Category: Uncategorized
-
Generative AI emerges for DevSecOps, with some qualms
Post ContentRead More
-

Free Download Manager Site Compromised to Distribute Linux Malware to Users for 3+ Years [email protected] (The Hacker News)
A download manager site served Linux users malware that stealthily stole passwords and other sensitive information for more than three years as part of a supply chain attack. The modus operandi entailed establishing a reverse shell to an actor-controlled server and installing a Bash stealer on the compromised system. The campaign, which took place between…
-
Kubernetes Vulnerability Leads to Remote Code Execution Ionut Arghire
A high-severity vulnerability can be exploited to execute code remotely on any Windows endpoint within a Kubernetes cluster. The post Kubernetes Vulnerability Leads to Remote Code Execution appeared first on SecurityWeek. Read More
-
Azure HDInsight Flaws Allowed Data Access, Session Hijacking, Payload Delivery Ionut Arghire
Orca Security details eight XSS vulnerabilities in Azure HDInsight that could lead to information leaks, session hijacking, and payload delivery. The post Azure HDInsight Flaws Allowed Data Access, Session Hijacking, Payload Delivery appeared first on SecurityWeek. Read More
-

Avoid These 5 IT Offboarding Pitfalls [email protected] (The Hacker News)
Employee offboarding is no one’s favorite task, yet it is a critical IT process that needs to be executed diligently and efficiently. That’s easier said than done, especially considering that IT organizations have less visibility and control over employees’ IT use than ever. Today, employees can easily adopt new cloud and SaaS applications whenever and…
-
LockBit Affiliate Deploys New 3AM Ransomware in Recent Attack Ionut Arghire
A LockBit affiliate has deployed the new 3AM ransomware family on a victim’s network, after LockBit’s execution was blocked. The post LockBit Affiliate Deploys New 3AM Ransomware in Recent Attack appeared first on SecurityWeek. Read More
-
North Korean Hackers Steal $53 Million in Cryptocurrency From CoinEx Ionut Arghire
North Korean hackers stole $53 million in cryptocurrency from crypto exchange CoinEx after the hot wallet private key was leaked. The post North Korean Hackers Steal $53 Million in Cryptocurrency From CoinEx appeared first on SecurityWeek. Read More
-
Ransomware Gang Takes Credit for Disruptive MGM Resorts Cyberattack Eduard Kovacs
A known ransomware gang has taken credit for the highly disruptive cyberattack on MGM Resorts, and the company has yet to restore impacted systems. The post Ransomware Gang Takes Credit for Disruptive MGM Resorts Cyberattack appeared first on SecurityWeek. Read More
-

N-Able’s Take Control Agent Vulnerability Exposes Windows Systems to Privilege Escalation [email protected] (The Hacker News)
A high-severity security flaw has been disclosed in N-Able’s Take Control Agent that could be exploited by a local unprivileged attacker to gain SYSTEM privileges. Tracked as CVE-2023-27470 (CVSS score: 8.8), the issue relates to a Time-of-Check to Time-of-Use (TOCTOU) race condition vulnerability, which, when successfully exploited, could be leveraged to delete arbitrary files on a WindowsRead More
-

Russian Journalist’s iPhone Compromised by NSO Group’s Zero-Click Spyware [email protected] (The Hacker News)
The iPhone belonging to Galina Timchenko, a prominent Russian journalist and critic of the government, was compromised with NSO Group’s Pegasus spyware, a new collaborative investigation from Access Now and the Citizen Lab has revealed. The infiltration is said to have happened on or around February 10, 2023. Timchenko is the executive editor and owner of Meduza, an independent news…
