<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Archives - Online Pitstop</title>
	<atom:link href="https://onlinepitstop.com/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>https://onlinepitstop.com/category/security/</link>
	<description>The best source for news on cybersecurity, cybercrime, privacy and more.</description>
	<lastBuildDate>Sat, 01 Mar 2025 01:03:56 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>
	<item>
		<title>Third-Party Attacks Drive Major Financial Losses in 2024</title>
		<link>https://onlinepitstop.com/2025/03/01/third-party-attacks-drive-major-financial-losses-in-2024/</link>
					<comments>https://onlinepitstop.com/2025/03/01/third-party-attacks-drive-major-financial-losses-in-2024/#respond</comments>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Sat, 01 Mar 2025 01:03:56 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://onlinepitstop.com/2025/03/01/third-party-attacks-drive-major-financial-losses-in-2024/</guid>

					<description><![CDATA[<p>Third-party attacks emerged as a significant driver of material financial losses from cyber incidents in 2024, according to cyber risk management firm Resilience. Third-party risks made up 31% of all client insurance claims and 23% of material losses last year. This marks a significant change from 2023, when no third-party claims led to material losses</p>
<p>The post <a href="https://onlinepitstop.com/2025/03/01/third-party-attacks-drive-major-financial-losses-in-2024/">Third-Party Attacks Drive Major Financial Losses in 2024</a> appeared first on <a href="https://onlinepitstop.com">Online Pitstop</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div></div>
<div id="layout-453e7af8-af92-4d13-827f-886ad6f5bc9a" data-layout-id="2" data-edit-folder-name="text" data-index="0" readability="76.118935837246">
<p>Third-party attacks emerged as a significant driver of material financial losses from cyber incidents in 2024, according to cyber risk management firm Resilience.</p>
<p><a href="https://www.infosecurity-magazine.com/news/third-party-risk-failures-uk/" target="_blank">Third-party risks</a> made up 31% of all client insurance claims and 23% of material losses last year. This marks a significant change from 2023, when no third-party claims led to material losses for Resilience clients.</p>
<p>&#x201C;This shift underscores the growing vulnerabilities created by interconnected systems and reliance on external vendors in 2023,&#x201D; the firm wrote in a report dated February 27.</p>
<h2><strong>Ransomware the Biggest Cause of Losses</strong></h2>
<p>Ransomware attacks targeting vendors made up 42% of the third-party claims, with losses from these incidents rising four-fold compared to 2023. The attack on <a href="https://www.infosecurity-magazine.com/news/ransomware-industries-downtime/" target="_blank">automotive software firm CDK</a>, which impacted thousands of car dealerships across the US and Canada, is an example of a ransomware attack on a vendor that financially impacts customers.</p>
<p>Vendor security failings, including the <a href="https://www.infosecurity-magazine.com/news/crowdstrike-fault-it-outages/" target="_blank">CrowdStrike global outage in July 2024</a>, made up 4% of all material claims. Not all the claims arising from this incident have been fully developed, Resilience noted.</p>
<p>The company said that this trend is driving insurance companies to adjust their underwriting practices regarding third-party risk.</p>
<p>Overall, <a href="https://www.infosecurity-magazine.com/news/ransomware-record-high-december/" target="_blank">ransomware</a> held its position as the top cause of material losses for businesses from 2023 to 2024. First-party ransomware incidents made up 44% of client &#x2018;s material claims, while ransomware targeting vendors contributed to 18% of such claims.</p>
<p>Altogether, 62% of claims with losses were related to ransomware.</p>
<p>Despite these figures, the researchers noted that there are indications that ransomware frequency may be declining in broader markets.</p>
<p>&#x201C;This is likely due to threat actors focusing on larger, high-profile organizations that yield bigger payouts, as opposed to the previous &#x201C;spray and prey&#x201D; approach,&#x201D; they said.</p>
</div>
<div id="layout-be50a645-80fe-46d0-9592-7841bafd836d" data-layout-id="2" data-edit-folder-name="text" data-index="2" readability="54">
<h2><strong>Phishing Claims Fall Significantly</strong></h2>
<p>Phishing-related cyber incidents made up 9% of incurred claims in 2024, representing a 55% fall compared to 2023.</p>
