category><author>Dimitris Gkoutzamanis</author></item><item><title>OpenSSH Version 9.2 Addresses Security Bugs</title><link>https://cisotimes.com/openssh-version-9-2-addresses-security-bugs/</link><guid isPermaLink="true">https://cisotimes.com/openssh-version-9-2-addresses-security-bugs/</guid><description>The maintainers of OpenSSH have released version 9.2 to address a pre-authentication double free vulnerability in the OpenSSH server (sshd). Learn about the vulnerability, its potential impact, and how to protect yourself</description><pubDate>Mon, 06 Feb 2023 00:00:00 GMT</pubDate><category>double free</category><category>memory safety</category><category>OpenSSH</category><category>pre-authentication</category><category>secure shell</category><category>Security Updates</category><category>security vulnerability</category><category>ssh protocol</category><author>TheCISO</author></item><item><title>HeadCrab Malware Threatens Redis Servers</title><link>https://cisotimes.com/headcrab-malware-threatens-redis-servers/</link><guid isPermaLink="true">https://cisotimes.com/headcrab-malware-threatens-redis-servers/</guid><description>Protect your Redis server from the fast-spreading HeadCrab malware. Learn about the malicious botnet network, its annual profit, and how to secure your environment.</description><pubDate>Sun, 05 Feb 2023 00:00:00 GMT</pubDate><category>botnet network</category><category>cryptocurrency mining</category><category>HeadCrab malware</category><category>Malware</category><category>Redis server security</category><category>security best practices</category><category>server protection</category><author>TheCISO</author></item><item><title>VMware Fixes High-Severity Privilege Escalation Flaw in Workstation</title><link>https://cisotimes.com/vmware-fixes-high-severity-privilege-escalation-flaw-in-workstation/</link><guid isPermaLink="true">https://cisotimes.com/vmware-fixes-high-severity-privilege-escalation-flaw-in-workstation/</guid><description>VMware has fixed a high-severity privilege escalation flaw in Workstation that allows attackers to delete arbitrary files. The issue was reported by Cirosec and updates are available to remedy the vulnerability.</description><pubDate>Sun, 05 Feb 2023 00:00:00 GMT</pubDate><category>arbitrary file deletion</category><category>privilege escalation</category><category>Security Updates</category><category>VMware</category><category>Vulnerability</category><category>Workstation</category><author>TheCISO</author></item><item><title>Critical Vulnerability Discovered in Jira Service Management Server and Data Center</title><link>https://cisotimes.com/critical-vulnerability-discovered-in-jira-service-management-server-and-data-center/</link><guid isPermaLink="true">https://cisotimes.com/critical-vulnerability-discovered-in-jira-service-management-server-and-data-center/</guid><description>Critical vulnerability (CVE-2023-22501) in Jira Service Management Server and Data Center, its impact, and how to fix it with the latest updates from Atlassian.</description><pubDate>Sat, 04 Feb 2023 00:00:00 GMT</pubDate><category>Atlassian</category><category>CVE-2023-22501</category><category>Data Center</category><category>Data Security</category><category>Jira</category><category>protection</category><category>Cybersecurity</category><category>Service Management Server</category><category>update</category><category>Vulnerability</category><author>TheCISO</author></item><item><title>PeopleConnect Confirms Data Breach Affecting Millions of TruthFinder and Instant Checkmate Customers</title><link>https://cisotimes.com/peopleconnect-confirms-data-breach-affecting-millions-of-truthfinder-and-instant-checkmate-customers/</link><guid isPermaLink="true">https://cisotimes.com/peopleconnect-confirms-data-breach-affecting-millions-of-truthfinder-and-instant-checkmate-customers/</guid><description>A recent data breach at PeopleConnect, the owners of TruthFinder and Instant Checkmate background check services. Over 20 million customer records were leaked in a 2019 backup database.</description><pubDate>Sat, 04 Feb 2023 00:00:00 GMT</pubDate><category>Customer Information</category><category>Cybersecurity.</category><category>Data Breach</category><category>Instant Checkmate</category><category>PeopleConnect</category><category>TruthFinder</category><author>TheCISO</author></item><item><title>Tallahassee Memorial HealthCare Hospital Hit by Cyberattack, IT Systems Taken Offline</title><link>https://cisotimes.com/tallahassee-memorial-healthcare-hospital-hit-by-cyberattack-it-systems-taken-offline/</link><guid isPermaLink="true">https://cisotimes.com/tallahassee-memorial-healthcare-hospital-hit-by-cyberattack-it-systems-taken-offline/</guid><description>Tallahassee Memorial HealthCare Hospital has suffered a cyberattack, forcing it to take its IT systems offline and cancel non-emergency procedures. Patients have been diverted to other hospitals, and the attack is being investigated as a potential ransomware attack. Get the latest updates on this…</description><pubDate>Sat, 04 Feb 2023 00:00:00 GMT</pubDate><category>Cyber Attacks</category><category>Hospital</category><category>IT Systems</category><category>Patient Services</category><category>Ransomware</category><category>Tallahassee Memorial HealthCare</category><author>TheCISO</author></item><item><title>Vice Media Data Breach Exposes Personal and Financial Information of Over 1,700 Individuals</title><link>https://cisotimes.com/vice-media-data-breach-exposes-personal-and-financial-information-of-over-1700-individuals/</link><guid isPermaLink="true">https://cisotimes.com/vice-media-data-breach-exposes-personal-and-financial-information-of-over-1700-individuals/</guid><description>Vice Media data breach of personal and financial information of over 1,700 individuals. Read on for details and remediation efforts.</description><pubDate>Sat, 04 Feb 2023 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>Data Breach</category><category>Equifax</category><category>financial information</category><category>Personal Data</category><category>Vice Media</category><author>TheCISO</author></item><item><title>Zero-Day Vulnerability Found in Fortra’s GoAnywhere MFT</title><link>https://cisotimes.com/zero-day-vulnerability-found-in-fortras-goanywhere-mft/</link><guid isPermaLink="true">https://cisotimes.com/zero-day-vulnerability-found-in-fortras-goanywhere-mft/</guid><description>A zero-day vulnerability in Fortra&apos;s GoAnywhere MFT managed file transfer application is being actively exploited in the wild. Security researchers have warned of over 1,000 on-premise instances publicly accessible on the internet. No patch is currently available, but Fortra has released workarou…</description><pubDate>Sat, 04 Feb 2023 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>data theft</category><category>Exploit</category><category>Fortra</category><category>GoAnywhere MFT</category><category>remote code injection</category><category>Zero-Day</category><author>TheCISO</author></item><item><title>Binwalk Security Tool Vulnerable to Path Traversal Attack</title><link>https://cisotimes.com/binwalk-security-tool-vulnerable-to-path-traversal-attack/</link><guid isPermaLink="true">https://cisotimes.com/binwalk-security-tool-vulnerable-to-path-traversal-attack/</guid><description>A security vulnerability in Binwalk, a popular Linux command-line tool used for analyzing and extracting firmware images, could lead to remote code execution. The path traversal issue is caused by a failed attempt to mitigate risk in the Professional File System extractor plugin. The vulnerabilit…</description><pubDate>Fri, 03 Feb 2023 00:00:00 GMT</pubDate><category>Binwalk</category><category>firmware analysis</category><category>Linux</category><category>path traversal</category><category>Remote Code Execution</category><category>reverse engineering</category><category>Cybersecurity</category><author>TheCISO</author></item><item><title>Cyberattack Disrupts ION Group Transactions</title><link>https://cisotimes.com/cyberattack-disrupts-ion-group-transactions/</link><guid isPermaLink="true">https://cisotimes.com/cyberattack-disrupts-ion-group-transactions/</guid><description>A subsidiary of the Dublin-based financial technology and trading firm ION Group, ION Cleared Derivatives, has been hit by a cyberattack that has disrupted</description><pubDate>Fri, 03 Feb 2023 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>Hacking</category><category>ION Group</category><category>LockBit</category><category>Ransomware</category><author>TheCISO</author></item><item><title>F5 BIG-IP Vulnerability: A Threat to System Stability</title><link>https://cisotimes.com/f5-big-ip-vulnerability-a-threat-to-system-stability/</link><guid isPermaLink="true">https://cisotimes.com/f5-big-ip-vulnerability-a-threat-to-system-stability/</guid><description>F5 has issued a warning about a high-severity format string vulnerability in BIG-IP. An authorized attacker may cause a denial-of-service or execute arbitrary code. Versions of BIG-IP from 13.1.5 to 17.0.0 are vulnerable. Protect your system by checking if your product is affected and using iHeal…</description><pubDate>Fri, 03 Feb 2023 00:00:00 GMT</pubDate><category>BIG-IP</category><category>CWE-134</category><category>Cybersecurity</category><category>denial-of-service</category><category>execute arbitrary code</category><category>F5</category><category>format string</category><category>iHealth</category><category>protection</category><category>system security</category><category>Vulnerability</category><author>TheCISO</author></item><item><title>The Future of Encryption</title><link>https://cisotimes.com/the-future-of-encryption/</link><guid isPermaLink="true">https://cisotimes.com/the-future-of-encryption/</guid><description>Explore the potential of quantum-safe cryptography and quantum cryptography as enhanced solutions for secure communication and data protection. The article covers the technology behind these cryptographic methods, their potential for eliminating ransomware attacks, and their role in ensuring data…</description><pubDate>Thu, 02 Feb 2023 00:00:00 GMT</pubDate><category>AI</category><category>Artificial Intelligence</category><category>Cryptography</category><category>Machine Learning</category><category>Quantum Cryptography</category><author>Nick Janka</author></item><item><title>Information Security Specialization Vs Generalization</title><link>https://cisotimes.com/information-security-specialization-vs-generalization/</link><guid isPermaLink="true">https://cisotimes.com/information-security-specialization-vs-generalization/</guid><description>Explore the pros and cons of both information security specialization and generalization, so you can make an informed decision about what is suitable for your career.</description><pubDate>Sat, 28 Jan 2023 00:00:00 GMT</pubDate><category>Career</category><category>Career Development</category><category>Cybersecurity</category><author>Dimitris Gkoutzamanis</author></item><item><title>Why Use a Penetration Testing Framework</title><link>https://cisotimes.com/why-use-a-penetration-testing-framework/</link><guid isPermaLink="true">https://cisotimes.com/why-use-a-penetration-testing-framework/</guid><description>Penetration testing is a crucial aspect of system security, but it&apos;s not always easy to know where to start or how to ensure that you&apos;re testing all the right areas.</description><pubDate>Thu, 26 Jan 2023 00:00:00 GMT</pubDate><category>Frameworks</category><category>Penetration Testing</category><author>Dimitris Gkoutzamanis</author></item><item><title>The Colorful Teams of Cybersecurity</title><link>https://cisotimes.com/the-colorful-teams-of-cybersecurity/</link><guid isPermaLink="true">https://cisotimes.com/the-colorful-teams-of-cybersecurity/</guid><description>What are all those colored security teams and all those colored hacker hats? What is the difference between them and why do we need them?</description><pubDate>Fri, 20 Jan 2023 00:00:00 GMT</pubDate><category>Black Hat</category><category>Blue Hat</category><category>Blue Team</category><category>Green Hat</category><category>Hacking</category><category>Penetration Testing</category><category>Purple Team</category><category>Red Hat</category><category>Red Team</category><category>Vulnerability</category><category>White Hat</category><author>Dimitris Gkoutzamanis</author></item><item><title>AI in Information Security: Real-World Examples and Benefits</title><link>https://cisotimes.com/ai-in-information-security-real-world-examples-and-benefits/</link><guid isPermaLink="true">https://cisotimes.com/ai-in-information-security-real-world-examples-and-benefits/</guid><description>By leveraging the power of machine learning algorithms, businesses can gain valuable insights into potential security threats and take proactive measures to protect their sensitive data.</description><pubDate>Sun, 15 Jan 2023 00:00:00 GMT</pubDate><category>AI</category><category>Artificial Intelligence</category><category>Darktrace</category><category>IBM</category><category>Incident Response</category><category>Machine Learning</category><author>Dimitris Gkoutzamanis</author></item><item><title>Is Penetration Testing Useful For Your Organization?</title><link>https://cisotimes.com/is-penetration-testing-useful-for-your-organization/</link><guid isPermaLink="true">https://cisotimes.com/is-penetration-testing-useful-for-your-organization/</guid><description>Ask yourself the following questions before you even start thinking of executing a penetration test in your organization.</description><pubDate>Thu, 05 Jan 2023 00:00:00 GMT</pubDate><category>Penetration Testing</category><category>Security Controls</category><author>Dimitris Gkoutzamanis</author></item><item><title>A Simple Guide To Secure IoT Devices</title><link>https://cisotimes.com/a-simple-guide-to-secure-iot-devices/</link><guid isPermaLink="true">https://cisotimes.com/a-simple-guide-to-secure-iot-devices/</guid><description>IoT devices introduce new security risks, as these devices may be vulnerable to multiple cyber threats. This is a simple guide to secure your IoT devices.</description><pubDate>Fri, 16 Dec 2022 00:00:00 GMT</pubDate><author>Dimitris Gkoutzamanis</author></item><item><title>Top Qualities of a Successful CISO</title><link>https://cisotimes.com/top-qualities-of-a-successful-ciso/</link><guid isPermaLink="true">https://cisotimes.com/top-qualities-of-a-successful-ciso/</guid><description>The top qualities of a successful CISO to enable them to perform their roles and protect their organization&apos;s data and systems.</description><pubDate>Fri, 16 Dec 2022 00:00:00 GMT</pubDate><category>CISO</category><category>Skills</category><author>Dimitris Gkoutzamanis</author></item><item><title>Top Tools For Kubernetes Security</title><link>https://cisotimes.com/top-tools-for-kubernetes-security/</link><guid isPermaLink="true">https://cisotimes.com/top-tools-for-kubernetes-security/</guid><description>Container technology has become increasingly popular but has also expanded your organization&apos;s attack surface. Here&apos;s how to secure it with free tools.</description><pubDate>Tue, 13 Dec 2022 00:00:00 GMT</pubDate><category>Application Security</category><category>Containers</category><category>Docker</category><category>Docker Security</category><category>Kubernetes</category><category>Microservices</category><author>Dimitris Gkoutzamanis</author></item><item><title>Understand And Reduce Your Attack Surface</title><link>https://cisotimes.com/understand-and-reduce-your-attack-surface/</link><guid isPermaLink="true">https://cisotimes.com/understand-and-reduce-your-attack-surface/</guid><description>Understand and reduce the possible entry points an attacker may try to exploit to gain access to systems and information.</description><pubDate>Tue, 13 Dec 2022 00:00:00 GMT</pubDate><category>Attack Surface</category><category>Attack Vector</category><category>Data Breach</category><category>Hacking</category><category>Phishing</category><category>Security Controls</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>Apple Announces New Security Features</title><link>https://cisotimes.com/apple-announces-new-security-features/</link><guid isPermaLink="true">https://cisotimes.com/apple-announces-new-security-features/</guid><description>Apple has announced the introduction of three new advanced security features focused on protecting against threats to user data in the cloud.</description><pubDate>Sun, 11 Dec 2022 00:00:00 GMT</pubDate><category>Apple</category><category>Application Security</category><category>Cloud Security</category><category>iCloud</category><category>iMessage</category><author>TheCISO</author></item><item><title>Top 10 CI/CD Security Risks Guideline From OWASP</title><link>https://cisotimes.com/top-10-ci-cd-security-risks-guideline-from-owasp/</link><guid isPermaLink="true">https://cisotimes.com/top-10-ci-cd-security-risks-guideline-from-owasp/</guid><description>A list compiled on the basis of extensive research and analysis to help you protect your CI/CD ecosystem.</description><pubDate>Sat, 10 Dec 2022 00:00:00 GMT</pubDate><category>CI/CD</category><category>Continuous Delivery</category><category>Continuous Integration</category><category>OWASP</category><author>Dimitris Gkoutzamanis</author></item><item><title>What Is The Difference Between GWAPT and OSWE Penetration Testing Certifications</title><link>https://cisotimes.com/what-is-the-difference-between-gwapt-and-oswe-penetration-testing-certifications/</link><guid isPermaLink="true">https://cisotimes.com/what-is-the-difference-between-gwapt-and-oswe-penetration-testing-certifications/</guid><description>GWAPT and OSWE are among the top certifications in security focused on penetration testers. Which would you choose to advance your career?</description><pubDate>Fri, 09 Dec 2022 00:00:00 GMT</pubDate><category>Certifications</category><category>GIAC</category><category>GWAPT</category><category>Hacking</category><category>Offensive Security</category><category>OSWE</category><category>Penetration Testing</category><category>Training</category><category>Web Application</category><author>Dimitris Gkoutzamanis</author></item><item><title>Rackspace Hosted Exchange Hit By Ransomware</title><link>https://cisotimes.com/rackspace-hosted-exchange-hit-by-ransomware/</link><guid isPermaLink="true">https://cisotimes.com/rackspace-hosted-exchange-hit-by-ransomware/</guid><description>Rackspace&apos;s hosted Microsoft Exchange environments were affected by a &quot;security incident&quot; which has knocked out email services to their customers.