Security Bulletin
23 Sep 2024
Biztonsági szemle
MC2 Data leak exposes nearly a third of US population
The misconfiguration revealed more than 106 million records with U.S. citizens' private information and over 2.3 million MC2 Data subscribers' data.
23 Sep 2024
Biztonsági szemle
Significant hacktivist attacks launched against Russia
After obtaining initial access via local or domain account exploitation, Twelve proceeds to leverage Remote Desktop Protocol to facilitate further infrastructure penetration, as well as utilize other tools, including Cobalt Strike, Chisel, Mimikatz...
23 Sep 2024
Biztonsági szemle
Another Ivanti CSA vulnerability leveraged in ongoing attacks
Such a development comes less than a week after the confirmed exploitation of the high-severity operating system command injection bug in CSA, tracked as CVE-2024-8190, which was believed to have been used alongside another vulnerability due to its...
23 Sep 2024
Biztonsági szemle
New EAGLEDOOR backdoor spread in suspected Chinese APT attacks against Asia-Pacific
Aside from leveraging spear-phishing emails, Earth Baxia also exploited the recently addressed critical GeoServer GeoTools flaw, tracked as CVE-2024-36401.
23 Sep 2024
Biztonsági szemle
When it comes to solving the ongoing cybersecurity crisis in healthcare, don’t bet on Congress
Look for large state governments like New York to lead the way in addressing many of healthcare’s cybersecurity issues, not Congress.
23 Sep 2024
Biztonsági szemle
China's 'Earth Baxia' Spies Exploit Geoserver to Target APAC Orgs
The APT group uses spear-phishing and a vulnerability in a geospatial data-sharing server to compromise organizations in Taiwan, Japan, the Philippines, and South Korea.
21 Sep 2024
Biztonsági szemle
Ukraine government says ‘nyet’ to Telegram app
The Ukrainian government banned the Russian-owned Telegram app for official communications.
21 Sep 2024
Biztonsági szemle
CISA Releases Plan to Align Cybersecurity Across Federal Agencies
The FOCAL plan outlines baselines to synchronize cybersecurity priorities and policies across, as well as within, agencies.
20 Sep 2024
Biztonsági szemle
Ivanti's Cloud Service Appliance Attacked via Second Vuln
The critical bug, CVE-2024-8963, can be used in conjunction with the prior known flaw to achieve remote code execution (RCE).
20 Sep 2024
Biztonsági szemle
Citrine Sleet Poisons PyPI Packages With Mac & Linux Malware
A North Korean advanced persistent threat (APT) actor (aka Gleaming Pisces) tried to sneak simple backdoors into public software packages.
20 Sep 2024
Biztonsági szemle
Shroombots, pagers, Tor, Raptor Train, GRU, Blue Light, Aaran Leyland, and More... - SWN #415
20 Sep 2024
Biztonsági szemle
New NIST program focuses on AI cybersecurity and privacy
The program seeks to adapt frameworks such as the NIST Cybersecurity Framework to address AI use.
Pagination
- Previous page ‹‹
- Page 437
- Next page ››