• Researchers Find Over 22,000 Removed PyPI Packages at Risk of Revival Hijack

    Researchers Find Over 22,000 Removed PyPI Packages at Risk of Revival Hijack

    A new supply chain attack technique targeting the Python Package Index (PyPI) registry has been exploited in the wild in an attempt to infiltrate downstream organizations. It has been codenamed Revival Hijack by software supply chain security firm JFrog, which said the attack method could be used to hijack 22,000 existing PyPI packages and result…

    Read More

  • The New Effective Way to Prevent Account Takeovers

    The New Effective Way to Prevent Account Takeovers

    Account takeover attacks have emerged as one of the most persistent and damaging threats to cloud-based SaaS environments. Yet despite significant investments in traditional security measures, many organizations continue to struggle with preventing these attacks. A new report, “Why Account Takeover Attacks Still Succeed, and Why the Browser is Your Secret Weapon in Stopping Them”…

    Read More

  • Zyxel Patches Critical OS Command Injection Flaw in Access Points and Routers

    Zyxel Patches Critical OS Command Injection Flaw in Access Points and Routers

    Zyxel has released software updates to address a critical security flaw impacting certain access point (AP) and security router versions that could result in the execution of unauthorized commands. Tracked as CVE-2024-7261 (CVSS score: 9.8), the vulnerability has been described as a case of operating system (OS) command injection. “The improper neutralization of special elements…

    Read More

  • Hacktivists Exploits WinRAR Vulnerability in Attacks Against Russia and Belarus

    Hacktivists Exploits WinRAR Vulnerability in Attacks Against Russia and Belarus

    A hacktivist group known as Head Mare has been linked to cyber attacks that exclusively target organizations located in Russia and Belarus. “Head Mare uses more up-to-date methods for obtaining initial access,” Kaspersky said in a Monday analysis of the group’s tactics and tools. “For instance, the attackers took advantage of the relatively recent CVE-2023-38831…

    Read More

  • New Rust-Based Ransomware Cicada3301 Targets Windows and Linux Systems

    New Rust-Based Ransomware Cicada3301 Targets Windows and Linux Systems

    Cybersecurity researchers have unpacked the inner workings of a new ransomware variant called Cicada3301 that shares similarities with the now-defunct BlackCat (aka ALPHV) operation. “It appears that Cicada3301 ransomware primarily targets small to medium-sized businesses (SMBs), likely through opportunistic attacks that exploit vulnerabilities as the initial access vector,” cybersecurity

    Read More

  • Rocinante Trojan Poses as Banking Apps to Steal Sensitive Data from Brazilian Android Users

    Rocinante Trojan Poses as Banking Apps to Steal Sensitive Data from Brazilian Android Users

    Mobile users in Brazil are the target of a new malware campaign that delivers a new Android banking trojan named Rocinante. “This malware family is capable of performing keylogging using the Accessibility Service, and is also able to steal PII from its victims using phishing screens posing as different banks,” Dutch security company ThreatFabric said.…

    Read More

  • Secrets Exposed: Why Your CISO Should Worry About Slack

    Secrets Exposed: Why Your CISO Should Worry About Slack

    In the digital realm, secrets (API keys, private keys, username and password combos, etc.) are the keys to the kingdom. But what if those keys were accidentally left out in the open in the very tools we use to collaborate every day? A Single Secret Can Wreak Havoc Imagine this: It’s a typical Tuesday in…

    Read More

  • National Voter Registration Day Sept. 17: WAGAP events in Bingen, Goldendale, Stevenson

    National Voter Registration Day Sept. 17: WAGAP events in Bingen, Goldendale, Stevenson

    THE GORGE — In honor of National Voter Registration Day Sept. 17, Washington Gorge Action Programs (WAGAP) is holding events to help community members register to vote in Klickitat and Skamania counties.

    Read More

  • News briefs for Sept. 4, 2024

    News briefs for Sept. 4, 2024

    Wasco Soil and Water have changed their meeting time, an advocacy launch is planned and candidate forums for October.

    Read More

  • New Flaws in Microsoft macOS Apps Could Allow Hackers to Gain Unrestricted Access

    New Flaws in Microsoft macOS Apps Could Allow Hackers to Gain Unrestricted Access

    Eight vulnerabilities have been uncovered in Microsoft applications for macOS that an adversary could exploit to gain elevated privileges or access sensitive data by circumventing the operating system’s permissions-based model, which revolves around the Transparency, Consent, and Control (TCC) framework. “If successful, the adversary could gain any privileges already granted to the affected

    Read More