Tag: Cybersecurity

(Cybersecurity) US Gov Executive Order would oblige to disclose security breach impacting gov users (Security Affairs)

Pierluigi Paganini According to a proposed executive order of the Biden administration, software vendors would have to disclose breaches to U.S. government users. https://securityaffairs.co/wordpress/116033/security/executive-order-data-breach.html

(Cybersecurity) Clop Ransomware gang now contacts victims’ customers to force victims into pay a ransom (Security Affairs)

Pierluigi Paganini Clop ransomware operators now email victim’s customers and ask them to demand a ransom payment to protect their privacy to force victims into paying...

(Cybersecurity) Experts spotted a new advanced Android spyware posing as “System Update” (Security Affairs)

Pierluigi Paganini Researchers spotted a sophisticated Android spyware that implements exfiltration capabilities and surveillance features, including recording audio and phone calls. https://securityaffairs.co/wordpress/116016/malware/android-spyware-system-update.html

(Cybersecurity) Apple released out-of-band updates for a new Zero‑Day actively exploited (Security Affairs)

Pierluigi Paganini  Apple has released new out-of-band updates for iOS, iPadOS, macOS and watchOS to address another zero‑day flaw, tracked CVE-2021-1879, actively exploited. https://securityaffairs.co/wordpress/116007/security/apple-zero%e2%80%91day.html

(Cybersecurity) German Parliament Bundestag targeted again by Russia-linked hackers (Security Affairs)

Pierluigi Paganini Several members of the German Parliament (Bundestag) and other members of the state parliament were hit by a targeted attack allegedly launched by Russia-linked...

(Cybersecurity) Hades ransomware gang targets big organizations in the US (Security Affairs)

Pierluigi Paganini  Accenture security researchers published an analysis of the latest Hades campaign, which is ongoing since at least December 2020. https://securityaffairs.co/wordpress/115994/cyber-crime/hades-ransomware.html  

(Cybersecurity) Solarwinds Orion Platform updates fix two remote code execution issues (Security Affairs)

Pierluigi Paganini  Solarwinds released security updates that address multiple vulnerabilities, including two flaws that be exploited by attackers for remote code execution. https://securityaffairs.co/wordpress/115983/security/solarwinds-updates-rce.html

(Cybersecurity) FBI published a flash alert on Mamba Ransomware attacks (Security Affairs)

Pierluigi Paganini The Federal Bureau of Investigation (FBI) issued an alert to warn that the Mamba ransomware is abusing the DiskCryptor open source tool to encrypt entire drives. https://securityaffairs.co/wordpress/115974/malware/fbi-mamba-ransomware.html

(Cybersecurity) OpenSSL Project released 1.1.1k version to fix two High-severity flaws (Security Affairs)

Pierluigi Paganini The OpenSSL Project addresses two high-severity vulnerabilities, including one related to verifying a certificate chain and one that can trigger a DoS condition. https://securityaffairs.co/wordpress/115968/security/openssl-flaws-2.html

(Cybersecurity) 62,000 Microsoft Exchange Servers potentially left unpatched, weeks after software bugs were first uncovered (Security Affairs)

Pierluigi Paganini The CyberNews investigation team found 62,174 potentially vulnerable unpatched Microsoft Exchange Servers. https://securityaffairs.co/wordpress/115965/hacking/microsoft-exchange-servers-unpatched.html

(Cybersecurity) Facebook took action against China-linked APT targeting Uyghur activists (Security Affairs)

Pierluigi Paganini Facebook has closed accounts used by a China-linked APT to distribute malware to spy on Uyghurs activists, journalists, and dissidents living outside China. https://securityaffairs.co/wordpress/115956/apt/facebook-china-apt-uyghur.html

(Cybersecurity) The surge of fake COVID-19 test results, vaccines and vaccination certificates on the Dark Web (Security Affairs)

Pierluigi Paganini Threat actors are offering fake COVID-19 test results and vaccination certificates in blackmarkets and hacking forums on the Dark Web. https://securityaffairs.co/wordpress/115943/cyber-crime/covid-19-dark-web.html

(Cybersecurity) 30 million Americans affected by the Astoria Company data breach (Security Affairs)

Pierluigi Paganini Researchers discovered the availability in the DarK Web of 30M of records of Americans affected by the Astoria Company data breach https://securityaffairs.co/wordpress/115934/breaking-news/astoria-company-data-leak.html

(Cybersecurity) Cisco Jabber for Windows, macOS, Android and iOS is affected by a critical issue (Security Affairs)

Pierluigi Paganini Cisco has addressed a critical arbitrary program execution flaw in its Cisco Jabber client software for Windows, macOS, Android, and iOS. https://securityaffairs.co/wordpress/115931/security/cisco-jabber-critical-flaw.html

(Cybersecurity) Billions of FBS Records Exposed in Online Trading Broker Data Leak (Security Affairs)

Pierluigi Paganini https://securityaffairs.co/wordpress/115925/data-breach/fbs-data-breach.html

(Cybersecurity) Black Kingdom ransomware is targeting Microsoft Exchange servers (Security Affairs)

Pierluigi Paganini Security experts reported that a second ransomware gang, named Black Kingdom, is targeting Microsoft Exchange servers. https://securityaffairs.co/wordpress/115912/malware/black-kingdom-microsoft-exchange.html