Security Bulletin
14 Dec 2024
Biztonsági szemle
PDQ Deploy users warned of credential-theft risk
An attacker with local access can grab admin credentials from active memory prior to deletion.
13 Dec 2024
Biztonsági szemle
Immediate patching of actively exploited Cleo flaw urged
Immediate blocking of IP addresses leveraging the issue has also been recommended by Cleo.
13 Dec 2024
Biztonsági szemle
Byte Federal breach exposes 58K clients
Infiltration of Byte Federal's systems exposed individuals' full names, birthdates, physical addresses, email addresses, phone numbers, Social Security numbers, government-issued IDs, photos, and transaction activity, according to the firm's data...
13 Dec 2024
Biztonsági szemle
DoS attacks, data compromise threaten over 330K Prometheus instances
Aside from disrupting servers through a deluge of requests to "debug/pprof/heap" and other endpoints, attackers could also exploit Prometheus' "metrics" endpoint to obtain information from internal API endpoints, Docker registries, subdomains, and...
13 Dec 2024
Biztonsági szemle
Upstart Pumakit Linux rootkit malware examined
Attacks with Pumakit commence with the deployment of the cron dropper, which executes the '/memfd:tgt' and '/memfd:wpn' payloads, with the former eventually launching the 'puma.ko' LKM rootkit module that loads only after ensuring secure boot status...
13 Dec 2024
Biztonsági szemle
New BoneSpy, PlainGnome Android spyware deployed by Gamaredon
Malicious battery charge tracking and photo gallery apps, as well as a phony Samsung Knox app and trojanized Telegram app, have been leveraged to distribute the similar BoneSpy and PlainGnome spyware, which facilitate compromise of device location...
13 Dec 2024
Biztonsági szemle
US, Israeli critical infrastructure subjected to attacks with novel IOCONTROL malware
Identified within a Gasboy fuel control system's payment terminal believed to have been targeted by the Iranian state-backed operation CyberAv3ngers, IOCONTROL features a modular configuration and sophisticated script enabling the persistent...
13 Dec 2024
Biztonsági szemle
US indicts, puts up bounty for North Koreans over IT worker fraud scheme
At least $88 million have already been earned by North Korean state-sponsored firms Yanbian Silverstar and Volasys Silverstar for leading operations of the six-year fraud scheme, which involved fake IT workers leveraging sophisticated obfuscation...
13 Dec 2024
Biztonsági szemle
Zerto Introduces Cloud Vault Solution for Enhanced Cyber Resilience Through MSPs
13 Dec 2024
Biztonsági szemle
Versa Introduces Integrated Endpoint Data Loss Prevention in SASE Solution
13 Dec 2024
Biztonsági szemle
Cleo MFT Zero-Day Exploits Are About Escalate, Analysts Warn
Defenders running the Cleo managed file transfer are urged to be on the lookout for the Cleopatra backdoor and other indicators of an ongoing ransomware campaign, as patching details remain foggy, and no CVE has been issued.
13 Dec 2024
Biztonsági szemle
Rydox data market trading in personal info shut down; feds arrest 3
DOJ announced that two arrested in Kosovo, a third in Albania tied to Rydox dark market website.
Pagination
- Previous page ‹‹
- Page 16
- Next page ››