Security Bulletin

20 Sep 2024
Biztonsági szemle
Updated CISA exploited vulnerabilities catalog adds several flaws
Most recent of the newly added vulnerabilities is a critical remote command execution issue in Apache HugeGraph-Server, tracked as CVE-2024-27348, which could be leveraged to facilitate sandbox restriction evasion.

20 Sep 2024
Biztonsági szemle
FTC: Mass surveillance conducted by social media, video streaming services
Aside from failing to remove data from former users, most of the said platforms also had no safeguards for data belonging to youths ages 13 to 17, according to the Federal Trade Commission.

20 Sep 2024
Biztonsági szemle
Disney reportedly ditching Slack after breach
Utilization of Slack will be halted across most of Disney's businesses by the end of the year, said Disney Chief Financial Officer Hugh Johnston in a report in the Status media newsletter.

20 Sep 2024
Biztonsági szemle
Dell claimed to be breached, over 10K employee records exposed
Information leaked by grep on BreachForums included Dell employees' full names, IDs, active status, department numbers, and internal identifiers, as well as two email addresses with the "dell.com" domain but no plain text credentials or personally...

20 Sep 2024
Biztonsági szemle
Lumma Stealer deployed via fraudulent CAPTCHA pages
Attacks involved the utilization of Amazon S3 bucket and Content Delivery Network-hosted sites spoofing Google CAPTCHA pages and other verification sites, which include instructions that trigger a malicious PowerShell command downloading Lumma...

20 Sep 2024
Biztonsági szemle
Several orgs purportedly attacked by novel Valencia Ransomware gang
Some of the 340 GB of sensitive data purportedly stolen from the City of Pleasanton, including names, birthdates, credit card numbers, and other personal and corporate financial information, have already been exposed by Valencia.

20 Sep 2024
Biztonsági szemle
Middle East backdoored by Iranian state-backed hackers
With its comprehensive passive/listener-based utilities for initial access and lateral movement, UNC1860 may have supported Iranian hacking attacks with the BABYWIPER malware against Israel last October and intrusions with the ROADSWEEP malware...

20 Sep 2024
Biztonsági szemle
How IT infrastructure provider Kyndryl made identity security central to its digital transformation
For companies undergoing digital transformation, overhauling identity and access management is central to the effort. Here are lessons learned from Kyndryl’s journey and how it was aided by its partnership with Okta.

20 Sep 2024
Biztonsági szemle
How integrated pentesting and bug bounty programs give security teams an edge
An integrated approach to pentesting and bug bounty programs promises to find vulnerabilities that would otherwise get missed.

20 Sep 2024
Biztonsági szemle
North Korean APT Bypasses DMARC Email Policies in Cyber-Espionage Attacks
How the Kimsuky nation-state group and other threat actors are exploiting poor email security — and what organizations can do to defend themselves.

20 Sep 2024
Biztonsági szemle
Mastercard's Recorded Future Deal Furthers Its AI Security Goals
Mastercard's $2.65 billion deal to acquire the threat intelligence provider will boost the credit-card company's AI-based cybersecurity protection capabilities.

20 Sep 2024
Biztonsági szemle
Only 1/3 of businesses have 24/7 security coverage, survey finds
Disconnects between IT departments and executive boards drive “alarming” cybersecurity trends.
Pagination
- Previous page ‹‹
- Page 363
- Next page ››