Cyber Defense Advisors

Year: 2024

  • by
  • May 23, 2024

Inside Operation Diplomatic Specter: Chinese APT Group’s Stealthy Tactics Exposed

Governmental entities in the Middle East, Africa, and Asia are the target of a Chinese advanced persistent threat (APT) group as part of an ongoing cyber espionage campaign dubbed Operation Diplomatic Specter since at least late 2022. “An analysis of this threat actor’s activity reveals long-term espionage operations against at least seven governmental entities,” Palo […]

Cyber News
  • by
  • May 23, 2024

Are Your SaaS Backups as Secure as Your Production Data?

Conversations about data security tend to diverge into three main threads: How can we protect the data we store on our on-premises or cloud infrastructure? What strategies and tools or platforms can reliably backup and restore data? What would losing all this data cost us, and how quickly could we get it back? All are […]

Cyber News
  • by
  • May 23, 2024

Personal AI Assistants and Privacy

MIThttps://www.technologyreview.com/2021/08/25/1032111/conscious-ai-can-machines-think/ “Machines with minds are mainstays of science fiction—the idea of a robot thatsomehow replicates consciousness through its hardware or software has been around so long it feels familiar. Such machines don’t exist, of course, and maybe never will. Indeed, the concept of a machine with a subjective experience of the world and a first-person […]

Cyber News
  • by
  • May 23, 2024

Ivanti Patches Critical Remote Code Execution Flaws in Endpoint Manager

Ivanti on Tuesday rolled out fixes to address multiple critical security flaws in Endpoint Manager (EPM) that could be exploited to achieve remote code execution under certain circumstances. Six of the 10 vulnerabilities – from CVE-2024-29822 through CVE-2024-29827 (CVSS scores: 9.6) – relate to SQL injection flaws that allow an unauthenticated attacker within the same […]

Cyber News
  • by
  • May 23, 2024

The End of an Era: Microsoft Phases Out VBScript for JavaScript and PowerShell

Microsoft on Wednesday outlined its plans to deprecate Visual Basic Script (VBScript) in the second half of 2024 in favor of more advanced alternatives such as JavaScript and PowerShell. “Technology has advanced over the years, giving rise to more powerful and versatile scripting languages such as JavaScript and PowerShell,” Microsoft Program Manager Naveen Shankar said. […]

Cyber News
  • by
  • May 22, 2024

Smashing Security podcast #373: iPhone undeleted photos, and stealing Scarlett Johansson’s voice

iPhone photos come back from the dead! Scarlett Johansson sounds upset about GPT-4o, and there’s a cockup involving celebrity fakes. All this and much more is discussed in the latest edition of the “Smashing Security” podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by special guest Anna Brading of Malwarebytes. Plus! […]

Cyber News
  • by
  • May 22, 2024

Researchers Warn of Chinese-Aligned Hackers Targeting South China Sea Countries

Cybersecurity researchers have disclosed details of a previously undocumented threat group called Unfading Sea Haze that’s believed to have been active since 2018. The intrusion singled out high-level organizations in South China Sea countries, particularly military and government targets, Bitdefender said in a report shared with The Hacker News. “The investigation revealed a troubling trend […]

Cyber News
  • by
  • May 22, 2024

23-year-old alleged founder of dark web Incognito Market arrested after FBI tracks cryptocurrency payments

Graham CLULEY May 22, 2024 Promo Protect all your devices, without slowing them down. Free 30-day trial The United States Department of Justice has dealt a blow to dark web drug traffickers by arresting a man alleged to operate the dark web drugs marketplace Incognito Market. According to a DOJ press release, the alleged operator […]

Cyber News
  • by
  • May 22, 2024

Rockwell Advises Disconnecting Internet-Facing ICS Devices Amid Cyber Threats

Rockwell Automation is urging its customers to disconnect all industrial control systems (ICSs) not meant to be connected to the public-facing internet to mitigate unauthorized or malicious cyber activity. The company said it’s issuing the advisory due to “heightened geopolitical tensions and adversarial cyber activity globally.” To that end, customers are required to take immediate […]

Cyber News