Source: securityaffairs.com – Author: Pierluigi Paganini A China-linked APT group tracked as UNC3886 has been spotted exploiting a VMware ESXi zero-day vulnerability. Mandiant researchers observed a...
Author:
LLM meets Malware: Starting the Era of Autonomous Threat – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Malware researchers analyzed the application of Large Language Models (LLM) to malware automation investigating future abuse in autonomous threats. In...
Microsoft Patch Tuesday for June 2023 fixes 6 critical flaws – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Microsoft Patch Tuesday security updates for June 2023 fixed 69 flaws in its products, including six critical issues. Microsoft Patch...
St. Margaret’s Health is the first hospital to cite a cyberattack as a reason for its closure – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini St. Margaret’s Health in Illinois is partly closing operations at its hospitals due to a 2021 ransomware attack that impacted...
A database containing data of +8.9 million Zacks users was leaked online – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini A database containing the personal information of more than 8.9 million Zacks Investment Research users was leaked on a cybercrime...
Fortinet urges to patch the critical RCE flaw CVE-2023-27997 in Fortigate firewalls – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Fortinet addressed a new critical flaw, tracked as CVE-2023-27997, in FortiOS and FortiProxy that is likely exploited in a limited number of...
UK communications regulator Ofcom hacked with a MOVEit file transfer zero-day – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini UK communications regulator Ofcom suffered a data breach after a Clop ransomware attack exploiting the MOVEit file transfer zero-day. UK’s...
Experts released PoC exploit for MOVEit Transfer CVE-2023-34362 flaw – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Security firm Horizon3 released proof-of-concept (PoC) exploit code for the remote code execution (RCE) flaw CVE-2023-34362 in the MOVEit Transfer...
Intellihartx data breach exposed the personal and health info of 490,000 individuals – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Intellihartx is notifying about 490,000 individuals that their personal information was compromised in the GoAnywhere zero-day attack in January. The...
FUD Malware obfuscation engine BatCloak continues to evolve – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Researchers detailed a fully undetectable (FUD) malware obfuscation engine named BatCloak that is used by threat actors. Researchers from Trend Micro have...
Fortinet urges to patch a critical RCE flaw in Fortigate firewalls – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Fortinet released security updates to fix a critical security flaw in its FortiGate firewalls that lead to remote code execution....
Xplain data breach also impacted the national Swiss railway FSS – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini The Play ransomware attack suffered by the IT services provider Xplain also impacted the national railway company of Switzerland (FSS)...
Microsoft warns of multi-stage AiTM phishing and BEC attacks – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Microsoft researchers warn of banking adversary-in-the-middle (AitM) phishing and BEC attacks targeting banking and financial organizations. Microsoft discovered multi-stage adversary-in-the-middle...
Security Affairs newsletter Round 423 by Pierluigi Paganini – International edition – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Privacy Overview This website uses cookies to improve your experience while you navigate through the website. Out of these cookies,...
Pro-Ukraine Cyber Anarchy Squad claims the hack of the Russian telecom provider Infotel JSC – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Pro-Ukraine hackers Cyber Anarchy Squad claimed responsibility for the attack that hit Russian telecom provider Infotel JSC. Pro-Ukraine hacking group...
Experts found new MOVEit Transfer SQL Injection flaws – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Progress Software released security updates to fix several new SQL injection vulnerabilities in the MOVEit Transfer application. Progress Software has...
The University of Manchester suffered a cyber attack and suspects a data breach – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini The University of Manchester suffered a cyberattack, attackers likely stole staff and students’ data from its systems. The University of...
Russians charged with hacking Mt. Gox exchange and operating BTC-e – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Two Russian nationals have been charged with the hack of the cryptocurrency exchange Mt. Gox in 2011 and money laundering....
Japanese Pharmaceutical giant Eisai hit by a ransomware attack – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini This week, the Japanese pharmaceutical giant Eisai has taken its systems offline in response to a ransomware attack. Eisai is...
Clop ransomware gang was testing MOVEit Transfer bug since 2021 – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Researchers discovered that the Clop ransomware gang was looking for a zero-day exploit in the MOVEit Transfer since 2021. Kroll...
Stealth Soldier backdoor used is targeted espionage attacks in Libya – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Researchers detected a cyberespionage campaign in Libya that employs a new custom, modular backdoor dubbed Stealth Soldier. Experts at the...
Researchers published PoC exploit code for actively exploited Windows elevation of privilege issue – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Researchers published an exploit for an actively exploited Microsoft Windows vulnerability tracked as CVE-2023-29336. The Microsoft Windows vulnerability CVE-2023-29336 (CVSS score 7.8)...
Experts detail a new Kimsuky social engineering campaign – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini North Korea-linked APT Kimsuky has been linked to a social engineering campaign aimed at experts in North Korean affairs. SentinelLabs researchers uncovered...
German recruiter Pflegia leaks sensitive job seeker info – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Pflegia, a German healthcare recruitment platform, has exposed hundreds of thousands of files with sensitive user data such as names,...
Cisco fixes privilege escalation bug in Cisco Secure Client – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Cisco addressed a high-severity flaw in Cisco Secure Client that can allow attackers to escalate privileges to the SYSTEM account....
Barracuda ESG appliances impacted by CVE-2023-2868 must be immediately replaced – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Barracuda warns customers to immediately replace Email Security Gateway (ESG) appliances impacted by the flaw CVE-2023-2868. At the end of...
VMware fixes a command injection flaw CVE-2023-20887 in VMware Aria Operations for Networks – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Virtualization giant VMware addressed critical and high-severity vulnerabilities in VMware Aria Operations for Networks. Virtualization technology giant VMware released security...
Clop ransomware gang claims the hack of hundreds of victims exploiting MOVEit Transfer bug – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Clop ransomware group claims to have hacked hundreds of companies globally by exploiting MOVEit Transfer vulnerability. The Clop ransomware group...
June 2023 Security Update for Android fixed Arm Mali GPU bug used by spyware – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini June 2023 security update for Android released by Google fixes about fifty flaws, including an Arm Mali GPU bug exploited...
New PowerDrop malware targets U.S. aerospace defense industry – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini A previously unknown threat actor has been observed targeting the U.S. aerospace defense sector with a new PowerShell malware dubbed...























