Source: www.bleepingcomputer.com – Author: Bill Toulas The WooCommerce Stripe Gateway plugin for WordPress was found to be vulnerable to a bug that allows any unauthenticated user...
Month: June 2023
Bulletproof hoster gets 3 years for pushing Urfsnif, Zeus malware – Source: www.bleepingcomputer.com
Source: www.bleepingcomputer.com – Author: Bill Toulas Romanian national Mihai Ionut Paunescu, aka “Virus,” was sentenced to three years in prison by a Manhattan federal court for...
Microsoft Patch Tuesday for June 2023 fixes 6 critical flaws – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Microsoft Patch Tuesday security updates for June 2023 fixed 69 flaws in its products, including six critical issues. Microsoft Patch...
St. Margaret’s Health is the first hospital to cite a cyberattack as a reason for its closure – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini St. Margaret’s Health in Illinois is partly closing operations at its hospitals due to a 2021 ransomware attack that impacted...
A database containing data of +8.9 million Zacks users was leaked online – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini A database containing the personal information of more than 8.9 million Zacks Investment Research users was leaked on a cybercrime...
Fortinet urges to patch the critical RCE flaw CVE-2023-27997 in Fortigate firewalls – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Fortinet addressed a new critical flaw, tracked as CVE-2023-27997, in FortiOS and FortiProxy that is likely exploited in a limited number of...
UK communications regulator Ofcom hacked with a MOVEit file transfer zero-day – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini UK communications regulator Ofcom suffered a data breach after a Clop ransomware attack exploiting the MOVEit file transfer zero-day. UK’s...
Experts released PoC exploit for MOVEit Transfer CVE-2023-34362 flaw – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Security firm Horizon3 released proof-of-concept (PoC) exploit code for the remote code execution (RCE) flaw CVE-2023-34362 in the MOVEit Transfer...
BrandPost: Your attack surfaces are expanding. These are the three you must defend – Source: www.csoonline.com
Source: www.csoonline.com – Author: About | When you have comprehensive security, the future is yours to build. Learn about the strategies and solutions to secure your...
MOVEit Transfer developer patches more critical flaws after security audit – Source: www.csoonline.com
Source: www.csoonline.com – Author: A third-party audit reveals new MOVEit vulnerabilities, for which Progress Software has issued patches. The developer of the recently exploited MOVEit Transfer...
Okta aims to unify IAM for Windows, macOS devices in hybrid work environments – Source: www.csoonline.com
Source: www.csoonline.com – Author: Okta Device Access aims to simpllfy and unify identity and access management (IAM) for corporate devices within hybrid workforces with customizable multifactor...
AI and tech innovation, economic pressures increase identity attack surface – Source: www.csoonline.com
Source: www.csoonline.com – Author: Identity-centric security cracks are beginning to show in organizations as investment in digital and cloud technology outpaces cybersecurity spend. shutterstock Tension between...
Artificial intelligence is coming to Windows: Are your security policy settings ready? – Source: www.csoonline.com
Source: www.csoonline.com – Author: AI seems to be getting embedded in everything these days, and it’s coming to Microsoft Windows. It’s time now to ensure your...
Beware: New DoubleFinger Loader Targets Cryptocurrency Wallets with Stealer – Source:thehackernews.com
Source: thehackernews.com – Author: . Jun 13, 2023Ravie LakshmananCrimeware / Cryptocurrency A novel multi-stage loader called DoubleFinger has been observed delivering a cryptocurrency stealer dubbed GreetingGhoul...
Over Half of Security Leaders Lack Confidence in Protecting App Secrets, Study Reveals – Source:thehackernews.com
Source: thehackernews.com – Author: . It might come as a surprise, but secrets management has become the elephant in the AppSec room. While security vulnerabilities like...
Adversary-in-the-Middle Attack Campaign Hits Dozens of Global Organizations – Source:thehackernews.com
Source: thehackernews.com – Author: . Jun 13, 2023Ravie LakshmananPhishing Attacks / BEC “Dozens” of organizations across the world have been targeted as part of a broad...
