More than 400 custom web injects for mobile malware are being offered for sale by the InTheBox darknet marketplace, which is thought to emerge in January 2020, reports The Hacker News.
Several U.S. federal agencies have been pushed by the Government Accountability Office to perform cybersecurity risk assessments on internet of things and operational technology systems in a bid to bolster critical infrastructure sectors' cybersecurity posture, according to SecurityWeek.
Numerous companies and organizations including Global Ordnance, UMO Poland, Blue Sky Network, and The Commission for International Justice and Accountability have been impersonated by Russian state-sponsored threat group SEABORGIUM, also known as TA446, Callisto, and COLDDRIVER, to serve as lures in a phishing operation, according to The Record, a news site by cybersecurity firm Recorded Future.
Eclypsium's research team has discovered 3 vulnerabilities in BMCs. Nate Warfield comes on the show to tell the full story! This has garnered much attention in the press: Original research post: https://eclypsium.com/2022/12/05/supply-chain-vulnerabilities-put-server-ecosystem-at-risk/, https://www.securityweek.com/security-flaws-ami-bmc-can-expose...
In an emergency cybersecurity directive issued Tuesday, the state flagged technologies from eight companies and prohibited state government employees from using them for official business.