Category: Uncategorized
-

High-Severity Flaws Uncovered in Bosch Thermostats and Smart Nutrunners [email protected] (The Hacker News)
Multiple security vulnerabilities have been disclosed in Bosch BCC100 thermostats and Rexroth NXA015S-36V-B smart nutrunners that, if successfully exploited, could allow attackers to execute arbitrary code on affected systems. Romanian cybersecurity firm Bitdefender, which discovered the flaw in Bosch BCC100 thermostats last August, said the issue could be weaponized by an attacker toRead More
-

Balada Injector Infects Over 7,100 WordPress Sites Using Plugin Vulnerability [email protected] (The Hacker News)
Thousands of WordPress sites using a vulnerable version of the Popup Builder plugin have been compromised with a malware called Balada Injector. First documented by Doctor Web in January 2023, the campaign takes place in a series of periodic attack waves, weaponizing security flaws WordPress plugins to inject backdoor designed to redirect visitors of infected sites to bogus…
-

DDoS Attacks on the Environmental Services Industry Surge by 61,839% in 2023 [email protected] (The Hacker News)
The environmental services industry witnessed an “unprecedented surge” in HTTP-based distributed denial-of-service (DDoS) attacks, accounting for half of all its HTTP traffic. This marks a 61,839% increase in DDoS attack traffic year-over-year, web infrastructure and security company Cloudflare said in its DDoS threat report for 2023 Q4 published last week. “This surge in cyber attacks…
-

New Findings Challenge Attribution in Denmark’s Energy Sector Cyberattacks [email protected] (The Hacker News)
The cyber attacks targeting the energy sector in Denmark last year may not have had the involvement of the Russia-linked Sandworm hacking group, new findings from Forescout show. The intrusions, which targeted around 22 Danish energy organizations in May 2023, occurred in two distinct waves, one which exploited a security flaw in Zyxel firewall (CVE-2023-28771) and aRead More
-

Critical RCE Vulnerability Uncovered in Juniper SRX Firewalls and EX Switches [email protected] (The Hacker News)
Juniper Networks has released updates to fix a critical remote code execution (RCE) vulnerability in its SRX Series firewalls and EX Series switches. The issue, tracked as CVE-2024-21591, is rated 9.8 on the CVSS scoring system. “An out-of-bounds write vulnerability in J-Web of Juniper Networks Junos OS SRX Series and EX Series allows an unauthenticated, network-based…
-

29-Year-Old Ukrainian Cryptojacking Kingpin Arrested for Exploiting Cloud Services [email protected] (The Hacker News)
A 29-year-old Ukrainian national has been arrested in connection with running a “sophisticated cryptojacking scheme,” netting them over $2 million (€1.8 million) in illicit profits. The person was apprehended in Mykolaiv, Ukraine, on January 9 by the National Police of Ukraine with support from Europol and an unnamed cloud service provider following “months of intensive…
-
Brad Arkin is New Chief Trust Officer at Salesforce SecurityWeek News
Veteran cybersecurity leader Brad Arkin has left Cisco and is joining Salesforce as SVP and Chief Trust Officer. The post Brad Arkin is New Chief Trust Officer at Salesforce appeared first on SecurityWeek. Read More
-
Laptop Maker Framework Says Customer Data Stolen in Third-Party Breach Ionut Arghire
Device maker Framework is notifying users that their personal information was stolen in a data breach at its external accounting partner. The post Laptop Maker Framework Says Customer Data Stolen in Third-Party Breach appeared first on SecurityWeek. Read More
-

Nation-State Actors Weaponize Ivanti VPN Zero-Days, Deploying 5 Malware Families [email protected] (The Hacker News)
As many as five different malware families were deployed by suspected nation-state actors as part of post-exploitation activities leveraging two zero-day vulnerabilities in Ivanti Connect Secure (ICS) VPN appliances since early December 2023. “These families allow the threat actors to circumvent authentication and provide backdoor access to these devices,” Mandiant said in anRead More
-
In Other News: WEF’s Unsurprising Cybersecurity Findings, KyberSlash Cryptography Flaw SecurityWeek News
Noteworthy stories that might have slipped under the radar: WEF releases a cybersecurity report with unsurprising findings, and KyberSlash cryptography vulnerabilities. The post In Other News: WEF’s Unsurprising Cybersecurity Findings, KyberSlash Cryptography Flaw appeared first on SecurityWeek. Read More