</description><pubDate>Tue, 06 Dec 2022 00:00:00 GMT</pubDate><category>Hacking</category><category>Microsoft Exchange</category><category>Rackspace</category><category>Ransomware</category><author>Dimitris Gkoutzamanis</author></item><item><title>Most Organizations Still Vulnerable To The Log4j Vulnerability</title><link>https://cisotimes.com/most-organizations-still-vulnerable-to-the-log4j-vulnerability/</link><guid isPermaLink="true">https://cisotimes.com/most-organizations-still-vulnerable-to-the-log4j-vulnerability/</guid><description>According to the data collected from over 500 million tests, 72% of organizations remain vulnerable to the Log4Shell vulnerability</description><pubDate>Thu, 01 Dec 2022 00:00:00 GMT</pubDate><category>Apache</category><category>Lo4j</category><category>Log4Shell</category><category>Tenable</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>Pentagon Supply Chain Fall Short Of Meeting Cybersecurity Requirements</title><link>https://cisotimes.com/pentagon-supply-chain-fall-short-of-meeting-cybersecurity-requirements/</link><guid isPermaLink="true">https://cisotimes.com/pentagon-supply-chain-fall-short-of-meeting-cybersecurity-requirements/</guid><description>A recent independent study revealed that a shocking 87% of federal contractors fall short of meeting the DFARS requirements.</description><pubDate>Thu, 01 Dec 2022 00:00:00 GMT</pubDate><category>Pentagon</category><category>Supply Chain</category><author>Dimitris Gkoutzamanis</author></item><item><title>APT Group Targeting Governments Worldwide</title><link>https://cisotimes.com/apt-group-targeting-governments-worldwide/</link><guid isPermaLink="true">https://cisotimes.com/apt-group-targeting-governments-worldwide/</guid><description>State-financed Chinese hackers have launched spear phishing campaigns to launch against international governments, academic, and research organizations.</description><pubDate>Sat, 26 Nov 2022 00:00:00 GMT</pubDate><category>Earth Preta</category><category>Email Security</category><category>Hacking</category><category>Malware</category><category>Phishing</category><category>Security Awareness</category><category>Spear Phishing</category><category>Trend Micro</category><author>Dimitris Gkoutzamanis</author></item><item><title>WhatsApp Data Breach: 500 million Phone Numbers On Sale</title><link>https://cisotimes.com/whatsapp-data-breach-500-million-phone-numbers-on-sale/</link><guid isPermaLink="true">https://cisotimes.com/whatsapp-data-breach-500-million-phone-numbers-on-sale/</guid><description>A threat actor is claiming that is selling almost 500 million WhatsApp user phone numbers through a hacking community forum.</description><pubDate>Sat, 26 Nov 2022 00:00:00 GMT</pubDate><category>Data Breach</category><category>Personal Data</category><category>Phone Numbers</category><category>WhatsApp</category><author>Dimitris Gkoutzamanis</author></item><item><title>Interpol Seizes Over $129 Million and Arrests Almost 1000 Suspects</title><link>https://cisotimes.com/interpol-seizes-over-129-million-and-arrests-almost-1000-suspects/</link><guid isPermaLink="true">https://cisotimes.com/interpol-seizes-over-129-million-and-arrests-almost-1000-suspects/</guid><description>In an operation lasting over five months, from the 28th of June to the 23rd of November, Interpol arrested almost 1000 suspects and seized 129 million.</description><pubDate>Fri, 25 Nov 2022 00:00:00 GMT</pubDate><category>Crime</category><category>Cybercrime</category><category>Interpol</category><author>TheCISO</author></item><item><title>“OK Google”, Patch A New Zero-Day Vulnerability</title><link>https://cisotimes.com/ok-google-patch-a-new-zero-day-vulnerability/</link><guid isPermaLink="true">https://cisotimes.com/ok-google-patch-a-new-zero-day-vulnerability/</guid><description>Yet another Chrome &quot;zero-day&quot; vulnerability was patched by Google, the 8th for 2022.</description><pubDate>Fri, 25 Nov 2022 00:00:00 GMT</pubDate><category>Chrome</category><category>Exploits</category><category>Google Chrome</category><category>Vulnerability</category><category>Zero-Day</category><author>Dimitris Gkoutzamanis</author></item><item><title>Pro-Russian Group Attacked The EU Parliament Website</title><link>https://cisotimes.com/pro-russian-group-attacked-the-eu-parliament-website/</link><guid isPermaLink="true">https://cisotimes.com/pro-russian-group-attacked-the-eu-parliament-website/</guid><description>The website of EUs Parliament was inaccessible for hours after a distributed denial-of-service (DDoS) attack by &quot;Pro-Kremlin&quot; attackers.</description><pubDate>Thu, 24 Nov 2022 00:00:00 GMT</pubDate><category>DDoS</category><category>EU</category><category>Russia</category><author>TheCISO</author></item><item><title>More Than 50 Million Passwords Stolen By Russian Cybercrime Groups</title><link>https://cisotimes.com/more-than-50-million-passwords-stolen-by-russian-cybercrime-groups/</link><guid isPermaLink="true">https://cisotimes.com/more-than-50-million-passwords-stolen-by-russian-cybercrime-groups/</guid><description>Russian-speaking groups distributing info-stealing malware under the stealer-as-a-service model infecting thousands of devices.</description><pubDate>Wed, 23 Nov 2022 00:00:00 GMT</pubDate><author>Dimitris Gkoutzamanis</author></item><item><title>CSRF Vulnerability Discovered in Plesk API</title><link>https://cisotimes.com/csrf-vulnerability-discovered-in-plesk-api/</link><guid isPermaLink="true">https://cisotimes.com/csrf-vulnerability-discovered-in-plesk-api/</guid><description>In Plesk versions starting from Plesk 17.8 attacker can execute commands and/or alter settings including the change of the admin&apos;s password.</description><pubDate>Sat, 12 Nov 2022 00:00:00 GMT</pubDate><category>CSRF</category><category>Exploit</category><category>Plesk</category><category>Vulnerability</category><author>TheCISO</author></item><item><title>Google Pixel Phone Lock Bypass</title><link>https://cisotimes.com/google-pixel-phone-lock-bypass/</link><guid isPermaLink="true">https://cisotimes.com/google-pixel-phone-lock-bypass/</guid><description>The vulnerability could allow an attacker to bypass lock-screen protections such as fingerprint or PIN authentication and obtain physical access to a target device.</description><pubDate>Sat, 12 Nov 2022 00:00:00 GMT</pubDate><category>Android</category><category>Bug</category><category>Bug Bounty</category><category>Google</category><category>Google Pixel</category><category>Hacking</category><category>Phone</category><category>Vulnerability</category><author>TheCISO</author></item><item><title>What is a Vishing Attack?</title><link>https://cisotimes.com/what-is-a-vishing-attack/</link><guid isPermaLink="true">https://cisotimes.com/what-is-a-vishing-attack/</guid><description>Social engineering attacks use the &quot;human loophole&quot; to get around security controls. Instead of hacking your accounts to steal your identity, they hack you.</description><pubDate>Thu, 10 Nov 2022 00:00:00 GMT</pubDate><category>Phishing</category><category>Scams</category><category>Social Engineering</category><category>Vishing</category><author>Dimitris Gkoutzamanis</author></item><item><title>Critical Vulnerabilities Affecting Citrix Gateway and ADC</title><link>https://cisotimes.com/critical-vulnerabilities-affecting-citrix-gateway-and-adc/</link><guid isPermaLink="true">https://cisotimes.com/critical-vulnerabilities-affecting-citrix-gateway-and-adc/</guid><description>Critical vulnerabilities have been discovered in Citrix Gateway and Citrix ADC which can allow an attacker to gain unauthorized access, perform remote desktop takeover and bypass user login brute force protection.</description><pubDate>Wed, 09 Nov 2022 00:00:00 GMT</pubDate><category>Citrix</category><category>Citrix ADC</category><category>Citrix Gateway</category><category>Vulnerability</category><author>TheCISO</author></item><item><title>Public Exploit is Available for NSX-V, VMware Urges Customers to Upgrade</title><link>https://cisotimes.com/public-exploit-is-available-for-nsx-v-vmware-urges-customers-to-upgrade/</link><guid isPermaLink="true">https://cisotimes.com/public-exploit-is-available-for-nsx-v-vmware-urges-customers-to-upgrade/</guid><description>VMware warns that an exploit has been made publicly available, and urges its customers to upgrade to the latest release.</description><pubDate>Tue, 01 Nov 2022 00:00:00 GMT</pubDate><category>CVE</category><category>Remote Code Execution</category><category>VMware</category><category>Vulnerability</category><author>TheCISO</author></item><item><title>Security Professionals, BEWARE of Fake PoCs</title><link>https://cisotimes.com/security-professionals-beware-of-fake-pocs/</link><guid isPermaLink="true">https://cisotimes.com/security-professionals-beware-of-fake-pocs/</guid><description>Researchers showed that fake Proof-of-Concepts (PoC) are targeting the security community, trying to plant malware and open backdoors to systems.</description><pubDate>Mon, 31 Oct 2022 00:00:00 GMT</pubDate><category>Backdoor</category><category>Exploit</category><category>Hacking</category><category>Malware</category><category>Penetration Testing</category><category>PoC</category><category>Proof of Concept</category><category>Red Team</category><category>Research</category><author>Dimitris Gkoutzamanis</author></item><item><title>Why Is Database Encryption Important?</title><link>https://cisotimes.com/why-is-database-encryption-important/</link><guid isPermaLink="true">https://cisotimes.com/why-is-database-encryption-important/</guid><description>Why is database encryption so important? How does database encryption benefits your business, your users and customers?</description><pubDate>Sat, 29 Oct 2022 00:00:00 GMT</pubDate><category>AES-256</category><category>Data at Rest</category><category>Data Breach</category><category>Data Encryption</category><category>Databases</category><category>Encryption</category><category>Encryption-At-Rest</category><category>PCI</category><category>Personal Data</category><category>RSA 2048</category><author>Dimitris Gkoutzamanis</author></item><item><title>Cybercrime: Face the Facts</title><link>https://cisotimes.com/cybercrime-face-the-facts/</link><guid isPermaLink="true">https://cisotimes.com/cybercrime-face-the-facts/</guid><description>You need to face the hard facts of Cybercrime, head-on and adopt an effective approach to secure your organization.</description><pubDate>Fri, 28 Oct 2022 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>Data Breach</category><category>Governance</category><category>Hacking</category><category>MFA</category><category>Vulnerability</category><category>Zero Trust</category><author>Vassilis Ioannidis</author></item><item><title>Apple patches its ninth vulnerability for this year</title><link>https://cisotimes.com/apple-patches-its-ninth-vulnerability-for-this-year/</link><guid isPermaLink="true">https://cisotimes.com/apple-patches-its-ninth-vulnerability-for-this-year/</guid><description>Since the start of 2022, Apple has addressed nine vulnerabilities with the latest one affecting iOS and iPad OS.</description><pubDate>Tue, 25 Oct 2022 00:00:00 GMT</pubDate><category>Apple</category><category>iOS</category><category>iPad</category><category>iPhone</category><category>Patching</category><category>Vulnerability</category><author>TheCISO</author></item><item><title>How to Detect and Fix the “Text4Shell” Vulnerability</title><link>https://cisotimes.com/how-to-detect-and-fix-the-text4shell-vulnerability/</link><guid isPermaLink="true">https://cisotimes.com/how-to-detect-and-fix-the-text4shell-vulnerability/</guid><description>Similar to the Spring4Shell and Log4Shell vulnerabilities, Text4Shell is a new vulnerability in the Apache Commons Text library.</description><pubDate>Mon, 24 Oct 2022 00:00:00 GMT</pubDate><category>Apache</category><category>Docker</category><category>Log4Shell</category><category>Text4Shell</category><category>Vulnerability</category><author>TheCISO</author></item><item><title>Best Information Security Books</title><link>https://cisotimes.com/best-information-security-books/</link><guid isPermaLink="true">https://cisotimes.com/best-information-security-books/</guid><description>The best books in information security to help you strengthen your knowledge in the field and progress your career.</description><pubDate>Fri, 14 Oct 2022 00:00:00 GMT</pubDate><category>Books</category><category>Cybersecurity</category><category>Hacking</category><category>Penetration Testing</category><author>Dimitris Gkoutzamanis</author></item><item><title>Steps to a Secure Portfolio: Due Diligence During M&amp;#038;A &amp;#038; Beyond</title><link>https://cisotimes.com/steps-to-a-secure-portfolio-due-diligence-during-ma-beyond/</link><guid isPermaLink="true">https://cisotimes.com/steps-to-a-secure-portfolio-due-diligence-during-ma-beyond/</guid><description>How due diligence on information security during mergers and acquisitions can fortify the organization&apos;s information security strategy across its portfolios.</description><pubDate>Tue, 11 Oct 2022 00:00:00 GMT</pubDate><category>Data Breach</category><category>Due Diligence</category><category>Mergers and Acquisitions</category><category>Risk Assessment</category><author>Gina Yacone</author></item><item><title>How to get Cybersecurity experience as a beginner?</title><link>https://cisotimes.com/how-to-get-cybersecurity-experience-as-a-beginner/</link><guid isPermaLink="true">https://cisotimes.com/how-to-get-cybersecurity-experience-as-a-beginner/</guid><description>Cybersecurity is one of the most important aspects of business today. You want to get a job in the field but don&apos;t have any cybersecurity experience.</description><pubDate>Sat, 08 Oct 2022 00:00:00 GMT</pubDate><category>Bash</category><category>Certifications</category><category>CIS</category><category>GNS3</category><category>LinkedIn</category><category>Penetration Testing</category><category>PowerShell</category><category>Python</category><category>Raspberry Pi</category><category>Scripting</category><category>Security Hardening</category><category>Twitter</category><category>VirtualBox</category><author>Dimitris Gkoutzamanis</author></item><item><title>Free Information Security Courses</title><link>https://cisotimes.com/free-information-security-courses/</link><guid isPermaLink="true">https://cisotimes.com/free-information-security-courses/</guid><description>Learning is a choice, you just pay in time and effort instead of money. Dive into free information security courses.</description><pubDate>Thu, 29 Sep 2022 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>Learning</category><category>Online Courses</category><category>University</category><author>TheCISO</author></item><item><title>Why you should choose a career in cybersecurity</title><link>https://cisotimes.com/why-you-should-choose-a-career-in-cybersecurity/</link><guid isPermaLink="true">https://cisotimes.com/why-you-should-choose-a-career-in-cybersecurity/</guid><description>There are many reasons why, but here are the key benefits that will explain why you should choose a career in cybersecurity.</description><pubDate>Wed, 28 Sep 2022 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>Jobs</category><author>Dimitris Gkoutzamanis</author></item><item><title>Flaws in Legacy Systems, BYOD and Remote Access: How they Impact Operations Security of the Enterprise</title><link>https://cisotimes.com/flaws-in-legacy-systems-byod-and-remote-access-how-they-impact-operations-security-of-the-enterprise/</link><guid isPermaLink="true">https://cisotimes.com/flaws-in-legacy-systems-byod-and-remote-access-how-they-impact-operations-security-of-the-enterprise/</guid><description>How flaws in legacy systems, BYOD practices and remote access impact operations security of the Enterprise.</description><pubDate>Sun, 25 Sep 2022 00:00:00 GMT</pubDate><category>BYOD</category><category>Remote Access</category><category>Remote Working</category><category>Software Patching</category><category>VPN</category><category>Vulnerability</category><author>Dr. Daniel Harrison</author></item><item><title>Is there a difference between cybersecurity and information security?</title><link>https://cisotimes.com/is-there-a-difference-between-cybersecurity-and-information-security/</link><guid isPermaLink="true">https://cisotimes.com/is-there-a-difference-between-cybersecurity-and-information-security/</guid><description>Cybersecurity and Information Security are not the same thing, even though the terms have been used interchangeably. Which are the key differences?</description><pubDate>Thu, 22 Sep 2022 00:00:00 GMT</pubDate><category>Cybersecurity</category><author>Dimitris Gkoutzamanis</author></item><item><title>Your Company’s Strongest Assets Are Its Weakest Links</title><link>https://cisotimes.com/your-companys-strongest-assets-are-its-weakest-links/</link><guid isPermaLink="true">https://cisotimes.com/your-companys-strongest-assets-are-its-weakest-links/</guid><description>Why building and maintaining a cybersecurity-aware culture should be your top strategic priority.</description><pubDate>Sat, 17 Sep 2022 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>Data Breach</category><category>IBM</category><category>Phishing</category><category>Strategy</category><category>Tessian</category><category>Uber</category><category>Verizon</category><author>Nick Janka</author></item><item><title>Instagram fined $400M for abuse of children’s data</title><link>https://cisotimes.com/instagram-fined-400m-for-abuse-of-childrens-data/</link><guid isPermaLink="true">https://cisotimes.com/instagram-fined-400m-for-abuse-of-childrens-data/</guid><description>Ireland&apos;s data privacy regulator has agreed to impose a record fine of $402M against Instagram following an investigation into its handling of children&apos;s data.</description><pubDate>Sun, 11 Sep 2022 00:00:00 GMT</pubDate><category>Data Protection</category><category>DPC</category><category>GDPR</category><category>Personal Data</category><author>TheCISO</author></item><item><title>Cool tools and accessories for your hacking bag</title><link>https://cisotimes.com/cool-tools-and-accessories-for-your-hacking-bag/</link><guid isPermaLink="true">https://cisotimes.com/cool-tools-and-accessories-for-your-hacking-bag/</guid><description>Have your hacking bag ready for your penetration tests and red team exercises with these tools and accessories.</description><pubDate>Thu, 08 Sep 2022 00:00:00 GMT</pubDate><category>2FA</category><category>Anti-Spy Detector</category><category>Data Eraser</category><category>Digispark</category><category>Hacking</category><category>Hacking Tools</category><category>MFA</category><category>Penetration Testing</category><category>Raspberry Pi</category><category>Rubber Ducky</category><category>Secure Deletion</category><author>Dimitris Gkoutzamanis</author></item><item><title>Customer data leaked in a newly disclosed Samsung breach</title><link>https://cisotimes.com/customer-data-leaked-in-a-newly-disclosed-samsung-breach/</link><guid isPermaLink="true">https://cisotimes.com/customer-data-leaked-in-a-newly-disclosed-samsung-breach/</guid><description>Samsung said that hackers have obtained some customer data in a newly disclosed breach.</description><pubDate>Sat, 03 Sep 2022 00:00:00 GMT</pubDate><category>Customer Data</category><category>Data Leak</category><category>Hacking</category><category>Personal Data</category><category>Samsung</category><author>TheCISO</author></item><item><title>New WatchGuard vulnerabilities could lead to appliance takeover</title><link>https://cisotimes.com/new-watchguard-vulnerabilities-could-lead-to-appliance-takeover/</link><guid isPermaLink="true">https://cisotimes.com/new-watchguard-vulnerabilities-could-lead-to-appliance-takeover/</guid><description>Ambisonics security engineer Charles Fol has discovered 5 vulnerabilities and built 8 exploits to gain root privileges on every WatchGuard Firebox/XTM appliance.