Category: Uncategorized
-
One-Click GNOME Exploit Could Pose Serious Threat to Linux Systems Eduard Kovacs
A one-click exploit targeting the Libcue component of the GNOME desktop environment could pose a serious threat to Linux systems. The post One-Click GNOME Exploit Could Pose Serious Threat to Linux Systems appeared first on SecurityWeek. Read More
-
Magecart Web Skimmer Hides in 404 Error Pages Ionut Arghire
A newly identified Magecart web skimming campaign is tampering with ‘404’ error pages to hide malicious code. The post Magecart Web Skimmer Hides in 404 Error Pages appeared first on SecurityWeek. Read More
-
Cable Giant Volex Targeted in Cyberattack Eduard Kovacs
UK-based cable manufacturing giant Volex has been targeted in a cyberattack that involved unauthorized access to IT systems and data. The post Cable Giant Volex Targeted in Cyberattack appeared first on SecurityWeek. Read More
-
Researcher Conversations: Natalie Silvanovich From Google’s Project Zero Kevin Townsend
SecurityWeek continues its Hacker Conversations series in a discussion with Natalie Silvanovich, a member of of Google’s Project Zero. The post Researcher Conversations: Natalie Silvanovich From Google’s Project Zero appeared first on SecurityWeek. Read More
-

New Report: Child Sexual Abuse Content and Online Risks to Children on the Rise [email protected] (The Hacker News)
Certain online risks to children are on the rise, according to a recent report from Thorn, a technology nonprofit whose mission is to build technology to defend children from sexual abuse. Research shared in the Emerging Online Trends in Child Sexual Abuse 2023 report, indicates that minors are increasingly taking and sharing sexual images of themselves.…
-

Researchers Uncover Grayling APT’s Ongoing Attack Campaign Across Industries [email protected] (The Hacker News)
A previously undocumented threat actor of unknown provenance has been linked to a number of attacks targeting organizations in the manufacturing, IT, and biomedical sectors in Taiwan. The Symantec Threat Hunter Team, part of Broadcom, attributed the attacks to an advanced persistent threat (APT) it tracks under the name Grayling. Evidence shows that the campaign began…
-

New Magecart Campaign Alters 404 Error Pages to Steal Shoppers’ Credit Cards [email protected] (The Hacker News)
A sophisticated Magecart campaign has been observed manipulating websites’ default 404 error page to conceal malicious code in what’s been described as the latest evolution of the attacks. The activity, per Akamai, targets Magento and WooCommerce websites, with some of the victims belonging to large organizations in the food and retail industries. “In this campaign, all the…
-

libcue Library Flaw Opens GNOME Linux Systems Vulnerable to RCE Attacks [email protected] (The Hacker News)
A new security flaw has been disclosed in the libcue library impacting GNOME Linux systems that could be exploited to achieve remote code execution (RCE) on affected hosts. Tracked as CVE-2023-43641 (CVSS score: 8.8), the issue is described as a case of memory corruption in libcue, a library designed for parsing cue sheet files. It impacts versions 2.2.1 and prior.…
-

Citrix Devices Under Attack: NetScaler Flaw Exploited to Capture User Credentials [email protected] (The Hacker News)
A recently disclosed critical flaw in Citrix NetScaler ADC and Gateway devices is being exploited by threat actors to conduct a credential harvesting campaign. IBM X-Force, which uncovered the activity last month, said adversaries exploited “CVE-2023-3519 to attack unpatched NetScaler Gateways to insert a malicious script into the HTML content of the authentication web page to capture…
-

PEACHPIT: Massive Ad Fraud Botnet Powered by Millions of Hacked Android and iOS [email protected] (The Hacker News)
An ad fraud botnet dubbed PEACHPIT leveraged an army of hundreds of thousands of Android and iOS devices to generate illicit profits for the threat actors behind the scheme. The botnet is part of a larger China-based operation codenamed BADBOX, which also entails selling off-brand mobile and connected TV (CTV) devices on popular online retailers and resale sites…
