Category: Uncategorized
-

North Korean Hackers Suspected in New Wave of Malicious npm Packages [email protected] (The Hacker News)
The npm package registry has emerged as the target of yet another highly targeted attack campaign that aims to entice developers into downloading malevolent modules. Software supply chain security firm Phylum told The Hacker News the activity exhibits similar behaviors to that of a previous attack wave uncovered in June, which has since been linked to North…
-
Colorado Health Agency Says 4 Million Impacted by MOVEit Hack Ionut Arghire
Colorado’s health programs administrator says the personal information of 4 million individuals was compromised in the recent MOVEit hack. The post Colorado Health Agency Says 4 Million Impacted by MOVEit Hack appeared first on SecurityWeek. Read More
-

QwixxRAT: New Remote Access Trojan Emerges via Telegram and Discord [email protected] (The Hacker News)
A new remote access trojan (RAT) called QwixxRAT is being advertised for sale by its threat actor through Telegram and Discord platforms. “Once installed on the victim’s Windows platform machines, the RAT stealthily collects sensitive data, which is then sent to the attacker’s Telegram bot, providing them with unauthorized access to the victim’s sensitive information,” Uptycs said in a…
-
Email – The System Running Since 71’ Matt Honea
Working remotely is here to stay and businesses should continue to make sure their basic forms of communication are properly configured and secured. The post Email – The System Running Since 71’ appeared first on SecurityWeek. Read More
-
US Cyber Safety Board to Review Cloud Attacks Ionut Arghire
The US government’s CSRB will conduct a review of cloud security to provide recommendations on improving identity management and authentication. The post US Cyber Safety Board to Review Cloud Attacks appeared first on SecurityWeek. Read More
-

Ongoing Xurum Attacks on E-commerce Sites Exploiting Critical Magento 2 Vulnerability [email protected] (The Hacker News)
E-commerce sites using Adobe’s Magento 2 software are the target of an ongoing campaign that has been active since at least January 2023. The attacks, dubbed Xurum by Akamai, leverage a now-patched critical security flaw (CVE-2022-24086, CVSS score: 9.8) in Adobe Commerce and Magento Open Source that, if successfully exploited, could lead to arbitrary code execution. “The…
-
Power Management Product Flaws Can Expose Data Centers to Damaging Attacks, Spying Eduard Kovacs
Vulnerabilities in CyberPower and Dataprobe power management products could be exploited in data center attacks, including to cause damage and for spying. The post Power Management Product Flaws Can Expose Data Centers to Damaging Attacks, Spying appeared first on SecurityWeek. Read More
-
US Shuts Down Bulletproof Hosting Service LolekHosted, Charges Its Polish Operator Ionut Arghire
US authorities have announced charges against a Polish national who allegedly operated the LolekHosted.net bulletproof hosting service. The post US Shuts Down Bulletproof Hosting Service LolekHosted, Charges Its Polish Operator appeared first on SecurityWeek. Read More
-

Identity Threat Detection and Response: Rips in Your Identity Fabric [email protected] (The Hacker News)
Why SaaS Security Is a Challenge In today’s digital landscape, organizations are increasingly relying on Software-as-a-Service (SaaS) applications to drive their operations. However, this widespread adoption has also opened the doors to new security risks and vulnerabilities. The SaaS security attack surface continues to widen. It started with managing misconfigurations and now requires aRead More
-

Charming Kitten Targets Iranian Dissidents with Advanced Cyber Attacks [email protected] (The Hacker News)
Germany’s Federal Office for the Protection of the Constitution (BfV) has warned of cyber attacks targeting Iranian persons and organizations in the country since the end of 2022. “The cyber attacks were mainly directed against dissident organizations and individuals – such as lawyers, journalists, or human rights activists – inside and outside Iran,” the agency said in…