</description><pubDate>Sat, 03 Sep 2022 00:00:00 GMT</pubDate><category>CVE</category><category>Exploits</category><category>Firewall</category><category>Vulnerability</category><category>WatchGuard</category><author>Dimitris Gkoutzamanis</author></item><item><title>Why you should not get into cybersecurity</title><link>https://cisotimes.com/why-you-should-not-get-into-cybersecurity/</link><guid isPermaLink="true">https://cisotimes.com/why-you-should-not-get-into-cybersecurity/</guid><description>If you&apos;re interested in cybersecurity, you should know that it&apos;s not all sunshine and rainbows. The field is growing rapidly, but it is also highly competitive.</description><pubDate>Thu, 01 Sep 2022 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>Jobs</category><author>Dimitris Gkoutzamanis</author></item><item><title>Cybersecurity Analyst Interview Questions</title><link>https://cisotimes.com/cybersecurity-analyst-interview-questions/</link><guid isPermaLink="true">https://cisotimes.com/cybersecurity-analyst-interview-questions/</guid><description>The questions serve as a starting point for you to practice for your interview and find any gaps in your knowledge that you must fill.</description><pubDate>Mon, 29 Aug 2022 00:00:00 GMT</pubDate><category>Application Security</category><category>Cryptography</category><category>Cybersecurity</category><category>Cybersecurity Analyst</category><category>Job Interview</category><category>Network Security</category><author>Dimitris Gkoutzamanis</author></item><item><title>Critical vulnerability discovered in Bitbucket Server and Data Center</title><link>https://cisotimes.com/critical-vulnerability-discovered-in-bitbucket-server-and-data-center/</link><guid isPermaLink="true">https://cisotimes.com/critical-vulnerability-discovered-in-bitbucket-server-and-data-center/</guid><description>This vulnerability could allow remote attackers with read permissions to a public or private Bitbucket repository to execute arbitrary code by sending a malicious HTTP request.</description><pubDate>Sat, 27 Aug 2022 00:00:00 GMT</pubDate><category>Bitbucket</category><category>Cloud</category><category>Command Injection</category><category>CVE</category><category>Vulnerability</category><author>TheCISO</author></item><item><title>Black Hat USA 2022: Are Cybersecurity Tool Standards on the Way?</title><link>https://cisotimes.com/black-hat-usa-2022-are-cybersecurity-tool-standards-on-the-way/</link><guid isPermaLink="true">https://cisotimes.com/black-hat-usa-2022-are-cybersecurity-tool-standards-on-the-way/</guid><description>One of the biggest challenges cybersecurity teams face is to integrate data from the various tools they use to protect their organizations. Enter OCSF.</description><pubDate>Fri, 26 Aug 2022 00:00:00 GMT</pubDate><category>AWS</category><category>Black Hat</category><category>IBM</category><category>OCSF</category><category>Palo Alto</category><category>Salesforce</category><category>Splunk</category><author>TheCISO</author></item><item><title>Password Management LastPass Breached, Source Code Stolen</title><link>https://cisotimes.com/password-management-lastpass-breached-source-code-stolen/</link><guid isPermaLink="true">https://cisotimes.com/password-management-lastpass-breached-source-code-stolen/</guid><description>Password management company LastPass disclosed a data breach that led to the disclosure of some portions of its source code to the attacker.</description><pubDate>Fri, 26 Aug 2022 00:00:00 GMT</pubDate><category>Data Breach</category><category>Hacking</category><category>LastPass</category><category>Password Manager</category><category>Source Code</category><author>TheCISO</author></item><item><title>United States increases Cybersecurity funding to address increasingly pervasive cyber-attacks</title><link>https://cisotimes.com/united-states-increases-cybersecurity-funding-to-address-increasingly-pervasive-cyber-attacks/</link><guid isPermaLink="true">https://cisotimes.com/united-states-increases-cybersecurity-funding-to-address-increasingly-pervasive-cyber-attacks/</guid><description>The House of Representatives finished marking up a dozen spending bills for fiscal 2023 that would altogether provide at least $15.6 billion for cybersecurity efforts across federal departments and agencies.</description><pubDate>Fri, 26 Aug 2022 00:00:00 GMT</pubDate><category>Biden</category><category>CISA</category><category>Cybersecurity</category><category>Department of Defence</category><category>DoD</category><category>Funding</category><category>USA</category><author>TheCISO</author></item><item><title>Pentest Interview Questions</title><link>https://cisotimes.com/pentest-interview-questions/</link><guid isPermaLink="true">https://cisotimes.com/pentest-interview-questions/</guid><description>A list of questions to prepare for your next pentest interview and help you land the job.</description><pubDate>Thu, 25 Aug 2022 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>Job Interview</category><category>Penetration Testing</category><author>Dimitris Gkoutzamanis</author></item><item><title>Half of Twitter’s Workers Have Access to Its Code And User Confidential Data</title><link>https://cisotimes.com/half-of-twitters-workers-have-access-to-its-code-and-user-confidential-data/</link><guid isPermaLink="true">https://cisotimes.com/half-of-twitters-workers-have-access-to-its-code-and-user-confidential-data/</guid><description>Twitter&apos;s former head of security accused the social media company and its executives of &quot;extensive legal violations.&quot;</description><pubDate>Wed, 24 Aug 2022 00:00:00 GMT</pubDate><category>Elon Musk</category><category>Peiter Zatko</category><category>Twitter</category><category>Whistle-Blower</category><author>TheCISO</author></item><item><title>Microsoft joins hands with Kaspersky for cyber threat intelligence</title><link>https://cisotimes.com/microsoft-joins-hands-with-kaspersky-for-cyber-threat-intelligence/</link><guid isPermaLink="true">https://cisotimes.com/microsoft-joins-hands-with-kaspersky-for-cyber-threat-intelligence/</guid><description>Microsoft partners with Kaspersky for cyber threat intelligence, with access to Kaspersky TI through Microsoft Sentinel to empower enterprises with the latest insights to counter cyberattacks.</description><pubDate>Wed, 24 Aug 2022 00:00:00 GMT</pubDate><category>Cloud</category><category>Cybersecurity</category><category>Kaspersky</category><category>Microsoft</category><category>Microsoft Sentinel</category><category>Threat Intelligence</category><author>TheCISO</author></item><item><title>GitLab Patches Critical Vulnerability</title><link>https://cisotimes.com/gitlab-patches-critical-vulnerability/</link><guid isPermaLink="true">https://cisotimes.com/gitlab-patches-critical-vulnerability/</guid><description>GitLab has released a security update to address a critical vulnerability that may lead to remote code execution.</description><pubDate>Tue, 23 Aug 2022 00:00:00 GMT</pubDate><category>Gitlab</category><category>Remote Code Execution</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>Hackers Demand 10 Million Dollars From a Paris Hospital As Ransom</title><link>https://cisotimes.com/hackers-demand-10-million-dollars-from-a-paris-hospital-as-ransom/</link><guid isPermaLink="true">https://cisotimes.com/hackers-demand-10-million-dollars-from-a-paris-hospital-as-ransom/</guid><description>The CHSF Hospital Centre in Corbeil-Essonnes, southeast of Paris, is the new recent victim of hackers.</description><pubDate>Tue, 23 Aug 2022 00:00:00 GMT</pubDate><category>C3N</category><category>Centre for Combating Digital Crime</category><category>CHSF</category><category>Data Breach</category><category>Hacking</category><category>Hospitals</category><category>Paris</category><category>Personal Data</category><category>Ransomware</category><author>TheCISO</author></item><item><title>Hackers Target Greek Natural Gas Operator</title><link>https://cisotimes.com/hackers-target-greek-natural-gas-operator/</link><guid isPermaLink="true">https://cisotimes.com/hackers-target-greek-natural-gas-operator/</guid><description>The Ragnar Locker ransomware gang has claimed responsibility for an attack on Greece&apos;s national gas system operator (DESFA).</description><pubDate>Tue, 23 Aug 2022 00:00:00 GMT</pubDate><category>Critical Infrastructure</category><category>Data Breach</category><category>DESFA</category><category>Greece</category><category>Hacking</category><category>Malware</category><category>Natural Gas</category><category>Ragnar Locker</category><category>Ransomware</category><category>Vulnerability</category><author>TheCISO</author></item><item><title>Palo Alto PAN-OS Flaw Added to CISA’s “Known Exploited Vulnerabilities Catalog”</title><link>https://cisotimes.com/palo-alto-pan-os-flaw-added-to-cisas-known-exploited-vulnerabilities-catalog/</link><guid isPermaLink="true">https://cisotimes.com/palo-alto-pan-os-flaw-added-to-cisas-known-exploited-vulnerabilities-catalog/</guid><description>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity flaw impacting Palo Alto Networks PAN-OS to its Known Exploited Vulnerabilities Catalog.</description><pubDate>Tue, 23 Aug 2022 00:00:00 GMT</pubDate><category>CISA</category><category>Palo Alto</category><category>PAN-OS</category><category>Vulnerability</category><author>TheCISO</author></item><item><title>Penetration Testing vs Vulnerability Scanning</title><link>https://cisotimes.com/penetration-testing-vs-vulnerability-scanning/</link><guid isPermaLink="true">https://cisotimes.com/penetration-testing-vs-vulnerability-scanning/</guid><description>There is a lot of misunderstanding and confusion in penetration testing vs vulnerability scanning. There are important differences you need to know.</description><pubDate>Thu, 18 Aug 2022 00:00:00 GMT</pubDate><category>Exploit</category><category>Hacking</category><category>Nessus</category><category>Penetration Testing</category><category>Qualys</category><category>VA</category><category>Vulnerability</category><category>Vulnerability Scanning</category><author>Dimitris Gkoutzamanis</author></item><item><title>Data Breaches Reach All-Time High</title><link>https://cisotimes.com/data-breaches-reach-all-time-high/</link><guid isPermaLink="true">https://cisotimes.com/data-breaches-reach-all-time-high/</guid><description>According to a new IBM security report, the global average cost of data breaches reached $4.35 million in 2022 which is an all time high, following the cost of $4.24 million in 2021.</description><pubDate>Tue, 02 Aug 2022 00:00:00 GMT</pubDate><category>Cloud</category><category>Data Breach</category><category>Hacking</category><category>Healthcare</category><category>IBM</category><category>Personal Data</category><author>TheCISO</author></item><item><title>Hacker claims to have obtained data of 1 billion Chinese citizens</title><link>https://cisotimes.com/hacker-claims-to-have-obtained-data-of-1-billion-chinese-citizens/</link><guid isPermaLink="true">https://cisotimes.com/hacker-claims-to-have-obtained-data-of-1-billion-chinese-citizens/</guid><description>The hacker claims to have 23 terabytes of data in his possession obtained by the Shanghai National Police (SHGA).</description><pubDate>Tue, 05 Jul 2022 00:00:00 GMT</pubDate><category>China</category><category>Data Breach</category><category>Hacking</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>8 Top Cybersecurity and Information Security Job Positions</title><link>https://cisotimes.com/top-cybersecurity-and-information-security-job-positions/</link><guid isPermaLink="true">https://cisotimes.com/top-cybersecurity-and-information-security-job-positions/</guid><description>The 8 top Cybersecurity and Information security job positions in this booming industry. Relevant job postings have grown significantly worldwide and are more likely for this demand to show more growth.</description><pubDate>Mon, 23 May 2022 00:00:00 GMT</pubDate><category>CEH</category><category>Certifications</category><category>CISA</category><category>CISSP</category><category>Cybersecurity</category><category>Job Positions</category><category>Jobs</category><category>Learning</category><category>Penetration Testing</category><category>Qualifications</category><author>Dimitris Gkoutzamanis</author></item><item><title>Passively Scanning Your Targets With Smap</title><link>https://cisotimes.com/passively-scanning-your-targets-with-smap/</link><guid isPermaLink="true">https://cisotimes.com/passively-scanning-your-targets-with-smap/</guid><description>Passively scan with Smap and avoid detection while gathering useful information on your targets.</description><pubDate>Tue, 10 May 2022 00:00:00 GMT</pubDate><category>Hacking</category><category>Information Gathering</category><category>Penetration Testing</category><category>Reconnaissance</category><category>Shodan</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>Three New Web Application Security Risks Climb Up The OWASP Top 10</title><link>https://cisotimes.com/three-new-web-application-security-risks-climb-up-the-owasp-top-10/</link><guid isPermaLink="true">https://cisotimes.com/three-new-web-application-security-risks-climb-up-the-owasp-top-10/</guid><description>Three new web application security risks climb up the OWASP top 10, the standard awareness document which represent a consensus about the most critical security risks to web applications.</description><pubDate>Fri, 22 Apr 2022 00:00:00 GMT</pubDate><category>CVE</category><category>Cybersecurity</category><category>Hacking</category><category>OWASP</category><category>Penetration Testing</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>Three Approaches to Penetration Testing</title><link>https://cisotimes.com/three-approaches-to-penetration-testing/</link><guid isPermaLink="true">https://cisotimes.com/three-approaches-to-penetration-testing/</guid><description>There are three primary approaches to conduct a penetration test. Choose between black, grey or white box depending on your end goals.</description><pubDate>Mon, 28 Mar 2022 00:00:00 GMT</pubDate><category>Black Box</category><category>Grey Box</category><category>Hacking</category><category>Network Security</category><category>Penetration Testing</category><category>Source Code</category><category>White Box</category><author>Dimitris Gkoutzamanis</author></item><item><title>Apple Releases Patches Fixing 39 Vulnerabilities</title><link>https://cisotimes.com/apple-releases-patches-fixing-39-vulnerabilities/</link><guid isPermaLink="true">https://cisotimes.com/apple-releases-patches-fixing-39-vulnerabilities/</guid><description>Apple releases patches fixing 39 vulnerabilities several of which could allow an attacker to execute arbitrary code on an affected device.</description><pubDate>Wed, 16 Mar 2022 00:00:00 GMT</pubDate><category>Apple</category><category>Hacking</category><category>iOS</category><category>iPad</category><category>Mac OS</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>Cyberattack Crashes Israeli Government Websites</title><link>https://cisotimes.com/cyberattack-crashes-israeli-government-websites/</link><guid isPermaLink="true">https://cisotimes.com/cyberattack-crashes-israeli-government-websites/</guid><description>Users attempting to enter sites with gov.il extensions were unable to for at least an hour, before the sites slowly began to come back online.</description><pubDate>Wed, 16 Mar 2022 00:00:00 GMT</pubDate><category>Cyber Attacks</category><category>DDoS</category><category>Israel</category><author>TheCISO</author></item><item><title>ThePhish: An Open Source Phishing Email Analysis Tool</title><link>https://cisotimes.com/thephish-an-open-source-phishing-email-analysis-tool/</link><guid isPermaLink="true">https://cisotimes.com/thephish-an-open-source-phishing-email-analysis-tool/</guid><description>A new open source phishing email analysis tool that automates the entire analysis process has been made freely available.</description><pubDate>Wed, 16 Mar 2022 00:00:00 GMT</pubDate><category>Email</category><category>Email Security</category><category>Hacking Tools</category><category>Open Source</category><category>Phishing</category><author>Dimitris Gkoutzamanis</author></item><item><title>Email Which Claims to Come from Saudi Aramco Delivers Malware</title><link>https://cisotimes.com/email-which-claims-to-come-from-saudi-aramco-delivers-malware/</link><guid isPermaLink="true">https://cisotimes.com/email-which-claims-to-come-from-saudi-aramco-delivers-malware/</guid><description>The email pretends to come from Saudi Aramco, a Saudi Arabian public petroleum and natural gas company, and one of the largest companies in the world by revenue.</description><pubDate>Sun, 06 Mar 2022 00:00:00 GMT</pubDate><category>Aramco</category><category>Email</category><category>FormBook</category><category>Malware</category><category>Phishing</category><category>Saudi Aramco</category><category>Vulnerability</category><author>TheCISO</author></item><item><title>Retailer Blames Third-Party for the Data Breach of More than 100,000 Payment Cards</title><link>https://cisotimes.com/retailer-blames-third-party-for-the-data-breach-of-more-than-100000-payment-cards/</link><guid isPermaLink="true">https://cisotimes.com/retailer-blames-third-party-for-the-data-breach-of-more-than-100000-payment-cards/</guid><description>Beauty product retailer Acro revealed that customers of two of its websites were impacted, exposing more than 100,000 payment cards</description><pubDate>Sun, 06 Mar 2022 00:00:00 GMT</pubDate><category>Credit Card</category><category>Data Breach</category><category>Japan</category><category>Personal Data</category><category>Vulnerability</category><author>TheCISO</author></item><item><title>Awesome Free Hacking Tool for Red Teams and Pentesters</title><link>https://cisotimes.com/awesome-free-hacking-tool-for-red-teams-and-pentesters/</link><guid isPermaLink="true">https://cisotimes.com/awesome-free-hacking-tool-for-red-teams-and-pentesters/</guid><description>An awesome free hacking tool extremely useful for red teams and pentesters during their penetration testing or red team exercises.</description><pubDate>Thu, 03 Mar 2022 00:00:00 GMT</pubDate><category>Bash</category><category>Cybersecurity</category><category>Hacking</category><category>Hacking Tool</category><category>HackTools</category><category>LFI</category><category>Netcat</category><category>Penetration Testing</category><category>PHP</category><category>PowerShell</category><category>Python</category><category>Red Team</category><category>Reverse Shells</category><author>Dimitris Gkoutzamanis</author></item><item><title>How to Secure Your Microservices</title><link>https://cisotimes.com/how-to-secure-your-microservices/</link><guid isPermaLink="true">https://cisotimes.com/how-to-secure-your-microservices/</guid><description>Along with the many benefits of updating to microservices architecture, there are also new security challenges that organizations need to address.