Source: securityaffairs.com – Author: Pierluigi Paganini The LockBit ransomware gang claims to have hacked Taiwan Semiconductor Manufacturing Company (TSMC). The LockBit ransomware group this week claimed...
Author:
Avast released a free decryptor for the Windows version of the Akira ransomware – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Avast released a free decryptor for the Akira ransomware that can allow victims to recover their data without paying the...
Iran-linked Charming Kitten APT enhanced its POWERSTAR Backdoor – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Iran-linked Charming Kitten group used an updated version of the PowerShell backdoor called POWERSTAR in a spear-phishing campaign. Security firm...
miniOrange’s WordPress Social Login and Register plugin was affected by a critical auth bypass bug – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini A critical authentication bypass flaw in miniOrange’s WordPress Social Login and Register plugin, can allow gaining access to any account on a...
North Korea-linked Andariel APT used a new malware named EarlyRat last year – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini North Korea-linked cyberespionage group Andariel used a previously undocumented malware called EarlyRat. Kaspersky researchers reported that the North Korea-linked APT group Andariel used a previously...
The phone monitoring app LetMeSpy disclosed a data breach – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Android app LetMeSpy disclosed a security breach, sensitive data associated with thousands of Android users were exposed. The phone monitoring app LetMeSpy...
Previously undetected ThirdEye malware appears in the threat landscape – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini A new Windows information stealer dubbed ThirdEye appeared in the threat landscape, it has been active since April. Fortinet FortiGuard Labs discovered...
Former Group-IB manager has been arrested in Kazahstan – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini The former head of network security at Group-IB has been arrested in Kazakhstan based on a request from U.S. law...
Experts published PoC exploits for Arcserve UDP authentication bypass issue – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Data protection firm Arcserve addressed an authentication bypass vulnerability in its Unified Data Protection (UDP) backup software. Data protection vendor...
Using Electromagnetic Fault Injection Attacks to take over drones – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Electromagnetic fault injection (EMFI) attacks on drones can potentially allow attackers to achieve arbitrary code execution and take over them....
Experts warn of a spike in May and June of 8Base ransomware attacks – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Researchers warn of a massive spike in May and June 2023 of the activity associated with the ransomware group named 8Base....
Critical SQL Injection flaws in Gentoo Soko can lead to Remote Code Execution – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini SQL injection vulnerabilities in Gentoo Soko could lead to remote code execution (RCE) on impacted systems. SonarSource researchers discovered two...
EncroChat dismantling led to 6,558 arrests and the seizure of $979M in criminal funds – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Europol announced that the takedown of the EncroChat encrypted chat network has led to the arrest of 6,558 people and...
Mockingjay process injection technique allows EDR bypass – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Mockingjay is a new process injection technique that can be exploited to bypass security solutions to execute malware on compromised...
Experts found hundreds of devices within federal networks having internet-exposed management interfaces – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Researchers at Censys have identified hundreds of devices deployed within federal networks that have internet-exposed management interfaces. Researchers at Censys...
Schneider Electric and Siemens Energy are two more victims of a MOVEit attack – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Clop ransomware group added five new victims of MOVEit attacks to its dark web leak site, including Schneider Electric and...
JOKERSPY used to target a cryptocurrency exchange in Japan – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini An unnamed Japanese cryptocurrency exchange was the victim of a cyber attack aimed at deploying an Apple macOS backdoor named...
Citizen of Croatia charged with running the Monopoly Market drug marketplace – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Milomir Desnica, a citizen of Croatia and Serbia, has been charged with running the Monopoly Market drug darknet marketplace. Milomir...
Energy company Suncor suffered a cyber attack and its company Petro-Canada gas reported problems at its gas stations in Canada – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini The cyber attack suffered by Suncor Energy impacted payment operations at Petro-Canada gas stations in Canada. Suncor Energy is Canada’s...
Internet Systems Consortium (ISC) fixed three DoS flaw in BIND – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini The Internet Systems Consortium (ISC) addressed three denial-of-service (DoS) vulnerabilities in the DNS software suite BIND. The Internet Systems Consortium...
China-linked APT group VANGUARD PANDA uses a new tradecraft in recent attacks – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini China-linked APT group VANGUARD PANDA, aka Volt Typhoon, was spotted observing a novel tradecraft to gain initial access to target...
Trojanized Super Mario Bros game spreads malware – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Researchers observed threat actors spreading a trojanized Super Mario Bros game installer to deliver multiple malware. Researchers from Cyble Research...
Twitter hacker sentenced to five years in prison for cybercrime offenses – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini A U.K. citizen, who was involved in the attack on Twitter in 2020, was sentenced to five years in prison...
Security Affairs newsletter Round 425 by Pierluigi Paganini – International edition – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Privacy Overview This website uses cookies to improve your experience while you navigate through the website. Out of these cookies,...
Someone is sending mysterious smartwatches to the US Military personnel – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini U.S. Army’s Criminal Investigation Division warns that US military personnel have reported receiving unsolicited smartwatches in the mail. The U.S. Army’s...
CISA orders govt agencies to fix recently disclosed flaws in Apple devices – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini U.S. Cybersecurity and Infrastructure Security Agency (CISA) added six new vulnerabilities to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity...
VMware fixed five memory corruption issues in vCenter Server – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini VMware addressed multiple memory corruption vulnerabilities in vCenter Server that can be exploited to achieve remote code execution. VMware released...
Fortinet fixes critical FortiNAC RCE, install updates asap – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Fortinet addressed a critical remote command execution vulnerability, tracked as CVE-2023-33299, affecting FortiNAC solution. FortiNAC is a network access control...
More than a million GitHub repositories potentially vulnerable to RepoJacking – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Researchers reported that millions of GitHub repositories are likely vulnerable to an attack called RepoJacking. A study conducted by Aqua...
New Mirai botnet targets tens of flaws in popular IoT devices – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Since March 2023, Unit 42 researchers have observed a variant of the Mirai botnet spreading by targeting tens of flaws...





























