Security Bulletin

25 Nov 2024
Biztonsági szemle
Neighboring Wi-Fi networks exploited in APT28 attack
After unsuccessfully exploiting the targeted organization's Wi-Fi credentials obtained via password spraying attacks due to multi-factor authentication, APT28 resorted to breaching other entities in close proximity before discovering a device within...

25 Nov 2024
Biztonsági szemle
Asia, Europe subjected to Russian cyberespionage campaign
TAG-110 leveraged vulnerable internet-exposed web apps and phishing emails to facilitate the delivery of the HATVIBE app loader that triggers that data exfiltrating CHERRYSPY backdoor.

25 Nov 2024
Biztonsági szemle
Social engineering becomes lucrative business for North Korean hackers
Deployment of credential and cryptocurrency stealing malware has been conducted by Sapphire Sleet not only through the impersonation of venture capitalists luring targets to join an online meeting about a supposed investment but also via fraudulent...

25 Nov 2024
Biztonsági szemle
Chinese hack of US telcos prompts White House meeting
Such an intrusion, which was noted to have involved attackers being deeply ingrained into certain telco networks, was regarded by Senate Intelligence Committee Chair Mark Warner, D-Va., to be the "worst telecom hack" in the U.S.

25 Nov 2024
Biztonsági szemle
The evolving rate of patch management and eISSU for financials
Learn how financial institutions can address ransomware and software and patch requirements to address public vulnerabilities.

25 Nov 2024
Biztonsági szemle
Closing the Cybersecurity Career Diversity Gap
Diversity isn't just an issue of fairness — it's about operational excellence and ensuring we have the best possible teams defending our national security.

25 Nov 2024
Biztonsági szemle
The strange case of disappearing Russian servers, (Mon, Nov 25th)
Few months ago, I noticed that something strange was happening with the number of servers seen by Shodan in Russia...
25 Nov 2024
Biztonsági szemle
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. CVE-2023-28461 Array Networks AG and vxAG ArrayOS Improper Authentication Vulnerability These types of vulnerabilities are...

24 Nov 2024
Biztonsági szemle
Quick & Dirty Obfuscated JavaScript Analysis, (Sun, Nov 24th)
As mentioned in diary entry " Increase In Phishing SVG Attachments", I have a phishing SVG sample with heavily obfuscated JavaScript.

23 Nov 2024
Biztonsági szemle
Decrypting a PDF With a User Password, (Sat, Nov 23rd)
In diary entry " Analyzing an Encrypted Phishing PDF", I decrypted a phishing PDF document. Because the PDF was encrypted for DRM (owner password), I didn&#39;t have to provide a password.

23 Nov 2024
Biztonsági szemle
Wireshark 4.4.2 Released, (Sat, Nov 23rd)
Wireshark release 4.4.2 fixes 2 vulnerabilities and 33 bugs.

22 Nov 2024
Biztonsági szemle
Bevy of smart doorbell bugs earn Ekon an FCC penalty for negligence
The US Federal Communications Commission (FCC) proposed a $734,872 penalty against a smart doorbell manufacturer that was anything but
Pagination
- Previous page ‹‹
- Page 356
- Next page ››