<p>The researchers believe this trend is a reflection of improvements in phishing defenses and the shift towards third-party attacks.</p>
<p>There was a marked increase in transfer fraud claims, making up 18% of claims in 2024 compared to 14% in 2023.</p>
<p>Transfer fraud is where a scammer tricks a person into transferring them money using psychological manipulation. Resilience said it has observed scammers&#x2019; use of AI to scale such social engineering campaigns, resulting in increased susceptibility and higher success rates.</p>
<p>&#x201C;As transfer fraud continues to grow, organizations must strengthen internal controls, educate employees on fraud prevention, and implement more robust verification processes for financial transactions,&#x201D; the firm commented.</p>
</div>
<p>The post <a href="https://onlinepitstop.com/2025/03/01/third-party-attacks-drive-major-financial-losses-in-2024/">Third-Party Attacks Drive Major Financial Losses in 2024</a> appeared first on <a href="https://onlinepitstop.com">Online Pitstop</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://onlinepitstop.com/2025/03/01/third-party-attacks-drive-major-financial-losses-in-2024/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>DragonForce Ransomware Hits Saudi Firm, 6TB Data Stolen</title>
		<link>https://onlinepitstop.com/2025/02/28/dragonforce-ransomware-hits-saudi-firm-6tb-data-stolen/</link>
					<comments>https://onlinepitstop.com/2025/02/28/dragonforce-ransomware-hits-saudi-firm-6tb-data-stolen/#respond</comments>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Fri, 28 Feb 2025 01:02:48 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://onlinepitstop.com/2025/02/28/dragonforce-ransomware-hits-saudi-firm-6tb-data-stolen/</guid>

					<description><![CDATA[<p>A new ransomware attack by DragonForce has targeted organizations in Saudi Arabia. The attack, which affected a prominent Riyadh-based real estate and construction firm, resulted in the exfiltration of over 6TB of sensitive data. According to a new advisory by Resecurity, threat actors first announced the breach on February 14, 2025, demanding ransom before publishing</p>
<p>The post <a href="https://onlinepitstop.com/2025/02/28/dragonforce-ransomware-hits-saudi-firm-6tb-data-stolen/">DragonForce Ransomware Hits Saudi Firm, 6TB Data Stolen</a> appeared first on <a href="https://onlinepitstop.com">Online Pitstop</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div></div>
<p>A new ransomware attack by<a href="https://www.infosecurity-magazine.com/news/dragonforce-ransomware-lockbit/" target="_blank"> DragonForce</a> has targeted organizations in Saudi Arabia.</p>
<p>The attack, which affected a prominent Riyadh-based real estate and construction firm, resulted in the exfiltration of over 6TB of sensitive data.</p>
<p>According to a new advisory by Resecurity, threat actors first announced the breach on February 14, 2025, demanding ransom before publishing the stolen information. The deadline was set for February 27, one day before the start of Ramadan.</p>
<h3><strong>Advanced Data Leak Strategies</strong></h3>
<p>Following the expiration of the ransom deadline, DragonForce published the stolen data through a dedicated leak site (DLS), separate from its primary platform.&#xA0;</p>
<p>The ransomware group, which operates on a Ransomware-as-a-Service (RaaS) model, continues to expand its affiliate network, providing tools and resources to cyber-criminals in exchange for a share of ransom payments. Notably, its DLS features advanced CAPTCHA mechanisms to prevent automated tracking by cybersecurity firms.</p>
<p>DragonForce has been active since December 2023, with its first known victim being the Heart of Texas Region MHMR Center. The group has since evolved, leveraging sophisticated encryption techniques, TOR-based communications and secure payment methods, including Bitcoin wallets and private chat systems.</p>
<p><em><a href="https://www.infosecurity-magazine.com/news/dragonforce-malaysia-windows-lpe/" target="_blank">Read more on this group: DragonForce Malaysia Group Releases Windows LPE Exploit and Turns to Ransomware Tactics</a></em></p>
<h3><strong>Ransom Payment Collection and Affiliate Network</strong></h3>
<p>The group recruits affiliates through the RAMP underground forum, offering one of the highest commission rates in the cybercrime market&#x2014;up to 80% of ransom proceeds.</p>
<p>Affiliates communicate via TOR-based instant messaging (TOX) and must prove their capability by demonstrating access to victim networks. To enhance security, DragonForce has tightened its vetting process after a previous leak exposed affiliate URLs.</p>