</description><pubDate>Thu, 03 Mar 2022 00:00:00 GMT</pubDate><category>Container Security</category><category>Containers</category><category>DAST</category><category>Defense in Depth</category><category>Docker</category><category>Microservices</category><category>SAST</category><category>Vulnerability</category><category>Vulnerability Scanning</category><author>Dimitris Gkoutzamanis</author></item><item><title>War Between Russia and Ukraine Goes Cyber</title><link>https://cisotimes.com/war-between-russia-and-ukraine-goes-cyber/</link><guid isPermaLink="true">https://cisotimes.com/war-between-russia-and-ukraine-goes-cyber/</guid><description>The war between Russia and Ukraine goes cyber with several ongoing cyber-attacks from the Russian side, targeting Ukraine&apos;s banks and government department websites.</description><pubDate>Fri, 25 Feb 2022 00:00:00 GMT</pubDate><category>Cyber Attacks</category><category>Cyber Warfare</category><category>Cybersecurity</category><category>Hacking</category><category>Malware</category><category>Russia</category><category>Ukraine</category><author>Dimitris Gkoutzamanis</author></item><item><title>A New Tool to Help You Reveal Sensitive Information</title><link>https://cisotimes.com/a-new-tool-to-help-you-reveal-sensitive-information/</link><guid isPermaLink="true">https://cisotimes.com/a-new-tool-to-help-you-reveal-sensitive-information/</guid><description>Researchers have released a new tool to help you reveal sensitive information which has been redacted by the method of pixelation from a document.</description><pubDate>Tue, 15 Feb 2022 00:00:00 GMT</pubDate><category>Hacking</category><category>Passwords</category><category>Pixelation</category><category>Sensitive Information</category><author>Dimitris Gkoutzamanis</author></item><item><title>Update Chrome Now to Patch an Actively Exploited Zero-Day Vulnerability</title><link>https://cisotimes.com/update-chrome-now-to-patch-an-actively-exploited-zero-day-vulnerability/</link><guid isPermaLink="true">https://cisotimes.com/update-chrome-now-to-patch-an-actively-exploited-zero-day-vulnerability/</guid><description>Google has released an update for its Chrome browser that includes eleven security fixes, one of which has been reportedly exploited in the wild.</description><pubDate>Tue, 15 Feb 2022 00:00:00 GMT</pubDate><category>Browser</category><category>Chrome</category><category>CVE</category><category>Google</category><category>Vulnerability</category><category>Zero-Day</category><author>Dimitris Gkoutzamanis</author></item><item><title>New Vulnerabilities Allow Hackers to Crash Siemens PLCs</title><link>https://cisotimes.com/new-vulnerabilities-allow-hackers-to-crash-siemens-plcs/</link><guid isPermaLink="true">https://cisotimes.com/new-vulnerabilities-allow-hackers-to-crash-siemens-plcs/</guid><description>Independent ICS security researcher Gao Jian recently discovered new vulnerabilities which can allow hackers to remotely crash Siemens PLCs.</description><pubDate>Sat, 12 Feb 2022 00:00:00 GMT</pubDate><category>Hacking</category><category>IoT</category><category>Killware</category><category>OT</category><category>PLC</category><category>Siemens</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>Google Cloud Gets Virtual Machine Threat Detection to Help Detect Crypto Mining</title><link>https://cisotimes.com/google-cloud-gets-virtual-machine-threat-detection-to-help-detect-crypto-mining/</link><guid isPermaLink="true">https://cisotimes.com/google-cloud-gets-virtual-machine-threat-detection-to-help-detect-crypto-mining/</guid><description>Google announced the public preview of a tool which helps identify threats within virtual machines running on its Google Cloud infrastructure.</description><pubDate>Wed, 09 Feb 2022 00:00:00 GMT</pubDate><category>Cryptocurrency</category><category>Cryptocurrencies</category><category>Google</category><category>Google Cloud</category><category>Malware</category><category>Threat Detection</category><category>VMTD</category><author>Dimitris Gkoutzamanis</author></item><item><title>Oil Port Terminal Operations Disrupted by Ransomware Attack</title><link>https://cisotimes.com/oil-port-terminal-operations-disrupted-by-ransomware-attack/</link><guid isPermaLink="true">https://cisotimes.com/oil-port-terminal-operations-disrupted-by-ransomware-attack/</guid><description>The ransomware attack affected dozens of terminals, oil storage and transport around the world, including Oiltanking in Germany, SEA-Invest in Belgium and Evos in the Netherlands.</description><pubDate>Tue, 08 Feb 2022 00:00:00 GMT</pubDate><category>Critical Infrastructure</category><category>Data Breach</category><category>Evos</category><category>Hacking</category><category>Malware</category><category>Oil Port</category><category>Oiltanking</category><category>SEA-Invest</category><category>Transport</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>Best Privacy Browsing Apps for Android</title><link>https://cisotimes.com/best-privacy-browsing-apps-for-android/</link><guid isPermaLink="true">https://cisotimes.com/best-privacy-browsing-apps-for-android/</guid><description>If you want to avoid websites tracking and saving personal information when you visit them, then you should consider using on of the best privacy browsing apps for android.</description><pubDate>Sun, 06 Feb 2022 00:00:00 GMT</pubDate><category>Android</category><category>Anonymity</category><category>Brave</category><category>Browsers</category><category>Cake</category><category>Firefox</category><category>Personal Data</category><category>Privacy</category><category>Tor</category><author>Dimitris Gkoutzamanis</author></item><item><title>Hacker Took Down the Internet in North Korea</title><link>https://cisotimes.com/hacker-took-down-the-internet-in-north-korea/</link><guid isPermaLink="true">https://cisotimes.com/hacker-took-down-the-internet-in-north-korea/</guid><description>An American hacker named P4x says he was behind a series of outages in North Korea&apos;s Internet a few weeks ago.</description><pubDate>Fri, 04 Feb 2022 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>Hacking</category><category>North Korea</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>$320 Million Stolen from Crypto Trading Platform</title><link>https://cisotimes.com/320-million-stolen-from-crypto-trading-platform/</link><guid isPermaLink="true">https://cisotimes.com/320-million-stolen-from-crypto-trading-platform/</guid><description>By exploiting a vulnerability in the software of a crypto trading platform, hackers stole 320 million in cryptocurrencies.</description><pubDate>Thu, 03 Feb 2022 00:00:00 GMT</pubDate><category>Cryptocurrency</category><category>Cryptocurrencies</category><category>Exploit</category><category>Hacking</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>Cisco patched 15 Vulnerabilities in Cisco Small Business RV Series Routers</title><link>https://cisotimes.com/cisco-patched-15-vulnerabilities-in-cisco-small-business-rv-series-routers/</link><guid isPermaLink="true">https://cisotimes.com/cisco-patched-15-vulnerabilities-in-cisco-small-business-rv-series-routers/</guid><description>Cisco published an advisory for 15 vulnerabilities in its Small Business RV Series Routers.</description><pubDate>Thu, 03 Feb 2022 00:00:00 GMT</pubDate><category>Cisco</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>Developers Accidentally Turned Off CSRF Protection in Popular PHP Framework</title><link>https://cisotimes.com/developers-accidentally-turned-off-csrf-protection-in-popular-php-framework/</link><guid isPermaLink="true">https://cisotimes.com/developers-accidentally-turned-off-csrf-protection-in-popular-php-framework/</guid><description>Developers of the Symfony PHP framework have reversed a recent change that inadvertently turned off protection against CSRF attacks.</description><pubDate>Thu, 03 Feb 2022 00:00:00 GMT</pubDate><category>CSRF</category><category>Symfony</category><category>Vulnerability</category><author>TheCISO</author></item><item><title>Hackers Use PowerPoint Files to Deliver Malicious Files</title><link>https://cisotimes.com/hackers-use-powerpoint-files-to-deliver-malicious-files/</link><guid isPermaLink="true">https://cisotimes.com/hackers-use-powerpoint-files-to-deliver-malicious-files/</guid><description>A little-known PowerPoint add-on, the .ppam file, has been used by hackers to hide and deliver malicious files.</description><pubDate>Thu, 03 Feb 2022 00:00:00 GMT</pubDate><category>Hacking</category><category>Malware</category><category>Phishing</category><category>PowerPoint</category><category>Virus</category><author>Dimitris Gkoutzamanis</author></item><item><title>Actor’s Twitter Account Hacked and Used to Spam on NFT Giveaways</title><link>https://cisotimes.com/actors-twitter-account-hacked-and-used-to-spam-on-nft-giveaways/</link><guid isPermaLink="true">https://cisotimes.com/actors-twitter-account-hacked-and-used-to-spam-on-nft-giveaways/</guid><description>On Thursday a verified twitter profile of Siobhan McSweeney, a well known Irish actor, was hacked and was used to spam on NFT giveaways.</description><pubDate>Mon, 31 Jan 2022 00:00:00 GMT</pubDate><category>Hacking</category><category>NFT</category><category>Phishing</category><category>Twitter</category><author>TheCISO</author></item><item><title>North Korean APT Spreading Malware Through Spear Phishing Attacks</title><link>https://cisotimes.com/north-korean-apt-spreading-malware-through-spear-phishing-attacks/</link><guid isPermaLink="true">https://cisotimes.com/north-korean-apt-spreading-malware-through-spear-phishing-attacks/</guid><description>The &quot;Lazarous Group&quot;, a North Korean APT conducted a spear phishing attack, weaponized with malicious documents</description><pubDate>Sun, 30 Jan 2022 00:00:00 GMT</pubDate><category>APT</category><category>Hacking</category><category>Lazarus</category><category>Malware</category><category>Phishing</category><category>Spear Phishing</category><author>Dimitris Gkoutzamanis</author></item><item><title>Tenable: Over 40 Billion Records Exposed in 2021</title><link>https://cisotimes.com/tenable-over-40-billion-records-exposed-in-2021/</link><guid isPermaLink="true">https://cisotimes.com/tenable-over-40-billion-records-exposed-in-2021/</guid><description>Over 40 billion records were exposed in cyber incidents during 2021, up nearly 78% from 2020</description><pubDate>Sun, 30 Jan 2022 00:00:00 GMT</pubDate><category>Data Breach</category><category>Malware</category><category>Personal Data</category><category>Research</category><category>Tenable</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>The New Norm: Parents Digitally Monitoring Their Children</title><link>https://cisotimes.com/the-new-norm-parents-digitally-monitoring-their-children/</link><guid isPermaLink="true">https://cisotimes.com/the-new-norm-parents-digitally-monitoring-their-children/</guid><description>The majority of parents participated in an online survey responded that they are digitally monitoring their children.</description><pubDate>Sun, 30 Jan 2022 00:00:00 GMT</pubDate><category>Monitoring</category><category>Online Security</category><category>Parenting</category><category>Privacy</category><category>Social Media</category><author>Dimitris Gkoutzamanis</author></item><item><title>Hackers Demand Ransom for Hijacked Instagram Accounts</title><link>https://cisotimes.com/hackers-demand-ransom-for-hijacked-instagram-accounts/</link><guid isPermaLink="true">https://cisotimes.com/hackers-demand-ransom-for-hijacked-instagram-accounts/</guid><description>Hackers then demand ransom to be paid for the hijacked Instagram accounts.</description><pubDate>Thu, 27 Jan 2022 00:00:00 GMT</pubDate><category>Data Breach</category><category>Hacking</category><category>Instagram</category><category>Personal Data</category><category>Phishing</category><category>Ransom</category><category>Social Media</category><author>Dimitris Gkoutzamanis</author></item><item><title>13 Known Exploited Vulnerabilities Added to CISA Catalog</title><link>https://cisotimes.com/13-known-exploited-vulnerabilities-added-to-cisa-catalog/</link><guid isPermaLink="true">https://cisotimes.com/13-known-exploited-vulnerabilities-added-to-cisa-catalog/</guid><description>CISA has added 13 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence that threat actors are actively exploiting the vulnerabilities.</description><pubDate>Sun, 23 Jan 2022 00:00:00 GMT</pubDate><category>CISA</category><category>Cybersecurity</category><category>Exploits</category><category>Hacking</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>515,000 People Affected By Red Cross Data Breach</title><link>https://cisotimes.com/515000-people-affected-by-red-cross-data-breach/</link><guid isPermaLink="true">https://cisotimes.com/515000-people-affected-by-red-cross-data-breach/</guid><description>Over 515,000 people are affected by the Red Cross data breach incident. The ICRC has no information on who carried out the attack.</description><pubDate>Sun, 23 Jan 2022 00:00:00 GMT</pubDate><category>Data Breach</category><category>Personal Data</category><category>Red Cross</category><author>TheCISO</author></item><item><title>53% of Connected Medical Devices Have Serious Vulnerabilities</title><link>https://cisotimes.com/53-of-connected-medical-devices-have-serious-vulnerabilities/</link><guid isPermaLink="true">https://cisotimes.com/53-of-connected-medical-devices-have-serious-vulnerabilities/</guid><description>Critical device risks in hospital environments leave hospitals and patients vulnerable to cyber attacks and data security issues.</description><pubDate>Sun, 23 Jan 2022 00:00:00 GMT</pubDate><category>Data Breach</category><category>Healthcare</category><category>IoT</category><category>Personal Data</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>Hackers Using Azure and AWS to Spread RATs</title><link>https://cisotimes.com/hackers-using-azure-and-aws-to-spread-rats/</link><guid isPermaLink="true">https://cisotimes.com/hackers-using-azure-and-aws-to-spread-rats/</guid><description>Researchers from Cisco Talos Intelligence found that hackers are using public cloud providers like Azure and AWS to spread RATs.</description><pubDate>Sun, 23 Jan 2022 00:00:00 GMT</pubDate><category>Azure</category><category>C2</category><category>Cloud</category><category>Hacking</category><category>Malware</category><category>RAT</category><author>Dimitris Gkoutzamanis</author></item><item><title>CISCO Recently Patched Critical Vulnerabilities</title><link>https://cisotimes.com/cisco-recently-patched-critical-vulnerabilities/</link><guid isPermaLink="true">https://cisotimes.com/cisco-recently-patched-critical-vulnerabilities/</guid><description>Cisco has patched a pair of vulnerabilities in its telco-focused Cisco Redundancy Configuration Manager (RCM) for Cisco StarOS software, including a critical flaw that presented a remote code execution risk.</description><pubDate>Sat, 22 Jan 2022 00:00:00 GMT</pubDate><category>Cisco</category><category>Data Leak</category><category>Network Security</category><category>Telecommunications</category><category>Vulnerability</category><author>TheCISO</author></item><item><title>Suspected Hacker Attack on Greek Parliament</title><link>https://cisotimes.com/suspected-hacker-attack-on-greek-parliament/</link><guid isPermaLink="true">https://cisotimes.com/suspected-hacker-attack-on-greek-parliament/</guid><description>A temporary shutdown of the legislature&apos;s web mail followed the hack of 60 Greek Parliament emails on Friday.</description><pubDate>Sat, 22 Jan 2022 00:00:00 GMT</pubDate><category>Data Breach</category><category>Data Leak</category><category>Email</category><category>Greece</category><category>Hacking</category><category>Parliament</category><category>Personal Data</category><author>Dimitris Gkoutzamanis</author></item><item><title>IT Company Fined for Massive Data Breach of Voters Information</title><link>https://cisotimes.com/it-company-fined-for-massive-voters-data-breach/</link><guid isPermaLink="true">https://cisotimes.com/it-company-fined-for-massive-voters-data-breach/</guid><description>The company had failed to notify the personal data breach to the data protection commissioner within the deadline stipulated by law. Nor had it informed victims of the breach that they had been affected.</description><pubDate>Tue, 18 Jan 2022 00:00:00 GMT</pubDate><category>Data Breach</category><category>Malta</category><category>Personal Data</category><category>Voting</category><author>TheCISO</author></item><item><title>Microsoft Defender Vulnerability Remains Unpatched</title><link>https://cisotimes.com/microsoft-defender-vulnerability-remains-unpatched/</link><guid isPermaLink="true">https://cisotimes.com/microsoft-defender-vulnerability-remains-unpatched/</guid><description>Security researchers discovered that the list of locations excluded from Microsoft Defender scan is unprotected and accessible to any local user.</description><pubDate>Tue, 18 Jan 2022 00:00:00 GMT</pubDate><category>Defender</category><category>Microsoft</category><category>Vulnerability</category><author>TheCISO</author></item><item><title>New Safari Vulnerability Can Leak Recent Browsing History and Some of your Google Account Information</title><link>https://cisotimes.com/new-safari-vulnerability-can-leak-recent-browsing-history-and-some-of-your-google-account-information/</link><guid isPermaLink="true">https://cisotimes.com/new-safari-vulnerability-can-leak-recent-browsing-history-and-some-of-your-google-account-information/</guid><description>A new Safari vulnerability disclosed by FingerprintJS, can leak recent browsing history and some information of your logged-in Google account.</description><pubDate>Tue, 18 Jan 2022 00:00:00 GMT</pubDate><category>Data Breach</category><category>MacOS</category><category>Personal Data</category><category>Safari</category><category>Vulnerability</category><author>TheCISO</author></item><item><title>You Need to Patch Windows Remote Desktop Vulnerability Now</title><link>https://cisotimes.com/you-need-to-patch-windows-remote-desktop-vulnerability-now/</link><guid isPermaLink="true">https://cisotimes.com/you-need-to-patch-windows-remote-desktop-vulnerability-now/</guid><description>This vulnerability enables any standard unprivileged user connected to a remote machine via remote desktop to gain file system access to the client machines</description><pubDate>Tue, 18 Jan 2022 00:00:00 GMT</pubDate><category>CyberArk</category><category>Hacking</category><category>Microsoft</category><category>Patching</category><category>Remote Desktop</category><category>Vulnerability</category><author>TheCISO</author></item><item><title>What are Dependency Confusion Attacks?</title><link>https://cisotimes.com/what-are-dependency-confusion-attacks/</link><guid isPermaLink="true">https://cisotimes.com/what-are-dependency-confusion-attacks/</guid><description>A dependency confusion attack occurs when a software installer script is tricked into pulling malicious code file from a public repository instead of the intended file of the same name from an internal repository.