Category: Uncategorized
-

APT28 Hacker Group Targeting Europe, Americas, Asia in Widespread Phishing Scheme [email protected] (The Hacker News)
The Russia-linked threat actor known as APT28 has been linked to multiple ongoing phishing campaigns that employ lure documents imitating government and non-governmental organizations (NGOs) in Europe, the South Caucasus, Central Asia, and North and South America. “The uncovered lures include a mixture of internal and publicly available documents, as well as possible actor-generatedRead More
-

Hackers Using Cracked Software on GitHub to Spread RisePro Info Stealer [email protected] (The Hacker News)
Cybersecurity researchers have found a number of GitHub repositories offering cracked software that are used to deliver an information stealer called RisePro. The campaign, codenamed gitgub, includes 17 repositories associated with 11 different accounts, according to G DATA. The repositories in question have since been taken down by the Microsoft-owned subsidiary. “The repositories lookRead More
-

GhostRace – New Data Leak Vulnerability Affects Modern CPUs [email protected] (The Hacker News)
A group of researchers has discovered a new data leakage attack impacting modern CPU architectures supporting speculative execution. Dubbed GhostRace (CVE-2024-2193), it is a variation of the transient execution CPU vulnerability known as Spectre v1 (CVE-2017-5753). The approach combines speculative execution and race conditions. “All the common synchronization primitives implementedRead More
-
Codezero Raises $3.5 Million for DevOps Security Solution Ionut Arghire
Secure enterprise microservices development firm Codezero raises $3.5 million in seed funding. The post Codezero Raises $3.5 Million for DevOps Security Solution appeared first on SecurityWeek. Read More
-
In Other News: CISA Hacked, Chinese Lock Backdoors, Exposed Secrets SecurityWeek News
Noteworthy stories that might have slipped under the radar: CISA hacked via Ivanti vulnerabilities, Chinese electronic lock backdoors, secrets exposed on GitHub. The post In Other News: CISA Hacked, Chinese Lock Backdoors, Exposed Secrets appeared first on SecurityWeek. Read More
-
Discontinued Security Plugins Expose Many WordPress Sites to Takeover Ionut Arghire
Thousands of WordPress sites are at risk of takeover due to a critical privilege escalation vulnerability in two closed MiniOrange plugins. The post Discontinued Security Plugins Expose Many WordPress Sites to Takeover appeared first on SecurityWeek. Read More
-

Third-Party ChatGPT Plugins Could Lead to Account Takeovers [email protected] (The Hacker News)
Cybersecurity researchers have found that third-party plugins available for OpenAI ChatGPT could act as a new attack surface for threat actors looking to gain unauthorized access to sensitive data. According to new research published by Salt Labs, security flaws found directly in ChatGPT and within the ecosystem could allow attackers to install malicious plugins without users’ consentRead…
-
Tech Support Firms Agree to $26M FTC Settlement Over Fake Services Ionut Arghire
Restoro and Reimage agree to a $26 million settlement after selling fake antivirus and tech services to undercover FTC agents. The post Tech Support Firms Agree to $26M FTC Settlement Over Fake Services appeared first on SecurityWeek. Read More
-
43 Million Possibly Impacted by French Government Agency Data Breach Eduard Kovacs
Recent data breach at unemployment agency France Travail (Pôle Emploi) could impact 43 million people. The post 43 Million Possibly Impacted by French Government Agency Data Breach appeared first on SecurityWeek. Read More
-
Threat Detection Report: Cloud Attacks Soar, Mac Threats and Malvertising Escalate Kevin Townsend
Red Canary’s 2024 Threat Detection Report is based on analysis of almost 60,000 threats across 216 petabytes of telemetry from over 1,000 customers’ endpoints. The post Threat Detection Report: Cloud Attacks Soar, Mac Threats and Malvertising Escalate appeared first on SecurityWeek. Read More
