Source: securityaffairs.com – Author: Pierluigi Paganini FortiGuard Labs researchers observed a worrisome level of attacks attempting to exploit an authentication bypass vulnerability in TBK DVR devices....
Author:
North Korea-linked ScarCruft APT uses large LNK files in infection chains – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini North Korea-linked ScarCruft APT group started using oversized LNK files to deliver the RokRAT malware starting in early July 2022. Check...
CISA adds TP-Link, Apache, and Oracle bugs to its Known Exploited Vulnerabilities catalog – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini US Cybersecurity and Infrastructure Security Agency (CISA) added TP-Link, Apache, and Oracle vulnerabilities to its Known Exploited Vulnerabilities catalog. U.S....
New Lobshot hVNC malware spreads via Google ads – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini The previously undetected LOBSHOT malware is distributed using Google ads and gives operators VNC access to Windows devices. Researchers from...
T-Mobile suffered the second data breach in 2023 – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini T-Mobile disclosed the second data breach of 2023, threat actors had access to the personal information of hundreds of customers...
Experts spotted a new sophisticated malware toolkit called Decoy Dog – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Infoblox researchers discovered a new sophisticated malware toolkit, dubbed Decoy Dog, targeting enterprise networks. While analyzing billions of DNS records, Infoblox researchers...
German IT provider Bitmarck hit by cyberattack – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Bitmarck, one of the largest IT service providers for social insurance carriers in Germany, announced yesterday that it has suffered a...
Iranian govt uses BouldSpy Android malware for internal surveillance operations – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Iranian authorities have been spotted using the BouldSpy Android malware to spy on minorities and traffickers. Researchers at the Lookout Threat...
Russian APT Nomadic Octopus hacked Tajikistani carrier – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Russian APT group Nomadic Octopus hacked a Tajikistani carrier to spy on government officials and public service infrastructures. Russian cyber...
Google banned 173k developer accounts in 2022 – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini In 2022, Google prevented 1.43 million policy-violating apps from being published in the official Google Play store. Google announced that...
Crooks broke into AT&T email accounts to empty their cryptocurrency wallets – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Threat actors are gaining access to AT&T email accounts in an attempt to hack into the victim’s cryptocurrency exchange accounts....
Russia-linked APT28 uses fake Windows Update instructions to target Ukraine govt bodies – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini CERT-UA warns of a spear-phishing campaign conducted by APT28 group targeting Ukrainian government bodies with fake ‘Windows Update’ guides. Russia-linked...
White hat hackers showed how to take over a European Space Agency satellite – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Thales cybersecurity researchers have shown this week how they seized control of a European Space Agency (ESA) satellite. This week,...
Security Affairs newsletter Round 417 by Pierluigi Paganini – International edition – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Privacy Overview This website uses cookies to improve your experience while you navigate through the website. Out of these cookies,...
ViperSoftX uses more sophisticated encryption and anti-analysis techniques – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini A new variant of the information-stealing malware ViperSoftX implements sophisticated techniques to avoid detection. Trend Micro researchers observed a new...
Atomic macOS Stealer is advertised on Telegram for $1,000 per month – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Atomic macOS Stealer is a new information stealer targeting macOS that is advertised on Telegram for $1,000 per month. Cyble...
CISA warns of a critical flaw affecting Illumina medical devices – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini U.S. CISA released an Industrial Control Systems (ICS) medical advisory warning of a critical flaw affecting Illumina medical devices. The...
OpenAI reinstates ChatGPT service in Italy after meeting Garante Privacy’s demands – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini OpenAI announced that access to its chatbot service ChatGPT is allowed again in Italy after the company met the demands...
Cisco discloses a bug in the Prime Collaboration Deployment solution – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Cisco is working on a patch for a bug in the Prime Collaboration Deployment solution that was reported by a...
Zyxel fixed a critical RCE flaw in its firewall devices and urges customers to install the patches – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini A vulnerability impacting Zyxel firewalls, tracked as CVE-2023-28771, can be exploited to execute arbitary code on vulnerable devices. Researchers from TRAPA...
Ukraine cyber police arrested a man for selling data of 300M people – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini The Ukrainian cyber police arrested a Ukraine man for selling the data of over 300 million people from different countries....
Google obtained a temporary court order against CryptBot distributors – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Google obtained a temporary court order in the U.S. to disrupt the operations of the CryptBot information stealer. Google announced that...
Researchers found the first Linux variant of the RTM locker – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini RTM ransomware-as-a-service (RaaS) started offering locker ransomware that targets Linux, NAS, and ESXi systems. The Uptycs threat research team discovered the first...
Crooks use PaperCut exploits to deliver Cl0p and LockBit ransomware – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Microsoft revealed that recent attacks against PaperCut servers aimed at distributing Cl0p and LockBit ransomware. Microsoft linked the recent attacks against...
CryptoRom: OkCupid scam cost Florida man $480k – we followed the money to Binance – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini CyberNews analyzed a classic cryptocurrency romance scam, also known as CryptoRom, explaining how scammers hid the money CryptoRom scammers hid...
Iranian Charming Kitten APT used a new BellaCiao malware in recent wave of attacks – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Iran-linked APT group Charming Kitten employed a new malware dubbed BellaCiao in attacks against victims in the U.S., Europe, the Middle East and...
China-linked Alloy Taurus APT uses a Linux variant of PingPull malware – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini China-linked threat actor tracked as Alloy Taurus is using a Linux variant of the PingPull backdoor and a new tool dubbed Sword2033....
A component in Huawei network appliances could be used to take down Germany’s telecoms networks – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini German government warns that technology to regulate power consumption in Huawei network appliances could be used for sabotage purposes. In...
Thousands of publicly-exposed Apache Superset installs exposed to RCE attacks – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Apache Superset open-source data visualization platform is affected by an insecure default configuration that could lead to remote code execution. Apache...
Pro-Russia hacking group executed a disruptive attack against a Canadian gas pipeline – Source: securityaffairs.com
Source: securityaffairs.com – Author: Pierluigi Paganini Pro-Russia hacking group Zarya caused a cybersecurity incident at a Canadian gas pipeline, the critical infrastructure sector is on alert....





