</description><pubDate>Fri, 14 Jan 2022 00:00:00 GMT</pubDate><category>Application Security</category><category>Dependency Confusion</category><category>Microsoft</category><category>Software Development</category><category>Supply Chain</category><category>Vulnerability</category><author>TheCISO</author></item><item><title>FBI Warning on Google Voice Authentication Scams</title><link>https://cisotimes.com/fbi-warning-on-google-voice-authentication-scams/</link><guid isPermaLink="true">https://cisotimes.com/fbi-warning-on-google-voice-authentication-scams/</guid><description>FBI has issued a warning regarding a new scam utilizing Google voice authentication.The scam targets people who share their numbers publicly.</description><pubDate>Thu, 13 Jan 2022 00:00:00 GMT</pubDate><category>Google</category><category>Hacking</category><category>Phishing</category><category>Scams</category><category>Voice</category><author>TheCISO</author></item><item><title>Huge Increase of WordPress Vulnerabilities in 2021</title><link>https://cisotimes.com/huge-increase-of-wordpress-vulnerabilities-in-2021/</link><guid isPermaLink="true">https://cisotimes.com/huge-increase-of-wordpress-vulnerabilities-in-2021/</guid><description>A huge increase of 142% of WordPress vulnerabilities in 2021 compare to 2020. Most of them exploitable.</description><pubDate>Thu, 13 Jan 2022 00:00:00 GMT</pubDate><category>Hacking</category><category>Patching</category><category>Vulnerability</category><category>WordPress</category><author>Dimitris Gkoutzamanis</author></item><item><title>Patch Microsoft Critical Flaw Now</title><link>https://cisotimes.com/patch-microsoft-critical-flaw-now/</link><guid isPermaLink="true">https://cisotimes.com/patch-microsoft-critical-flaw-now/</guid><description>Microsoft recommends that you install the latest security updates which will patch the critical flaw now.</description><pubDate>Thu, 13 Jan 2022 00:00:00 GMT</pubDate><author>TheCISO</author></item><item><title>Indian Hackers Scored an Embarrassing Own Goal</title><link>https://cisotimes.com/indian-hackers-scored-an-embarrassing-own-goal/</link><guid isPermaLink="true">https://cisotimes.com/indian-hackers-scored-an-embarrassing-own-goal/</guid><description>Indian hackers infected themselves with their own RAT. Making it possible for security researchers to gather information on their methods.</description><pubDate>Mon, 10 Jan 2022 00:00:00 GMT</pubDate><category>APT</category><category>Hacking</category><category>Malware</category><category>Patchwork</category><category>Phishing</category><author>TheCISO</author></item><item><title>Easy Way to Steal WiFi Passwords</title><link>https://cisotimes.com/easy-way-to-steal-wifi-passwords/</link><guid isPermaLink="true">https://cisotimes.com/easy-way-to-steal-wifi-passwords/</guid><description>Why waste time and resources capturing traffic and brute forcing WiFi passwords if there is an easy way to steal them?</description><pubDate>Fri, 07 Jan 2022 00:00:00 GMT</pubDate><category>Arduino</category><category>Digispark</category><category>Hacking</category><category>Passwords</category><category>Penetration Testing</category><category>WiFi</category><category>Wireless</category><author>Dimitris Gkoutzamanis</author></item><item><title>Automated OSINT for Security Assessments</title><link>https://cisotimes.com/automated-osint-for-security-assessments/</link><guid isPermaLink="true">https://cisotimes.com/automated-osint-for-security-assessments/</guid><description>If you are a red teamer or a penetration tester you got to love automated OSINT tools which will help your security assessments. Here is one of the best ones.</description><pubDate>Wed, 05 Jan 2022 00:00:00 GMT</pubDate><category>OSINT</category><category>Penetration Testing</category><category>Reconnaissance</category><category>SpiderFoot</category><author>Dimitris Gkoutzamanis</author></item><item><title>NIST Publications on Penetration Testing</title><link>https://cisotimes.com/nist-publications-on-penetration-testing/</link><guid isPermaLink="true">https://cisotimes.com/nist-publications-on-penetration-testing/</guid><description>Penetration Testing is being mentioned in several NIST publications. See which those publications are and get more info on their recommendations.</description><pubDate>Tue, 04 Jan 2022 00:00:00 GMT</pubDate><category>Compliance</category><category>CSF</category><category>Framework</category><category>Hacking</category><category>NIST</category><category>NIST 800-53</category><category>Penetration Testing</category><author>Dimitris Gkoutzamanis</author></item><item><title>Data Breach Statistics for 2021</title><link>https://cisotimes.com/data-breach-statistics-for-2021/</link><guid isPermaLink="true">https://cisotimes.com/data-breach-statistics-for-2021/</guid><description>The top five countries with the largest number of data breaches account for more than half of all breaches of 2021.</description><pubDate>Fri, 31 Dec 2021 00:00:00 GMT</pubDate><category>Data Breach</category><category>Personal Data</category><category>Statistics</category><category>United States</category><author>Dimitris Gkoutzamanis</author></item><item><title>Information Security Best Practices for IoT</title><link>https://cisotimes.com/information-security-best-practices-for-iot/</link><guid isPermaLink="true">https://cisotimes.com/information-security-best-practices-for-iot/</guid><description>IoT devices are at risk of attack by a variety of malicious actors which can take advantage of poor information security design of an IoT solution.</description><pubDate>Fri, 31 Dec 2021 00:00:00 GMT</pubDate><category>Application Security</category><category>Cloud</category><category>Cybersecurity</category><category>Data Classification</category><category>Encryption</category><category>Hacking</category><category>IoT</category><category>Network Security</category><category>Operating System</category><category>Physical Security</category><author>Dimitris Gkoutzamanis</author></item><item><title>35 Ways to Protect Yourself Online</title><link>https://cisotimes.com/35-ways-to-protect-yourself-online/</link><guid isPermaLink="true">https://cisotimes.com/35-ways-to-protect-yourself-online/</guid><description>The internet is a jungle of a million threats. Take action to protect yourself with the following 35 ways to protect yourself online.</description><pubDate>Thu, 30 Dec 2021 00:00:00 GMT</pubDate><category>Antivirus</category><category>Cloud</category><category>Email</category><category>Hacking</category><category>Malware</category><category>Personal Data</category><category>Social Media</category><category>Software</category><category>Updates</category><category>Web Browsing</category><author>Dimitris Gkoutzamanis</author></item><item><title>T-Mobile Suffers Another Data Breach</title><link>https://cisotimes.com/t-mobile-suffers-another-data-breach/</link><guid isPermaLink="true">https://cisotimes.com/t-mobile-suffers-another-data-breach/</guid><description>After a previous breach in August where nearly 50 million customer data were leaked, T-Mobile suffered another data breach, this time less severe. It has affected only a small subset of customers.</description><pubDate>Thu, 30 Dec 2021 00:00:00 GMT</pubDate><category>Data Breach</category><category>Mobile</category><category>SIM Swaps</category><category>T-Mobile</category><author>TheCISO</author></item><item><title>4 Free Online Tools to Check if a Website is Dangerous</title><link>https://cisotimes.com/4-free-online-tools-to-check-if-a-website-is-dangerous/</link><guid isPermaLink="true">https://cisotimes.com/4-free-online-tools-to-check-if-a-website-is-dangerous/</guid><description>A common method for malicious actors is to direct you to a phishing site in order to harvest your username and passwords and also to make you download malicious software (malware). Always safely check if a website is dangerous before you click.</description><pubDate>Wed, 29 Dec 2021 00:00:00 GMT</pubDate><category>Hacking</category><category>Malware</category><category>Phishing</category><category>VirusTotal</category><category>Websites</category><author>Dimitris Gkoutzamanis</author></item><item><title>A 19 Year Old Hacker Received $4,500 Bug Bounty for an Easy-To-Exploit Vulnerability</title><link>https://cisotimes.com/a-19-year-old-hacker-received-4500-bug-bounty-for-an-easy-to-exploit-vulnerability/</link><guid isPermaLink="true">https://cisotimes.com/a-19-year-old-hacker-received-4500-bug-bounty-for-an-easy-to-exploit-vulnerability/</guid><description>A high impact privacy bug was found in Facebook&apos;s Android application by a young bug bounty hunter. The 19 year old hacker received a $4,500 bug bounty</description><pubDate>Tue, 28 Dec 2021 00:00:00 GMT</pubDate><category>Android</category><category>Application</category><category>Bug Bounty</category><category>Facebook</category><category>Meta</category><category>Vulnerability</category><author>TheCISO</author></item><item><title>Penetration Testing: Create a DNS Zone Transfer Lab</title><link>https://cisotimes.com/penetration-testing-create-a-dns-zone-transfer-lab/</link><guid isPermaLink="true">https://cisotimes.com/penetration-testing-create-a-dns-zone-transfer-lab/</guid><description>DNS zone transfers use the AXFR protocol to replicate DNS records across DNS servers. If you do not protect your name servers, attackers can get information about all your hosts with AXFR.</description><pubDate>Mon, 27 Dec 2021 00:00:00 GMT</pubDate><category>Containers</category><category>DNS</category><category>Docker</category><category>Vulhub</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>Vulnerability vs Exploit, Do You Know The Difference?</title><link>https://cisotimes.com/vulnerability-vs-exploit-do-you-know-the-difference/</link><guid isPermaLink="true">https://cisotimes.com/vulnerability-vs-exploit-do-you-know-the-difference/</guid><description>Many news and articles keep on referring to words like vulnerability and exploits. But do you really know the difference?</description><pubDate>Mon, 27 Dec 2021 00:00:00 GMT</pubDate><category>Exploit</category><category>Risk Assessment</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>How To Check If Your Phone Has Been Hacked</title><link>https://cisotimes.com/how-to-check-if-your-phone-has-been-hacked/</link><guid isPermaLink="true">https://cisotimes.com/how-to-check-if-your-phone-has-been-hacked/</guid><description>Is your device behaving weirdly? Outgoing calls you did not make, your device is getting hot without reason? Maybe its time to check if your phone has been hacked.</description><pubDate>Sun, 26 Dec 2021 00:00:00 GMT</pubDate><category>Data Breach</category><category>Hacking</category><category>Malware</category><category>Phishing</category><category>Smartphones</category><author>Dimitris Gkoutzamanis</author></item><item><title>Copies of “Spider-Man: No Way Home” Infected with Malware</title><link>https://cisotimes.com/copies-of-spider-man-no-way-home-infected-with-malware/</link><guid isPermaLink="true">https://cisotimes.com/copies-of-spider-man-no-way-home-infected-with-malware/</guid><description>The long awaited Marvel movie &quot;Spider-Man: No Way Home&quot; is out. People are trying to download an illegal copy are up for an unpleasant surprise.</description><pubDate>Fri, 24 Dec 2021 00:00:00 GMT</pubDate><category>Cryptominer</category><category>Hacking</category><category>Malware</category><category>Marvel</category><category>Movies</category><category>Spiderman</category><author>Dimitris Gkoutzamanis</author></item><item><title>Find Information About a Person on Instagram with OSINTgram</title><link>https://cisotimes.com/find-information-about-a-person-on-instagram-with-osintgram/</link><guid isPermaLink="true">https://cisotimes.com/find-information-about-a-person-on-instagram-with-osintgram/</guid><description>Social media platforms can betray a considerable amount of information on a person or organization which can be useful during a pentest information gathering.</description><pubDate>Thu, 23 Dec 2021 00:00:00 GMT</pubDate><category>Hacking</category><category>Instagram</category><category>OSINT</category><category>Penetration Testing</category><category>Phishing</category><author>Dimitris Gkoutzamanis</author></item><item><title>Popular Game Series “Just Dance” Targeted by Attackers</title><link>https://cisotimes.com/popular-game-series-just-dance-targeted-by-attackers/</link><guid isPermaLink="true">https://cisotimes.com/popular-game-series-just-dance-targeted-by-attackers/</guid><description>Ubisoft Entertainment a French video game company recently announced that they have identified an intrusion in their IT Infrastructure targeting Just Dance.</description><pubDate>Thu, 23 Dec 2021 00:00:00 GMT</pubDate><category>Data Breach</category><category>Hacking</category><category>Personal Data</category><category>Ubisoft</category><author>TheCISO</author></item><item><title>A List of Tools to Help you Detect the Log4j Vulnerability</title><link>https://cisotimes.com/a-list-of-tools-to-help-you-detect-the-log4j-vulnerability/</link><guid isPermaLink="true">https://cisotimes.com/a-list-of-tools-to-help-you-detect-the-log4j-vulnerability/</guid><description>How can you detect the Log4j zero day vulnerability (known as Log4shell)? Here&apos;s a list of FREE Log4j vulnerability scanner tools.</description><pubDate>Wed, 22 Dec 2021 00:00:00 GMT</pubDate><category>Amazon</category><category>Arctic Wolf</category><category>CISA</category><category>Hacking</category><category>Log4j</category><category>Log4Shell</category><category>Penetration Testing</category><category>TrendMicro</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>NCA Shares 585 Million Compromised Passwords With “Have I Been Pwned”</title><link>https://cisotimes.com/nca-shares-585-million-compromised-passwords-with-have-i-been-pwned/</link><guid isPermaLink="true">https://cisotimes.com/nca-shares-585-million-compromised-passwords-with-have-i-been-pwned/</guid><description>The National Crime Agency of United Kingdom (NCA) shared a collection of more than 585 million compromised passwords that were found during an investigation with the infamous Have I Been Pwned website.</description><pubDate>Wed, 22 Dec 2021 00:00:00 GMT</pubDate><category>Data Breach</category><category>FBI</category><category>HaveIBeenPwned</category><category>HIBP</category><category>Passwords</category><author>TheCISO</author></item><item><title>Hacking Group Leaked Confidential UK Police Data</title><link>https://cisotimes.com/hacking-group-leaked-confidential-uk-police-data/</link><guid isPermaLink="true">https://cisotimes.com/hacking-group-leaked-confidential-uk-police-data/</guid><description>Russian hacking group &quot;Clop&quot; leaked confidential information held by the UK police onto the dark web. The data were stolen from Dacoll, an IT company which handles the Police National Computer.</description><pubDate>Mon, 20 Dec 2021 00:00:00 GMT</pubDate><category>Clop</category><category>Data Breach</category><category>Hacking</category><category>Phishing</category><author>TheCISO</author></item><item><title>Threat Actors Impersonating Pfizer</title><link>https://cisotimes.com/threat-actors-impersonating-pfizer/</link><guid isPermaLink="true">https://cisotimes.com/threat-actors-impersonating-pfizer/</guid><description>Phishing campaigns that use COVID-19 as a hook are still on the rise. Hackers are increasingly using vaccine-related emails in their targeted spear-phishing attacks.</description><pubDate>Mon, 20 Dec 2021 00:00:00 GMT</pubDate><category>COVID-19</category><category>Hacking</category><category>Pfizer</category><category>Phishing</category><author>TheCISO</author></item><item><title>Audio Tech Giant Exposed Thousands of Customers’ Data</title><link>https://cisotimes.com/audio-tech-giant-exposed-thousands-of-customers-data/</link><guid isPermaLink="true">https://cisotimes.com/audio-tech-giant-exposed-thousands-of-customers-data/</guid><description>The data may be old, but it&apos;s still valuable to criminals and hackers, and the leak itself could have been much worse. It represents a massive oversight by a huge, multinational, well-known company.</description><pubDate>Sun, 19 Dec 2021 00:00:00 GMT</pubDate><category>AWS</category><category>Cloud</category><category>Data Breach</category><category>S3 Bucket</category><author>TheCISO</author></item><item><title>Why Do Data Breaches Happen</title><link>https://cisotimes.com/why-do-data-breaches-happen/</link><guid isPermaLink="true">https://cisotimes.com/why-do-data-breaches-happen/</guid><description>We have gotten used to seeing news every day of sensitive data being exposed to unauthorized parties, but do you know why do data breaches happen?</description><pubDate>Sun, 19 Dec 2021 00:00:00 GMT</pubDate><category>Cloud</category><category>Data Breach</category><category>Hacking</category><category>Malware</category><category>Personal Data</category><category>Phishing</category><category>Social Engineering</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>Build a Penetration Testing Lab on a Raspberry Pi with DVWA</title><link>https://cisotimes.com/build-a-penetration-testing-lab-on-a-raspberry-pi-with-dvwa/</link><guid isPermaLink="true">https://cisotimes.com/build-a-penetration-testing-lab-on-a-raspberry-pi-with-dvwa/</guid><description>You can build a pentest lab on a raspberry pi with DVWA to test your skills and also learn new tricks on how to attack and/or secure web applications.</description><pubDate>Sat, 18 Dec 2021 00:00:00 GMT</pubDate><category>Brute Force</category><category>Docker</category><category>DVWA</category><category>Hacking</category><category>Lab</category><category>Penetration Testing</category><category>Vulnerability</category><category>XSS</category><author>Dimitris Gkoutzamanis</author></item><item><title>Hunt a Username on Social Media with Sherlock</title><link>https://cisotimes.com/hunt-a-username-on-social-media-with-sherlock/</link><guid isPermaLink="true">https://cisotimes.com/hunt-a-username-on-social-media-with-sherlock/</guid><description>Many users register themselves on websites using the same username. If you are performing an investigation on a person, and especially if you know a username or handle they are usually using online, you may hunt for usernames on social media platforms with Sherlock.</description><pubDate>Sat, 18 Dec 2021 00:00:00 GMT</pubDate><category>Penetration Testing</category><category>Reconnaissance</category><category>Sherlock</category><category>Social Media</category><category>Usernames</category><author>Dimitris Gkoutzamanis</author></item><item><title>Facebook Owner Meta Bans Fake Accounts Used by Cyber-Spy Firms</title><link>https://cisotimes.com/facebook-owner-meta-bans-fake-accounts-used-by-cyber-spy-firms/</link><guid isPermaLink="true">https://cisotimes.com/facebook-owner-meta-bans-fake-accounts-used-by-cyber-spy-firms/</guid><description>Facebook said it canceled 1,500 fake social media accounts used by seven surveillance-for-hire firms to conduct online attacks against government critics and members of civil society.</description><pubDate>Fri, 17 Dec 2021 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>Facebook</category><category>Meta</category><category>Surveillance</category><author>TheCISO</author></item><item><title>Web Dashboard for your Nmap Scans</title><link>https://cisotimes.com/web-dashboard-for-your-nmap-scans/</link><guid isPermaLink="true">https://cisotimes.com/web-dashboard-for-your-nmap-scans/</guid><description>WebMap is a web dashboard for your nmap scans. This tool, which is free, can provide you with more management capabilities of your scan results.