Category: Uncategorized
-
In Other News: Ubisoft Hack, NASA Security Guidance, TikTok Requests iPhone Passcode SecurityWeek News
Noteworthy stories that might have slipped under the radar: Ubisoft investigating alleged hack, NASA releases security guidance, TikTok scares iPhone users. The post In Other News: Ubisoft Hack, NASA Security Guidance, TikTok Requests iPhone Passcode appeared first on SecurityWeek. Read More
-
Pentagon Wants Feedback on Revised Cybersecurity Maturity Model Certification Program Ionut Arghire
DoD is requesting public opinion on proposed changes to the Cybersecurity Maturity Model Certification program rules. The post Pentagon Wants Feedback on Revised Cybersecurity Maturity Model Certification Program appeared first on SecurityWeek. Read More
-
Vulnerabilities in Google Kubernetes Engine Could Allow Cluster Takeover Ionut Arghire
Two flaws in Google Kubernetes Engine could be exploited to escalate privileges and take over the Kubernetes cluster. The post Vulnerabilities in Google Kubernetes Engine Could Allow Cluster Takeover appeared first on SecurityWeek. Read More
-
Critical Apache OFBiz Vulnerability in Attacker Crosshairs Eduard Kovacs
Shadowserver sees possible in-the-wild exploitation of a critical Apache OFBiz vulnerability tracked as CVE-2023-49070. The post Critical Apache OFBiz Vulnerability in Attacker Crosshairs appeared first on SecurityWeek. Read More
-

CERT-UA Uncovers New Malware Wave Distributing OCEANMAP, MASEPIE, STEELHOOK [email protected] (The Hacker News)
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new phishing campaign orchestrated by the Russia-linked APT28 group to deploy previously undocumented malware such as OCEANMAP, MASEPIE, and STEELHOOK to harvest sensitive information. The activity, which was detected by the agency between December 15 and 25, 2023, targets government entitiesRead More
-
Europe’s Largest Parking App Provider Informs Customers of Data Breach Eduard Kovacs
EasyPark says hackers stole European customer information, including partial IBAN or payment card numbers. The post Europe’s Largest Parking App Provider Informs Customers of Data Breach appeared first on SecurityWeek. Read More
-
Operations, Trading of Eagers Automotive Disrupted by Cyberattack Eduard Kovacs
Eagers Automotive, a vehicle dealer in Australia and New Zealand, has halted trading after being targeted in a cyberattack. The post Operations, Trading of Eagers Automotive Disrupted by Cyberattack appeared first on SecurityWeek. Read More
-

Kimsuky Hackers Deploying AppleSeed, Meterpreter, and TinyNuke in Latest Attacks [email protected] (The Hacker News)
Nation-state actors affiliated to North Korea have been observed using spear-phishing attacks to deliver an assortment of backdoors and tools such as AppleSeed, Meterpreter, and TinyNuke to seize control of compromised machines. South Korea-based cybersecurity company AhnLab attributed the activity to an advanced persistent threat group known as Kimsuky. “A notable point about attacks thatRead More
-

Microsoft Disables MSIX App Installer Protocol Widely Used in Malware Attacks [email protected] (The Hacker News)
Microsoft on Thursday said it’s once again disabling the ms-appinstaller protocol handler by default following its abuse by multiple threat actors to distribute malware. “The observed threat actor activity abuses the current implementation of the ms-appinstaller protocol handler as an access vector for malware that may lead to ransomware distribution,” the Microsoft Threat IntelligenceRead More
-
Cyberattack Targets Albanian Parliament’s Data System, Halting Its Work Associated Press
Albania’s Parliament said it had suffered a cyberattack with hackers trying to get into its data system, resulting in a temporary halt in its services. The post Cyberattack Targets Albanian Parliament’s Data System, Halting Its Work appeared first on SecurityWeek. Read More
