Security Bulletin
27 Jan 2025
Biztonsági szemle
Suspected Phemex hack leads to theft of over $69M
Such an incident — which comes within six months of separate crypto heists against fellow Singaporean cryptocurrency platforms BingX and Penpie — showcased levels of sophistication that could have only been conducted by North Korean threat actors...
27 Jan 2025
Biztonsági szemle
RID hijacking conducted by Andariel
After leveraging a vulnerability and the privilege escalation tools PsExec and JuicyPotato to gain SYSTEM access on targeted devices, Andariel stealthily established a low-privilege local user before altering the Security Account Manager registry to...
27 Jan 2025
Biztonsági szemle
Covert VMware ESXI-targeted ransomware hack facilitated by SSH tunneling
After infiltrating ESXi instances by leveraging known vulnerabilities or stolen admin credentials, ransomware gangs proceed to utilize the built-in SSH service to facilitate lateral movement and ransomware delivery without being detected, according...
26 Jan 2025
Biztonsági szemle
AI Red Teaming Comes to Bug Bounties - Michiel Prins - ESW #391
24 Jan 2025
Biztonsági szemle
CISOs Are Gaining C-Suite Swagger, but Has It Come With a Cost?
The number of CISOs who report directly to the CEO is up sharply in recent years, but many still say it's not enough to secure adequate resources.
24 Jan 2025
Biztonsági szemle
Attacks on Ivanti appliances demonstrate danger of chained exploits
CISA warned that attackers are chaining a number of CVE-listed vulnerabilities into a single exploit script.
24 Jan 2025
Biztonsági szemle
Reddit, WeTransfer pages spoofed in Lumma Stealer campaign
Nearly 1,000 imitation pages were discovered, targeting users looking for other software.
24 Jan 2025
Biztonsági szemle
Cursive Funk, Microsoft, Ivanti, Sonic Wall, Exchange, PowerSchool, Aaran Leyland... - SWN #445
24 Jan 2025
Biztonsági szemle
DoJ Busts Up Another Multinational DPRK IT Worker Scam
A departmentwide initiative has now led to five major law enforcement actions, in an attempt to curb the increasingly common trend of North Korean hackers posing as IT job applicants.
24 Jan 2025
Biztonsági szemle
QNAP patches six Rsync bugs that could lead to RCEs on NAS devices
Small and midsize companies tend not to check for NAS updates, so customers advised to patch right away.
24 Jan 2025
Biztonsági szemle
MITRE's Latest ATT&CK Simulations Tackle Cloud Defenses
The MITRE framework's applied exercise provides defenders with critical feedback about how to detect and defend against common, but sophisticated, attacks.
24 Jan 2025
Biztonsági szemle
Cisco: Critical Meeting Management Bug Requires Urgent Patch
The bug has been given a 9.9 CVSS score, and could allow authenticated threat actors to escalate their privileges to admin-level if exploited.
Pagination
- Previous page ‹‹
- Page 250
- Next page ››