News
-
"US CISA adds MS Exchange bug CVE-2022-41080 to its Known Exploited Vulnerabilities Catalog"The US Department of Homeland Security's Cybersecurity and Infrastructure Security Agency (CISA) has added two more vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog. The first flaw is a Microsoft Exchange server privilege escalation…
-
"British Manufacturing Firm Morgan Advanced Materials Investigating Cyberattack"UK-based manufacturing company Morgan Advanced Materials revealed recently that it’s investigating a cybersecurity incident. The company has launched an investigation after detecting unauthorized activity on its network. The company stated…
-
"251k Impacted by Data Breach at Insurance Firm Bay Bridge Administrators"A third-party administrator of insurance products, Bay Bridge Administrators (BBA), is informing roughly 250,000 individuals that their personal information might have been compromised in a September 2022 data breach. Recently the Austin, Texas-…
-
"Customer and Employee Data the Top Prize for Hackers – Imperva"Security researchers at Imperva discovered that the theft of customer and employee data accounts for almost half (45%) of all stolen data between July 2021 and June 2022. Companies’ source code and proprietary information accounted for 6.7% and 6.5…
-
"Vidar Info-Stealing Malware Promoted by More Than 1,300 Fabricated AnyDesk Websites"The AnyDesk website is being spoofed in a malicious campaign involving over 1,300 domains, all of which link to a Dropbox folder containing the information-stealing malware called Vidar. AnyDesk, a popular remote desktop application for Windows, Linux,…
-
"More Than 120 Models of Siemens' S7-1500 PLCs Contain a Serious Vulnerability—and No Fix Is on the Way"The computer worm Stuxnet crippled hundreds of centrifuges within Iran's Natanz uranium enrichment plant in 2009 by targeting the software running on the facility's industrial computers, known as Programmable Logic Controllers (PLCs). All of the…
-
"'Dark Pink' Hacking Group Targets Government and Military in Southeast Asia"Group-IB has released a report on a new Advanced Persistent Threat (APT) campaign targeting Southeast Asian and Eastern European countries for espionage. The APT dubbed "Dark Pink" is considered to be a new threat actor. Dark Pink has targeted military…
-
"Government Watchdog Cracks Thousands of Passwords at US Federal Agency in Minutes"The Inspector General of the Department of the Interior (DOI) conducted a security audit of the agency's password management policies and has now released a report stating that they were able to crack more than 18,000 of the department's Active Directory…
-
"Lorenz Ransomware Gang Plants Backdoors to Use Months Later"Security experts warn that patching critical flaws that enable network access is insufficient protection against ransomware attacks. Some ransomware gangs are using critical vulnerabilities to plant a backdoor while the window of opportunity is still…
-
"StrongPity Hackers Distribute Trojanized Telegram App to Target Android Users"StrongPity, also known as APT-C-41 and Promethium, is an Advanced Persistent Threat (APT) group that has been targeting Android users with a Trojanized version of the Telegram software via a fake website impersonating the Shagle video chat service. The…
-
"How Can We Make the Electric Grid More Resilient to Cyberattacks?"Junho Hong, Assistant Professor of Electrical and Computer Engineering at the University of Michigan-Dearborn, and his colleague Professor Wencong Su are leading a new project funded with a grant from the US Department of Energy (DOE). They are teaming…
-
"Widespread 2FA Bypass Attack Compromised Comcast Xfinity Accounts; Targets Coinbase, Gemini, Evernote, and Dropbox"Comcast Xfinity customers have reported that their accounts have been compromised by a campaign employing a two-factor authentication (2FA) bypass technique. Despite enabling 2FA, Xfinity email customers began receiving messages that their account…