Category: Uncategorized
-

Cybersecurity for Healthcare—Diagnosing the Threat Landscape and Prescribing Solutions for Recovery [email protected] (The Hacker News)
On Thanksgiving Day 2023, while many Americans were celebrating, hospitals across the U.S. were doing quite the opposite. Systems were failing. Ambulances were diverted. Care was impaired. Hospitals in three states were hit by a ransomware attack, and in that moment, the real-world repercussions came to light—it wasn’t just computer networks that were brought to a…
-

New ‘VietCredCare’ Stealer Targeting Facebook Advertisers in Vietnam [email protected] (The Hacker News)
Facebook advertisers in Vietnam are the target of a previously unknown information stealer dubbed VietCredCare at least since August 2022. The malware is “notable for its ability to automatically filter out Facebook session cookies and credentials stolen from compromised devices, and assess whether these accounts manage business profiles and if they maintain a positive Meta ad creditRead…
-

Signal Introduces Usernames, Allowing Users to Keep Their Phone Numbers Private [email protected] (The Hacker News)
End-to-end encrypted (E2EE) messaging app Signal said it’s piloting a new feature that allows users to create unique usernames (not to be confused with profile names) and keep the phone numbers away from prying eyes. “If you use Signal, your phone number will no longer be visible to everyone you chat with by default,” Signal’s…
-

Russian Hackers Target Ukraine with Disinformation and Credential-Harvesting Attacks [email protected] (The Hacker News)
Cybersecurity researchers have unearthed a new influence operation targeting Ukraine that leverages spam emails to propagate war-related disinformation. The activity has been linked to Russia-aligned threat actors by Slovak cybersecurity company ESET, which also identified a spear-phishing campaign aimed at a Ukrainian defense company in October 2023 and a European Union agency in November 2023Read…
-

VMware Alert: Uninstall EAP Now – Critical Flaw Puts Active Directory at Risk [email protected] (The Hacker News)
VMware is urging users to uninstall the deprecated Enhanced Authentication Plugin (EAP) following the discovery of a critical security flaw. Tracked as CVE-2024-22245 (CVSS score: 9.6), the vulnerability has been described as an arbitrary authentication relay bug. “A malicious actor could trick a target domain user with EAP installed in their web browser into requesting and relayingRead…
-
Ransomware Declines as InfoStealers and AI Threats Gain Ground: IBM X-Force Kevin Townsend
The ransomware threat is declining as actors pivot to infostealing, according to IBM, which says that attacks on cloud services and critical infrastructures are growing. The post Ransomware Declines as InfoStealers and AI Threats Gain Ground: IBM X-Force appeared first on SecurityWeek. Read More
-
ConnectWise Rushes to Patch Critical Vulns in Remote Access Tool Ryan Naraine
ConnectWise ships patches for extremely critical security defects in its ScreenConnect remote desktop access product and urges emergency patching. The post ConnectWise Rushes to Patch Critical Vulns in Remote Access Tool appeared first on SecurityWeek. Read More
-

New Migo Malware Targeting Redis Servers for Cryptocurrency Mining [email protected] (The Hacker News)
A novel malware campaign has been observed targeting Redis servers for initial access with the ultimate goal of mining cryptocurrency on compromised Linux hosts. “This particular campaign involves the use of a number of novel system weakening techniques against the data store itself,” Cado security researcher Matt Muir said in a technical report. The cryptojacking attack is…
-
Recent Zero-Day Could Impact Up to 97,000 Microsoft Exchange Servers Ionut Arghire
Shadowserver Foundation has identified roughly 28,000 Microsoft Exchange servers impacted by a recent zero-day. The post Recent Zero-Day Could Impact Up to 97,000 Microsoft Exchange Servers appeared first on SecurityWeek. Read More
-
Cyber Insights 2024: Supply Chain Kevin Townsend
Supply chain security insights: A successful attack against a supplier can lead to multiple opportunities against the supplier’s downstream customers. The post Cyber Insights 2024: Supply Chain appeared first on SecurityWeek. Read More
