
Blog Series
Month: February 2023

An Update on AlmaLinux Since...
TuxCare was there with you right at the start of the CentOS crisis, just as Red Hat suddenly pulled the rug from one of the most commonly used enterprise Linux...
New obfuscated malware targets sensitive...
Researchers have discovered a new type of obfuscated malware that is specifically designed to steal sensitive data from victims’ computers. Malware is distributed through phishing emails that appear to be...
CentOS-8 is End of Life....
With Centos-8 EOL, open-source communities of enterprise users and web hosts now face a great amount of risk. But, extended lifecycle support solutions can buy you time and make the...
Firebrick Ostrich uses open-source tactics...
Abnormal Security discovered a new business email attack threat actor known as “Firebrick Ostrich” performing Business email compromise (BEC) on a near-industrial scale. It also employs a stealth strategy to...
W4SP Stealer: Why Discord Malware...
We first reported on W4SP Stealer in November in response to widespread news of a new Python supply chain attack. Unfortunately, as it so often happens, W4SP Stealer looks like...
Unpatched QNAP storage devices exposed...
Censys, a security firm, has warned that up to 29,000 network storage devices manufactured by Taiwan-based QNAP are vulnerable to easily executed SQL injection attacks, granting complete control to unauthenticated...
How Live Patching Can Help...
Agile methodologies, cloud computing, and automation tools allow software development teams to work faster and more efficiently. They emphasize fast iteration and continuous delivery, enabling teams to deliver software faster....
Lazarus launches attacks on medical...
A Lazarus Group cyberattack is targeting the medical research and energy industries, and their supply chain partners, through exploiting known vulnerabilities found in unpatched Zimbra devices, according to WithSecure research....
Explaining the Value of Live...
Ever been in a position where you needed to validate an important technical purchase to a group of executives who just didn’t understand what value the business would get if...
Atlassian resolves critical security...
Atlassian has addressed a serious security vulnerability in its Jira Service Management Server and Data Center that could have allowed an attacker to impersonate another user and gain unauthorized access....
The Dilemmas of FIPS 140-3...
FIPS 140-3 is a standard issued by the National Institute of Standards and Technology (NIST) that aims to provide a consistent and secure method for processing sensitive information using a...
ESXiArgs ransomware targets unpatched VMware...
Admins, hosting providers, and the French Computer Emergency Response Team (CERT-FR) have warned of a new ransomware attack named ESXiArgs that is targeting VMware ESXi servers which have not been...