<p>Affiliates also receive support services, such as:</p>
<ul readability="0">
<li readability="-1">
<p>&#x2018;Call services&#x2019; for direct victim intimidation</p>
</li>
<li readability="-1">
<p>NTLM/Kerberos hash decryption to aid post-compromise operations</p>
</li>
<li readability="-1">
<p>A highly flexible ransomware builder allowing customization of encryption settings</p>
</li>
</ul>
<h3><strong>Tools, Tactics&#xA0;and Exploited Vulnerabilities</strong></h3>
<p>DragonForce employs phishing attacks and exploits vulnerabilities in Remote Desktop Protocol (RDP) and Virtual Private Network (VPN) services to gain initial access.</p>
<p>The group also employs dual extortion tactics, encrypting victim data while threatening to publish stolen information if ransom demands are unmet. Additionally, DragonForce has been known to release audio recordings of ransom negotiations, increasing pressure on victims to comply.</p>
<p>&#x201C;The combination of wealthy targets, cybersecurity gaps and geopolitical factors make the Middle East an attractive region for ransomware groups to exploit, making these attacks more profitable,&#x201D; Resecurity wrote.</p>
<p>&#x201C;The DragonForce ransomware targeting KSA and the associated data leak from the recent victim in KSA underscore the urgent need for enhanced cybersecurity measures to protect vital national assets and sensitive information.&#x201D;</p>
<p>The post <a href="https://onlinepitstop.com/2025/02/28/dragonforce-ransomware-hits-saudi-firm-6tb-data-stolen/">DragonForce Ransomware Hits Saudi Firm, 6TB Data Stolen</a> appeared first on <a href="https://onlinepitstop.com">Online Pitstop</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://onlinepitstop.com/2025/02/28/dragonforce-ransomware-hits-saudi-firm-6tb-data-stolen/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>99% of Organizations Report API-Related Security Issues</title>
		<link>https://onlinepitstop.com/2025/02/27/99-of-organizations-report-api-related-security-issues/</link>
					<comments>https://onlinepitstop.com/2025/02/27/99-of-organizations-report-api-related-security-issues/#respond</comments>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Thu, 27 Feb 2025 00:56:32 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://onlinepitstop.com/2025/02/27/99-of-organizations-report-api-related-security-issues/</guid>

					<description><![CDATA[<p>A growing reliance on APIs has fueled security concerns, with nearly all organizations (99%) reporting API-related security issues in the past year. According to the Q1 2025 State of API Security Report by Salt Security, the rapid expansion of API ecosystems&#x2014;driven by cloud migration, platform integration and data monetization&#x2014;is outpacing security measures and exposing organizations</p>
<p>The post <a href="https://onlinepitstop.com/2025/02/27/99-of-organizations-report-api-related-security-issues/">99% of Organizations Report API-Related Security Issues</a> appeared first on <a href="https://onlinepitstop.com">Online Pitstop</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div id="layout-cca3e6a0-9a43-4ee3-b42e-08b86fb1bce8" class="content-module " data-layout-id="2" data-edit-folder-name="text" data-index="0" readability="46">
<p>A growing reliance on APIs has fueled security concerns, with nearly all organizations (99%) reporting API-related security issues in the past year.</p>
<p>According to the <em>Q1 2025 State of API Security Report</em> by Salt Security, the rapid expansion of API ecosystems&#x2014;driven by cloud migration, platform integration and data monetization&#x2014;is outpacing security measures and exposing organizations to increased risk.</p>
<h3><strong>API Growth and Security Gaps</strong></h3>
<p>The report, published on Febrary 26, highlights significant API growth, with 30% of organizations experiencing a 51-100% increase in APIs over the past year and 25% reporting growth exceeding 100%.</p>
</div>
<figure id="layout-e560298d-e6eb-4e5a-9cdc-bb28f60424cd" class="content-module media" data-layout-id="4" data-edit-folder-name="image" data-index="1"><img decoding="async" src="https://assets.infosecurity-magazine.com/content/span/30aafe19-bb34-4a14-9239-ee6156196975.png" alt="API Growth Over the Past 12 Months. Credit: Salt Security."><figcaption class="media-caption">API Growth Over the Past 12 Months. Credit: Salt Security.</figcaption></figure>
<div id="layout-eb7b404b-79ff-447e-8322-345baf241472" class="content-module " data-layout-id="2" data-edit-folder-name="text" data-index="2" readability="48">