As MOVEit hackers’ deadline approaches, Ofcom reveals it is amongst victims – Source: www.bitdefender.com
Source: www.bitdefender.com – Author: Graham Cluley Just a moment… Enable JavaScript and cookies to continue Original Post URL: https://www.bitdefender.com/blog/hotforsecurity/as-moveit-hackers-deadline-approaches-ofcom-reveals-it-is-amongst-victims/ Category & Tags: Data loss,Guest blog,Ransomware,Vulnerability,Cl0p,data breach,extortion,MOVEit,Ofcom,vulnerability...
US charges two men with Mt. Gox heist, the world’s largest cryptocurrency hack – Source: www.tripwire.com
Source: www.tripwire.com – Author: Graham Cluley More than ten years after the hack of the now-defunct Mt. Gox cryptocurrency exchange, the US Department of Justice says...
Surprise! Staff don’t like receiving phishing tests from their firms that pose as salary increases – Source: grahamcluley.com
Source: grahamcluley.com – Author: Graham Cluley UK law firm Knights certainly has an interesting way of keeping its staff happy. After disappointing its staff in a...
Microsoft Patches Critical Windows Vulns, Warn of Code Execution Risks – Source: www.securityweek.com
Source: www.securityweek.com – Author: Ryan Naraine Microsoft’s security response team on Tuesday rolled out a massive batch of software updates to address major security gaps in...
Chinese Cyberspies Caught Exploiting VMware ESXi Zero-Day – Source: www.securityweek.com
Source: www.securityweek.com – Author: Ionut Arghire A Chinese cyberespionage group tracked as UNC3886 has been observed exploiting a VMware ESXi zero-day vulnerability to escalate privileges on...
Patch Tuesday: Critical Flaws in Adobe Commerce Software – Source: www.securityweek.com
Source: www.securityweek.com – Author: Ryan Naraine Silicon Valley software giant Adobe on Tuesday shipped patches for critical flaws in multiple products, including a dozen issues that...
CosmicEnergy ICS Malware Poses No Immediate Threat, but Should Not Be Ignored – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs The recently discovered CosmicEnergy malware, which is designed to target industrial control systems (ICS), does not pose an immediate threat...
Virtual Event Today: CISO Forum 2023 – Register to Join – Source: www.securityweek.com
Source: www.securityweek.com – Author: Mike Lennon SecurityWeek’s 2023 CISO Forum Virtual Summit is taking place June 13-14 as a fully immersive online experience. Designed for senior...
Romanian Operator of Bulletproof Hosting Service Sentenced to Prison in US – Source: www.securityweek.com
Source: www.securityweek.com – Author: Ionut Arghire A Romanian national who operated a bulletproof hosting service used by trojans such as Gozi, Zeus, and SpyEye was sentenced...
New Research Shows Potential of Electromagnetic Fault Injection Attacks Against Drones – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs New research shows the potential of electromagnetic fault injection (EMFI) attacks against unmanned aerial vehicles, with experts showing how drones...
Ransomware Attack Played Major Role in Shutdown of Illinois Hospital – Source: www.securityweek.com
Source: www.securityweek.com – Author: Ionut Arghire St. Margaret’s Health is shutting down hospitals and other facilities in Peru and Spring Valley, Illinois, and says a 2021...
Data of 8.8 Million Zacks Users Emerges Online – Source: www.securityweek.com
Source: www.securityweek.com – Author: Ionut Arghire A database containing the personal information of more than 8.8 million Zacks Investment Research users has emerged on a hacking...
Fortinet Warns Customers of Possible Zero-Day Exploited in Limited Attacks – Source: www.securityweek.com
Source: www.securityweek.com – Author: Eduard Kovacs Fortinet warned customers on Monday that the recently patched vulnerability tracked as CVE-2023-27997 could be a zero-day flaw that has...
Google Recruits Allies to Apply Generative AI to Cybersecurity – Source: securityboulevard.com
Source: securityboulevard.com – Author: Michael Vizard At the Google Cloud Security Summit, Google today announced that Broadcom, Crowdstrike, Egnyte, Exabeam, F5, Fortinet, Netskope, Securiti, SentinelOne, Sysdig,...




























