Security Bulletin
21 Aug 2024
Biztonsági szemle
Misconfigured database exposes Al-Anon data
Information leaked by the misconfigured database included individuals' full names, emails, phone numbers, encrypted passwords, and verification tokens, as well as join dates and private chats.
21 Aug 2024
Biztonsági szemle
Cyberattack impacts Microchip operations
Impacted systems were isolated while others were taken down immediately after the discovery of the breach, said Microchip, a U.S. defense industry chip supplier, in a regulatory filing.
21 Aug 2024
Biztonsági szemle
AvosLocker ransomware attack against CannonDesign confirmed
Unauthorized access to CannonDesign's network from Jan. 19 to 25 has prompted attackers to exfiltrate names, Social Security numbers, addresses, and driver's license numbers, said the firm in breach notification letters that emphasized the lack of...
21 Aug 2024
Biztonsági szemle
Takeovers likely across over 100K WordPress sites due to critical plugin bug
Such a vulnerability, tracked as CVE-2024-5932, could be leveraged by threat actors to facilitate PHP object injection and subsequent Property Oriented Programming chain abuse involving the manipulation of deserialized objects for remote code...
21 Aug 2024
Biztonsági szemle
New banking-targeted phishing scheme involves progressive web apps
Attackers have used automated voice calls, social media ads, and SMS messages to lure targets into downloading the PWAs, which resemble legitimate apps and enable stealthy compromise of devices' camera, microphone, geolocation, and other browser...
21 Aug 2024
Biztonsági szemle
Blind Eagle attacks target Latin America with RATs
Blind Eagle's intrusions commence with the distribution of government and financial organization-spoofing phishing emails with malicious attachments containing links that redirect to a website hosting a compressed ZIP archive as an initial dropper...
21 Aug 2024
Biztonsági szemle
Attack campaign with new AnvilEcho malware launched by Iranian hackers
New AnvilEcho PowerShell trojan distribution has been sought by Iranian state-backed threat operation TA453 in a spear phishing attack campaign against a major Jewish personality that commenced late last month.
21 Aug 2024
Biztonsági szemle
Novel Msupedge backdoor deployed via patched PHP RCE exploit
Infiltration of vulnerable systems via the security issue, which was addressed by PHP maintainers in early June, was followed by the deployment of Msupedge as a pair of dynamic link libraries, an analysis from Symantec's Threat Hunter Team showed.
21 Aug 2024
Biztonsági szemle
Time to finally get serious about stopping the attacks on the healthcare supply chain
The healthcare supply chain has been under attack for the last decade – it will take a national effort to keep our medical systems secure.
21 Aug 2024
Biztonsági szemle
Microsoft Copilot Studio Exploit Leaks Sensitive Cloud Data
A server-side request forgery (SSRF) bug in Microsoft's tool for creating custom AI chatbots potentially exposed info across multiple tenants within cloud environments.
21 Aug 2024
Biztonsági szemle
Researchers Highlight How Poisoned LLMs Can Suggest Vulnerable Code
CodeBreaker technique can create code samples that poison the output of code-completing large language models, resulting in vulnerable — and undetectable — code suggestions.
21 Aug 2024
Biztonsági szemle
Ransomware on track for record profits, even as fewer victims pay
A mid-year report found ransom payment prices have increased drastically among big game hunters.
Pagination
- Previous page ‹‹
- Page 443
- Next page ››