</description><pubDate>Thu, 16 Dec 2021 00:00:00 GMT</pubDate><category>nmap</category><category>Penetration Testing</category><category>WebMap</category><author>Dimitris Gkoutzamanis</author></item><item><title>How To Find Domains Owned by a Company</title><link>https://cisotimes.com/how-to-find-domains-owned-by-a-company/</link><guid isPermaLink="true">https://cisotimes.com/how-to-find-domains-owned-by-a-company/</guid><description>During a black box, or grey box penetration testing engagement for a company, one of the main things you will need to find domains owned by the company.</description><pubDate>Wed, 15 Dec 2021 00:00:00 GMT</pubDate><category>Domains</category><category>Hacking</category><category>Penetration Testing</category><category>Reconnaissance</category><category>reverse whois</category><author>Dimitris Gkoutzamanis</author></item><item><title>Cryptocurrency Exchange Hacked</title><link>https://cisotimes.com/cryptocurrency-exchange-hacked/</link><guid isPermaLink="true">https://cisotimes.com/cryptocurrency-exchange-hacked/</guid><description>On Sunday, AscendEX announced via Twitter that it had identified a number of unauthorized transactions from one of its hot wallets on Saturday.</description><pubDate>Tue, 14 Dec 2021 00:00:00 GMT</pubDate><category>Cryptocurrencies</category><category>Data Breach</category><category>Hacking</category><author>TheCISO</author></item><item><title>HR Management Platform Hit by Ransomware</title><link>https://cisotimes.com/hr-management-platform-hit-by-ransomware/</link><guid isPermaLink="true">https://cisotimes.com/hr-management-platform-hit-by-ransomware/</guid><description>HR management platform Kronos has been hit by a ransomware attack and information from its customers may have been accessed.</description><pubDate>Tue, 14 Dec 2021 00:00:00 GMT</pubDate><category>Data Breach</category><category>Hacking</category><category>Malware</category><category>Ransomware</category><author>Dimitris Gkoutzamanis</author></item><item><title>Massive Internet Scans and Log4j Exploit Attempts</title><link>https://cisotimes.com/massive-internet-scans-and-log4j-exploit-attempts/</link><guid isPermaLink="true">https://cisotimes.com/massive-internet-scans-and-log4j-exploit-attempts/</guid><description>Many organizations have noticed a surge in internet scans to discover vulnerable systems and exploit attempts on them.</description><pubDate>Tue, 14 Dec 2021 00:00:00 GMT</pubDate><category>Apache</category><category>Exploit</category><category>Hacking</category><category>Malware</category><category>Vulnerability</category><author>TheCISO</author></item><item><title>Top Malware for November 2021</title><link>https://cisotimes.com/top-malware-for-november-2021/</link><guid isPermaLink="true">https://cisotimes.com/top-malware-for-november-2021/</guid><description>Checkpoint Research through its global threat index revelas the top malware for November 2021.</description><pubDate>Tue, 14 Dec 2021 00:00:00 GMT</pubDate><category>Malware</category><author>TheCISO</author></item><item><title>What is a Botnet</title><link>https://cisotimes.com/what-is-a-botnet/</link><guid isPermaLink="true">https://cisotimes.com/what-is-a-botnet/</guid><description>Many cyber attacks are carried out by malicious actors with the use of &quot;Botnets&quot;. But what is a botnet? Botnet is short for &quot;robot-network&quot;.</description><pubDate>Wed, 08 Dec 2021 00:00:00 GMT</pubDate><category>Botnets</category><category>Cybersecurity</category><category>Dark Nexus</category><category>DDoS</category><category>Hacking</category><category>Malware</category><category>Methbot</category><category>Mirai</category><category>Phishing</category><author>Dimitris Gkoutzamanis</author></item><item><title>More than 2,1 Million People Affected After DNA Testing Center Data Breach</title><link>https://cisotimes.com/more-than-21-million-people-affected-after-dna-testing-center-data-breach/</link><guid isPermaLink="true">https://cisotimes.com/more-than-21-million-people-affected-after-dna-testing-center-data-breach/</guid><description>An Ohio based DNA testing company has reported a data breach that lead to the leak of personal information including Social Security Numbers and banking information of 2,102,436 people.</description><pubDate>Wed, 01 Dec 2021 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>Data Breach</category><category>Hacking</category><category>Personal Data</category><author>TheCISO</author></item><item><title>Panasonic Network Has Been Hacked</title><link>https://cisotimes.com/panasonic-network-has-been-hacked/</link><guid isPermaLink="true">https://cisotimes.com/panasonic-network-has-been-hacked/</guid><description>The Japanese company Panasonic said that its network was illegally accessed by a third party on November 11 and that some data on a file server had been accessed during the intrusion.</description><pubDate>Wed, 01 Dec 2021 00:00:00 GMT</pubDate><category>Cyber Attacks</category><category>Data Breach</category><category>Hacking</category><category>Panasonic</category><author>TheCISO</author></item><item><title>Enhanced Automated Vulnerability Management for Cloud Workloads Announced by AWS</title><link>https://cisotimes.com/enhanced-automated-vulnerability-management-for-cloud-workloads-announced-by-aws/</link><guid isPermaLink="true">https://cisotimes.com/enhanced-automated-vulnerability-management-for-cloud-workloads-announced-by-aws/</guid><description>Newly added capabilities for the Amazon Inspector service will meet the &quot;critical need to detect and remediate at speed&quot; in order to secure cloud workloads. %</description><pubDate>Tue, 30 Nov 2021 00:00:00 GMT</pubDate><category>AWS</category><category>Cloud</category><category>Risk</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>Find Web Server Vulnerabilities With Nikto</title><link>https://cisotimes.com/find-web-server-vulnerabilities-with-nikto/</link><guid isPermaLink="true">https://cisotimes.com/find-web-server-vulnerabilities-with-nikto/</guid><description>Nikto is an open source scanner capable of scanning for over 6700 items to detect any misconfigurations on web servers like Apache, Nginx, Litespeed etc. as well as discovery of exposed files, user enumeration and outdated components.</description><pubDate>Tue, 30 Nov 2021 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>Hacking</category><category>nikto</category><category>Penetration Testing</category><category>Web Application</category><author>Dimitris Gkoutzamanis</author></item><item><title>How to Secure Your Zoom Meetings</title><link>https://cisotimes.com/how-to-secure-your-zoom-meetings/</link><guid isPermaLink="true">https://cisotimes.com/how-to-secure-your-zoom-meetings/</guid><description>Zoom has around 300 million daily meeting participants! It also has security issues like &quot;Zoom bombings&quot; where uninvited guests may show up at meetings and another more &quot;creepy&quot; vulnerability which left millions of users exposed, which offered access to user&apos;s cameras and microphones.</description><pubDate>Tue, 30 Nov 2021 00:00:00 GMT</pubDate><category>Application Security</category><category>Vulnerability</category><category>Zoom</category><author>Dimitris Gkoutzamanis</author></item><item><title>Google Warns for Hacked Cloud Accounts Used for Crypto Mining</title><link>https://cisotimes.com/google-warns-for-hacked-cloud-accounts-used-for-crypto-mining/</link><guid isPermaLink="true">https://cisotimes.com/google-warns-for-hacked-cloud-accounts-used-for-crypto-mining/</guid><description>recently launched Google Cybersecurity Action Team (GCAT) provided specific insights, such as when malicious hackers exploit improperly-secured cloud instances to download cryptocurrency mining software to the system—sometimes within 22 seconds of being compromised.</description><pubDate>Mon, 29 Nov 2021 00:00:00 GMT</pubDate><category>Cloud</category><category>Cryptocurrency</category><category>Google</category><category>Malware</category><category>Phishing</category><author>Dimitris Gkoutzamanis</author></item><item><title>Marine Services Provider Swire Pacific Offshore suffers data breach following cyber-attack</title><link>https://cisotimes.com/marine-services-rovider-swire-pacific-offshore-suffers-data-breach-following-cyber-attack/</link><guid isPermaLink="true">https://cisotimes.com/marine-services-rovider-swire-pacific-offshore-suffers-data-breach-following-cyber-attack/</guid><description>SPO has taken immediate actions to reinforce existing security measures and to mitigate the potential impact of the incident. SPO has reported the incident to the relevant authorities and will work closely with them in relation to the incident. SPO is contacting potentially affected parties to in…</description><pubDate>Mon, 29 Nov 2021 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>Data Breach</category><category>Hacking</category><category>Maritime</category><category>Personal Data</category><category>Swire Pacific Offshore</category><author>Dimitris Gkoutzamanis</author></item><item><title>Information Security Black Friday Deals You Should Grab Now</title><link>https://cisotimes.com/information-security-black-friday-deals-you-should-grab-now/</link><guid isPermaLink="true">https://cisotimes.com/information-security-black-friday-deals-you-should-grab-now/</guid><description>Many information security black friday deals you should grab right now, if you are a professional, a student, a researcher, or just a curious person who wants</description><pubDate>Thu, 25 Nov 2021 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>Learning</category><category>Penetration Testing</category><author>Dimitris Gkoutzamanis</author></item><item><title>Apple sues company known for hacking iPhones</title><link>https://cisotimes.com/apple-sues-company-known-for-hacking-iphones/</link><guid isPermaLink="true">https://cisotimes.com/apple-sues-company-known-for-hacking-iphones/</guid><description>Apple sues company known for hacking iPhones on behalf of governments. An Israeli firm called NSO Group, provided software to government agencies and law enforcement that enables them to hack iPhones and read the data on them, including messages and other communications.</description><pubDate>Wed, 24 Nov 2021 00:00:00 GMT</pubDate><category>Apple</category><category>iPhone</category><category>NSO</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>Discover Subdomains During A Penetration Testing Engagement</title><link>https://cisotimes.com/discover-subdomains-during-a-penetration-testing-engagement/</link><guid isPermaLink="true">https://cisotimes.com/discover-subdomains-during-a-penetration-testing-engagement/</guid><description>During an external penetration test, and especially if it is a black-box engagement, one of the most important steps is to find subdomains used by the target company.</description><pubDate>Wed, 24 Nov 2021 00:00:00 GMT</pubDate><category>Domains</category><category>Penetration Testing</category><category>Reconnaissance</category><category>Subdomains</category><author>Dimitris Gkoutzamanis</author></item><item><title>More than Half of Organizations Are Not Effectively Defending Against Cyberattacks</title><link>https://cisotimes.com/more-than-half-of-organizations-are-not-effectively-defending-against-cyberattacks/</link><guid isPermaLink="true">https://cisotimes.com/more-than-half-of-organizations-are-not-effectively-defending-against-cyberattacks/</guid><description>According to a recent Accenture study, more than half of organizations are not effectively defending against cyberattacks.</description><pubDate>Wed, 24 Nov 2021 00:00:00 GMT</pubDate><category>accenture</category><category>Cybersecurity</category><category>risks</category><author>Dimitris Gkoutzamanis</author></item><item><title>Researcher Publishes Exploit Affecting All Windows Versions</title><link>https://cisotimes.com/researcher-publishes-exploit-affecting-all-windows-versions/</link><guid isPermaLink="true">https://cisotimes.com/researcher-publishes-exploit-affecting-all-windows-versions/</guid><description>A security researcher has published a public exploit on Github that allows a low privileged user on all client and server windows operating systems, to gain administrative rights.</description><pubDate>Wed, 24 Nov 2021 00:00:00 GMT</pubDate><category>Exploit</category><category>Windows</category><author>Dimitris Gkoutzamanis</author></item><item><title>GoDaddy Data Breach Affects 1.2 Million Customer Accounts</title><link>https://cisotimes.com/godaddy-data-breach-affects-1-2-million-customer-accounts/</link><guid isPermaLink="true">https://cisotimes.com/godaddy-data-breach-affects-1-2-million-customer-accounts/</guid><description>The company detected unauthorized access to its systems where customer&apos;s Wordpress servers are hosted and managed.</description><pubDate>Tue, 23 Nov 2021 00:00:00 GMT</pubDate><category>Cloud</category><category>Data Breach</category><category>GoDaddy</category><category>Hacking</category><category>WordPress</category><author>Dimitris Gkoutzamanis</author></item><item><title>Find Out If Any of Your Accounts Has Been Hacked</title><link>https://cisotimes.com/find-out-if-any-of-your-accounts-has-been-hacked/</link><guid isPermaLink="true">https://cisotimes.com/find-out-if-any-of-your-accounts-has-been-hacked/</guid><description>A few ways to discover if any of your accounts has been hacked. Either with the help of Google Chrome or with the use of online tools.</description><pubDate>Mon, 22 Nov 2021 00:00:00 GMT</pubDate><category>Avast</category><category>Data Breach</category><category>F-Secure</category><category>Google</category><category>Hacking</category><category>HaveIBeenPwned</category><category>Passwords</category><category>Personal Data</category><author>Dimitris Gkoutzamanis</author></item><item><title>88% of Boards of Directors View Cybersecurity as a Business Risk</title><link>https://cisotimes.com/88-of-boards-of-directors-view-cybersecurity-as-a-business-risk/</link><guid isPermaLink="true">https://cisotimes.com/88-of-boards-of-directors-view-cybersecurity-as-a-business-risk/</guid><description>The influx of ransomware and supply chain attacks seen throughout 2021, many of which targeted operation- and mission-critical environments, should be a wake-up call that security is a business issue, and not just another problem for IT to solve</description><pubDate>Sun, 21 Nov 2021 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>Gartner</category><category>Survey</category><author>Dimitris Gkoutzamanis</author></item><item><title>Robinhood revealed that a data breach last week exposed millions of customers’ emails and other personal information</title><link>https://cisotimes.com/robinhood-revealed-that-a-data-breach-last-week-exposed-millions-of-customers-emails-and-other-personal-information/</link><guid isPermaLink="true">https://cisotimes.com/robinhood-revealed-that-a-data-breach-last-week-exposed-millions-of-customers-emails-and-other-personal-information/</guid><description>Robinhood said that hackers obtained around 5 million email addresses and full names for different group of approximately two million people.</description><pubDate>Sun, 21 Nov 2021 00:00:00 GMT</pubDate><category>Mandiant</category><category>Robinhood</category><author>TheCISO</author></item><item><title>Watch Out Shoppers! Number of Malicious Shopping Websites Jumps 178% ahead of Black Friday Sales</title><link>https://cisotimes.com/watch-out-shoppers-number-of-malicious-shopping-websites-jumps-178-ahead-of-black-friday-sales/</link><guid isPermaLink="true">https://cisotimes.com/watch-out-shoppers-number-of-malicious-shopping-websites-jumps-178-ahead-of-black-friday-sales/</guid><description>Check Point Research spotted over 5300 malicious websites per week, marking it the highest since the beginning of 2021. The number of malicious websites made to trick you and obtaining your credit card and your login information, many times for well known websites as amazon.</description><pubDate>Sat, 20 Nov 2021 00:00:00 GMT</pubDate><category>Black Friday</category><category>Passwords</category><category>Phishing</category><author>Dimitris Gkoutzamanis</author></item><item><title>The King of Most Common Passwords Still Sits on its Throne</title><link>https://cisotimes.com/the-king-of-most-common-passwords-still-sits-on-its-throne/</link><guid isPermaLink="true">https://cisotimes.com/the-king-of-most-common-passwords-still-sits-on-its-throne/</guid><description>NordPass has published a study with the top 200 most common passwords for 2021. The study covered 50 countries.</description><pubDate>Thu, 18 Nov 2021 00:00:00 GMT</pubDate><category>Hacking</category><category>Leaks</category><author>Dimitris Gkoutzamanis</author></item><item><title>FBI Email System Hacked and Sent out Fake Cyber Attack Alerts</title><link>https://cisotimes.com/fbi-email-system-hacked-and-sent-out-fake-cyber-attack-alerts/</link><guid isPermaLink="true">https://cisotimes.com/fbi-email-system-hacked-and-sent-out-fake-cyber-attack-alerts/</guid><description>FBI has confirmed that an unnamed actor was able to gain access to the FBI&apos;s Law Enforcement Enterprise Portal (LEEP) to send the emails to thousands of recipients about a fake cyberattack.</description><pubDate>Wed, 17 Nov 2021 00:00:00 GMT</pubDate><category>Email</category><category>FBI</category><category>Hacking</category><author>Dimitris Gkoutzamanis</author></item><item><title>The Rise Of Killware</title><link>https://cisotimes.com/the-rise-of-killware/</link><guid isPermaLink="true">https://cisotimes.com/the-rise-of-killware/</guid><description>The objective of the attacker is to cause harm to humans using killware in the Operational Technology environment. Many similar attacks have been identified since the year 2000, even though they were not called killware back then.</description><pubDate>Sat, 30 Oct 2021 00:00:00 GMT</pubDate><category>Cyber Attacks</category><category>Killware</category><category>Malware</category><category>OT</category><author>Dimitris Gkoutzamanis</author></item><item><title>New Azure AD Bug Allows Attackers Brute-Force Passwords</title><link>https://cisotimes.com/azure-active-directory-brute-force-attack/</link><guid isPermaLink="true">https://cisotimes.com/azure-active-directory-brute-force-attack/</guid><description>An unpatched security weakness in Azure Active Directory might be leveraged by attackers to conduct undetected brute-force attacks, according to security researchers.</description><pubDate>Sat, 02 Oct 2021 00:00:00 GMT</pubDate><category>Azure</category><category>Brute-Force</category><category>Microsoft</category><category>PoC</category><author>Dimitris Gkoutzamanis</author></item><item><title>Coinbase Users Hacked!