Category: Uncategorized
-

PoC Exploit Released for Critical VMware Aria’s SSH Auth Bypass Vulnerability [email protected] (The Hacker News)
Proof-of-concept (PoC) exploit code has been made available for a recently disclosed and patched critical flaw impacting VMware Aria Operations for Networks (formerly vRealize Network Insight). The flaw, tracked as CVE-2023-34039, is rated 9.8 out of a maximum of 10 for severity and has been described as a case of authentication bypass due to a lack…
-

Okta Warns of Social Engineering Attacks Targeting Super Administrator Privileges [email protected] (The Hacker News)
Identity services provider Okta on Friday warned of social engineering attacks orchestrated by threat actors to obtain elevated administrator permissions. “In recent weeks, multiple US-based Okta customers have reported a consistent pattern of social engineering attacks against IT service desk personnel, in which the caller’s strategy was to convince service desk personnel to reset allRead…
-
Exploit Code Published for Critical-Severity VMware Security Defect Ryan Naraine
Exploit code and root-cause analysis released by SinSinology documents the problem as a case where VMWare “forgot to regenerate” SSH keys. The post Exploit Code Published for Critical-Severity VMware Security Defect appeared first on SecurityWeek. Read More
-

Threat Actors Targeting Microsoft SQL Servers to Deploy FreeWorld Ransomware [email protected] (The Hacker News)
Threat actors are exploiting poorly secured Microsoft SQL (MS SQL) servers to deliver Cobalt Strike and a ransomware strain called FreeWorld. Cybersecurity firm Securonix, which has dubbed the campaign DB#JAMMER, said it stands out for the way the toolset and infrastructure is employed. “Some of these tools include enumeration software, RAT payloads, exploitation and credential…
-
In Other News: Hacking Encrypted Linux Computers, Android Fuzzing, Skype Leaking IPs SecurityWeek News
Weekly cybersecurity news roundup providing a summary of noteworthy stories that might have slipped under the radar. The post In Other News: Hacking Encrypted Linux Computers, Android Fuzzing, Skype Leaking IPs appeared first on SecurityWeek. Read More
-
Free Decryptor Available for ‘Key Group’ Ransomware Ionut Arghire
EclecticIQ has released a free decryption tool to help victims of the Key Group ransomware recover their data without paying a ransom. The post Free Decryptor Available for ‘Key Group’ Ransomware appeared first on SecurityWeek. Read More
-
Elon Musk Says X, Formerly Twitter, Will Have Voice and Video Calls, Updates Privacy Policy Associated Press
Twitter has updated its privacy policies, which will allow for the collection of biometric data and employment history, among other information. The post Elon Musk Says X, Formerly Twitter, Will Have Voice and Video Calls, Updates Privacy Policy appeared first on SecurityWeek. Read More
-

Russian State-Backed ‘Infamous Chisel’ Android Malware Targets Ukrainian Military [email protected] (The Hacker News)
Cybersecurity and intelligence agencies from Australia, Canada, New Zealand, the U.K., and the U.S. on Thursday disclosed details of a mobile malware strain targeting Android devices used by the Ukrainian military. The malicious software, dubbed Infamous Chisel and attributed to a Russian state-sponsored actor called Sandworm, has capabilities to “enable unauthorized access to compromisedRead More
-
Industry Reactions to Qakbot Botnet Disruption: Feedback Friday Eduard Kovacs
Industry professionals comment on the law enforcement operation targeting the Qakbot botnet and its implications. The post Industry Reactions to Qakbot Botnet Disruption: Feedback Friday appeared first on SecurityWeek. Read More
-
Threat Actors Adopt, Modify Open Source ‘SapphireStealer’ Information Stealer Ionut Arghire
Cisco has observed multiple threat actors adopting the SapphireStealer information stealer after its source code was released on GitHub. The post Threat Actors Adopt, Modify Open Source ‘SapphireStealer’ Information Stealer appeared first on SecurityWeek. Read More