<p>This expansion has created challenges in maintaining accurate API inventories, as 58% of organizations monitor their APIs less than daily and lack confidence in inventory accuracy. Only 20% have achieved real-time monitoring, leaving most vulnerable to security threats.</p>
<p>Key API security challenges include:</p>
<ul readability="1">
<li readability="0">
<p>37% of security issues stem from vulnerabilities such as misconfigurations and broken object-level authorization</p>
</li>
<li readability="-1">
<p>34% involve sensitive data exposure</p>
</li>
<li readability="0">
<p>29% relate to authentication failures, highlighting weak access controls</p>
</li>
</ul>
<p>&#x201C;Organizations are facing the challenge of properly cataloging all their APIs so they can be placed into the proper security testing and awareness program,&#x201D; said Thomas Richards, principal consultant at Black Duck. &#x201C;The technology can improve workflows and benefit organizations, but we can&#x2019;t forget the basics of cybersecurity to document, test, and verify best practices in order to innovate securely and manage software risk.&#x201D;</p>
</div>
<figure id="layout-e785c23f-c1dc-43c1-8b25-8651bc9357a3" class="content-module media" data-layout-id="4" data-edit-folder-name="image" data-index="3"><img decoding="async" src="https://assets.infosecurity-magazine.com/content/span/c076efba-62e3-47c5-9431-8bd576f48c8b.png" alt="Security challenges in production APIs over the past year. Credit: Salt Security."><figcaption class="media-caption">Security challenges in production APIs over the past year. Credit: Salt Security.</figcaption></figure>
<div id="layout-fdee12ae-00a9-448b-925a-b9f8f6dcc67e" class="content-module " data-layout-id="2" data-edit-folder-name="text" data-index="4" readability="62.498023715415">
<p>Despite increasing investments, security gaps persist. Over half of organizations have boosted API security budgets, yet 30% cite limited funds as a key challenge.</p>
<p>Additionally, 22% struggle with personnel shortages and 10% lack proper security tools.</p>
<p>Many organizations (55%) have delayed application rollouts due to API security concerns, while 14% find their API programs difficult to manage.</p>
<p>&#x201C;Because API attacks most often result from unauthorized or inappropriate access credential use, modern security requires access control that goes well beyond traditional perimeter-based identity access and authentication strategies,&#x201D; explained Piyush Pandey, CEO at Pathlock. &#x201C;Dynamic, agile access controls that start with compliant provisioning, continue with high-risk access monitoring and finish with critical application infrastructure health maintenance [are essential].&#x201D;</p>
<p><em><a href="https://www.infosecurity-magazine.com/blogs/address-api-security/" target="_blank">Read more on API security trends and best practices: How to Address Shortcomings in API Security</a></em></p>
<h3><strong>Attack Trends and Emerging Risks</strong></h3>
<p>An analysis of API attack patterns reveals that 95% of attacks originate from authenticated users, underscoring the risk of compromised accounts. External-facing APIs remain a primary attack vector, with 98% of attack attempts targeting these interfaces. Among the most exploited vulnerabilities:</p>
<ul readability="0">
<li readability="-1">
<p>Security misconfigurations (54%)</p>
</li>
<li readability="-1">
<p>Broken object-level authorization (27%)</p>
</li>
<li readability="-1">
<p>API authentication failures (1%)</p>
</li>
</ul>
<p>Generative AI (GenAI) is also reshaping the security landscape,<a href="https://www.infosecurity-magazine.com/news/wiz-discovers-flaws-generative-ai/" target="_blank"> introducing new threats</a> and concerns. One-third of respondents report a lack of confidence in detecting AI-driven attacks, while 31% worry about the security of AI-generated code. Organizations are responding by implementing governance frameworks (26%) and AI-specific security tools (37%).</p>
</div>
<figure id="layout-efc41826-8ef8-4415-9c11-06aef3e6c109" class="content-module media" data-layout-id="4" data-edit-folder-name="image" data-index="5"><img decoding="async" src="https://assets.infosecurity-magazine.com/content/span/a9edef86-b464-4dff-bd76-6aca025e6a93.png" alt="Security problems found in production APIs over the past 12 months. Credit: Salt Security."><figcaption class="media-caption">Security problems found in production APIs over the past 12 months. Credit: Salt Security.</figcaption></figure>
