Category: Uncategorized
-

AWS Patches Critical ‘FlowFixation’ Bug in Airflow Service to Prevent Session Hijacking [email protected] (The Hacker News)
Cybersecurity researchers have shared details of a now-patched security vulnerability in Amazon Web Services (AWS) Managed Workflows for Apache Airflow (MWAA) that could be potentially exploited by a malicious actor to hijack victims’ sessions and achieve remote code execution on underlying instances. The vulnerability, now addressed by AWS, has been codenamed FlowFixation by Tenable.Read More
-
39,000 Websites Infected in ‘Sign1’ Malware Campaign Ionut Arghire
Over 39,000 websites have been infected with the Sign1 malware that redirects visitors to scam domains. The post 39,000 Websites Infected in ‘Sign1’ Malware Campaign appeared first on SecurityWeek. Read More
-
US Government Issues New DDoS Mitigation Guidance Ionut Arghire
CISA, the FBI, and MS-ISAC have released new guidance on how federal agencies can defend against DDoS attacks. The post US Government Issues New DDoS Mitigation Guidance appeared first on SecurityWeek. Read More
-

China-Linked Group Breaches Networks via Connectwise, F5 Software Flaws [email protected] (The Hacker News)
A China-linked threat cluster leveraged security flaws in Connectwise ScreenConnect and F5 BIG-IP software to deliver custom malware capable of delivering additional backdoors on compromised Linux hosts as part of an “aggressive” campaign. Google-owned Mandiant is tracking the activity under its uncategorized moniker UNC5174 (aka Uteus or Uetus), describing it as a “formerRead More
-

Massive Sign1 Campaign Infects 39,000+ WordPress Sites with Scam Redirects [email protected] (The Hacker News)
A massive malware campaign dubbed Sign1 has compromised over 39,000 WordPress sites in the last six months, using malicious JavaScript injections to redirect users to scam sites. The most recent variant of the malware is estimated to have infected no less than 2,500 sites over the past two months alone, Sucuri said in a report published this…
-

Implementing Zero Trust Controls for Compliance [email protected] (The Hacker News)
The ThreatLocker® Zero Trust Endpoint Protection Platform implements a strict deny-by-default, allow-by-exception security posture to give organizations the ability to set policy-based controls within their environment and mitigate countless cyber threats, including zero-days, unseen network footholds, and malware attacks as a direct result of user error. With the capabilities of theRead More
-
BlueFlag Security Emerges From Stealth With $11.5M in Funding Ionut Arghire
BlueFlag Security emerges from stealth mode with $11.5 million in a seed funding round led by Maverick Ventures and Ten Eleven Ventures. The post BlueFlag Security Emerges From Stealth With $11.5M in Funding appeared first on SecurityWeek. Read More
-
Saflok Lock Vulnerability Can Be Exploited to Open Millions of Doors Ionut Arghire
Vulnerability in Dormakaba’s Saflok electronic locks allow hackers to forge keycards and open millions of doors. The post Saflok Lock Vulnerability Can Be Exploited to Open Millions of Doors appeared first on SecurityWeek. Read More
-
New ‘GoFetch’ Apple CPU Attack Exposes Crypto Keys Eduard Kovacs
Researchers detail GoFetch, a new side-channel attack impacting Apple CPUs that could allow an attacker to obtain secret keys. The post New ‘GoFetch’ Apple CPU Attack Exposes Crypto Keys appeared first on SecurityWeek. Read More
-
Tesla, OS, Software Exploits Earn Hackers $1.1 Million at Pwn2Own 2024 Eduard Kovacs
Exploits targeting Tesla cars, operating systems, and popular software earned participants over $1.1 million at Pwn2Own Vancouver 2024. The post Tesla, OS, Software Exploits Earn Hackers $1.1 Million at Pwn2Own 2024 appeared first on SecurityWeek. Read More
