Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Archives for Kirsten Doyle - Page 45

Kirsten Doyle

Kirsten Doyle

Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

VanHelsingRaaS Strikes: Sinking Its Fangs into Windows, Linux, and More

Kirsten DoyleMarch 25, 20253 Mins Read

Over the last few weeks, an emerging and rapidly growing ransomware-as-a-service (RaaS) operation dubbed VanHelsingRaaS has been attracting attention in the cybercrime world. Check Point Research has discovered two variants of this scourge, targeting Windows, but in its advert, VanHelsingRaas says it offers tools “targeting Linux, BSD, ARM, and ESXi systems”. Mirroring legitimate tools, the program offers an intuitive control panel that makes operating ransomware attacks child’s play. The two variants Check Point Research obtained were compiled only five days apart, with the latest version featuring significant updates—a sign of how quickly this ransomware is evolving. Debuted on 7 March,…

Read More

Research: Rooting Tools vs The Mobile Security Industry

Kirsten DoyleMarch 25, 20256 Mins Read

Once widespread for facilitating deeper customization and removing OS limitations on mobile devices, rooting and jailbreaking, are becoming primarily the domain of power users, as manufacturers have made giant leaps to limit this practice via two different approaches. Firstly, by adding additional customization options to prevent users from feeling restricted, and secondly, by introducing more stringent security protocols into stock Android and iOS versions. However, despite a drop in the number of rooted and jailbroken devices in general, they still represent a very dire security threat, not to the user alone, but to entities who allow staff members to access…

Read More

ABYSSWORKER: A New EDR-Killer in Medusa Ransomware Attacks

Kirsten DoyleMarch 24, 20252 Mins Read

Elastic Security Labs has observed a financially motivated campaign delivering Medusa ransomware via a HEARTCRYPT-packed loader.   This loader is deployed alongside a driver, signed with a revoked certificate from a Chinese vendor, which Elastic has named ABYSSWORKER. Once installed on the victim’s machine, the driver is used to disable various EDR solutions. This EDR-disrupting driver was previously reported by ConnectWise in a separate campaign, where it utilized a different certificate and IO control codes, and some of its functionalities were analyzed at that time. According to Elastic Security Labs, “Cybercriminals are increasingly bringing their own drivers — either exploiting a…

Read More

The Looming Quantum Threat: NCSC Urges Encryption Upgrades

Kirsten DoyleMarch 24, 20255 Mins Read

The danger to cryptography posed by next-generation large-scale, fault-tolerant quantum computers is widely understood. Although current encryption methods, which are used to secure everything from banking to communications, are based on mathematical algorithms that the everyday PC is unable to crack, a new era of incredibly fast quantum computers is just a few years away, poised to revolutionize problem-solving, communication, and computation. Modern cryptography relies on algorithms specifically designed to be as difficult to break as possible. For instance, today’s public key algorithms—such as RSA, Diffie-Hellman, and Elliptic Curve—are used to help communicating parties establish cryptographic keys or to generate…

Read More

California Cryobank Alerts Consumers to Data Breach

Kirsten DoyleMarch 21, 20253 Mins Read

California Cryobank (CCB), one of the world’s largest reproductive tissue banks, has begun informing consumers about a data breach impacting an unspecified number of individuals. The biotechnology company reported detecting unauthorized activity on certain computers on 21 April last year, and subsequently isolated them from its IT network. Protecting Data Confidentiality In a statement, the company said it is committed to protecting the confidentiality and security of the information it maintains. “CCB recently completed our investigation of an incident that involved unauthorized activity on certain computers in our information technology (“IT”) environment. Upon identifying the activity, it said it isolated…

Read More

Windows Shortcut Zero-Day Under Active Attack

Kirsten DoyleMarch 21, 20254 Mins Read

A highly advanced zero-day vulnerability has been covertly exploited for years by multiple state-sponsored hacking groups, underscoring its severe security risks. This flaw leverages Windows shortcut (.lnk) files, enabling attackers to stealthily execute malicious commands without detection. However, Microsoft tagged it as “not meeting the bar servicing” in late September and said it wouldn’t release security updates to address it. While Microsoft has yet to assign a CVE-ID to this vulnerability, Trend Micro is tracking it internally as ZDI-CAN-25373 and said it enables bad actors to execute arbitrary code on affected Windows systems. Trend Micro’s experts have linked the…

Read More

Western Alliance Bank Data Breach Affects Nearly 22,000 Individuals

Kirsten DoyleMarch 20, 20255 Mins Read

Western Alliance Bank has announced a data breach affecting 21,899 people, that was caused by an October 2024 cyberattack on a third-party file transfer software. The breach exposed sensitive personal and financial information, including names, Social Security numbers, driver’s license details, and financial account numbers. The bank said the malicious actors exploited a zero-day vulnerability in the third-party software to breach a limited number of Western Alliance systems and exfiltrate files stored on the compromised devices. Western Alliance found that customer data was exfiltrated from its network only after discovering that the attackers leaked some files stolen from its systems. The breach happened on 12…

Read More

Apache Tomcat Under Siege: RCE Exploit Spreads Globally

Kirsten DoyleMarch 19, 20253 Mins Read

A newly discovered remote code execution (RCE) vulnerability, CVE-2025-24813, is actively being exploited, putting Apache Tomcat servers at risk—malicious actors need but a single PUT API request to gain full control over vulnerable systems. The exploit was initially published by a Chinese forum user, iSee857, with a proof-of-concept (PoC) code now readily available online. How a Simple PUT Request Leads to Full RCE The attack takes advantage of Tomcat’s default session persistence mechanism and its support for partial PUT requests. Wallarm says it follows a straightforward two-step process: Step 1: Uploading a Malicious Serialized Session According to Wallarm: “The attacker…

Read More

Targeted Microsoft 365 Tenants: Attackers Exploit Billing Emails for Phishing

Kirsten DoyleMarch 19, 20255 Mins Read

Security researchers at Guardz have warned of new malicious campaigns that abuse Microsoft 365 for phishing , or target the service’s users to take over their accounts. As part of one campaign, malicious actors are leveraging legitimate Microsoft domains and tenant misconfigurations in BEC attacks likely aimed at stealing credentials and performing account takeover (ATO).   According to the researchers, this attack exploits genuine Microsoft services to fashion a trusted delivery mechanism for phishing content, making it tricky for technical controls and security practitioners to detect. Operating Within Microsoft’s Ecosystem Unlike conventional phishing, which depends on fake domains crafted to appear…

Read More

Massive RSA Encryption Flaw Exposes Millions of IoT Devices to Attack

Kirsten DoyleMarch 18, 20254 Mins Read

A major security flaw has been found in RSA encryption keys used across the internet. Researchers discovered that about one in 172 online certificates are at risk due to a mathematical weakness. The issue mainly affects Internet of Things (IoT) devices but could impact any system using improperly generated RSA keys, arising from poor random number generation during key creation, particularly in devices with limited entropy sources.  If RSA keys lack enough randomness, they could share prime factors with other keys, making them easy to break using a factorization attack. Factorization Attacks This type of attack takes advantage of a…

Read More
Previous 1 … 43 44 45 46 47 … 61 Next
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}