Security Bulletin

23 Sep 2024
Biztonsági szemle
MC2 Data leak exposes nearly a third of US population
The misconfiguration revealed more than 106 million records with U.S. citizens' private information and over 2.3 million MC2 Data subscribers' data.

23 Sep 2024
Biztonsági szemle
Significant hacktivist attacks launched against Russia
After obtaining initial access via local or domain account exploitation, Twelve proceeds to leverage Remote Desktop Protocol to facilitate further infrastructure penetration, as well as utilize other tools, including Cobalt Strike, Chisel, Mimikatz...

23 Sep 2024
Biztonsági szemle
Another Ivanti CSA vulnerability leveraged in ongoing attacks
Such a development comes less than a week after the confirmed exploitation of the high-severity operating system command injection bug in CSA, tracked as CVE-2024-8190, which was believed to have been used alongside another vulnerability due to its...

23 Sep 2024
Biztonsági szemle
New EAGLEDOOR backdoor spread in suspected Chinese APT attacks against Asia-Pacific
Aside from leveraging spear-phishing emails, Earth Baxia also exploited the recently addressed critical GeoServer GeoTools flaw, tracked as CVE-2024-36401.

23 Sep 2024
Biztonsági szemle
When it comes to solving the ongoing cybersecurity crisis in healthcare, don’t bet on Congress
Look for large state governments like New York to lead the way in addressing many of healthcare’s cybersecurity issues, not Congress.

23 Sep 2024
Biztonsági szemle
Phishing links with @ sign and the need for effective security awareness building, (Mon, Sep 23rd)
While going over a batch of phishing e-mails that were delivered to us here at the Internet Storm Center during the first half of September, I noticed one message which was somewhat unusual. Not because it was untypically sophisticated or because it...

23 Sep 2024
Biztonsági szemle
ISC Stormcast For Monday, September 23rd, 2024 https://isc.sans.edu/podcastdetail/9148, (Mon, Sep 23rd)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

23 Sep 2024
Biztonsági szemle
China's 'Earth Baxia' Spies Exploit Geoserver to Target APAC Orgs
The APT group uses spear-phishing and a vulnerability in a geospatial data-sharing server to compromise organizations in Taiwan, Japan, the Philippines, and South Korea.

21 Sep 2024
Biztonsági szemle
Ukraine government says ‘nyet’ to Telegram app
The Ukrainian government banned the Russian-owned Telegram app for official communications.

21 Sep 2024
Biztonsági szemle
CISA Releases Plan to Align Cybersecurity Across Federal Agencies
The FOCAL plan outlines baselines to synchronize cybersecurity priorities and policies across, as well as within, agencies.

20 Sep 2024
Biztonsági szemle
Ivanti's Cloud Service Appliance Attacked via Second Vuln
The critical bug, CVE-2024-8963, can be used in conjunction with the prior known flaw to achieve remote code execution (RCE).

20 Sep 2024
Biztonsági szemle
Citrine Sleet Poisons PyPI Packages With Mac & Linux Malware
A North Korean advanced persistent threat (APT) actor (aka Gleaming Pisces) tried to sneak simple backdoors into public software packages.
Pagination
- Previous page ‹‹
- Page 460
- Next page ››