Category: Uncategorized
-

Turla Updates Kazuar Backdoor with Advanced Anti-Analysis to Evade Detection [email protected] (The Hacker News)
The Russia-linked hacking crew known as Turla has been observed using an updated version of a known second-stage backdoor referred to as Kazuar. The new findings come from Palo Alto Networks Unit 42, which is tracking the adversary under its constellation-themed moniker Pensive Ursa. “As the code of the upgraded revision of Kazuar reveals, the authors…
-

Alert: F5 Warns of Active Attacks Exploiting BIG-IP Vulnerability [email protected] (The Hacker News)
F5 is warning of active abuse of a critical security flaw in BIG-IP less than a week after its public disclosure that could result in the execution of arbitrary system commands as part of an exploit chain. Tracked as CVE-2023-46747 (CVSS score: 9.8), the vulnerability allows an unauthenticated attacker with network access to the BIG-IP system through the management…
-
Cybersecurity Leaders Spooked by SEC Lawsuit Against SolarWinds CISO Mike Lennon
The SEC’s lawsuit against the CISO of SolarWinds is leaving CISOs across the industry spooked and reevaluating their roles. The post Cybersecurity Leaders Spooked by SEC Lawsuit Against SolarWinds CISO appeared first on SecurityWeek. Read More
-
Palo Alto Networks to Acquire Cloud Security Start-Up Dig Security SecurityWeek News
Palo Alto Networks has entered into a definitive agreement to acquire Dig Security, a provider of Data Security Posture Management (DSPM) technology. The post Palo Alto Networks to Acquire Cloud Security Start-Up Dig Security appeared first on SecurityWeek. Read More
-
Atlassian CISO Urges Quick Action to Protect Confluence Instances From Critical Vulnerability Ionut Arghire
Atlassian warns that a critical vulnerability in Confluence Data Center and Server could lead to significant data loss if exploited. The post Atlassian CISO Urges Quick Action to Protect Confluence Instances From Critical Vulnerability appeared first on SecurityWeek. Read More
-
No patches yet for Apple iLeakage side-channel attack
Post ContentRead More
-
IAM Credentials in Public GitHub Repositories Harvested in Minutes Ionut Arghire
A threat actor is reportedly harvesting IAM credentials from public GitHub repositories within five minutes of exposure. The post IAM Credentials in Public GitHub Repositories Harvested in Minutes appeared first on SecurityWeek. Read More
-
Attackers Exploiting Critical F5 BIG-IP Vulnerability Ionut Arghire
Exploitation of a critical vulnerability (CVE-2023-46747) in F5’s BIG-IP product started less than five days after public disclosure and PoC exploit code was published. The post Attackers Exploiting Critical F5 BIG-IP Vulnerability appeared first on SecurityWeek. Read More
-
SEC charges SolarWinds for security failures, fraud
Post ContentRead More
-

Arid Viper Targeting Arabic Android Users with Spyware Disguised as Dating App [email protected] (The Hacker News)
The threat actor known as Arid Viper (aka APT-C-23, Desert Falcon, or TAG-63) has been attributed as behind an Android spyware campaign targeting Arabic-speaking users with a counterfeit dating app designed to harvest data from infected handsets. “Arid Viper’s Android malware has a number of features that enable the operators to surreptitiously collect sensitive information from victims’…
