Source: www.securityweek.com – Author: Ionut Arghire Fintech firm EquiLend is investigating a cyberattack (possibly a ransomware attack) that knocked some of its systems offline. The post...
Author:
Cisco Patches Critical Vulnerability in Enterprise Collaboration Products – Source: www.securityweek.com
Source: www.securityweek.com – Author: Ionut Arghire A critical flaw in Cisco Unified Communications and Contact Center Solutions products could lead to remote code execution. The post...
Thousands of GitLab Instances Unpatched Against Critical Password Reset Bug – Source: www.securityweek.com
Source: www.securityweek.com – Author: Ionut Arghire Over 5,000 GitLab servers have yet to be patched against CVE-2023-7028, a critical password reset vulnerability. The post Thousands of...
Firefox 122 Patches 15 Vulnerabilities – Source: www.securityweek.com
Source: www.securityweek.com – Author: Ionut Arghire Updates released for Firefox and Thunderbird resolve 15 vulnerabilities, including five high-severity bugs. The post Firefox 122 Patches 15 Vulnerabilities...
Orca Flags Dangerous Google Kubernetes Engine Misconfiguration – Source: www.securityweek.com
Source: www.securityweek.com – Author: Ionut Arghire Attackers could take over a Kubernetes cluster if access privileges are granted to all authenticated users in Google Kubernetes Engine....
PoC Code Published for Just-Disclosed Fortra GoAnywhere Vulnerability – Source: www.securityweek.com
Source: www.securityweek.com – Author: Ionut Arghire PoC code exploiting a critical Fortra GoAnywhere MFT vulnerability gets published one day after public disclosure. The post PoC Code...
340,000 Jason’s Deli Customers Potentially Impacted by Credential Stuffing Attack – Source: www.securityweek.com
Source: www.securityweek.com – Author: Ionut Arghire Jason’s Deli says hackers targeted users in credential stuffing attacks, likely compromising their personal information. The post 340,000 Jason’s Deli...
Chrome 121 Patches 17 Vulnerabilities – Source: www.securityweek.com
Source: www.securityweek.com – Author: Ionut Arghire Google releases Chrome 121 to the stable channel with 17 security fixes, including 11 reported by external researchers. The post...
Vulnerabilities in Lamassu Bitcoin ATMs Can Allow Hackers to Drain Wallets – Source: www.securityweek.com
Source: www.securityweek.com – Author: Ionut Arghire Hackers could exploit Lamassu Douro ATM vulnerabilities to take over devices, steal bitcoin from users. The post Vulnerabilities in Lamassu...
AI Testing Startup RagaAI Emerges From Stealth With $4.7M in Seed Funding – Source: www.securityweek.com
Source: www.securityweek.com – Author: Ionut Arghire AI testing platform RagaAI raises $4.7 million in seed funding to help identify AI issues and improve security and reliability....
High-Severity Vulnerability Patched in Splunk Enterprise – Source: www.securityweek.com
Source: www.securityweek.com – Author: Ionut Arghire The latest Splunk Enterprise releases patch multiple vulnerabilities, including a high-severity flaw in the Windows version. The post High-Severity Vulnerability...
Aviation Leasing Giant AerCap Hit by Ransomware Attack – Source: www.securityweek.com
Source: www.securityweek.com – Author: Ionut Arghire AerCap, the largest aviation leasing company in the world, was hit by a ransomware attack on January 17th. The post...
SEC Says X Account Hacked via SIM Swapping – Source: www.securityweek.com
Source: www.securityweek.com – Author: Ionut Arghire SEC says hackers used SIM swapping to take over its X (formerly Twitter) account on January 9. The post SEC...
Owner of Cybercrime Website BreachForums Sentenced to Supervised Release – Source: www.securityweek.com
Source: www.securityweek.com – Author: Ionut Arghire Conor Brian Fitzpatrick, the owner of the cybercrime website BreachForums, was sentenced to time served and supervised release. The post...
Chinese Spies Exploited VMware vCenter Server Vulnerability Since 2021 – Source: www.securityweek.com
Source: www.securityweek.com – Author: Ionut Arghire CVE-2023-34048, a vCenter Server vulnerability patched in October 2023, had been exploited as zero-day for a year and a half....
