Category: Uncategorized
-

Mastodon Vulnerability Allows Hackers to Hijack Any Decentralized Account [email protected] (The Hacker News)
The decentralized social network Mastodon has disclosed a critical security flaw that enables malicious actors to impersonate and take over any account. “Due to insufficient origin validation in all Mastodon, attackers can impersonate and take over any remote account,” the maintainers said in a terse advisory. The vulnerability, tracked as CVE-2024-23832, has a severity rating of…
-

AnyDesk Hacked: Popular Remote Desktop Software Mandates Password Reset [email protected] (The Hacker News)
Remote desktop software maker AnyDesk disclosed on Friday that it suffered a cyber attack that led to a compromise of its production systems. The German company said the incident, which it discovered following a security audit, is not a ransomware attack and that it has notified relevant authorities. “We have revoked all security-related certificates and…
-
US Slaps Sanctions on ‘Dangerous’ Iranian Hackers Linked to Water Utility Hacks Ryan Naraine
The US government slaps sanctions against six Iranian government officials linked to cyberattacks against Israeli PLC vendor Unitronics. The post US Slaps Sanctions on ‘Dangerous’ Iranian Hackers Linked to Water Utility Hacks appeared first on SecurityWeek. Read More
-
Layoffs Hit Security Vendors Okta, Proofpoint, Netography SecurityWeek News
Prominent security vendors Okta and Proofpoint announced layoffs affecting almost 1,000 employees in the United States and Israel. The post Layoffs Hit Security Vendors Okta, Proofpoint, Netography appeared first on SecurityWeek. Read More
-
Clorox Says Cyberattack Costs Exceed $49 Million Eduard Kovacs
Cleaning products maker Clorox puts the impact of the damaging cyberattack at $49 million so far and expects to incur more costs in 2024. The post Clorox Says Cyberattack Costs Exceed $49 Million appeared first on SecurityWeek. Read More
-
FTC Orders Blackbaud to Address Poor Security Practices Eduard Kovacs
FTC and fundraising software company Blackbaud reach settlement over poor security practices that led to a major data breach. The post FTC Orders Blackbaud to Address Poor Security Practices appeared first on SecurityWeek. Read More
-

Russian APT28 Hackers Targeting High-Value Orgs with NTLM Relay Attacks [email protected] (The Hacker News)
Russian state-sponsored actors have staged NT LAN Manager (NTLM) v2 hash relay attacks through various methods from April 2022 to November 2023, targeting high-value targets worldwide. The attacks, attributed to an “aggressive” hacking crew called APT28, have set their eyes on organizations dealing with foreign affairs, energy, defense, and transportation, as well as those involved withRead…
-
GenAI development should follow secure-by-design principles
Post ContentRead More
-
Cloudflare discloses breach related to stolen Okta data
Post ContentRead More
-

DirtyMoe Malware Infects 2,000+ Ukrainian Computers for DDoS and Cryptojacking [email protected] (The Hacker News)
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned that more than 2,000 computers in the country have been infected by a strain of malware called DirtyMoe. The agency attributed the campaign to a threat actor it calls UAC-0027. DirtyMoe, active since at least 2016, is capable of carrying out cryptojacking and distributed denial-of-service (DDoS) attacks. In…
