Category: Uncategorized
-

LUCR-3: Scattered Spider Getting SaaS-y in the Cloud [email protected] (The Hacker News)
LUCR-3 overlaps with groups such as Scattered Spider, Oktapus, UNC3944, and STORM-0875 and is a financially motivated attacker that leverages the Identity Provider (IDP) as initial access into an environment with the goal of stealing Intellectual Property (IP) for extortion. LUCR-3 targets Fortune 2000 companies across various sectors, including but not limited to Software, Retail,…
-

APIs: Unveiling the Silent Killer of Cyber Security Risk Across Industries [email protected] (The Hacker News)
Introduction In today’s interconnected digital ecosystem, Application Programming Interfaces (APIs) play a pivotal role in enabling seamless communication and data exchange between various software applications and systems. APIs act as bridges, facilitating the sharing of information and functionalities. However, as the use of APIs continues to rise, they have become an increasingly attractiveRead More
-

Silent Skimmer: A Year-Long Web Skimming Campaign Targeting Online Payment Businesses [email protected] (The Hacker News)
A financially motivated campaign has been targeting online payment businesses in the Asia Pacific, North America, and Latin America with web skimmers for more than a year. The BlackBerry Research and Intelligence Team is tracking the activity under the name Silent Skimmer, attributing it to an actor who is knowledgeable in the Chinese language. Prominent victims…
-
Johnson Controls Ransomware Attack Could Impact DHS Ionut Arghire
DHS is reportedly investigating the impact of the recent Johnson Controls ransomware attack on its systems and facilities. The post Johnson Controls Ransomware Attack Could Impact DHS appeared first on SecurityWeek. Read More
-
Unpatched Exim Vulnerabilities Expose Many Mail Servers to Attacks Eduard Kovacs
Patches are being developed for serious Exim vulnerabilities that could expose many mail servers to attacks. The post Unpatched Exim Vulnerabilities Expose Many Mail Servers to Attacks appeared first on SecurityWeek. Read More
-
CISA Kicks Off Cybersecurity Awareness Month With New Program Ionut Arghire
CISA has announced the Secure Our World cybersecurity awareness program, targeting both businesses and end users. The post CISA Kicks Off Cybersecurity Awareness Month With New Program appeared first on SecurityWeek. Read More
-
Recently Patched TeamCity Vulnerability Exploited to Hack Servers Eduard Kovacs
In-the-wild exploitation of a critical vulnerability in the TeamCity CI/CD server started shortly after a patch was released by developers. The post Recently Patched TeamCity Vulnerability Exploited to Hack Servers appeared first on SecurityWeek. Read More
-
Silverfort Open Sources Lateral Movement Detection Tool Ionut Arghire
Silverfort has released the source code for its lateral movement detection tool LATMA, to help identify and analyze intrusions. The post Silverfort Open Sources Lateral Movement Detection Tool appeared first on SecurityWeek. Read More
-

OpenRefine’s Zip Slip Vulnerability Could Let Attackers Execute Malicious Code [email protected] (The Hacker News)
A high-severity security flaw has been disclosed in the open-source OpenRefine data cleanup and transformation tool that could result in arbitrary code execution on affected systems. Tracked as CVE-2023-37476 (CVSS score: 7.8), the vulnerability is a Zip Slip vulnerability that could have adverse impacts when importing a specially crafted project in versions 3.7.3 and below. “Although OpenRefineRead…
-

BunnyLoader: New Malware-as-a-Service Threat Emerges in the Cybercrime Underground [email protected] (The Hacker News)
Cybersecurity experts have discovered yet another malware-as-a-service (MaaS) threat called BunnyLoader that’s being advertised for sale on the cybercrime underground. “BunnyLoader provides various functionalities such as downloading and executing a second-stage payload, stealing browser credentials and system information, and much more,” Zscaler ThreatLabz researchers Niraj Shivtarkar andRead More