Critical Vulnerabilities Found in Open Source AI/ML Platforms – Source: www.securityweek.com
Source: www.securityweek.com – Author: Ionut Arghire Security researchers flag multiple severe vulnerabilities in open source AI/ML solutions MLflow, ClearML, Hugging Face. The post Critical Vulnerabilities Found...
VF Corp Says Data Breach Resulting From Ransomware Attack Impacts 35 Million – Source: www.securityweek.com
Source: www.securityweek.com – Author: Ionut Arghire Apparel and footwear brands owner VF Corp shares more details on the impact of a December 2023 ransomware attack. The...
US Gov Publishes Cybersecurity Guidance for Water and Wastewater Utilities – Source: www.securityweek.com
Source: www.securityweek.com – Author: Ionut Arghire CISA, FBI and EPA document aims to help water and wastewater organizations improve their cyber resilience and incident response. The...
Software Supply Chain Security Startup Kusari Raises $8 Million – Source: www.securityweek.com
Source: www.securityweek.com – Author: Ionut Arghire Kusari has raised $8 million to help organizations gain visibility into and secure their software supply chain. The post Software...
Energy Department to Invest $30 Million in Clean Energy Cybersecurity Solutions – Source: www.securityweek.com
Source: www.securityweek.com – Author: Ionut Arghire Organizations can earn up to $3 million in federal funding for cyber tools securing the clean energy infrastructure. The post...
List Containing Millions of Credentials Distributed on Hacking Forum, but Passwords Old – Source: www.securityweek.com
Source: www.securityweek.com – Author: Ionut Arghire Naz.API credential stuffing list containing 70 million unique email addresses and old passwords found on hacking forum. The post List...
Customer Information of Toyota Insurance Company Exposed Due to Misconfigurations – Source: www.securityweek.com
Source: www.securityweek.com – Author: Ionut Arghire Exposed credentials for an email address at an Indian Toyota insurance broker led to customer information compromise. The post Customer...
Atlassian Warns of Critical RCE Vulnerability in Outdated Confluence Instances – Source: www.securityweek.com
Source: www.securityweek.com – Author: Ionut Arghire Out-of-date Confluence Data Center and Server instances are haunted by a critical vulnerability leading to remote code execution. The post...
GitHub Rotates Credentials in Response to Vulnerability – Source: www.securityweek.com
Source: www.securityweek.com – Author: Ionut Arghire GitHub rotates credentials and releases patches after being alerted of a vulnerability affecting GitHub.com and GitHub Enterprise Server. The post...
Oracle Patches 200 Vulnerabilities With January 2024 CPU – Source: www.securityweek.com
Source: www.securityweek.com – Author: Ionut Arghire Oracle releases 389 new security patches to address 200 vulnerabilities as part of the first Critical Patch Update of 2024....
Vulnerabilities Expose PAX Payment Terminals to Hacking – Source: www.securityweek.com
Source: www.securityweek.com – Author: Ionut Arghire Vulnerabilities in Android-based PoS terminals from PAX can be exploited to downgrade bootloaders, execute arbitrary code. The post Vulnerabilities Expose...
Remote Code Execution Vulnerability Found in Opera File Sharing Feature – Source: www.securityweek.com
Source: www.securityweek.com – Author: Ionut Arghire A vulnerability in Opera browser’s file sharing feature My Flow could be exploited for remote code execution. The post Remote...
180k Internet-Exposed SonicWall Firewalls Vulnerable to DoS Attacks, Possibly RCE – Source: www.securityweek.com
Source: www.securityweek.com – Author: Ionut Arghire Two DoS vulnerabilities patched in 2022 and 2023 haunt nearly 180,000 internet-exposed SonicWall firewalls. The post 180k Internet-Exposed SonicWall Firewalls...
Hacker Behind $2 Million Cryptocurrency Mining Scheme Arrested in Ukraine – Source: www.securityweek.com
Source: www.securityweek.com – Author: Ionut Arghire Ukrainian authorities have arrested an individual allegedly involved in a $2 million cryptojacking operation. The post Hacker Behind $2 Million...
Information Stealer Exploits Windows SmartScreen Bypass – Source: www.securityweek.com
Source: www.securityweek.com – Author: Ionut Arghire Attackers exploit a recent Windows SmartScreen bypass vulnerability to deploy the Phemedrone information stealer. The post Information Stealer Exploits Windows...