Category: Securityaffairs

North Korean Andariel APT used a new malware named EarlyRatSecurity Affairs
30
Jun
2023

North Korean Andariel APT used a new malware named EarlyRatSecurity Affairs

North Korea-linked cyberespionage group Andariel used a previously undocumented malware called EarlyRat. Kaspersky researchers reported that the North Korea-linked APT group Andariel used a previously…

miniOrange’s WordPress Social Login and Register plugin affected by a critical auth bypassSecurity Affairs
30
Jun
2023

miniOrange’s WordPress Social Login and Register plugin affected by a critical auth bypassSecurity Affairs

A critical authentication bypass flaw in miniOrange’s WordPress Social Login and Register plugin, can allow gaining access to any account on a…

The phone monitoring app LetMeSpy disclosed a data breachSecurity Affairs
29
Jun
2023

The phone monitoring app LetMeSpy disclosed a data breachSecurity Affairs

Android app LetMeSpy disclosed a security breach, sensitive data associated with thousands of Android users were exposed. The phone monitoring app LetMeSpy…

Previously undetected ThirdEye appears in the threat landscapeSecurity Affairs
29
Jun
2023

Previously undetected ThirdEye appears in the threat landscapeSecurity Affairs

A new Windows information stealer dubbed ThirdEye appeared in the threat landscape, it has been active since April. Fortinet FortiGuard Labs discovered…

Former Group-IB manager has been arrested in KazahstanSecurity Affairs
29
Jun
2023

Former Group-IB manager has been arrested in KazahstanSecurity Affairs

The former head of network security at Group-IB has been arrested in Kazakhstan based on a request from U.S. law…

Experts published PoC for Arcserve UDP auth bypass issueSecurity Affairs
29
Jun
2023

Experts published PoC for Arcserve UDP auth bypass issueSecurity Affairs

Data protection firm Arcserve addressed an authentication bypass vulnerability in its Unified Data Protection (UDP) backup software. Data protection vendor…

Using Electromagnetic Fault Injection Attacks to take over dronesSecurity Affairs
28
Jun
2023

Using Electromagnetic Fault Injection Attacks to take over dronesSecurity Affairs

Electromagnetic fault injection (EMFI) attacks on drones can potentially allow attackers to achieve arbitrary code execution and take over them….

Experts warn of a spike in May/June of 8Base ransomware attacksSecurity Affairs
28
Jun
2023

Experts warn of a spike in May/June of 8Base ransomware attacksSecurity Affairs

Researchers warn of a massive spike in May and June 2023 of the activity associated with the ransomware group named 8Base….

Critical SQL Injection flaws in Gentoo Soko can lead to RCESecurity Affairs
28
Jun
2023

Critical SQL Injection flaws in Gentoo Soko can lead to RCESecurity Affairs

SQL injection vulnerabilities in Gentoo Soko could lead to remote code execution (RCE) on impacted systems. SonarSource researchers discovered two…

EncroChat dismantling led to 6,558 arrests and the seizure of $979M in criminal fundsSecurity Affairs
28
Jun
2023

EncroChat dismantling led to 6,558 arrests and the seizure of $979M in criminal fundsSecurity Affairs

Europol announced that the takedown of the EncroChat encrypted chat network has led to the arrest of 6,558 people and…

Mockingjay process injection technique allows EDR bypassSecurity Affairs
27
Jun
2023

Mockingjay process injection technique allows EDR bypassSecurity Affairs

Mockingjay is a new process injection technique that can be exploited to bypass security solutions to execute malware on compromised…

Experts found hundreds of devices within federal networks having internet-exposed management interfacesSecurity Affairs
27
Jun
2023

Experts found hundreds of devices within federal networks having internet-exposed management interfacesSecurity Affairs

Researchers at Censys have identified hundreds of devices deployed within federal networks that have internet-exposed management interfaces. Researchers at Censys…