Source: securityaffairs.com – Author: Pierluigi Paganini Privacy Overview This website uses cookies to improve your experience while you navigate through the website. Out of these cookies,...
Author:
Shadowserver reported that +15K Citrix servers are likely vulnerable to attacks exploiting the flaw CVE-2023-3519 – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Researchers reported that more than 15000 Citrix servers exposed online are likely vulnerable to attacks exploiting the vulnerability CVE-2023-3519. The...
Multiple DDoS botnets were observed targeting Zyxel devices – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Researchers warn of several DDoS botnets exploiting a critical flaw tracked as CVE-2023-28771 in Zyxel devices. Fortinet FortiGuard Labs researchers...
CISA warns of attacks against Citrix NetScaler ADC and Gateway Devices – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini The US CISA warns of cyber attacks targeting Citrix NetScaler Application Delivery Controller (ADC) and Gateway devices. The U.S. Cybersecurity...
Experts believe North Korea behind JumpCloud supply chain attack – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini SentinelOne researchers attribute the recent supply chain attacks on JumpCloud to North Korea-linked threat actors. JumpCloud is a cloud-based directory...
Nice Suzuki, sport: shame dealer left your data up for grabs – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Cybernews research team discovered that two Suzuki-authorized dealer websites were leaking customers’ sensitive information. Suzuki or otherwise, buying a new...
Experts attribute WyrmSpy and DragonEgg spyware to the Chinese APT41 group – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini China-linked group APT41 was spotted using two previously undocumented Android spyware called WyrmSpy and DragonEgg China-linked APT group APT41 has...
ALPHV/BlackCat and Clop gangs claim to have hacked cosmetics giant Estée Lauder – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini The American cosmetics giant company Estée Lauder was hacked by two distinct ransomware groups, the ALPHV/BlackCat and Clop gangs. Yesterday...
P2PInfect, a Rusty P2P worm targets Redis Servers on Linux and Windows systems – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Cybersecurity researchers discovered a new peer-to-peer (P2P) worm called P2PInfect that targets Redis servers. Palo Alto Networks Unit 42 researchers have discovered...
Adobe out-of-band update addresses an actively exploited ColdFusion zero-day – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Adobe released an emergency update to address critical vulnerabilities in ColdFusion, including an actively exploited zero-day. Adobe released an out-of-band...
Ukraine’s cyber police dismantled a massive bot farm spreading propaganda – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini The Cyber Police Department of the National Police of Ukraine dismantled a massive bot farm and seized 150,000 SIM cards....
US Gov adds surveillance firms Cytrox and Intellexa to Entity List for trafficking in cyber exploits – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini The U.S. government added surveillance technology vendors Cytrox and Intellexa to an economic blocklist for trafficking in cyber exploits. The...
Citrix warns of actively exploited zero-day in ADC and Gateway – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Citrix is warning customers of an actively exploited critical vulnerability in NetScaler Application Delivery Controller (ADC) and Gateway. Citrix is...
FIA World Endurance Championship driver passports leaked – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Le Mans Endurance Management, operating the FIA World Endurance Championship’s website, exposed the data of hundreds of drivers by leaking...
Virustotal data leak exposed data of some registered customers, including intelligence members – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini The online malware scanning service VirusTotal leaked data associated with some registered customers, German newspapers reported. German newspapers Der Spiegel and Der...
FIN8 Group spotted delivering the BlackCat Ransomware – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini The cybercrime group FIN8 is using a revamped version of the Sardonic backdoor to deliver the BlackCat ransomware. The financially motivated group...
Hacking campaign targets sites using WordPress WooCommerce Payments Plugin – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Threat actors are actively exploiting a critical flaw, tracked as CVE-2023-28121, in the WooCommerce Payments WordPress plugin. Threat actors are actively...
JumpCloud revealed it was hit by a sophisticated attack by a nation-state actor – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Software firm JumpCloud announced it was the victim of a sophisticated cyber attack carried out by a nation-state actor. JumpCloud...
Adobe warns customers of a critical ColdFusion RCE exploited in attacks – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Adobe is warning customers of a critical ColdFusion pre-authentication RCE bug, tracked as CVE-2023-29300, which is actively exploited. Adobe warns...
Admins of Genesis Market marketplace sold their infrastructure on a hacker forum – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini The admins of the darkweb Genesis Market announced the sale of their platform to a threat actor that will restart...
Cisco fixed a critical flaw in SD-WAN vManage – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Cisco warns of a critical unauthenticated REST API access vulnerability, tracked as CVE-2023-20214, impacting its SD-WAN vManage. Cisco addressed a...
Pompompurin, the BreachForums owner, pleads guilty to hacking charges and possession of child pornography – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini The owner of the BreachForums Conor Brian Fitzpatrick, aka Pompompurin, pleads guilty to hacking charges. The owner of the BreachForums...
WormGPT, the generative AI tool to launch sophisticated BEC attacks – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini The WormGPT case: How Generative artificial intelligence (AI) can improve the capabilities of cybercriminals and allows them to launch sophisticated...
Security Affairs newsletter Round 428 by Pierluigi Paganini – International edition – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Privacy Overview This website uses cookies to improve your experience while you navigate through the website. Out of these cookies,...
HCA Healthcare data breach impacted 11 million patients – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini HCA Healthcare disclosed a data breach that exposed the personal information of roughly 11 million patients. HCA Healthcare this week...
Apple issued Rapid Security Response updates to fix a zero-day but pulled them due to a Safari bug – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Apple released Rapid Security Response updates for iOS, iPadOS, macOS, and Safari web browser to address an actively exploited zero-day. Apple has released Rapid Security...
VMware warns customers of exploit available for critical vRealize RCE flaw CVE-2023-20864 – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini VMware warns customers of the public availability of an exploit code for the RCE vulnerability CVE-2023-20864 affecting vRealize. VMware warned...
Cybercriminals Evolve Antidetect Tooling for Mobile OS-Based Fraud – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Resecurity identified the emergence of adversarial mobile Android-based Antidetect Tooling for Mobile OS-Based Fraud. Resecurity has identified the emergence of...
Experts released PoC exploit for Ubiquiti EdgeRouter flaw – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini A Proof-of-Concept (PoC) exploit for the CVE-2023-31998 vulnerability in the Ubiquiti EdgeRouter has been publicly released. The CVE-2023-31998 flaw (CVSS...
RomCom RAT attackers target groups supporting NATO membership of Ukraine – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Threat actors are targeting NATO and groups supporting Ukraine in a spear-phishing campaign distributing the RomCom RAT. On July 4, the...





