<div id="layout-c7530f30-e20a-471e-84b5-44aa22379c8a" class="content-module " data-layout-id="2" data-edit-folder-name="text" data-index="6" readability="59">
<h3><strong>Strengthening API Security</strong></h3>
<p>The report urges organizations to adopt a proactive security strategy, emphasizing real-time monitoring, robust posture governance, and adherence to frameworks such as the OWASP API Security Top Ten. Stronger API inventory management and investment in AI-driven security tools are also critical to mitigating emerging risks.</p>
<p>&#x201C;The main driver of API adoption is the need for loose coupling between complex systems,&#x201D; explains Jason Soroko, senior fellow at Sectigo. &#x201C;APIs are abstraction layers that decouple underlying complexities, enabling rapid integration and development, which fuels digital transformation. [However], as organizations increasingly rely on APIs, the rapid expansion often outpaces security measures.&#x201D;</p>
<p>To stay ahead, Soroko recommends that &#x201C;cloud platforms and other purveyors of APIs need to offer security diagnostics to make it easier to rapidly deploy and maintain APIs with secure configurations.&#x201D;</p>
<p>With API usage continuing to surge, organizations must prioritize security strategies that evolve alongside their expanding ecosystems to safeguard sensitive data and infrastructure against emerging threats.</p>
</div>
<p>The post <a href="https://onlinepitstop.com/2025/02/27/99-of-organizations-report-api-related-security-issues/">99% of Organizations Report API-Related Security Issues</a> appeared first on <a href="https://onlinepitstop.com">Online Pitstop</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://onlinepitstop.com/2025/02/27/99-of-organizations-report-api-related-security-issues/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>61% of Hackers Use New Exploit Code Within 48 Hours of Attack</title>
		<link>https://onlinepitstop.com/2025/02/26/61-of-hackers-use-new-exploit-code-within-48-hours-of-attack/</link>
					<comments>https://onlinepitstop.com/2025/02/26/61-of-hackers-use-new-exploit-code-within-48-hours-of-attack/#respond</comments>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Wed, 26 Feb 2025 00:53:56 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://onlinepitstop.com/2025/02/26/61-of-hackers-use-new-exploit-code-within-48-hours-of-attack/</guid>

					<description><![CDATA[<p>In 2024, cyber-criminals have launched attacks within 48 hours of discovering a vulnerability, with 61% of hackers using new exploit code in this short timeframe. Companies faced an average of 68 days of critical cyber-attacks, while ransomware remained the most significant threat. The healthcare industry was particularly affected, with ransomware responsible for 95% of all</p>
<p>The post <a href="https://onlinepitstop.com/2025/02/26/61-of-hackers-use-new-exploit-code-within-48-hours-of-attack/">61% of Hackers Use New Exploit Code Within 48 Hours of Attack</a> appeared first on <a href="https://onlinepitstop.com">Online Pitstop</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div id="layout-4726b408-7b52-4be0-bbde-b241f7431313" class="content-module " data-layout-id="2" data-edit-folder-name="text" data-index="0" readability="46.272463768116">
<p>In 2024, cyber-criminals have launched attacks within 48 hours of discovering a vulnerability, with 61% of hackers using new exploit code in this short timeframe.</p>
<p>Companies faced an average of 68 days of critical cyber-attacks, while ransomware remained the most significant threat. The healthcare industry was<a href="https://www.infosecurity-magazine.com/opinions/disaster-cyberwarfare-threat/" target="_blank"> particularly affected</a>, with ransomware responsible for 95% of all breaches and impacting more than 198 million US patients.</p>
<p>These figures come from SonicWall&#x2019;s <a href="https://www.sonicwall.com/threat-report" target="_self"><em>Annual Cyber Threat Report</em></a>, which also suggested&#xA0;that attackers are leveraging AI-driven automation and advanced evasion techniques, making it increasingly difficult for SMBs to defend themselves.</p>
<p><em><a href="https://www.infosecurity-magazine.com/opinions/demystifying-cyber-resilience-best/" target="_blank">Read more on cybersecurity best practices: Demystifying Cyber Resilience: From Best Practice to Execution</a></em></p>
<h3><strong>Key Cyber Threat Trends</strong></h3>
<p>These were some of the key cyber threat identified by SonicWall in 2024:</p>
<ul readability="6">
<li readability="0">
