"Developer Errors Lead to Long-Term Exposure of Sensitive Data in Git Repos"

"Developer Errors Lead to Long-Term Exposure of Sensitive Data in Git Repos"

New Aqua Security research found secrets from organizations, including credentials, Application Programming Interface (API) tokens, and passkeys, that have been exposed for years. Researchers discovered active secrets from open source organizations and enterprises providing access to sensitive data and software. This discovery was made by scanning the most popular 100 organizations on GitHub, which has over 50,000 publicly accessible repositories. This article continues to discuss findings regarding the significant exposure of enterprise secrets.

Submitted by grigby1 CPVI on

"Hackers Target New MOVEit Transfer Critical Auth Bypass Bug"

"Hackers Target New MOVEit Transfer Critical Auth Bypass Bug"

Threat actors are exploiting a new critical authentication bypass flaw in Progress MOVEit Transfer, which is a Managed File Transfer (MFT) solution used to securely transfer files between business partners and customers. The new security flaw enables attackers to bypass authentication in the Secure File Transfer Protocol (SFTP) module. This flaw allows an attacker to access sensitive data, delete files, intercept file transfers, and more. This article continues to discuss the exploitation of a new MOVEit Transfer flaw.

Submitted by grigby1 CPVI on

"Siemens Sicam Vulnerabilities Could Facilitate Attacks on Energy Sector"

"Siemens Sicam Vulnerabilities Could Facilitate Attacks on Energy Sector"

Siemens recently patched several vulnerabilities in some of its Sicam products that could be exploited in attacks against the energy sector. In May, Siemens released updates for its Sicam A8000 remote terminal unit, Sicam EGS grid sensors, and Sicam 8 power automation software. One of the vulnerabilities is a buffer overread issue that can enable attackers to read sensitive data from memory, potentially leading to arbitrary code execution in the context of the current process or to a Denial-of-Service (DoS) condition.

Submitted by grigby1 CPVI on

"Novel Banking Malware Targets Customers in Southeast Asia"

"Novel Banking Malware Targets Customers in Southeast Asia"

Promon research highlights a new malware strain called "Snowblind" targeting banking customers in Southeast Asia. The new malware disables Android banking apps' ability to detect malicious modifications, thus avoiding detection. Snowblind exploits accessibility services on apps, which have extensive permissions to interact with and modify app interfaces. According to Promon, Snowblind uses these services to access sensitive information, navigate the device, and more. This article continues to discuss findings regarding the Snowblind malware.

Submitted by grigby1 CPVI on

"Credential Stuffing Attack Hits 72,000 Levi’s Accounts"

"Credential Stuffing Attack Hits 72,000 Levi’s Accounts"

Levi's recently announced that tens of thousands of their customers may have had their accounts compromised after a credential stuffing attack.  The company noted that 72,231 individuals may have been impacted by the incident, which occurred on June 13.  After the credential stuffing attack was discovered, Levi's said that it promptly forced a password reset the same day for all user accounts that were accessed during the relevant time period.  If any accounts were compromised, the threat actors wouldn't have been able to take much.

Submitted by Adam Ekwall on

"Several Plugins Compromised in WordPress Supply Chain Attack"

"Several Plugins Compromised in WordPress Supply Chain Attack"

According to security researchers at Defiant, malicious code injected over the past week in five WordPress plugins creates a new administrative account.  The code was discovered on Monday after the researchers learned that a threat actor had taken over the Social Warfare plugin and added the malicious code in recent versions.  The researchers noted that starting June 22, several versions of the plugin were released with the injected code inside.

Submitted by Adam Ekwall on

"NIST Launches Collaborative Research Effort on Digital Identity to Support Secure Delivery of Public Benefits"

"NIST Launches Collaborative Research Effort on Digital Identity to Support Secure Delivery of Public Benefits"

The National Institute of Standards and Technology (NIST) has launched a collaborative project to adapt its digital identity guidelines to support public benefits programs, such as those that help beneficiaries pay for food, housing, and more. NIST, together with the Digital Benefits Network (DBN) at Georgetown University’s Beeck Center for Social Impact + Innovation and the nonprofit Center for Democracy & Technology (CDT), will develop resources to help providers balance security, privacy, equity, and usability.

Submitted by grigby1 CPVI on

"'P2PInfect' Worm Grows Teeth With Miner, Ransomware & Rootkit"

"'P2PInfect' Worm Grows Teeth With Miner, Ransomware & Rootkit"

"P2PInfect" is a worm that uses the Redis in-memory database application to spread across networks in a peer-to-peer, worm-like way, building a botnet in the process. When it was discovered about a year ago, it had not yet caused any significant damage. However, this is no longer the case, as, according to Cado Security, an update has been distributed globally across P2PInfect infections, including a brand new rootkit, cryptominer, and ransomware.

Submitted by grigby1 CPVI on

"New Attack Technique Exploits Microsoft Management Console Files"

"New Attack Technique Exploits Microsoft Management Console Files"

Threat actors are using a new attack method involving specially crafted Management Saved Console (MSC) files to gain full code execution through Microsoft Management Console (MMC) and dodge security defenses. Researchers at Elastic Security Labs named the approach "GrimResource." This article continues to discuss the findings regarding the GrimResource approach.

THN reports "New Attack Technique Exploits Microsoft Management Console Files"

Submitted by grigby1
 

Submitted by grigby1 CPVI on
Subscribe to