Category: Uncategorized
-

Microsoft Warns of Hackers Exploiting OAuth for Cryptocurrency Mining and Phishing [email protected] (The Hacker News)
Microsoft has warned that adversaries are using OAuth applications as an automation tool to deploy virtual machines (VMs) for cryptocurrency mining and launch phishing attacks. “Threat actors compromise user accounts to create, modify, and grant high privileges to OAuth applications that they can misuse to hide malicious activity,” the Microsoft Threat Intelligence team said in anRead More
-

Major Cyber Attack Paralyzes Kyivstar – Ukraine’s Largest Telecom Operator [email protected] (The Hacker News)
Ukraine’s biggest telecom operator Kyivstar has become the victim of a cyber attack, disrupting customer access to mobile and internet services. “The cyberattack on Ukraine’s #Kyivstar telecoms operator has impacted all regions of the country with high impact to the capital, metrics show, with knock-on impacts reported to air raid alert network and banking sector as work continuesRead…
-
Sophos Patches EOL Firewalls Against Exploited Vulnerability Ionut Arghire
Sophos has patched EOL Firewall versions against a critical flaw exploited in the wild, after identifying a new exploit. The post Sophos Patches EOL Firewalls Against Exploited Vulnerability appeared first on SecurityWeek. Read More
-
How ransomware gangs are engaging — and using — the media
Post ContentRead More
-

Microsoft’s Final 2023 Patch Tuesday: 33 Flaws Fixed, Including 4 Critical [email protected] (The Hacker News)
Microsoft released its final set of Patch Tuesday updates for 2023, closing out 33 flaws in its software, making it one of the lightest releases in recent years. Of the 33 shortcomings, four are rated Critical and 29 are rated Important in severity. The fixes are in addition to 18 flaws Microsoft addressed in its Chromium-based Edge browser since…
-
Lazarus RAT Attack (CVE-2021-44228)
What is the Attack? A new attack campaign led by the Lazarus threat actor group is seen employing new DLang-based Remote Access Trojan (RAT) malware. The attack attempt to exploit the Apache Log4j2 vulnerability (CVE-2021-44228) as initial access. Once compromised, it eventually creates a command and control (C2) channel. What is the Vendor Solution? Apache…
-
Cyberattack Cripples Ukraine’s Largest Telcom Operator SecurityWeek News
Kyivstar, the largest mobile network operator in Ukraine, was hit by a massive cyberattack on Tuesday, disrupting mobile and internet communications for millions of citizens. The post Cyberattack Cripples Ukraine’s Largest Telcom Operator appeared first on SecurityWeek. Read More
-
Microsoft Patch Tuesday: Critical Spoofing and Remote Code Execution Flaws Ryan Naraine
Microsoft warns of critical spoofing and remote code execution bugs in the Windows MSHTML Platform and Microsoft Power Platform Connector. The post Microsoft Patch Tuesday: Critical Spoofing and Remote Code Execution Flaws appeared first on SecurityWeek. Read More
-
Adobe Patches 207 Security Bugs in Mega Patch Tuesday Bundle Ryan Naraine
Adobe warned users on both Windows and macOS systems about exposure to code execution, memory leaks and denial-of-service security issues. The post Adobe Patches 207 Security Bugs in Mega Patch Tuesday Bundle appeared first on SecurityWeek. Read More
-
Lazarus RAT Attack
A new campaign conducted by the Lazarus Group is seen employing new DLang-based Remote Access Trojans (RATs) malware in the wild. The APT groups has been seen to target manufacturing, agricultural and physical security companies by exploiting the Log4j vulnerability and using it for initial access leading to a C2 (command and control) channel with…
