Tag: Cybersecurity

Zerodium will pay $300K for WordPress RCE exploits (Security Affairs)

Pierluigi Paganini Zero-day broker Zerodium announced that will triples payouts for remote code execution exploits for the popular WordPress content management system. https://securityaffairs.co/wordpress/116605/hacking/zerodium-wordpress-exploits.html    

Cisco will not release updates to fix critical RCE flaw in EoF Business Routers (Security Affairs)

Pierluigi Paganini Cisco announced it will not release security updates to address a critical security vulnerability affecting some of its Small Business routers. https://securityaffairs.co/wordpress/116598/security/rce-eof-cisco-business-routers.html

Pwn2Own 2021: participants earned $1,2M of the $1.5M prize pool (Security Affairs)

Pierluigi Paganini The Pwn2Own 2021 hacking competition was concluded, participants earned more than $1.2 million, the greatest total payout ever. https://securityaffairs.co/wordpress/116593/hacking/pwn2own-2021-day-3.html

CISA releases post-compromise tool Aviary to review Microsoft 365 (Security Affairs)

Pierluigi Paganini CISA released a Splunk-based dashboard for post-compromise activity in Microsoft Azure Active Directory (AD), Office 365, and MS 365 environments. https://securityaffairs.co/wordpress/116584/security/cisa-aviary-microsoft-365.html

330K stolen payment cards and 895K stolen gift cards sold on dark web (Security Affairs)

Pierluigi Paganini A threat actor has sold almost 900,000 gift cards and over 300,000 payment cards on a cybercrime forum on the dark web. https://securityaffairs.co/wordpress/116558/deep-web/gift-cards-sold-dark-web.html

Gigaset Android smartphones infected with malware after supply chain attack (Security Affairs)

Pierluigi Paganini A new supply chain attack made the headlines, threat actors compromised at least one update server of smartphone maker Gigaset to deliver malware. https://securityaffairs.co/wordpress/116450/cyber-crime/gigaset-malware-supply-chain-attack.html

European Commission and other institutions were hit by a major cyber-attack (Security Affairs)

Pierluigi Paganini Not only the European Commission, but many other organizations of the European Union have been targeted by a cyberattack in March. https://securityaffairs.co/wordpress/116441/hacking/european-commission-institutions-cyberattack.html

SAP systems are targeted within 72 hours after updates are released (Security Affairs)

Pierluigi Paganini On-premises SAP systems are targeted by threat actors within 72 hours after security patches are released, security SAP security firm Onapsis warns. https://securityaffairs.co/wordpress/116431/reports/sap-systems-under-attacks.html

Experts found critical flaws in Rockwell FactoryTalk AssetCentre (Security Affairs)

Pierluigi Paganini Rockwell Automation has recently addressed nine critical vulnerabilities in its FactoryTalk AssetCentre product with the release of version v11. https://securityaffairs.co/wordpress/116391/ics-scada/rockwell-factorytalk-assetcentre-flaws.html

(Cybersecurity) Malware attack on Applus blocked vehicle inspections in some US states (Security Affairs)

Pierluigi Paganini A malware attack against vehicle inspection services provider Applus Technologies paralyzed preventing vehicle inspections in eight US states. https://securityaffairs.co/wordpress/116338/malware/malware-attack-on-applus.html

(Cybersecurity) Clop Ransomware operators plunder US universities (Security Affairs)

Pierluigi Paganini Clop ransomware gang leaked online data stolen from Stanford Medicine, University of Maryland Baltimore, and the University of California. https://securityaffairs.co/wordpress/116325/uncategorized/clop-ransomware-us-universities.html

(Cybersecurity) Data of 533 million Facebook users leaked in a hacking forum for free (Security Affairs)

Pierluigi Paganini On April 3, a user has leaked the phone numbers and personal data of 533 million Facebook users in a hacking forum for free...

(Cybersecurity) Capital One discovered more customers’ SSNs exposed in 2019 hack (Security Affairs)

Pierluigi Paganini More clients of Capital One have been impacted in the 2019 data breach, the US bank is notifying them of their SSNs exposure. https://securityaffairs.co/wordpress/116309/data-breach/capital-one-ssns.html

(Cybersecurity) Activision warns of Call of Duty Cheat tool used to deliver RAT (Security Affairs)

Pierluigi Paganini The popular video game publisher Activision is warning gamers that threat actors are actively disguising a remote-access trojan (RAT) in Duty Cheat cheat tool. https://securityaffairs.co/wordpress/116301/malware/activision-call-of-duty-cheat-tool.html

(Cybersecurity/Security Affairs) Attackers are abusing GitHub infrastructure to mine cryptocurrency (Security Affairs)

Pierluigi Paganini The popular code repository hosting service GitHub is investigating a crypto-mining campaign abusing its infrastructure. https://securityaffairs.co/wordpress/116294/malware/github-infrastructure-attacks-miner.html

(Cybersecurity) Evolution and rise of the Avaddon Ransomware-as-a-Service (Security Affairs)

Pierluigi Paganini The Avaddon ransomware operators updated their malware after security researchers released a public decryptor in February 2021. https://securityaffairs.co/wordpress/116282/cyber-crime/avaddon-ransomware-evolution.html