Category: Uncategorized
-

BianLian Threat Actors Exploiting JetBrains TeamCity Flaws in Ransomware Attacks [email protected] (The Hacker News)
The threat actors behind the BianLian ransomware have been observed exploiting security flaws in JetBrains TeamCity software to conduct their extortion-only attacks. According to a new report from GuidePoint Security, which responded to a recent intrusion, the incident “began with the exploitation of a TeamCity server which resulted in the deployment of a PowerShell implementation ofRead More
-

Proof-of-Concept Exploit Released for Progress Software OpenEdge Vulnerability [email protected] (The Hacker News)
Technical specifics and a proof-of-concept (PoC) exploit have been made available for a recently disclosed critical security flaw in Progress Software OpenEdge Authentication Gateway and AdminServer, which could be potentially exploited to bypass authentication protections. Tracked as CVE-2024-1403, the vulnerability has a maximum severity rating of 10.0 on the CVSS scoring system. ItRead More
-

Magnet Goblin Hacker Group Leveraging 1-Day Exploits to Deploy Nerbian RAT [email protected] (The Hacker News)
A financially motivated threat actor called Magnet Goblin is swiftly adopting one-day security vulnerabilities into its arsenal in order to opportunistically breach edge devices and public-facing services and deploy malware on compromised hosts. “Threat actor group Magnet Goblin’s hallmark is its ability to swiftly leverage newly disclosed vulnerabilities, particularly targetingRead More
-

Microsoft Confirms Russian Hackers Stole Source Code, Some Customer Secrets [email protected] (The Hacker News)
Microsoft on Friday revealed that the Kremlin-backed threat actor known as Midnight Blizzard (aka APT29 or Cozy Bear) managed to gain access to some of its source code repositories and internal systems following a hack that came to light in January 2024. “In recent weeks, we have seen evidence that Midnight Blizzard is using information initially exfiltrated from ourRead…
-
Microsoft Says Russian Gov Hackers Stole Source Code After Spying on Executive Emails Ryan Naraine
Microsoft says the Midnight Blizzard APT group may still be poking around its internal network after stealing source code, spying on emails. The post Microsoft Says Russian Gov Hackers Stole Source Code After Spying on Executive Emails appeared first on SecurityWeek. Read More
-
CISA Outlines Efforts to Secure Open Source Software Ionut Arghire
Concluding a two-day OSS security summit, CISA details key actions to help improve open source security. The post CISA Outlines Efforts to Secure Open Source Software appeared first on SecurityWeek. Read More
-
Reach Security Raises $20M to Help Manage Cybersecurity Products Ryan Naraine
California startup banks $20 million Series A financing for technology to help businesses manage the maze of security tools and products. The post Reach Security Raises $20M to Help Manage Cybersecurity Products appeared first on SecurityWeek. Read More
-
Defense Unicorns Raises $35 Million for National Security Software Solutions Ionut Arghire
Sapphire Ventures and Ansa Capital have invested $35 million in national security systems software startup Defense Unicorns. The post Defense Unicorns Raises $35 Million for National Security Software Solutions appeared first on SecurityWeek. Read More
-
In Other News: Google AI Hacking, Font Vulnerabilities, IBM Training Facility SecurityWeek News
Noteworthy stories that might have slipped under the radar: Google AI bug bounties, font vulnerabilities, IBM opens new training facility. The post In Other News: Google AI Hacking, Font Vulnerabilities, IBM Training Facility appeared first on SecurityWeek. Read More
-
Change Healthcare Restores Pharmacy Services Disrupted by Ransomware Ionut Arghire
Change Healthcare says it has made significant progress in restoring systems impacted by a recent ransomware attack. The post Change Healthcare Restores Pharmacy Services Disrupted by Ransomware appeared first on SecurityWeek. Read More