<p>Ransomware Surge: North America saw an 8% rise, while Latin America experienced a 259% spike</p>
</li>
<li readability="0">
<p>IoT Attacks: Increased 124% year-over-year, with hackers targeting unprotected devices</p>
</li>
<li readability="1">
<p>Business Email Compromise (BEC): Accounted for 33% of reported cyber insurance events, up from 9% in 2023</p>
</li>
<li readability="2">
<p>Malware Variants: SonicWall identified 210,258 never-before-seen malware variants, averaging 637 new threats daily</p>
</li>
<li readability="0">
<p>Living Off the Land Binaries (LOLBins): Attackers increasingly use native system tools to evade detection</p>
</li>
</ul>
</div>
<figure id="layout-6daaaf24-cdbe-4255-89ea-a32388e882b3" class="content-module media" data-layout-id="4" data-edit-folder-name="image" data-index="1"><img decoding="async" src="https://assets.infosecurity-magazine.com/content/span/ca7cd3ae-02eb-44d6-85bc-e4b58c807f9c.png" alt="Top 10 LOLBins by percentage. Credit: SonicWall."><figcaption class="media-caption">Top 10 LOLBins by percentage. Credit: SonicWall.</figcaption></figure>
<div id="layout-f9c99ade-42a5-459a-b3f0-d59bc20c2905" class="content-module " data-layout-id="2" data-edit-folder-name="text" data-index="2" readability="45.92789968652">
<h3><strong>AI-enabled and File-based Attacks</strong></h3>
<p>According to the report, AI-driven tools are making cyber-attacks more accessible and complex. Server-side request forgery (SSRF) attacks rose by 452% as AI enhances obfuscation techniques and automates exploit chaining.</p>
<p>Business Email Compromise (BEC) attacks are also evolving, with generative AI enabling cybercriminals to<a href="https://www.infosecurity-magazine.com/news/bec-attacks-surge-20-annually-ai/" target="_blank"> craft highly convincing phishing emails.</a></p>
<p>File-based attacks, particularly involving malicious PDFs and HTML phishing files, also experienced a significant increase.</p>
<p>According to SonicWall data, 38% of detected malicious files were HTML-based, while PDFs followed closely at 22%.</p>
</div>
<figure id="layout-6ef30b38-e4f1-4aa2-bfdb-b9279b86db45" class="content-module media" data-layout-id="4" data-edit-folder-name="image" data-index="3"><img decoding="async" src="https://assets.infosecurity-magazine.com/content/span/ba920a22-15d9-4593-8025-4fe2c9081137.png" alt="Breakdown of everyday files used by threat actors. Credit: SonicWall."><figcaption class="media-caption">Breakdown of everyday files used by threat actors. Credit: SonicWall.</figcaption></figure>
<div id="layout-791b6c4e-5341-47c9-a455-5dc08b389e6a" class="content-module " data-layout-id="2" data-edit-folder-name="text" data-index="4" readability="39">
<h3><strong>Strengthening Cyber Defenses</strong></h3>
<p>To counter these threats, businesses must adopt a multi-layered cybersecurity strategy.</p>
<p>Key recommendations from SonicWall include:</p>
<ul readability="2.5">
<li readability="-1">
<p>Real-Time Patch Management: Apply security patches within 48 hours of disclosure</p>
</li>
<li readability="-1">
<p>Zero Trust Security Models: Restrict access and validate all network traffic</p>
</li>
<li readability="-1">
<p>24/7 Threat Monitoring: Partner with MSSPs for continuous security oversight</p>
</li>
<li readability="0">
<p>Enhanced Ransomware Defenses: Implement network segmentation and endpoint detection &amp; response (EDR)</p>
</li>
<li readability="-1">
<p>IoT Security: Secure connected devices by changing default credentials and updating firmware</p>
</li>
</ul>
<p>With cyber-criminals accelerating their tactics, SMBs must act promptly to strengthen their defenses and mitigate financial and reputational damage.</p>
</div>
<p>The post <a href="https://onlinepitstop.com/2025/02/26/61-of-hackers-use-new-exploit-code-within-48-hours-of-attack/">61% of Hackers Use New Exploit Code Within 48 Hours of Attack</a> appeared first on <a href="https://onlinepitstop.com">Online Pitstop</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://onlinepitstop.com/2025/02/26/61-of-hackers-use-new-exploit-code-within-48-hours-of-attack/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Essential Addons for Elementor XSS Vulnerability Discovered</title>
		<link>https://onlinepitstop.com/2025/02/25/essential-addons-for-elementor-xss-vulnerability-discovered/</link>
					<comments>https://onlinepitstop.com/2025/02/25/essential-addons-for-elementor-xss-vulnerability-discovered/#respond</comments>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Tue, 25 Feb 2025 00:53:20 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://onlinepitstop.com/2025/02/25/essential-addons-for-elementor-xss-vulnerability-discovered/</guid>

