Category: Uncategorized
-
Google Researchers Discover In-the-Wild Exploitation of Zimbra Zero-Day Eduard Kovacs
Google researchers have discovered that a Zimbra zero-day vulnerability has been exploited in the wild, with users being advised to manually patch their installations. The post Google Researchers Discover In-the-Wild Exploitation of Zimbra Zero-Day appeared first on SecurityWeek. Read More
-

New SOHO Router Botnet AVrecon Spreads to 70,000 Devices Across 20 Countries [email protected] (The Hacker News)
A new malware strain has been found covertly targeting small office/home office (SOHO) routers for more than two years, infiltrating over 70,000 devices and creating a botnet with 40,000 nodes spanning 20 countries. Lumen Black Lotus Labs has dubbed the malware AVrecon, making it the third such strain to focus on SOHO routers after ZuoRAT and HiatusRAT over the past…
-

Zimbra Warns of Critical Zero-Day Flaw in Email Software Amid Active Exploitation [email protected] (The Hacker News)
Zimbra has warned of a critical zero-day security flaw in its email software that has come under active exploitation in the wild. “A security vulnerability in Zimbra Collaboration Suite Version 8.8.15 that could potentially impact the confidentiality and integrity of your data has surfaced,” the company said in an advisory. It also said that the issue has…
-
API Flaw in QuickBlox Framework Exposed PII of Millions of Users Kevin Townsend
QuickBlox SDK and API vulnerabilities impact chat and video applications used by industries including telemedicine, smart IoT, and finance. The post API Flaw in QuickBlox Framework Exposed PII of Millions of Users appeared first on SecurityWeek. Read More
-

PicassoLoader Malware Used in Ongoing Attacks on Ukraine and Poland [email protected] (The Hacker News)
Government entities, military organizations, and civilian users in Ukraine and Poland have been targeted as part of a series of campaigns designed to steal sensitive data and gain persistent remote access to the infected systems. The intrusion set, which stretches from April 2022 to July 2023, leverages phishing lures and decoy documents to deploy a…
-

TeamTNT’s Silentbob Botnet Infecting 196 Hosts in Cloud Attack Campaign [email protected] (The Hacker News)
As many as 196 hosts have been infected as part of an aggressive cloud campaign mounted by the TeamTNT group called Silentbob. “The botnet run by TeamTNT has set its sights on Docker and Kubernetes environments, Redis servers, Postgres databases, Hadoop clusters, Tomcat and Nginx servers, Weave Scope, SSH, and Jupyter applications,” Aqua security researchers Ofek…
-
Microsoft: Government agencies breached in email attacks
Post ContentRead More
-
Cisco Shopping Spree Adds Oort ID Threat Detection Tech Ryan Naraine
The planned Oort purchase is Cisco’s fourth acquisition of a cybersecurity company in the first half of 2023. The post Cisco Shopping Spree Adds Oort ID Threat Detection Tech appeared first on SecurityWeek. Read More
-
BlackLotus UEFI Bootkit Source Code Leaked on GitHub Ionut Arghire
The source code for the BlackLotus UEFI bootkit has been leaked on GitHub and an expert has issued a warning over the risks. The post BlackLotus UEFI Bootkit Source Code Leaked on GitHub appeared first on SecurityWeek. Read More
-
Honeywell DCS Platform Vulnerabilities Can Facilitate Attacks on Industrial Organizations Eduard Kovacs
Cybersecurity company Armis has identified several vulnerabilities in Honeywell ICS products that could expose industrial organizations to attacks. The post Honeywell DCS Platform Vulnerabilities Can Facilitate Attacks on Industrial Organizations appeared first on SecurityWeek. Read More
