Category: Industry News

Top Software Testing Services

Access To User’s Email Inboxes Was Being Sold By An Employee Of Yandex

Yandex is a Russian Dutch-domiciled search engine, ride-hailing, and email service provider, who on Friday uncovered a data breach in which email accounts of 4,887 of its users were breached or compromised. The organization accused an anonymous employee of the occurrence of this event, who had been giving unauthorized access to the clients’ email inboxes…
Read more

Telegram’s Feature Secret Chat Stores Self-Destructing Media Files On Shared Device

Telegram, a mainstream popular messaging application, recently fixed a privacy crushing bug in its macOS version of the application that made it conceivable to access the self-destructing video and audio messages or files even after they have vanished from secret chats for a long period of time. The vulnerability was found by the cybersecurity researcher…
Read more

Pre-Valentine Malware Attack Using Phishing Emails To Imposter Well-Known Lingerie & Flower Stores

As Valentine’s Day approaches at the end of this week, a lot of people have recently received order confirmation emails for lingerie and flowers. But actually, these confirmation emails are a part of a spear-phishing assault that will eventually drive casualties to a noxious document or file that will execute the BazaLoader malware. The BazaLoader…
Read more

SaaS Security Posture Management With Misconfigured SaaS Settings

Not all but most of the organizations in today’s world, which is full of cybercriminals and cybercrime groups, are mainly concerned about their cloud security situation or reputation. What’s even more concerning for organizations is the SaaS (Software-as-a-service) Security Posture Management (SSPM). A recent attack faced and revealed by Malwarebytes explained how they were targeted…
Read more

What Financial Organizations Should Consider to Avoid/Prevent Cyber Threats

Banks and Financial organizations/institutions due to their access to sensitive and confidential client data are an ideal objective for cyber attackers, particularly in the present powerful and active environment. With numerous representatives working remotely during the pandemic, the assault surface has expanded rapidly and massively, making employees simpler targets. As per Boston Consulting Group, organizations…
Read more

Severity Differences Between SSRF & XXE

SSRF stands for Server-Side Request Forgery and is a type of attack in which a vulnerable server is forced by the attacker/hacker to trigger unwanted malicious requests to the third-party servers and/or to internal resources. XML stands for XML External Entity and is a type of attack that is performed over an application that parses…
Read more

Best Practices For DevSecOps

A simple DevSecOps definition is that it is short for development, security, and operations. Its  mantra is to make everyone accountable for security with the objective of implementing security decisions and actions at the same scale and speed as development and operations decisions and actions. Every organization with a DevOps framework should be looking to…
Read more

Preventing Risks From Subdomain Takeover – Cloud Exploits

33 billion records were leaked in 2018 and 2019 because of inappropriate cloud security. Since 2019, an expansion of more than 300% in the number of penetration tests performed against cloud environments. During cloud penetration tests, configuration errors are regularly discovered which could prompt significant issues, for instance, misconfigured openly visible AWS S3 storage buckets.…
Read more

All Your Queries About Vulnerability Management

In the previous years, all of us may have heard the reports of data breaches that took place over some of the most popular and reputed platforms. For instance, a breach took place in 2020 on Twitter in which a number of Twitter handles were captured and were being ransomed for $1000 to $2000. Fake…
Read more

Developer Of The World’s Largest Phishing Service, U-Admin, Arrested By Ukrainian Police

Officials from the law enforcement agencies in Ukraine, last week coordinated with the authorities of Australia and the U.S.and successfully shut down the worlds biggest phishing services which were utilized to select and attack institutions and organizations of financial services in around 11 countries, resulting in losses of tens of millions of dollars. The Ukrainian…
Read more