Category: Uncategorized
-

New Security Vulnerabilities Uncovered in pfSense Firewall Software – Patch Now [email protected] (The Hacker News)
Multiple security vulnerabilities have been discovered in the open-source Netgate pfSense firewall solution called pfSense that could be chained by an attacker to execute arbitrary commands on susceptible appliances. The issues relate to two reflected cross-site scripting (XSS) bugs and one command injection flaw, according to new findings from Sonar. “Security inside a local network…
-
Recent Apache Struts 2 Vulnerability in Attacker Crosshairs Ionut Arghire
Attackers are attempting to exploit a critical RCE flaw in Apache Struts 2 after researchers publish PoC code. The post Recent Apache Struts 2 Vulnerability in Attacker Crosshairs appeared first on SecurityWeek. Read More
-
Food Giant Kraft Heinz Targeted by Ransomware Group Eduard Kovacs
A ransomware group claims to have breached the systems of Kraft Heinz, but the food giant says it’s unable to verify the claims. The post Food Giant Kraft Heinz Targeted by Ransomware Group appeared first on SecurityWeek. Read More
-

Google’s New Tracking Protection in Chrome Blocks Third-Party Cookies [email protected] (The Hacker News)
Google on Thursday announced that it will start testing a new feature called “Tracking Protection” starting January 4, 2024, to 1% of Chrome users as part of its efforts to deprecate third-party cookies in the web browser. The setting is designed to limit “cross-site tracking by restricting website access to third-party cookies by default,” Anthony Chavez, vice…
-

New NKAbuse Malware Exploits NKN Blockchain Tech for DDoS Attacks [email protected] (The Hacker News)
A novel multi-platform threat called NKAbuse has been discovered using a decentralized, peer-to-peer network connectivity protocol known as NKN (short for New Kind of Network) as a communications channel. “The malware utilizes NKN technology for data exchange between peers, functioning as a potent implant, and equipped with both flooder and backdoor capabilities,” RussianRead More
-
Russian APT exploiting JetBrains TeamCity vulnerability
Post ContentRead More
-

116 Malware Packages Found on PyPI Repository Infecting Windows and Linux Systems [email protected] (The Hacker News)
Cybersecurity researchers have identified a set of 116 malicious packages on the Python Package Index (PyPI) repository that are designed to infect Windows and Linux systems with a custom backdoor. “In some cases, the final payload is a variant of the infamous W4SP Stealer, or a simple clipboard monitor to steal cryptocurrency, or both,” ESET researchers…
-
New Threat Actor Uses SQL Injection Attacks to Steal Data From APAC Companies Ionut Arghire
GambleForce uses SQL injections to hack gambling, government, retail, and travel websites to steal sensitive information. The post New Threat Actor Uses SQL Injection Attacks to Steal Data From APAC Companies appeared first on SecurityWeek. Read More
-

New Pierogi++ Malware by Gaza Cyber Gang Targeting Palestinian Entities [email protected] (The Hacker News)
A pro-Hamas threat actor known as Gaza Cyber Gang is targeting Palestinian entities using an updated version of a backdoor dubbed Pierogi. The findings come from SentinelOne, which has given the malware the name Pierogi++ owing to the fact that it’s implemented in the C++ programming language unlike its Delphi- and Pascal-based predecessor. “Recent Gaza Cybergang activities…
-

Iranian State-Sponsored OilRig Group Deploys 3 New Malware Downloaders [email protected] (The Hacker News)
The Iranian state-sponsored threat actor known as OilRig deployed three different downloader malware throughout 2022 to maintain persistent access to victim organizations located in Israel. The three new downloaders have been named ODAgent, OilCheck, and OilBooster by Slovak cybersecurity company ESET. The attacks also involved the use of an updated version of a known OilRig downloaderRead More