</title><link>https://cisotimes.com/coinbase-users-hacked/</link><guid isPermaLink="true">https://cisotimes.com/coinbase-users-hacked/</guid><description>vulnerability in the SMS multi-factor authentication mechanism of Coinbase was used by hackers to steal funds from 6000 users</description><pubDate>Sat, 02 Oct 2021 00:00:00 GMT</pubDate><category>Coinbase</category><category>Cryptocurrency</category><category>Hacking</category><category>SMS</category><author>Dimitris Gkoutzamanis</author></item><item><title>The Biggest DDoS Attack in History</title><link>https://cisotimes.com/the-biggest-ddos-attack-in-history/</link><guid isPermaLink="true">https://cisotimes.com/the-biggest-ddos-attack-in-history/</guid><description>Russian tech company Yandex said that it suffered from the largest DDoS attack ever recorded in the history of the internet.</description><pubDate>Sun, 12 Sep 2021 00:00:00 GMT</pubDate><category>Attack</category><category>Botnet</category><category>DDoS</category><category>Yandex</category><author>Dimitris Gkoutzamanis</author></item><item><title>Enumerate and Capture Website Files Metadata</title><link>https://cisotimes.com/enumerate-medata-of-files-on-websites/</link><guid isPermaLink="true">https://cisotimes.com/enumerate-medata-of-files-on-websites/</guid><description>Many organizations are uploading files on their websites like pdf, word and excel without being aware that they are exposing sensitive information. You can enumerate and capture the files and its metadata.</description><pubDate>Sat, 11 Sep 2021 00:00:00 GMT</pubDate><category>enumeration</category><category>Penetration Testing</category><category>Tools</category><author>Dimitris Gkoutzamanis</author></item><item><title>United Nations Breached by Hackers</title><link>https://cisotimes.com/united-nations-breached-by-hackers/</link><guid isPermaLink="true">https://cisotimes.com/united-nations-breached-by-hackers/</guid><description>Hackers breached the United Nations&apos; computer networks earlier this year and made off with a trove of data that could be used to target agencies within the intergovernmental organization.</description><pubDate>Sat, 11 Sep 2021 00:00:00 GMT</pubDate><category>Breach</category><category>Hacking</category><category>UN</category><category>United Nations</category><author>TheCISO</author></item><item><title>Microsoft Released Mitigations on Recently Discovered Attack Method</title><link>https://cisotimes.com/microsoft-released-mitigations-on-recently-discovered-attack-method/</link><guid isPermaLink="true">https://cisotimes.com/microsoft-released-mitigations-on-recently-discovered-attack-method/</guid><description>PetitPotam takes advantage of servers where the Active Directory Certificate Services (AD CS) is not configured with protections for NTLM</description><pubDate>Mon, 26 Jul 2021 00:00:00 GMT</pubDate><category>Microsoft</category><category>NTLM</category><category>PetitPotam</category><author>TheCISO</author></item><item><title>Spreading Malware Using Old Techniques. It Still Works!</title><link>https://cisotimes.com/spreading-malware-using-old-techniques-it-still-works/</link><guid isPermaLink="true">https://cisotimes.com/spreading-malware-using-old-techniques-it-still-works/</guid><description>Operators of the malware known as SolarMarker, are using an old technique called SEO poisoning to trick users to follow links on PDF documents stuffed with many SEO keywords and redirect them to malware.</description><pubDate>Tue, 15 Jun 2021 00:00:00 GMT</pubDate><category>Malware</category><category>Microsoft</category><category>SEO</category><category>SolarMarker</category><author>Dimitris Gkoutzamanis</author></item><item><title>Cool Nmap Tricks and Techniques</title><link>https://cisotimes.com/cool-nmap-tricks-and-techniques/</link><guid isPermaLink="true">https://cisotimes.com/cool-nmap-tricks-and-techniques/</guid><description>A list of not so commonly used but powerful Nmap commands to help you bring your enumeration skills to the next level.</description><pubDate>Sun, 06 Jun 2021 00:00:00 GMT</pubDate><category>enumeration</category><category>nmap</category><category>Penetration Testing</category><category>Port Scan</category><category>Scanning</category><author>Dimitris Gkoutzamanis</author></item><item><title>IBM Announces Cybersecurity Grants for Public Schools</title><link>https://cisotimes.com/ibm-announces-cybersecurity-grants-for-public-schools/</link><guid isPermaLink="true">https://cisotimes.com/ibm-announces-cybersecurity-grants-for-public-schools/</guid><description>IBM announced that it would be introducing in-kind grants to six school districts valued at $3 million to boost cybersecurity in schools.</description><pubDate>Sat, 06 Feb 2021 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>IBM</category><category>Training</category><author>TheCISO</author></item><item><title>How much are your details worth on the dark web?</title><link>https://cisotimes.com/how-much-are-your-details-worth-on-the-dark-web/</link><guid isPermaLink="true">https://cisotimes.com/how-much-are-your-details-worth-on-the-dark-web/</guid><description>Researchers from Comparitech, a UK-based online security firm, analyzed more than 40 dark web marketplaces to see how much identities and bundles of full user</description><pubDate>Wed, 03 Feb 2021 00:00:00 GMT</pubDate><category>Credentials</category><category>Credit Card</category><category>Dark Web</category><category>Data Breach</category><category>Personal Data</category><category>Phishing</category><author>TheCISO</author></item><item><title>Top Threats for WordPress Sites in 2020</title><link>https://cisotimes.com/top-threats-for-wordpress-sites/</link><guid isPermaLink="true">https://cisotimes.com/top-threats-for-wordpress-sites/</guid><description>Security firm Wordfence released a report identifying the top security vulnerabilities and threats and common attacks against wordpress websites.</description><pubDate>Tue, 02 Feb 2021 00:00:00 GMT</pubDate><category>Malware</category><category>Report</category><category>Threats</category><category>Vulnerability</category><category>Wordfence</category><category>WordPress</category><author>Dimitris Gkoutzamanis</author></item><item><title>Apple iOS 14 Introduces “BlastDoor” to Prevent Execution of Malicious Code</title><link>https://cisotimes.com/apple-ios-14-introduces-blastdoor-to-prevent-execution-of-malicious-code/</link><guid isPermaLink="true">https://cisotimes.com/apple-ios-14-introduces-blastdoor-to-prevent-execution-of-malicious-code/</guid><description>Apple introduces new security mechanism to iMessage, called BlastDoor. What does it do?</description><pubDate>Sun, 31 Jan 2021 00:00:00 GMT</pubDate><category>Apple</category><category>BlastDoor</category><category>iMessage</category><category>iOS</category><author>TheCISO</author></item><item><title>Even the smartest people get hacked</title><link>https://cisotimes.com/even-the-smartest-people-get-hacked/</link><guid isPermaLink="true">https://cisotimes.com/even-the-smartest-people-get-hacked/</guid><description>Mensa UK , the &quot;high IQ society&quot; organization had failed to secure the data of its 18,000 members properly.</description><pubDate>Sun, 31 Jan 2021 00:00:00 GMT</pubDate><category>Breach</category><category>IQ</category><category>Mensa</category><author>TheCISO</author></item><item><title>U.S. Wireless Carrier with 4.9 Million Customers Hacked</title><link>https://cisotimes.com/u-s-wireless-carrier-with-4-9-million-customers-hacked/</link><guid isPermaLink="true">https://cisotimes.com/u-s-wireless-carrier-with-4-9-million-customers-hacked/</guid><description>Retail store&apos;s employee were scammed into downloading software on a computer which allowed an attacker to access the computer remotely. The hacker gained access to the company&apos;s CRM records since the employee was already logged in to the system.</description><pubDate>Sat, 30 Jan 2021 00:00:00 GMT</pubDate><category>CRM</category><category>Data Breach</category><author>TheCISO</author></item><item><title>What is a “Zero-Day” Exploit</title><link>https://cisotimes.com/what-is-a-zero-day-exploit/</link><guid isPermaLink="true">https://cisotimes.com/what-is-a-zero-day-exploit/</guid><description>Understand what a zero-day exploit is and how your organization can defend against such attacks which target unknown vulnerabilities of your systems and applications.</description><pubDate>Tue, 26 Jan 2021 00:00:00 GMT</pubDate><category>Attacks</category><category>BlueKeep</category><category>Exploits</category><category>Hacking</category><category>Heartbleed</category><category>Shellshock</category><category>Vulnerability</category><category>zero day</category><author>Dimitris Gkoutzamanis</author></item><item><title>Don’t FAIL your DLP Program</title><link>https://cisotimes.com/dont-fail-your-dlp-program/</link><guid isPermaLink="true">https://cisotimes.com/dont-fail-your-dlp-program/</guid><description>Plan your DLP implementation with the right steps. Dont fail before you start. Here are a list of steps to take to ensure success.</description><pubDate>Wed, 07 Oct 2020 00:00:00 GMT</pubDate><category>DLP</category><author>Dimitris Gkoutzamanis</author></item><item><title>PenTest Reports That Bring Value to your Customer</title><link>https://cisotimes.com/pentest-reports-that-brings-value-to-your-customer/</link><guid isPermaLink="true">https://cisotimes.com/pentest-reports-that-brings-value-to-your-customer/</guid><description>Penetration Test Reports must bring value to your clients. There are key elements every proper pentest report must include.</description><pubDate>Mon, 27 Jul 2020 00:00:00 GMT</pubDate><author>Dimitris Gkoutzamanis</author></item><item><title>The Basics of IT Security Audit</title><link>https://cisotimes.com/the-basics-of-it-security-audit/</link><guid isPermaLink="true">https://cisotimes.com/the-basics-of-it-security-audit/</guid><description>An IT security audit is an evaluation of the security of a company&apos;s information systems by measuring how well they conform to a set of established and agreed-upon criteria.</description><pubDate>Thu, 09 Jul 2020 00:00:00 GMT</pubDate><category>Audit</category><category>CAAT</category><category>IT Audit</category><category>Cybersecurity</category><author>Dimitris Gkoutzamanis</author></item><item><title>Famous mobile apps are spying on you!</title><link>https://cisotimes.com/famous-mobile-apps-are-spying-on-you/</link><guid isPermaLink="true">https://cisotimes.com/famous-mobile-apps-are-spying-on-you/</guid><description>During the last few weeks there have been several occasions where famous and widely used mobile applications have been caught on spying on your device&apos;s</description><pubDate>Tue, 07 Jul 2020 00:00:00 GMT</pubDate><category>Apps</category><category>iOS</category><category>Mobile</category><author>TheCISO</author></item><item><title>Types of Man-In-The-Middle Attacks</title><link>https://cisotimes.com/types-of-man-in-the-middle-attacks/</link><guid isPermaLink="true">https://cisotimes.com/types-of-man-in-the-middle-attacks/</guid><description>What is a Man-In-The-Middle attack and how the attacker can use it against you. Is there a way to protect yourself from such attacks?</description><pubDate>Tue, 07 Jul 2020 00:00:00 GMT</pubDate><author>Dimitris Gkoutzamanis</author></item><item><title>US Secret Service: Rise in hacks of managed service providers (MSPs)</title><link>https://cisotimes.com/us-secret-service-rise-in-hacks-of-managed-service-providers-msps/</link><guid isPermaLink="true">https://cisotimes.com/us-secret-service-rise-in-hacks-of-managed-service-providers-msps/</guid><description>The US Secret Service sent out a security alert last month to the US private sector and government organizations warning about an increase in hacks of managed service providers (MSPs).</description><pubDate>Tue, 07 Jul 2020 00:00:00 GMT</pubDate><category>Attacks</category><category>Cyber Attacks</category><category>Hacking</category><category>MSP</category><category>Report</category><author>TheCISO</author></item><item><title>Compliance Does Not Equal Security</title><link>https://cisotimes.com/compliance-does-not-equal-security/</link><guid isPermaLink="true">https://cisotimes.com/compliance-does-not-equal-security/</guid><description>Do not assume that being compliant with a security framework your organization is secure. You need to understand how compliance differs from security.</description><pubDate>Sat, 04 Jul 2020 00:00:00 GMT</pubDate><category>Compliance</category><category>GRC</category><category>ISO</category><category>NIST</category><category>PCI</category><author>Dimitris Gkoutzamanis</author></item><item><title>Hackers extorted $1.14m from University of California, San Francisco</title><link>https://cisotimes.com/hackers-extorted-1-14m-from-university-of-california-san-francisco/</link><guid isPermaLink="true">https://cisotimes.com/hackers-extorted-1-14m-from-university-of-california-san-francisco/</guid><description>A leading medical-research institution working on a cure for Covid-19 has admitted it paid hackers a $1.14m (£910,000) ransom after a covert negotiation</description><pubDate>Tue, 30 Jun 2020 00:00:00 GMT</pubDate><category>Ransomware</category><author>TheCISO</author></item><item><title>Indian government hack exposes 80,000 coronavirus patients’ data</title><link>https://cisotimes.com/indian-government-hack-exposes-80000-coronavirus-patients-data/</link><guid isPermaLink="true">https://cisotimes.com/indian-government-hack-exposes-80000-coronavirus-patients-data/</guid><description>Indian hackers claim to have accessed more than 80,000 coronavirus patients&apos; healthcare records that were insecurely stored on government servers.</description><pubDate>Tue, 30 Jun 2020 00:00:00 GMT</pubDate><author>TheCISO</author></item><item><title>Fileless Malware Are NOT New But Are Still Dangerous</title><link>https://cisotimes.com/fileless-malware-are-not-new-but-are-is-dangerous/</link><guid isPermaLink="true">https://cisotimes.com/fileless-malware-are-not-new-but-are-is-dangerous/</guid><description>File-less malware is an advanced threat that can use legitimate software to compromise systems to steal information.</description><pubDate>Fri, 26 Jun 2020 00:00:00 GMT</pubDate><category>Malware</category><category>PowerShell</category><author>Dimitris Gkoutzamanis</author></item><item><title>South African bank to replace 12m cards after employees stole the master key</title><link>https://cisotimes.com/south-african-bank-to-replace-12m-cards-after-employees-stole-the-master-key/</link><guid isPermaLink="true">https://cisotimes.com/south-african-bank-to-replace-12m-cards-after-employees-stole-the-master-key/</guid><description>The Sunday Times of South Africa, which revealed the story, said the incident took place in December 2018 when someone printed the bank&apos;s master key on a</description><pubDate>Tue, 16 Jun 2020 00:00:00 GMT</pubDate><category>Cards</category><category>Keys</category><author>TheCISO</author></item><item><title>Free and Essential Security Tools You Should Already Be Using</title><link>https://cisotimes.com/free-and-essential-security-tools-you-should-already-be-using/</link><guid isPermaLink="true">https://cisotimes.com/free-and-essential-security-tools-you-should-already-be-using/</guid><description>The most important, free and powerful security tools which you should be using right now to assess your systems and network and uncover vulnerabilities.</description><pubDate>Fri, 12 Jun 2020 00:00:00 GMT</pubDate><category>Scanning</category><category>Tools</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>Google faces $5 billion lawsuit for tracking people in incognito mode</title><link>https://cisotimes.com/google-faces-5-billion-lawsuit-for-tracking-people-in-incognito-mode/</link><guid isPermaLink="true">https://cisotimes.com/google-faces-5-billion-lawsuit-for-tracking-people-in-incognito-mode/</guid><description>Google faces a lawsuit that accuses the company of invading people&apos;s privacy and tracking internet use even when browsers are set to &quot;private&quot; mode.</description><pubDate>Wed, 03 Jun 2020 00:00:00 GMT</pubDate><author>TheCISO</author></item><item><title>How to be Anonymous Online</title><link>https://cisotimes.com/how-to-be-anonymous-online/</link><guid isPermaLink="true">https://cisotimes.com/how-to-be-anonymous-online/</guid><description>Tools and techniques for the protection of your identity online. Be as anonymous as possible. Protect your personal data.</description><pubDate>Sun, 31 May 2020 00:00:00 GMT</pubDate><category>Anonymous</category><category>DuckDuckGo</category><category>Personal Data</category><category>Privacy</category><category>Tor</category><category>VPN</category><author>Dimitris Gkoutzamanis</author></item><item><title>How to Detect and Prevent Crypto Mining in your Environment</title><link>https://cisotimes.com/how-to-detect-and-prevent-crypto-mining-in-your-environment/</link><guid isPermaLink="true">https://cisotimes.com/how-to-detect-and-prevent-crypto-mining-in-your-environment/</guid><description>Cryptojacking has become increasingly popular and you have to be aware of the protection measures you must take to protect your environment from it.</description><pubDate>Sat, 23 May 2020 00:00:00 GMT</pubDate><category>Cryptocurrencies</category><category>Cryptojacking</category><category>Cryptos</category><category>Malware</category><category>Mining</category><author>Dimitris Gkoutzamanis</author></item><item><title>Malware Opens RDP Ports for Future Access</title><link>https://cisotimes.com/malware-opens-rdp-ports-for-future-access/</link><guid isPermaLink="true">https://cisotimes.com/malware-opens-rdp-ports-for-future-access/</guid><description>The Sarwent malware is a lesser-known backdoor trojan that has been around since 2018. In a recent campaign it received two critical updates.</description><pubDate>Fri, 22 May 2020 00:00:00 GMT</pubDate><category>Malware</category><category>Remote Desktop</category><author>TheCISO</author></item><item><title>How to Become a Cybersecurity Expert</title><link>https://cisotimes.com/how-to-become-a-cybersecurity-expert/</link><guid isPermaLink="true">https://cisotimes.com/how-to-become-a-cybersecurity-expert/</guid><description>What are the skills needed to start in the cybersecurity field? Here are some practical steps you can take to dive in and build your skills.</description><pubDate>Wed, 20 May 2020 00:00:00 GMT</pubDate><category>Cloud</category><category>COBIT</category><category>Container</category><category>Frameworks</category><category>Cybersecurity</category><category>ISO</category><category>NIST</category><category>PCI DSS</category><category>Penetration Testing</category><category>Programming</category><category>Standards</category><author>Dimitris Gkoutzamanis</author></item><item><title>Microsoft Confirms Serious Vulnerability</title><link>https://cisotimes.com/microsoft-confirms-thunderspy-vulnerability/</link><guid isPermaLink="true">https://cisotimes.com/microsoft-confirms-thunderspy-vulnerability/</guid><description>Microsoft has confirmed the risk that &quot;an attacker with physical access to a system can use Thunderspy to read and copy data even from systems</description><pubDate>Mon, 18 May 2020 00:00:00 GMT</pubDate><category>Microsoft</category><category>Thunderspy</category><author>TheCISO</author></item><item><title>Cloud Threat Report 2020</title><link>https://cisotimes.com/cloud-threat-report-2020/</link><guid isPermaLink="true">https://cisotimes.com/cloud-threat-report-2020/</guid><description>The &quot;Cloud Threat and Security Report 2020&quot; which identifies the key risks and challenges that organizations face as they implement and maintain cloud solutions</description><pubDate>Sun, 17 May 2020 00:00:00 GMT</pubDate><category>Cloud</category><category>Cyber Attacks</category><category>DevOps</category><category>Oracle</category><category>Report</category><category>Threat</category><author>TheCISO</author></item><item><title>Hackers Threaten to Reveal “Dirty Laundry” on Donald Trump</title><link>https://cisotimes.com/hackers-threaten-to-reveal-dirty-laundry-on-donald-trump/</link><guid isPermaLink="true">https://cisotimes.com/hackers-threaten-to-reveal-dirty-laundry-on-donald-trump/</guid><description>Mr. Trump, if you want to stay president, poke a sharp stick at the guys, otherwise, you may forget this ambition forever. And to you voters, we can let you know that after such a publication, you certainly don&apos;t want to see him as president. The deadline is one week.