Category: Uncategorized
-
Top Guns: Defending Corporate Clouds from Malicious Mavericks Tom Eston
While applications and cloud infrastructure present different risk profiles and require different security assessments, they must not be viewed separately with regards to enterprise defense. The post Top Guns: Defending Corporate Clouds from Malicious Mavericks appeared first on SecurityWeek. Read More
-
Russian Pleads Guilty to Role in Developing TrickBot Malware Ionut Arghire
Russian national Vladimir Dunaev pleaded guilty to involvement in the development and use of the TrickBot malware that caused tens of millions of dollars in losses. The post Russian Pleads Guilty to Role in Developing TrickBot Malware appeared first on SecurityWeek. Read More
-
North Korean Hackers Have Stolen Over $3 Billion in Cryptocurrency: Report Ionut Arghire
Recorded Future calculates that North Korean state-sponsored threat actors are believed to have stolen more than $3 billion in cryptocurrency. The post North Korean Hackers Have Stolen Over $3 Billion in Cryptocurrency: Report appeared first on SecurityWeek. Read More
-

New BLUFFS Bluetooth Attack Expose Devices to Adversary-in-the-Middle Attacks [email protected] (The Hacker News)
New research has unearthed multiple novel attacks that break Bluetooth Classic’s forward secrecy and future secrecy guarantees, resulting in adversary-in-the-middle (AitM) scenarios between two already connected peers. The issues, collectively named BLUFFS, impact Bluetooth Core Specification 4.2 through 5.4. They are tracked under the identifier CVE-2023-24023 (CVSS score: 6.8)Read More
-
ICS at Multiple US Water Facilities Targeted by Hackers Affiliated With Iranian Government Eduard Kovacs
Security agencies say the Cyber Av3ngers group targeting ICS at multiple water facilities is affiliated with the Iranian government. The post ICS at Multiple US Water Facilities Targeted by Hackers Affiliated With Iranian Government appeared first on SecurityWeek. Read More
-
New Relic Says Hackers Accessed Internal Environment Using Stolen Credentials Ionut Arghire
New Relic said hackers gained access to an environment using social engineering and stolen credentials for an employee account. The post New Relic Says Hackers Accessed Internal Environment Using Stolen Credentials appeared first on SecurityWeek. Read More
-

Make a Fresh Start for 2024: Clean Out Your User Inventory to Reduce SaaS Risk [email protected] (The Hacker News)
As work ebbs with the typical end-of-year slowdown, now is a good time to review user roles and privileges and remove anyone who shouldn’t have access as well as trim unnecessary permissions. In addition to saving some unnecessary license fees, a clean user inventory significantly enhances the security of your SaaS applications. From reducing risk…
-

New P2PInfect Botnet MIPS Variant Targeting Routers and IoT Devices [email protected] (The Hacker News)
Cybersecurity researchers have discovered a new variant of an emerging botnet called P2PInfect that’s capable of targeting routers and IoT devices. The latest version, per Cado Security Labs, is compiled for Microprocessor without Interlocked Pipelined Stages (MIPS) architecture, broadening its capabilities and reach. “It’s highly likely that by targeting MIPS, the P2PInfect developersRead More
-

LogoFAIL: UEFI Vulnerabilities Expose Devices to Stealth Malware Attacks [email protected] (The Hacker News)
The Unified Extensible Firmware Interface (UEFI) code from various independent firmware/BIOS vendors (IBVs) has been found vulnerable to potential attacks through high-impact flaws in image parsing libraries embedded into the firmware. The shortcomings, collectively labeled LogoFAIL by Binarly, “can be used by threat actors to deliver a malicious payload and bypass Secure Boot, IntelRead More
-

Microsoft Warns of Malvertising Scheme Spreading CACTUS Ransomware [email protected] (The Hacker News)
Microsoft has warned of a new wave of CACTUS ransomware attacks that leverage malvertising lures to deploy DanaBot as an initial access vector. The DanaBot infections led to “hands-on-keyboard activity by ransomware operator Storm-0216 (Twisted Spider, UNC2198), culminating in the deployment of CACTUS ransomware,” the Microsoft Threat Intelligence team said in a series of posts on X…
