Category: Securityaffairs

Experts warn of OSS supply chain attacks on the banking sectorSecurity Affairs
24
Jul
2023

Experts warn of OSS supply chain attacks on the banking sectorSecurity Affairs

Checkmark researchers have uncovered the first known targeted OSS supply chain attacks against the banking sector. In the first half of…

Apple could opt to stop iMessage and FaceTime services due to the government's surveillance demandsSecurity Affairs
24
Jul
2023

Apple could opt to stop iMessage and FaceTime services due to the government’s surveillance demandsSecurity Affairs

Apple could opt to pull iMessage and FaceTime services in the U.K. in response to the government’s surveillance demands. In…

Security Affairs newsletter Round 424 by Pierluigi Paganini – International edition
23
Jul
2023

Security Affairs newsletter Round 429 by Pierluigi Paganini – International edition

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free…

Shadowserver reported that +15K Citrix servers are likely vulnerable to attacks exploiting the flaw CVE-2023-3519Security Affairs
23
Jul
2023

Shadowserver reported that +15K Citrix servers are likely vulnerable to attacks exploiting the flaw CVE-2023-3519Security Affairs

Researchers reported that more than 15000 Citrix servers exposed online are likely vulnerable to attacks exploiting the vulnerability CVE-2023-3519. The…

Multiple DDoS botnets were observed targeting Zyxel devicesSecurity Affairs
22
Jul
2023

Multiple DDoS botnets were observed targeting Zyxel devicesSecurity Affairs

Researchers warn of several DDoS botnets exploiting a critical flaw tracked as CVE-2023-28771 in Zyxel devices. Fortinet FortiGuard Labs researchers…

CISA adds recently disclosed Apple flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs
21
Jul
2023

CISA warns of attacks against Citrix NetScaler ADC and Gateway DevicesSecurity Affairs

The US CISA warns of cyber attacks targeting Citrix NetScaler Application Delivery Controller (ADC) and Gateway devices. The U.S. Cybersecurity…

Experts believe North Korea behind JumpCloud supply chain attackSecurity Affairs
21
Jul
2023

Experts believe North Korea behind JumpCloud supply chain attackSecurity Affairs

SentinelOne researchers attribute the recent supply chain attacks on JumpCloud to North Korea-linked threat actors. JumpCloud is a cloud-based directory…

Bangladesh government website leaked data of millions of citizensSecurity Affairs
21
Jul
2023

shame dealer left your data up for grabsSecurity Affairs

Cybernews research team discovered that two Suzuki-authorized dealer websites were leaking customers’ sensitive information. Suzuki or otherwise, buying a new…

Experts attribute WyrmSpy and DragonEgg spyware to the Chinese APT41 groupSecurity Affairs
20
Jul
2023

Experts attribute WyrmSpy and DragonEgg spyware to the Chinese APT41 groupSecurity Affairs

China-linked group APT41 was spotted using two previously undocumented Android spyware called WyrmSpy and DragonEgg China-linked APT group APT41 has…

ALPHV/BlackCat and Clop gangs claim to have hacked cosmetics giant Estée LauderSecurity Affairs
20
Jul
2023

ALPHV/BlackCat and Clop gangs claim to have hacked cosmetics giant Estée LauderSecurity Affairs

The American cosmetics giant company Estée Lauder was hacked by two distinct ransomware groups, the ALPHV/BlackCat and Clop gangs. Yesterday…

P2PInfect, a Rusty P2P worm targets Redis Servers on Linux and Windows systems
20
Jul
2023

P2PInfect, a Rusty P2P worm targets Redis Servers on Linux and Windows systems

Cybersecurity researchers discovered a new peer-to-peer (P2P) worm called P2PInfect that targets Redis servers. Palo Alto Networks Unit 42 researchers have discovered…

Adobe warns customers of critical ColdFusion RCE exploited in attacksSecurity Affairs
20
Jul
2023

Adobe out-of-band update addresses an actively exploited ColdFusion zero-daySecurity Affairs

Adobe released an emergency update to address critical vulnerabilities in ColdFusion, including an actively exploited zero-day. Adobe released an out-of-band…