Category: Uncategorized
-
MoustachedBouncer: Foreign Embassies in Belarus Likely Targeted via ISPs Eduard Kovacs
MoustachedBouncer is a cyberespionage group that targets foreign diplomats in Belarus via ISP adversary-in-the-middle attacks. The post MoustachedBouncer: Foreign Embassies in Belarus Likely Targeted via ISPs appeared first on SecurityWeek. Read More
-

15 New CODESYS SDK Flaws Expose OT Environments to Remote Attacks [email protected] (The Hacker News)
A set of 15 high-severity security flaws have been disclosed in the CODESYS V3 software development kit (SDK) that could result in remote code execution and denial-of-service under specific conditions, posing risks to operational technology (OT) environments. The flaws, tracked from CVE-2022-47379 through CVE-2022-47393 and dubbed CoDe16, carry a CVSS score of 8.8 with the exception ofRead More
-

CISA Adds Microsoft .NET Vulnerability to KEV Catalog Due to Active Exploitation [email protected] (The Hacker News)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a recently patched security flaw in Microsoft’s .NET and Visual Studio products to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. Tracked as CVE-2023-38180 (CVSS score: 7.5), the high-severity flaw relates to a case denial-of-service (DoS) impacting .NET and Visual Studio. ItRead More
-
Check Point to Acquire SASE Security Firm Perimeter 81 for $490 Million Mike Lennon
Check Point will acquire SASE and ZTNA cybersecurity firm Perimeter 81 for $490 million, a big discount to its $1 billion valuation in 2022. The post Check Point to Acquire SASE Security Firm Perimeter 81 for $490 Million appeared first on SecurityWeek. Read More
-
Palo Alto: SugarCRM zero-day reveals growing cloud threats
Post ContentRead More
-
Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability
Ivanti Endpoint Manager Mobile (EPMM, formerly MobileIron Core) contains an authentication bypass vulnerability (CVE-2023-35078) that allows unauthenticated access to specific API paths and a path traversal vulnerability (CVE-2023-35081). An attacker with access to these API paths can access personally identifiable information (PII) such as names, phone numbers, and other mobile device details for users on…
-
Kemba Walden: We need to secure open source software
Post ContentRead More
-
![New Attack Alert: Freeze[.]rs Injector Weaponized for XWorm Malware Attacks info@thehackernews.com (The Hacker News)](https://sekuritasit.com/wp-content/uploads/2023/08/malware-RRPqmP.jpeg)
New Attack Alert: Freeze[.]rs Injector Weaponized for XWorm Malware Attacks [email protected] (The Hacker News)
Malicious actors are using a legitimate Rust-based injector called Freeze[.]rs to deploy a commodity malware called XWorm in victim environments. The novel attack chain, detected by Fortinet FortiGuard Labs on July 13, 2023, is initiated via a phishing email containing a booby-trapped PDF file. It has also been used to introduce Remcos RAT by means of a…
-
Trend Micro discloses ‘silent threat’ flaws in Azure ML
Post ContentRead More
-

New Statc Stealer Malware Emerges: Your Sensitive Data at Risk [email protected] (The Hacker News)
A new information malware strain called Statc Stealer has been found infecting devices running Microsoft Windows to siphon sensitive personal and payment information. “Statc Stealer exhibits a broad range of stealing capabilities, making it a significant threat,” Zscaler ThreatLabz researchers Shivam Sharma and Amandeep Kumar said in a technical report published this week. “It can stealRead More