					<description><![CDATA[<p>A critical security vulnerability in Essential Addons for Elementor has been identified, potentially impacting over two&#xA0;million WordPress websites. The flaw, a reflected cross-site scripting (XSS) vulnerability, was discovered due to insufficient validation of the popup-selector query argument, allowing malicious scripts to be executed. The issue, tracked with CVE-2025-24752, was first uncovered by Patchstack Alliance researcher</p>
<p>The post <a href="https://onlinepitstop.com/2025/02/25/essential-addons-for-elementor-xss-vulnerability-discovered/">Essential Addons for Elementor XSS Vulnerability Discovered</a> appeared first on <a href="https://onlinepitstop.com">Online Pitstop</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div></div>
<p>A critical security vulnerability in Essential Addons for Elementor has been identified, potentially impacting over two&#xA0;million WordPress websites.</p>
<p>The flaw, a reflected cross-site scripting (XSS) vulnerability, was discovered due to insufficient validation of the popup-selector query argument, allowing malicious scripts to be executed.</p>
<p>The issue, tracked with CVE-2025-24752, was first uncovered by Patchstack Alliance researcher xssium on September 30, 2024. After notifying the plugin vendor, a fix was implemented in version 6.0.15.</p>
<h3><strong>Understanding the Vulnerability</strong></h3>
<p>Essential Addons for Elementor is the most popular extension for the Elementor page builder, counting over 2 million active installations.</p>
<p>It enhances Elementor&#x2019;s functionality by providing additional creative elements that help users design more dynamic and visually appealing web pages.</p>
<p>The flaw originated from the src/js/view/general.js file, where the plugin failed to properly sanitize the popup-selector argument.</p>
<p>When triggered, this could allow attackers to execute malicious scripts by embedding harmful content into the page.</p>
<p><em><a href="https://www.infosecurity-magazine.com/news/wordpress-ase-plugin-flaw/" target="_blank">Read more on WordPress plugin security: WordPress ASE Plugin Vulnerability Threatens Site Security</a></em></p>
<h3><strong>How the Patch Fixes the Issue</strong></h3>
<p>The WPDeveloper&#xA0;resolved the vulnerability by enforcing stricter validation, permitting only alphanumeric characters and a limited set of symbols in the popup-selector argument. This prevents common XSS attack methods from exploiting the flaw.</p>
<p>WordPress developers are reminded of the importance of properly validating and sanitizing user-provided data.</p>
<p>&#x201C;When working with user-provided data, developers need to ensure this data is properly validated and sanitized against potential processes that could lead to XSS,&#x201D; Patchstack warned.</p>
<p>&#x201C;Additionally, when rendering user-provided data back onto the website, it is important to make sure the content is properly escaped to help ensure potential XSS vulnerability.&#x201D;</p>
<p>Failure to do so can expose websites to significant security risks, including unauthorized access and data breaches.</p>
<p>The post <a href="https://onlinepitstop.com/2025/02/25/essential-addons-for-elementor-xss-vulnerability-discovered/">Essential Addons for Elementor XSS Vulnerability Discovered</a> appeared first on <a href="https://onlinepitstop.com">Online Pitstop</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://onlinepitstop.com/2025/02/25/essential-addons-for-elementor-xss-vulnerability-discovered/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>BlackBasta Ransomware Chatlogs Leaked Online</title>
		<link>https://onlinepitstop.com/2025/02/24/blackbasta-ransomware-chatlogs-leaked-online/</link>
					<comments>https://onlinepitstop.com/2025/02/24/blackbasta-ransomware-chatlogs-leaked-online/#respond</comments>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Mon, 24 Feb 2025 00:52:54 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://onlinepitstop.com/2025/02/24/blackbasta-ransomware-chatlogs-leaked-online/</guid>

					<description><![CDATA[<error>
    <code>internal_server_error</code>
    <title><![CDATA[WordPress &amp;rsaquo; Error]]></title>
    <message><![CDATA[&lt;p&gt;There has been a critical error on this website.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://wordpress.org/documentation/article/faq-troubleshooting/&quot;&gt;Learn more about troubleshooting WordPress.&lt;/a&gt;&lt;/p&gt;]]></message>
    <data>
        <status>500</status>
    </data>
</error>
