Category: Uncategorized
-
Atlassian Ships Urgent Patch for Exploited Confluence Zero-Day Ryan Naraine
Atlassian confirms that “a handful of customers” were hit by exploits targeting a remotely exploitable flaw in its Confluence Data Center and Server products. The post Atlassian Ships Urgent Patch for Exploited Confluence Zero-Day appeared first on SecurityWeek. Read More
-
Critical Atlassian Confluence zero-day flaw under attack
Post ContentRead More
-

Researchers Link DragonEgg Android Spyware to LightSpy iOS Surveillanceware [email protected] (The Hacker News)
New findings have identified connections between an Android spyware called DragonEgg and another sophisticated modular iOS surveillanceware tool named LightSpy. DragonEgg, alongside WyrmSpy (aka AndroidControl), was first disclosed by Lookout in July 2023 as a strain of malware capable of gathering sensitive data from Android devices. It was attributed to the Chinese nation-state group APT41. OnRead More
-
New Supermicro BMC Vulnerabilities Could Expose Many Servers to Remote Attacks Ionut Arghire
Supermicro has released BMC IPMI firmware updates to address multiple vulnerabilities impacting select motherboard models. The post New Supermicro BMC Vulnerabilities Could Expose Many Servers to Remote Attacks appeared first on SecurityWeek. Read More
-
Lyca Mobile Services Significantly Disrupted by Cyberattack Eduard Kovacs
International mobile network operator Lyca Mobile says a cyberattack has significantly disrupted its services in many countries. The post Lyca Mobile Services Significantly Disrupted by Cyberattack appeared first on SecurityWeek. Read More
-
Severe Glibc Privilege Escalation Vulnerability Impacts Major Linux Distributions Ionut Arghire
A local privilege escalation vulnerability (CVE-2023-4911) in the GNU C Library (glibc) can be exploited to gain full root privileges. The post Severe Glibc Privilege Escalation Vulnerability Impacts Major Linux Distributions appeared first on SecurityWeek. Read More
-

Wing Disrupts the Market by Introducing Affordable SaaS Security [email protected] (The Hacker News)
Today, mid-sized companies and their CISOs are struggling to handle the growing threat of SaaS security with limited manpower and tight budgets. Now, this may be changing. By focusing on the critical SaaS security needs of these companies, a new approach has emerged that can be launched for $1,500 a year. If the name Wing Security…
-
Google, Yahoo Boosting Email Spam Protections Ionut Arghire
Google and Yahoo are introducing new requirements for bulk senders, to improve phishing and spam protections. The post Google, Yahoo Boosting Email Spam Protections appeared first on SecurityWeek. Read More
-
Mozilla Warns of Fake Thunderbird Downloads Delivering Ransomware Eduard Kovacs
Mozilla issues warning over fake Thunderbird downloads after a ransomware group was caught using this technique to deliver malware. The post Mozilla Warns of Fake Thunderbird Downloads Delivering Ransomware appeared first on SecurityWeek. Read More
-

Rogue npm Package Deploys Open-Source Rootkit in New Supply Chain Attack [email protected] (The Hacker News)
A new deceptive package hidden within the npm package registry has been uncovered deploying an open-source rootkit called r77, marking the first time a rogue package has delivered rootkit functionality. The package in question is node-hide-console-windows, which mimics the legitimate npm package node-hide-console-window in what’s an instance of a typosquatting campaign. It was downloaded 704Read More