</description><pubDate>Fri, 15 May 2020 00:00:00 GMT</pubDate><category>Data Breach</category><category>FBI</category><category>Hacking</category><category>Hackers</category><category>Trump</category><author>TheCISO</author></item><item><title>“Thunderspy” Attack Impacts Millions of Apple, Windows, Linux Machines</title><link>https://cisotimes.com/thunderspy-attack-impacts-millions-of-apple-windows-linux-machines/</link><guid isPermaLink="true">https://cisotimes.com/thunderspy-attack-impacts-millions-of-apple-windows-linux-machines/</guid><description>A researcher discovered a security flaw in Intel&apos;s Thunderbolt ports, common to many laptops produced before 2019.</description><pubDate>Fri, 15 May 2020 00:00:00 GMT</pubDate><category>Apple</category><category>Hacking</category><category>Thunderbolt</category><category>Vulnerability</category><category>Windows</category><author>TheCISO</author></item><item><title>Penetration Testing: Pre-Engagement Interactions</title><link>https://cisotimes.com/penetration-testing-pre-engagement-interactions/</link><guid isPermaLink="true">https://cisotimes.com/penetration-testing-pre-engagement-interactions/</guid><description>There are many important actions you should focus on prior to diving into a penetration test. PenTests are not just point-and-shoot activities.</description><pubDate>Thu, 14 May 2020 00:00:00 GMT</pubDate><category>Hacking</category><category>Penetration Testing</category><author>Dimitris Gkoutzamanis</author></item><item><title>How to protect your company from insider threats</title><link>https://cisotimes.com/how-to-protect-your-company-from-insider-threats/</link><guid isPermaLink="true">https://cisotimes.com/how-to-protect-your-company-from-insider-threats/</guid><description>What is an insider threat for an organization, how it can materialize and what can you do to defend against such threats.</description><pubDate>Mon, 11 May 2020 00:00:00 GMT</pubDate><category>Data Leak</category><category>Fraud</category><category>Insider Threats</category><category>Threat</category><author>Dimitris Gkoutzamanis</author></item><item><title>A Simple Summary of GDPR</title><link>https://cisotimes.com/a-simple-summary-of-gdpr/</link><guid isPermaLink="true">https://cisotimes.com/a-simple-summary-of-gdpr/</guid><description>Know what GDPR is and how it can protect and give you more control over your personal data. You have rights over your data, learn what those are and how you can use them through this summary of GDPR.</description><pubDate>Sun, 10 May 2020 00:00:00 GMT</pubDate><category>GDPR</category><author>Dimitris Gkoutzamanis</author></item><item><title>Law Firm Representing Madonna, Lady Gaga and Others Suffer Data Breach</title><link>https://cisotimes.com/law-firm-representing-madonna-lady-gaga-and-others-suffer-data-breach/</link><guid isPermaLink="true">https://cisotimes.com/law-firm-representing-madonna-lady-gaga-and-others-suffer-data-breach/</guid><description>The stolen data include sensitive information like contracts, phone numbers, email addresses, personal correspondence.</description><pubDate>Sun, 10 May 2020 00:00:00 GMT</pubDate><category>Dark Web</category><category>Data Breach</category><category>Hacking</category><category>Personal Data</category><author>TheCISO</author></item><item><title>Vulnerabilities Found in Top VPN Providers</title><link>https://cisotimes.com/vulnerabilities-found-in-top-vpn-providers/</link><guid isPermaLink="true">https://cisotimes.com/vulnerabilities-found-in-top-vpn-providers/</guid><description>Vulnerabilities where found in two of the top 20 VPN providers.</description><pubDate>Fri, 08 May 2020 00:00:00 GMT</pubDate><category>VPN</category><author>TheCISO</author></item><item><title>Microsoft Offers $100,000 to Hack their Linux OS</title><link>https://cisotimes.com/microsoft-offers-100000-to-hack-their-linux-os/</link><guid isPermaLink="true">https://cisotimes.com/microsoft-offers-100000-to-hack-their-linux-os/</guid><description>Microsoft Offers 100,000 if you hack their custom Linux OS.</description><pubDate>Thu, 07 May 2020 00:00:00 GMT</pubDate><category>Azure</category><category>Cloud</category><category>Hacking</category><category>MCU</category><category>Microsoft</category><author>TheCISO</author></item><item><title>Unacademy Hacked, 22Mil User Information for Sale</title><link>https://cisotimes.com/unacademy-hacked-22mil-user-information-for-sale/</link><guid isPermaLink="true">https://cisotimes.com/unacademy-hacked-22mil-user-information-for-sale/</guid><description>Unacademy is one of the largest online learning platforms in India. According to security firm Cyble Inc, a hacker is offering the user database which contains 21,909,707 records, for $2,000.</description><pubDate>Thu, 07 May 2020 00:00:00 GMT</pubDate><category>Data Breach</category><category>Data Leak</category><category>Hacking</category><category>Personal Data</category><category>Unacademy</category><author>TheCISO</author></item><item><title>Many Ways to Attack DNS Servers</title><link>https://cisotimes.com/types-of-dns-attacks/</link><guid isPermaLink="true">https://cisotimes.com/types-of-dns-attacks/</guid><description>Learn the types of DNS attacks that can harm your organisation so you know what you are dealing with and recognise them when the time comes.</description><pubDate>Wed, 06 May 2020 00:00:00 GMT</pubDate><category>DNS</category><category>DNS Attack</category><category>DNS Cache</category><category>DNS Flood</category><category>DNS Hijack</category><author>Dimitris Gkoutzamanis</author></item><item><title>Critical Vulnerability Gives Remote Command Execution as Root!</title><link>https://cisotimes.com/critical-vulnerability-gives-remote-command-execution-as-root/</link><guid isPermaLink="true">https://cisotimes.com/critical-vulnerability-gives-remote-command-execution-as-root/</guid><description>Two critical vulnerabilities in the software of the open-source Salt project have been awarded the highest possible CVSS score of 10!</description><pubDate>Tue, 05 May 2020 00:00:00 GMT</pubDate><category>F-Secure</category><category>LineageOS</category><category>Salt</category><category>Saltstack</category><author>TheCISO</author></item><item><title>Only Half of Organizations Say Their Security Teams Are Prepared for CyberAttacks</title><link>https://cisotimes.com/only-half-of-organizations-say-their-security-teams-are-prepared-for-cyberattacks/</link><guid isPermaLink="true">https://cisotimes.com/only-half-of-organizations-say-their-security-teams-are-prepared-for-cyberattacks/</guid><description>Only 51 percent of technology professionals and leaders are highly confident that their cybersecurity teams are ready to detect and respond to the rising cybersecurity attacks.</description><pubDate>Tue, 05 May 2020 00:00:00 GMT</pubDate><category>COVID</category><category>Cyber Attacks</category><category>ISACA</category><category>Survey</category><author>TheCISO</author></item><item><title>Five Penetration Testing Frameworks and Methodologies</title><link>https://cisotimes.com/five-top-penetration-testing-frameworks-and-methodologies/</link><guid isPermaLink="true">https://cisotimes.com/five-top-penetration-testing-frameworks-and-methodologies/</guid><description>Which are the best frameworks for penetration testing? What are the attributes of each and which one is best for your organization?</description><pubDate>Mon, 04 May 2020 00:00:00 GMT</pubDate><category>NIST</category><category>OSSTMM</category><category>OWASP</category><category>Penetration Testing</category><category>PTES</category><author>Dimitris Gkoutzamanis</author></item><item><title>40 Million(!) Class Action Complaint for Personal Data Disclosure</title><link>https://cisotimes.com/40-million-class-action-complaint-for-personal-data-disclosure/</link><guid isPermaLink="true">https://cisotimes.com/40-million-class-action-complaint-for-personal-data-disclosure/</guid><description>Maurice Blackburn Lawyers has launched a class action complaint against Optus which claims that Optus disclosed the personal data of 50,000 customers in a privacy breach.</description><pubDate>Mon, 27 Apr 2020 00:00:00 GMT</pubDate><category>Australia</category><category>Data Leak</category><category>Personal Data</category><category>Privacy</category><category>Telecom</category><author>TheCISO</author></item><item><title>Sophos XG Firewall Hacked. Hotfix Available</title><link>https://cisotimes.com/sophos-xgfirewall-hacked-hotfix-available/</link><guid isPermaLink="true">https://cisotimes.com/sophos-xgfirewall-hacked-hotfix-available/</guid><description>Hackers were spotted exploiting a vulnerability on Sophos XG firewalls which lead to the abuse of the firewall configuration, exposing information such as usernames and passwords.</description><pubDate>Mon, 27 Apr 2020 00:00:00 GMT</pubDate><category>Firewall</category><category>Hotfix</category><category>Sophos</category><category>SQL injection</category><author>TheCISO</author></item><item><title>What Is Google Dorking?</title><link>https://cisotimes.com/what-is-google-dorking/</link><guid isPermaLink="true">https://cisotimes.com/what-is-google-dorking/</guid><description>Google Dorking is great for penetration testing activities and security researching but can also be used to aid in the protection of sensitive information.</description><pubDate>Mon, 27 Apr 2020 00:00:00 GMT</pubDate><category>Google</category><category>Personal Data</category><category>Search</category><author>Dimitris Gkoutzamanis</author></item><item><title>160,000 Nintendo Player Accounts Hacked</title><link>https://cisotimes.com/160000-nintendo-player-accounts-hacked/</link><guid isPermaLink="true">https://cisotimes.com/160000-nintendo-player-accounts-hacked/</guid><description>Recently 160,000 Nintendo player accounts got hacked. The hackers exploited a weakness and gained access to player data.</description><pubDate>Sat, 25 Apr 2020 00:00:00 GMT</pubDate><category>Data Breach</category><category>Hacking</category><category>Nintendo</category><author>TheCISO</author></item><item><title>New GIAC Cybersecurity Certification</title><link>https://cisotimes.com/new-certification-offered-by-giac/</link><guid isPermaLink="true">https://cisotimes.com/new-certification-offered-by-giac/</guid><description>The new GIAC cybersecurity certification shows that you can put modern principles into practice in an automated and repeatable manner</description><pubDate>Sat, 25 Apr 2020 00:00:00 GMT</pubDate><category>Automation</category><category>Cloud</category><category>Exam</category><category>GIAC</category><category>Training</category><author>TheCISO</author></item><item><title>DevSecOps: Why You Should Put “Sec” in DevOps.</title><link>https://cisotimes.com/devsecops-why-you-should-put-sec-in-devops/</link><guid isPermaLink="true">https://cisotimes.com/devsecops-why-you-should-put-sec-in-devops/</guid><description>It is important to understand the need for security integration in the DevOps environment. Security belongs in the DevOps lifecycle.</description><pubDate>Fri, 24 Apr 2020 00:00:00 GMT</pubDate><category>DevOps</category><category>DevSecOps</category><author>Dimitris Gkoutzamanis</author></item><item><title>iPhones Crashing From Simple Text Messages</title><link>https://cisotimes.com/iphones-crashing-from-simple-text-messages/</link><guid isPermaLink="true">https://cisotimes.com/iphones-crashing-from-simple-text-messages/</guid><description>The latest Apple mobile OS version iOS 13.4.1 has a text bomb bug that forces iPhones Crashing From Simple Text Messages.</description><pubDate>Fri, 24 Apr 2020 00:00:00 GMT</pubDate><category>Apple</category><category>Application</category><category>iPhone</category><category>SMS</category><category>Vulnerability</category><author>TheCISO</author></item><item><title>Docker Security Practices</title><link>https://cisotimes.com/docker-security-practices/</link><guid isPermaLink="true">https://cisotimes.com/docker-security-practices/</guid><description>A list of docker security practices for securely configuring your Docker containers and images.</description><pubDate>Thu, 23 Apr 2020 00:00:00 GMT</pubDate><category>Application</category><category>Container</category><category>Docker</category><category>Images</category><category>Cybersecurity</category><category>Vulnerability</category><author>Dimitris Gkoutzamanis</author></item><item><title>Warning to Apple Users! Possible Device Hack by Just Sending Email</title><link>https://cisotimes.com/warning-to-apple-users-possible-device-hack-by-just-sending-email/</link><guid isPermaLink="true">https://cisotimes.com/warning-to-apple-users-possible-device-hack-by-just-sending-email/</guid><description>Bugs were found in the Apple mail app which can allow RCE (Remote Code Execution), due to an out-of-bounds write bug and a heap overflow issue.</description><pubDate>Wed, 22 Apr 2020 00:00:00 GMT</pubDate><category>Apple</category><category>Exploit</category><author>TheCISO</author></item><item><title>Personal Data of 267 Million Users Sold by Hackers</title><link>https://cisotimes.com/personal-data-of-267-million-users-sold-by-hackers/</link><guid isPermaLink="true">https://cisotimes.com/personal-data-of-267-million-users-sold-by-hackers/</guid><description>Hackers have sold personal data from 267 Million Facebook users causing another major reputation blow on the tech giant.</description><pubDate>Tue, 21 Apr 2020 00:00:00 GMT</pubDate><category>Facebook</category><category>Personal Data</category><category>Vulnerability</category><author>TheCISO</author></item><item><title>Zoom Videoconferencing Security Issues Were known to Dropbox</title><link>https://cisotimes.com/zoom-videoconferencing-security-issues-were-known-to-dropbox/</link><guid isPermaLink="true">https://cisotimes.com/zoom-videoconferencing-security-issues-were-known-to-dropbox/</guid><description>Security vulnerabilities have been unveiled that could allow attackers to covertly control user&apos;s computers.</description><pubDate>Tue, 21 Apr 2020 00:00:00 GMT</pubDate><category>Hacking</category><category>Tenable</category><category>Vulnerability</category><category>Zoom</category><author>TheCISO</author></item><item><title>Defense in Depth – The Layered Approach to Cybersecurity</title><link>https://cisotimes.com/defense-in-depth-the-layered-approach-to-cybersecurity/</link><guid isPermaLink="true">https://cisotimes.com/defense-in-depth-the-layered-approach-to-cybersecurity/</guid><description>Defense In Depth is a common terminology in modern day cybersecurity practices. It is a strategy that employs a series of mechanisms, to stop an attack on your organization.</description><pubDate>Fri, 17 Apr 2020 00:00:00 GMT</pubDate><category>Application Security</category><category>Data Security</category><category>Defence in Depth</category><category>Endpoint Security</category><category>Network Security</category><category>Physical Security</category><category>Secure Architecture</category><category>Cybersecurity</category><author>Dimitris Gkoutzamanis</author></item><item><title>Microsoft Offers Free Cybersecurity Service Protection to Healthcare Staff</title><link>https://cisotimes.com/microsoft-offers-free-cybersecurity-service-protection-to-healthcare-staff/</link><guid isPermaLink="true">https://cisotimes.com/microsoft-offers-free-cybersecurity-service-protection-to-healthcare-staff/</guid><description>Recently numerous hospitals became the target of cyber attacks both in Europe and the United States. Microsoft decided to offer its security service AccountGuard for free to healthcare staff as well as human rights and humanitarian organizations.</description><pubDate>Wed, 15 Apr 2020 00:00:00 GMT</pubDate><category>COVID</category><category>Cybersecurity</category><category>Microsoft</category><author>TheCISO</author></item><item><title>NIST is Providing Online Cybersecurity Training Resources</title><link>https://cisotimes.com/nist-is-providing-online-cybersecurity-training-resources/</link><guid isPermaLink="true">https://cisotimes.com/nist-is-providing-online-cybersecurity-training-resources/</guid><description>The National Institute of Standards and Technology (NIST) has provided information and links to free and low-cost security training content.</description><pubDate>Tue, 14 Apr 2020 00:00:00 GMT</pubDate><category>CISO</category><category>Cybersecurity</category><category>NIST</category><category>Training</category><author>TheCISO</author></item><item><title>All Data Breaches in 2019 &amp;#038; 2020</title><link>https://cisotimes.com/all-data-breaches-in-2019-2020/</link><guid isPermaLink="true">https://cisotimes.com/all-data-breaches-in-2019-2020/</guid><description>Many organizations, big and small, have suffered data breaches in 2019 and 2020. The breach details are shown in the table below.</description><pubDate>Mon, 13 Apr 2020 00:00:00 GMT</pubDate><category>Data Breach</category><author>TheCISO</author></item><item><title>Zoom Usernames and Passwords Compromised and Listed on Dark Web Forum</title><link>https://cisotimes.com/zoom-usernames-and-passwords-compromised-and-listed-on-dark-web-forum/</link><guid isPermaLink="true">https://cisotimes.com/zoom-usernames-and-passwords-compromised-and-listed-on-dark-web-forum/</guid><description>The Coronavirus crisis has forced many organizations to embrace &quot;work from home&quot;. Zoom platform has become increasingly famous due to this, but also for its</description><pubDate>Mon, 13 Apr 2020 00:00:00 GMT</pubDate><category>Exploit</category><category>Password</category><author>TheCISO</author></item><item><title>Microsoft Exchange Servers Still Unpatched, Leaves them open to Remote Code Execution Vulnerability</title><link>https://cisotimes.com/microsoft-exchange-servers-still-unpatched-leaves-them-open-to-remote-code-execution-vulnerability/</link><guid isPermaLink="true">https://cisotimes.com/microsoft-exchange-servers-still-unpatched-leaves-them-open-to-remote-code-execution-vulnerability/</guid><description>Based on a Rapid7 survey more than 357 thousand Exchange Servers are vulnerable to a latest RCE vulnerability which allows an attacker to use an Exchange user</description><pubDate>Wed, 08 Apr 2020 00:00:00 GMT</pubDate><category>Microsoft</category><category>Vulnerability</category><author>TheCISO</author></item></channel></rss>