Tag: Cybersecurity

(Cybersecurity) RCE flaw in Apache OFBiz could allow to take over the ERP system (Security Affairs)

Pierluigi Paganini The Apache Software Foundation fixed a high severity remote code execution flaw in Apache OFBiz that could have allowed attackers to take over the...

(Cybersecurity) Which is the Threat landscape for the ICS sector in 2020? (Security Affairs)

Pierluigi Paganini The Kaspersky ICS CERT published a report that provided details about the threat landscape for computers in the ICS engineering and integration sector in...

(Cybersecurity) CISA releases CHIRP, a tool to detect SolarWinds malicious activity (Security Affairs)

Pierluigi Paganini US CISA has released a new tool that allows detecting malicious activity associated with the SolarWinds hackers in compromised on-premises enterprise environments. https://securityaffairs.co/wordpress/115821/security/cisa-chirp-solarwinds-tool.html

(Cybersecurity) Swiss expert Till Kottmann indicted for conspiracy, wire fraud, and aggravated identity theft (Security Affairs)

Pierluigi Paganini Department of Justice announced that Swiss hacker Till Kottmann, 21, has been indicted for conspiracy, wire fraud, and aggravated identity theft. https://securityaffairs.co/wordpress/115808/cyber-crime/till-kottmann-indicted-crimes.html

(Cybersecurity) Microsoft Defender can now protect servers against ProxyLogon attacks (Security Affairs)

Pierluigi Paganini Microsoft announced that its Defender Antivirus and System Center Endpoint Protection now protects users against attacks exploiting Exchange Server vulnerabilities. https://securityaffairs.co/wordpress/115801/hacking/microsoft-defender-microsoft-exchange.html

(Cybersecurity) Russian National pleads guilty to conspiracy to plant malware on Tesla systems (Security Affairs)

Pierluigi Paganini The Russian national who attempted to convince a Tesla employee to plant malware on Tesla systems has pleaded guilty. https://securityaffairs.co/wordpress/115770/cyber-crime/russian-man-malware-tesla.html

(Cybersecurity) Threat actors are attempting to exploit CVE-2021-22986 in F5 BIG-IP devices in the wild (Security Affairs)

Pierluigi Paganini Cybersecurity experts warn of ongoing attacks aimed at exploiting a recently patched critical vulnerability in F5 BIG-IP and BIG-IQ networking devices. https://securityaffairs.co/wordpress/115760/hacking/f5-big-ip-attacks-cve-2021-22986.html

(Cybersecurity) Why Focusing on Container Runtimes Is the Most Critical Piece of Security for EKS Workloads? (Security Affairs)

Pierluigi Paganini Amazon Elastic Kubernetes Service (EKS), a platform which gives customers the ability to run Kubernetes apps in the AWS cloud or on premises. https://securityaffairs.co/wordpress/115755/security/amazon-elastic-kubernetes-service-eks.html

(Cybersecurity) Millions of sites could be hacked due to flaws in popular WordPress plugins (Security Affairs)

Pierluigi Paganini Experts found vulnerabilities in two WordPress plugins that could be exploited to run arbitrary code and potentially take over a website. https://securityaffairs.co/wordpress/115750/hacking/wordpress-plugins-flaws.html

(Cybersecurity) CISA and FBI warn of ongoing TrickBot attacks (Security Affairs)

Pierluigi Paganini CISA and FBI are warning of ongoing TrickBot attacks despite security firms took down the C2 infrastructure of the infamous botnet in October. https://securityaffairs.co/wordpress/115743/malware/cisa-fbi-trickbot-attacks.html

(Cybersecurity) Millions of People Can Lose Sensitive Data through Travel Apps, Privacysavvy reports (Security Affairs)

Pierluigi Paganini According to a report published by researchers at PrivacySavvy, many travel companies expose users’ data through their booking apps. https://securityaffairs.co/wordpress/115737/digital-id/travel-apps-data-exposure.html

(Cybersecurity) How African states can improve their cybersecurity (Brookings)

Landry Signé and Kevin Signé The COVID-19 pandemic has accelerated digitalization around the world, but as life has shifted increasingly online, cybercriminals have exploited the opportunity to...

(Cybersecurity) ProxyLogon Microsoft Exchange exploit is completely out of the bag by now (Security Affairs)

Pierluigi Paganini A security researcher released a new PoC exploit for ProxyLogon issues that could be adapted to install web shells on vulnerable Microsoft Exchange servers. https://securityaffairs.co/wordpress/115616/hacking/microsoft-exchange-exploit-is-out.html

(Cybersecurity) NCSC is not aware of ransomware attacks compromising UK orgs through Microsoft Exchange bugs (Security Affairs)

Pierluigi Paganini The UK’s National Cyber Security Centre (NCSC) urges UK organizations to install the patches for the recently disclosed vulnerabilities in Microsoft Exchange. https://securityaffairs.co/wordpress/115605/hacking/ncsc-microsoft-exchange-assessment.html

(Cybersecurity) Google fixes the third actively exploited Chrome 0-Day since January (Security Affairs)

Pierluigi Paganini Google has addressed a new zero-day flaw in its Chrome browser that has been actively exploited in the wild, the second one within a...

(Cybersecurity) Experts found 15 flaws in Netgear JGS516PE switch, including a critical RCE (Security Affairs)

Pierluigi Paganini Netgear has released security and firmware updates for its JGS516PE Ethernet switch to address 15 vulnerabilities, including a critica remote code execution issue. https://securityaffairs.co/wordpress/115586/hacking/netgear-soho-flaws.html