CyberWire Daily
Follow
The guest nobody invited.
CISA has mandated the patching of vulnerabilities in TrueConf Server due to active exploitation. LockBit ransomware group is threatening to release stolen banking data unless a ransom is paid. Security researchers have identified a critical type confusion vulnerability in a Node.js library, potentially leading to remote code execution. A new campaign involving Agent Tesla malware version 4 exhibits improved evasion techniques. Attackers are utilizing FTP server banners as a novel method to conceal malware delivery commands. Apple has addressed a serious flaw in its image-processing software that could be exploited for spyware. North Korea is believed to be behind a software supply chain attack targeting the Rust programming ecosystem. Latvian officials have resigned following a significant data breach affecting over a million individuals. Defense contractors report increased confidence in CMMC compliance but struggle with proving it. Patrick Coughlin, CEO of Savi Security, discusses Scamwise, a free tool to combat AI-driven scams targeting the "sandwich generation."