Tag: Cybersecurity

(Cybersecurity) ProxyLogon Microsoft Exchange exploit is completely out of the bag by now (Security Affairs)

Pierluigi Paganini A security researcher released a new PoC exploit for ProxyLogon issues that could be adapted to install web shells on vulnerable Microsoft Exchange servers. https://securityaffairs.co/wordpress/115616/hacking/microsoft-exchange-exploit-is-out.html

(Cybersecurity) NCSC is not aware of ransomware attacks compromising UK orgs through Microsoft Exchange bugs (Security Affairs)

Pierluigi Paganini The UK’s National Cyber Security Centre (NCSC) urges UK organizations to install the patches for the recently disclosed vulnerabilities in Microsoft Exchange. https://securityaffairs.co/wordpress/115605/hacking/ncsc-microsoft-exchange-assessment.html

(Cybersecurity) Google fixes the third actively exploited Chrome 0-Day since January (Security Affairs)

Pierluigi Paganini Google has addressed a new zero-day flaw in its Chrome browser that has been actively exploited in the wild, the second one within a...

(Cybersecurity) Experts found 15 flaws in Netgear JGS516PE switch, including a critical RCE (Security Affairs)

Pierluigi Paganini Netgear has released security and firmware updates for its JGS516PE Ethernet switch to address 15 vulnerabilities, including a critica remote code execution issue. https://securityaffairs.co/wordpress/115586/hacking/netgear-soho-flaws.html

(Cybersecurity) Google releases Spectre PoC code exploit for Chrome browser (Security Affairs)

Pierluigi Paganini Google released proof-of-concept code to conduct Spectre attacks against its Chrome browser to share knowledge of browser-based side-channel attacks. https://securityaffairs.co/wordpress/115573/hacking/google-chrome-spectre-poc.html

(Cybersecurity) Researchers warn of a surge in cyber attacks against Microsoft Exchange (Security Affairs)

Pierluigi Paganini Researchers warn of a surge in cyber attacks against Microsoft Exchange servers exploiting the recently disclosed ProxyLogon vulnerabilities. https://securityaffairs.co/wordpress/115532/hacking/microsoft-exchange-servers-hacks.html

(Cybersecurity) Malspam campaign uses icon files to delivers NanoCore RAT (Security Affairs)

Pierluigi Paganini Researchers at Trustwave spotted a new malspam campaign that is abusing icon files to trick victims into installing the NanoCore Trojan. https://securityaffairs.co/wordpress/115520/malware/nanocore-rat-malspam-icon-files.html

(Cybersecurity) RedXOR, a new powerful Linux backdoor in Winnti APT arsenal (Security Affairs)

Pierluigi Paganini Intezer experts have spotted a new strain of Linux backdoor dubbed RedXOR that is believed to be part of the arsenal of China-linked Winniti...

(Cybersecurity) F5 addresses critical vulnerabilities in BIG-IP and BIG-IQ (Security Affairs)

Pierluigi Paganini Security firm F5 announced the availability of patches for seven vulnerabilities in BIG-IP, four of which have been rated as “critical” severity. https://securityaffairs.co/wordpress/115481/security/f5-flaws-big-ip-big-iq.html

(Cybersecurity) White hat hackers gained access more than 150,000 surveillance cameras (Security Affairs)

Pierluigi Paganini A group of hackers claimed to have compromised more than 150,000 surveillance cameras at banks, jails, schools, and prominent companies like Tesla and Equinox. https://securityaffairs.co/wordpress/115466/hacking/surveillance-cameras-hacked.html

(Cybersecurity) OVH data centers suffered a fire, many popular sites are offline (Security Affairs)

Pierluigi Paganini OVH, the largest hosting provider in Europe, has suffered a terrible fire that destroyed the data centers located in Strasbourg. https://securityaffairs.co/wordpress/115457/breaking-news/ovh-data-centers-fire.html

(Cybersecurity) A flaw in The Plus Addons for Elementor WordPress plugin allows sites takeover (Security Affairs)

Pierluigi Paganini Researchers from the Wordfence team found a critical vulnerability in The Plus Addons for Elementor WordPress plugin that could be exploited to take over...

(Cybersecurity) Microsoft’s March Patch Tuesday fixes 14 Critical flaws (Security Affairs)

Pierluigi Paganini Microsoft’s March Patch Tuesday security updates address 89 vulnerabilities in its products, 14 are listed as Critical and 75 are listed as Important in...

(Cybersecurity) Bug in Apple’s Find My Feature Could’ve Exposed Users’ Location Histories (The Hacker News)

Ravie Lakshmanan Cybersecurity researchers on Thursday disclosed two distinct design and implementation flaws in Apple's crowdsourced Bluetooth location tracking system that can lead to a...

(Cybersecurity) Mazafaka — Elite Hacking and Cybercrime Forum — Got Hacked! (The Hacker News)

Ravie Lakshmanan In what's a case of hackers getting hacked, a prominent underground online criminal forum by the name of Maza has been compromised by...

(Cybersecurity) Researchers Find 3 New Malware Strains Used by SolarWinds Hackers (The Hacker News)

Ravie Lakshmanan FireEye and Microsoft on Thursday said they discovered three more malware strains in connection with the SolarWinds supply-chain attack, including a "sophisticated second-stage...