The Leading Company for Securing Access Between Workloads Recognized for the Aembit Workload IAM Platform Aembit, the Workload Identity and Access Management (IAM) Company, has been named one of the …
‘The Manipulaters’ Improve Phishing, Still Fail at Opsec
Roughly nine years ago, KrebsOnSecurity profiled a Pakistan-based cybercrime group called “The Manipulaters,” a sprawling web hosting network of phishing and spam delivery platforms. In January 2024, The Manipulaters pleaded …
WP-Members Plugin Expose WordPress Sites To Injection Attacks
A security researcher reported a critical vulnerability in the WP-Members Membership Plugin that allows attackers to inject malicious scripts and potentially take over websites. Administrators could take advantage of the …
StrelaStealer Attacking Users to Steal Logins from Outlook & Thunderbird
A sophisticated variant of StrelaStealer malware has been identified, targeting Spanish-speaking users with the primary aim of pilfering email account credentials from popular email clients Outlook and Thunderbird. This updated …
New Chrome Feature Blocks Hackers From Stealing Your Cookie
Google has unveiled a new web feature called “Device Bound Session Credentials (DBSC)” that will help protect users from cookie theft. Malware that steals cookies from users and allows attackers …
What is Malware Packers? How To Analyse With ANY.RUN Sandbox – SOC/DIFR Guide
Antiviruses can quickly detect malicious executable files, but attackers can bypass this by using packers to compress and obfuscate the code, making it difficult for antivirus software to analyze. Packers …
Chinese Hackers Hijack Swedish Routers to Launch Cyber Attacks
The Security Police (Säpo) has disclosed that a Chinese hacker group, APT31, has commandeered Swedish routers to perpetrate cyber attacks against multiple countries. This sophisticated cyber espionage campaign, believed to …
New Pikabot Campaign Weaponizes HTML, Javascript & Excel Files
A new player has emerged with a sophisticated approach to infiltrating systems worldwide. Dubbed Pikabot, this malicious backdoor has been active since early 2023, but recent activities have showcased its …
JumpServer Critical Flaws Let Attackers Execute Arbitrary Remote Code
The critical vulnerabilities in JumpServer’s Ansible that allowed attackers to execute arbitrary remote code have been patched. With a CVSS base score of 10, the critical vulnerabilities identified as CVE-2024-29201 …
Authentic8 and CISA Launch Silo Shield to Safeguard High-Risk Communities
Authentic8, provider of the leading OSINT research platform Silo for Research, today launched its Silo Shield Program to enhance online security for high-risk communities. Also today, the U.S. Cybersecurity and …



