Tag: Cybersecurity

(Cybersecurity/Facebook) Facebook data on more than 500 million accounts found online (Arab News)

Facebook has been grappling with data security issues for years https://www.arabnews.com/node/1837171/media

(USA/Cybersecurity/Democracy) Biden rebuilds cybersecurity alliances but risks creating a techno-democratic clique (East Asia Forum)

Julia Voo, Harvard Kennedy School Under Donald Trump, US global leadership on cyber issues came to a screeching halt. But ‘America is back’ under President...

(Cybersecurity) Army developing tool for US cities to practice cyberattack response (Defense News)

Mark Pomerleau The Army Cyber Institute is building a portable, tailorable platform for cities to practice responding to cyberattacks targeting critical infrastructure. https://www.c4isrnet.com/cyber/2021/03/31/army-developing-tool-for-us-cities-to-practice-cyberattack-response/

(Cybersecurity) VMware addresses SSRF flaw in vRealize Operations that allows stealing admin credentials (Security Affairs)

Pierluigi Paganini VMware addressed a high severity vulnerability in vRealize Operations that could allow stealing admin credentials from vulnerable servers. https://securityaffairs.co/wordpress/116145/security/vmware-vrealize-operations-ssrf-flaw.html

(Cybersecurity) Reflected XSS Vulnerability In “Ivory Search” WP Plugin Impact Over 60K sites (Security Affairs)

Pierluigi Paganini Researchers discovered a reflected XSS vulnerability in the Ivory Search WordPress Plugin installed on over 60,000 sites. https://securityaffairs.co/wordpress/116140/hacking/reflected-xss-ivory-search-wp-plugin.html

(Cybersecurity) Experts found 2 Linux Kernel flaws that can allow bypassing Spectre mitigations (Security Affairs)

Pierluigi Paganini Linux kernel recently fixed a couple of vulnerabilities that could allow an attacker to bypass mitigations designed to protect devices against Spectre attacks. https://securityaffairs.co/wordpress/116131/security/linux-kernel-flaws-spectre-bypass.html

(Cybersecurity) Hundreds of thousands of projects affected by a flaw in netmask npm package (Security Affairs)

Pierluigi Paganini A vulnerability in the netmask npm package, tracked as CVE-2021-28918, could be exploited by attackers to conduct a variety of attacks. https://securityaffairs.co/wordpress/116126/hacking/netmask-npm-package-flaw.html

(Cybersecurity) 30 Docker images downloaded 20M times in cryptojacking attacks (Security Affairs)

Pierluigi Paganini Experts discovered that 30 malicious Docker images with a total number of 20 million pulls were involved in cryptomining operations. https://securityaffairs.co/wordpress/116111/cyber-crime/docker-cryptojacking-attacks.html

(Cybersecurity) London-based academies Harris Federation hit by ransomware attack (Security Affairs)

Pierluigi Paganini Harris Federation, the multi-academy trust of 50 primary and secondary academies in and around London, was hit by a ransomware attack. https://securityaffairs.co/wordpress/116101/malware/harris-federation-hit-ransomware.html

(Cybersecurity) China-linked RedEcho APT took down part of its C2 domains (Security Affairs)

Pierluigi Paganini China-linked APT group RedEcho has taken down its attack infrastructure after it was exposed at the end of February by security researchers. https://securityaffairs.co/wordpress/116094/apt/redecho-apt-c2-shutdown.html

(Cybersecurity) Hackers breached the PHP ‘s Git Server and inserted a backdoor in the source code (Security Affairs)

Pierluigi Paganini Threat actors hacked the official Git server of the PHP programming language and pushed unauthorized updates to insert a backdoor into the source code. https://securityaffairs.co/wordpress/116088/hacking/php-git-server-hack.html

(Cybersecurity) Ziggy ransomware admin announced it will refund victims who paid the ransom (Security Affairs)

Pierluigi Paganini Administrator of Ziggy ransomware recently announced the end of the operation, and now is promising that its victims will have back their money. https://securityaffairs.co/wordpress/116079/malware/ziggy-ransomware-refunds-victims.html

(Cybersecurity) New Purple Fox version includes Rootkit and implements wormable propagation (Security Affairs)

Pierluigi Paganini Researchers from Guardicore have spotted a new variant of the Purple Fox Windows malware that implements worm-like propagation capabilities. https://securityaffairs.co/wordpress/116070/malware/purple-fox-rootkit-version.html

(Cybersecurity) Experts found two flaws in Facebook for WordPress Plugin (Security Affairs)

Pierluigi Paganini A critical flaw in the official Facebook for WordPress plugin could be abused exploited for remote code execution attacks. https://securityaffairs.co/wordpress/116063/social-networks/facebook-wordpress-plugin-attacks.html

(Cybersecurity) Hackers disrupted live broadcasts at Channel Nine. Is it a Russian retaliation? (Security Affairs)

Pierluigi Paganini A cyber attack has disrupted the Australian Channel Nine’s live broadcasts, the company was unable to transmit its Sunday morning news program. https://securityaffairs.co/wordpress/116053/breaking-news/channel-nine-cyber-attack.html

(Cybersecurity) QNAP urges users to take action to protect devices against Brute-Force attacks (Security Affairs)

Pierluigi Paganini Taiwanese manufacturer QNAP published an alert urging its customers to secure their devices after a growing number of users reported that their devices have been hit...