Category: Securityaffairs

OAuth apps used in cryptocurrency mining, phishing campaigns, and BEC attacks
13
Dec
2023

OAuth apps used in cryptocurrency mining, phishing campaigns, and BEC attacks

OAuth apps used in cryptocurrency mining, phishing campaigns, and BEC attacks Pierluigi Paganini December 13, 2023 Microsoft warns that threat…

Sophos backports fix for CVE-2022-3236 for EOL firewall firmware
13
Dec
2023

Sophos backports fix for CVE-2022-3236 for EOL firewall firmware

Sophos backports fix for CVE-2022-3236 for EOL firewall firmware versions due to ongoing attacks Pierluigi Paganini December 13, 2023 Sophos…

Microsoft September 2023 Patch Tuesday fixed 2 actively exploited zero-day flaws
13
Dec
2023

December 2023 Microsoft Patch Tuesday fixed 4 critical flaws

December 2023 Microsoft Patch Tuesday fixed 4 critical flaws Pierluigi Paganini December 13, 2023 Microsoft Patch Tuesday security updates for…

Phishing campaign targets Ukrainian military entities with drone manual lures
13
Dec
2023

Ukrainian military intelligence service hacked the Russian Federal Taxation Service

Ukrainian military intelligence service hacked the Russian Federal Taxation Service Pierluigi Paganini December 12, 2023 The Ukrainian government’s military intelligence…

Phishing campaign targets Ukrainian military entities with drone manual lures
12
Dec
2023

Kyivstar, Ukraine’s largest mobile carrier brought down by a cyberattack

Kyivstar, Ukraine’s largest mobile carrier brought down by a cyber attack Pierluigi Paganini December 12, 2023 Kyivstar, the largest Ukraine…

Dubai’s largest taxi app exposes 220K+ users
12
Dec
2023

Dubai’s largest taxi app exposes 220K+ users

Dubai’s largest taxi app exposes 220K+ users Pierluigi Paganini December 12, 2023 The Dubai Taxi Company (DTC) app, which provides…

Lazarus exploits Log4j flaws to deploy DLang malware
12
Dec
2023

Lazarus exploits Log4j flaws to deploy DLang malware

Operation Blacksmith: Lazarus exploits Log4j flaws to deploy DLang malware Pierluigi Paganini December 12, 2023 North Korea-linked APT group Lazarus…

Apple discloses 2 actively exploited zero-days in iPhones, Macs
12
Dec
2023

Apple released iOS 17.2 to address a dozen of security flaws

Apple released iOS 17.2 to address a dozen of security flaws Pierluigi Paganini December 12, 2023 Apple rolled out emergency…

Toyota Financial Services discloses data breach
12
Dec
2023

Toyota Financial Services discloses data breach

Toyota Financial Services discloses a data breach Pierluigi Paganini December 11, 2023 Toyota Financial Services (TFS) disclosed a data breach,…

Apache fixed Critical RCE flaw CVE-2023-50164 in Struts 2
11
Dec
2023

Apache fixed Critical RCE flaw CVE-2023-50164 in Struts 2

Apache fixed Critical RCE flaw CVE-2023-50164 in Struts 2 Pierluigi Paganini December 11, 2023 The Apache Software Foundation addressed a…

US CISA added critical Apache RocketMQ flaw to its Known Exploited Vulnerabilities catalog
11
Dec
2023

CISA adds Qlik Sense flaws to its Known Exploited Vulnerabilities catalog

CISA adds Qlik Sense flaws to its Known Exploited Vulnerabilities catalog Pierluigi Paganini December 11, 2023 U.S. Cybersecurity and Infrastructure…

CISA and ENISA signed a Working Arrangement to enhance cooperation
11
Dec
2023

CISA and ENISA signed a Working Arrangement to enhance cooperation

CISA and ENISA signed a Working Arrangement to enhance cooperation Pierluigi Paganini December 11, 2023 ENISA has signed a Working…