Tag: Cybersecurity

(Cybersecurity) Malspam campaign uses icon files to delivers NanoCore RAT (Security Affairs)

Pierluigi Paganini Researchers at Trustwave spotted a new malspam campaign that is abusing icon files to trick victims into installing the NanoCore Trojan. https://securityaffairs.co/wordpress/115520/malware/nanocore-rat-malspam-icon-files.html

(Cybersecurity) RedXOR, a new powerful Linux backdoor in Winnti APT arsenal (Security Affairs)

Pierluigi Paganini Intezer experts have spotted a new strain of Linux backdoor dubbed RedXOR that is believed to be part of the arsenal of China-linked Winniti...

(Cybersecurity) F5 addresses critical vulnerabilities in BIG-IP and BIG-IQ (Security Affairs)

Pierluigi Paganini Security firm F5 announced the availability of patches for seven vulnerabilities in BIG-IP, four of which have been rated as “critical” severity. https://securityaffairs.co/wordpress/115481/security/f5-flaws-big-ip-big-iq.html

(Cybersecurity) White hat hackers gained access more than 150,000 surveillance cameras (Security Affairs)

Pierluigi Paganini A group of hackers claimed to have compromised more than 150,000 surveillance cameras at banks, jails, schools, and prominent companies like Tesla and Equinox. https://securityaffairs.co/wordpress/115466/hacking/surveillance-cameras-hacked.html

(Cybersecurity) OVH data centers suffered a fire, many popular sites are offline (Security Affairs)

Pierluigi Paganini OVH, the largest hosting provider in Europe, has suffered a terrible fire that destroyed the data centers located in Strasbourg. https://securityaffairs.co/wordpress/115457/breaking-news/ovh-data-centers-fire.html

(Cybersecurity) A flaw in The Plus Addons for Elementor WordPress plugin allows sites takeover (Security Affairs)

Pierluigi Paganini Researchers from the Wordfence team found a critical vulnerability in The Plus Addons for Elementor WordPress plugin that could be exploited to take over...

(Cybersecurity) Microsoft’s March Patch Tuesday fixes 14 Critical flaws (Security Affairs)

Pierluigi Paganini Microsoft’s March Patch Tuesday security updates address 89 vulnerabilities in its products, 14 are listed as Critical and 75 are listed as Important in...

(Cybersecurity) Bug in Apple’s Find My Feature Could’ve Exposed Users’ Location Histories (The Hacker News)

Ravie Lakshmanan Cybersecurity researchers on Thursday disclosed two distinct design and implementation flaws in Apple's crowdsourced Bluetooth location tracking system that can lead to a...

(Cybersecurity) Mazafaka — Elite Hacking and Cybercrime Forum — Got Hacked! (The Hacker News)

Ravie Lakshmanan In what's a case of hackers getting hacked, a prominent underground online criminal forum by the name of Maza has been compromised by...

(Cybersecurity) Researchers Find 3 New Malware Strains Used by SolarWinds Hackers (The Hacker News)

Ravie Lakshmanan FireEye and Microsoft on Thursday said they discovered three more malware strains in connection with the SolarWinds supply-chain attack, including a "sophisticated second-stage...

(Cybersecurity) Massive Supply-Chain Cyberattack Breaches Several Airlines (Cybercrime Magazine)

Becky Bracken The cyberattack on SITA, a nearly ubiquitous airline service provider, has compromised frequent-flyer data across many carriers. https://threatpost.com/supply-chain-cyberattack-airlines/164549/

(Cybersecurity) New York State Education Department Warns of Phishing Campaign (Cybercrime Magazine)

Stu Sjouwerman The New York State Education Department (NYSED) released an advisory warning that scammers are impersonating its employees in an attempt to steal social...

(Cybersecurity) Government briefed on breach of at least 30,000 Microsoft Exchange Servers (SC Media)

Joe Uchill Cybersecurity experts briefed government investigators that at least 30,000 Microsoft Exchange Servers have been breached using a chain of vulnerabilities Microsoft patched on...

(Cybersecurity) Public companies may not grasp responsibility to investors in sharing info on cyber risk (SC Media)

Derek B. Johnson Publicly traded companies must start disclosing more “actionable” information to shareholders and regulators around their cyber risks and vulnerabilities. https://www.scmagazine.com/home/security-news/data-breach/public-companies-may-not-grasp-responsibility-to-investors-in-sharing-info-on-cyber-risk/

(Cybersecurity) ‘Educational’ ransomware program may instead become a how-to guide for attackers (SC Media)

Bradley Barth A developer published via GitHub a proof-of-concept (POC) ransomware program featuring strong compatibility with the post-exploitation tool Cobalt Strike, open-source coding, and extensionless...

(Cybersecurity) Through automation, New Belgium Brewing has privacy on tap (SC Media)

Teri Robinson Beer and privacy might not seem like natural allies, but at New Belgium Brewing, privacy is the premium brew. https://www.scmagazine.com/home/security-news/privacy-compliance/through-automation-new-belgium-brewing-has-privacy-on-tap/