Source: securityaffairs.com – Author: Pierluigi Paganini The proof-of-concept (PoC) exploit code for high-severity vulnerability (CVE-2023-20178) in Cisco AnyConnect Secure was published online. A security researcher has...
Author:
Norton parent firm Gen Digital, was victim of a MOVEit ransomware attack too – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Norton parent firm, Gen Digital, was the victim of a ransomware attack that exploited the recently disclosed MOVEit zero-day vulnerability....
Apple addressed actively exploited zero-day flaws in iOS, macOS, and Safari – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Apple rolled out security updates to address actively exploited zero-day flaws in iOS, iPadOS, macOS, watchOS, and Safari. Apple addressed...
Analyzing the TriangleDB implant used in Operation Triangulation – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Kaspersky provided more details about Operation Triangulation, including the exploitation chain and the implant used by the threat actors. Kaspersky...
Russia-linked APT28 hacked Roundcube email servers of Ukrainian entities – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Russia-linked APT28 group hacked into Roundcube email servers belonging to multiple Ukrainian organizations. A joint investigation conducted by Ukraine’s Computer...
New Condi DDoS botnet targets TP-Link Wi-Fi routers – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Researchers discovered a new strain of malware called Condi that targets TP-Link Archer AX21 (AX1800) Wi-Fi routers. Fortinet FortiGuard Labs Researchers discovered a...
Critical RCE flaw CVE-2023-20887 in VMware vRealize exploited in the wild – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini VMware is warning customers that critical remote code execution vulnerability CVE-2023-20887 is being actively exploited in attacks. VMware is warning...
3CX data exposed, third-party to blame – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini A third-party vendor of 3CX, a popular Voice over Internet Protocol (VoIP) comms provider, left an open server and exposed...
New Tsunami botnet targets Linux SSH servers – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Researchers warn of an ongoing Tsunami DDoS botnet campaign targeting inadequately protected Linux SSH servers. Researchers from AhnLab Security Emergency...
Zyxel addressed critical flaw CVE-2023-27992 in NAS Devices – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Zyxel released security updates to address a critical vulnerability affecting its network-attached storage (NAS) devices. Zyxel released security updates to...
Tackling Data Sovereignty with DDR – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Data-centric distributed resilience (DDR) offers a compelling approach to addressing data sovereignty in cybersecurity. As much of our modern life...
ASUS addressed critical flaws in some router models – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini ASUS addressed critical vulnerabilities in multiple router models, urging customers to immediately install firmware updates. ASUS is warning customers to...
Experts found components of a complex toolkit employed in macOS attacks – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Researchers uncovered a set of malicious files with backdoor capabilities that they believe is part of a toolkit targeting Apple...
EU member states are urged to restrict without delay 5G equipment from risky suppliers – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini The European Commission urges member states to limit “without delay” equipment from Chinese suppliers from their 5G networks, specifically Huawei...
Diicot cybercrime gang expands its attack capabilities – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Researchers found evidence that Diicot threat actors are expanding their capabilities with new payloads and the Cayosin Botnet. Cado researchers...
Microsoft: June Outlook and cloud platform outages were caused by DDoS – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Microsoft confirmed that the recent outages to the Azure, Outlook, and OneDrive services were caused by cyber attacks. In early...
Reddit Files: BlackCat/ALPHV ransomware gang claims to have stolen 80GB of data from Reddit – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini The BlackCat/ALPHV ransomware gang claims to have stolen 80GB of data from the Reddit in February cyberattack. In February, the...
US govt offers $10 million bounty for info linking Clop ransomware gang to a foreign government. – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini The U.S. government announced up to a $10 million bounty for information linking the Clop ransomware gang to a foreign...
Security Affairs newsletter Round 424 by Pierluigi Paganini – International edition – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Privacy Overview This website uses cookies to improve your experience while you navigate through the website. Out of these cookies,...
Law enforcement shutdown a long-standing DDoS-for-hire service – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Polish police, as part of the international law enforcement operation PowerOFF, dismantled a DDoS-for-hire service that has been active since...
A Russian national charged for committing LockBit Ransomware attacks – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini DoJ charged a Russian national with conspiring to carry out LockBit ransomware attacks against U.S. and foreign businesses. The Justice...
Oil and gas giant Shell is another victim of Clop ransomware attacks – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini British multinational oil and gas company Shell has confirmed that it has suffered a ransomware attack conducted by the Clop group. Oil and Gas giant...
Progress fixed a third flaw in MOVEit Transfer software – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Progress Software addressed a third vulnerability impacting its MOVEit Transfer application that could lead to privilege escalation and information disclosure....
Updated Android spyware GravityRAT steals WhatsApp Backups – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini An updated version of the Android remote access trojan GravityRAT can steal WhatsApp backup files and can delete files ESET researchers...
Barracuda ESG zero-day exploited by China-linked APT – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Experts linked the UNC4841 threat actor behind the attacks exploiting the recently patched Barracuda ESG zero-day to China. Mandiant researchers...
Russia-linked APT Gamaredon update TTPs in recent attacks against Ukraine – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Russia-linked APT group Gamaredon is using a new toolset in attacks aimed at critical organizations in Ukraine. The Gamaredon APT...
Cybersecurity agencies published a joint LockBit ransomware advisory – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini The LockBit ransomware group successfully extorted roughly $91 million from approximately 1,700 U.S. organizations since 2020. According to a joint...
Microsoft links Cadet Blizzard APT to Russia’s military intelligence GRU – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Microsoft linked a series of wiping attacks to a Russia-linked APT group, tracked as Cadet Blizzard, that is under the control...
Critical flaw found in WooCommerce Stripe Gateway Plugin used by +900K sites – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Hundreds of thousands of online stores are potentially exposed to hacking due to a critical vulnerability in the WooCommerce Stripe...
Unveiling the Balada injector: a malware epidemic in WordPress – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Learn the shocking truth behind the Balada Injector campaign and find out how to protect your organization from this relentless...





























