Category: Uncategorized
-
Exploitation of Critical Confluence Vulnerability Begins Ionut Arghire
Threat actors have started exploiting a recent critical vulnerability in Confluence Data Center and Confluence Server. The post Exploitation of Critical Confluence Vulnerability Begins appeared first on SecurityWeek. Read More
-
Iranian APT Targets Israeli Education, Tech Sectors With New Wipers Ionut Arghire
The Iran-linked APT Agrius has been targeting higher education and technology organizations in Israel with new wipers. The post Iranian APT Targets Israeli Education, Tech Sectors With New Wipers appeared first on SecurityWeek. Read More
-

Iranian Hackers Launches Destructive Cyberattacks on Israeli Tech and Education Sectors [email protected] (The Hacker News)
Israeli higher education and tech sectors have been targeted as part of a series of destructive cyber attacks that commenced in January 2023 with an aim to deploy previously undocumented wiper malware. The intrusions, which took place as recently as October, have been attributed to an Iranian nation-state hacking crew it tracks under the name…
-
Microsoft Says Exchange ‘Zero Days’ Disclosed by ZDI Already Patched or Not Urgent Eduard Kovacs
Microsoft says four Exchange ‘zero-days’ disclosed by ZDI have either already been patched or they don’t require immediate attention. The post Microsoft Says Exchange ‘Zero Days’ Disclosed by ZDI Already Patched or Not Urgent appeared first on SecurityWeek. Read More
-
A Cyber Breach Delays Poll Worker Training in Mississippi’s Largest County Before the Statewide Vote Associated Press
Election officials in Mississippi’s most populous county had to scramble to complete required poll worker training after an early September breach involving county computers. The post A Cyber Breach Delays Poll Worker Training in Mississippi’s Largest County Before the Statewide Vote appeared first on SecurityWeek. Read More
-

Google Warns How Hackers Could Abuse Calendar Service as a Covert C2 Channel [email protected] (The Hacker News)
Google is warning of multiple threat actors sharing a public proof-of-concept (PoC) exploit that leverages its Calendar service to host command-and-control (C2) infrastructure. The tool, called Google Calendar RAT (GCR), employs Google Calendar Events for C2 using a Gmail account. It was first published to GitHub in June 2023. “The script creates a ‘Covert Channel’…
-

U.S. Treasury Targets Russian Money Launderer in Cybercrime Crackdown [email protected] (The Hacker News)
The U.S. Department of the Treasury imposed sanctions against a Russian woman for taking part in the laundering of virtual currency for the country’s elites and cybercriminal crews, including the Ryuk ransomware group. Ekaterina Zhdanova, per the department, is said to have facilitated large cross border transactions to assist Russian individuals to gain access to…
-

StripedFly Malware Operated Unnoticed for 5 Years, Infecting 1 Million Devices [email protected] (The Hacker News)
An advanced strain of malware masquerading as a cryptocurrency miner has managed to fly the radar for over five years, infecting no less than one million devices around the world in the process. That’s according to findings from Kaspersky, which has codenamed the threat StripedFly, describing it as an “intricate modular framework that supports both Linux…
-

Okta’s Recent Customer Support Data Breach Impacted 134 Customers [email protected] (The Hacker News)
Identity and authentication management provider Okta on Friday disclosed that the recent support case management system breach affected 134 of its 18,400 customers. It further noted that the unauthorized intruder gained access to its systems from September 28 to October 17, 2023, and ultimately accessed HAR files containing session tokens that could be used for session hijacking…
-

Google Play Store Introduces ‘Independent Security Review’ Badge for Apps [email protected] (The Hacker News)
Google is rolling out an “Independent security review” badge in the Play Store’s Data safety section for Android apps that have undergone a Mobile Application Security Assessment (MASA) audit. “We’ve launched this banner beginning with VPN apps due to the sensitive and significant amount of user data these apps handle,” Nataliya Stanetsky of the Android Security and…
