Category: Securityaffairs

Security Affairs newsletter Round 424 by Pierluigi Paganini – International edition
25
Jun
2023

Security Affairs newsletter Round 425 by Pierluigi Paganini – International edition

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free…

Someone sent mysterious smartwatches to US Military personnelSecurity Affairs
24
Jun
2023

Someone sent mysterious smartwatches to US Military personnelSecurity Affairs

U.S. Army’s Criminal Investigation Division warns that US military personnel have reported receiving unsolicited smartwatches in the mail. The U.S. Army’s…

CISA adds recently disclosed Apple flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs
24
Jun
2023

CISA adds recently disclosed Apple flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs

U.S. Cybersecurity and Infrastructure Security Agency (CISA) added six new vulnerabilities to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity…

VMware fixed five memory corruption issues in vCenter ServerSecurity Affairs
23
Jun
2023

VMware fixed five memory corruption issues in vCenter ServerSecurity Affairs

VMware addressed multiple memory corruption vulnerabilities in vCenter Server that can be exploited to achieve remote code execution. VMware released…

Fortinet urges to patch the critical RCE flaw CVE-2023-27997 in Fortigate firewallsSecurity Affairs
23
Jun
2023

Fortinet fixes critical FortiNAC RCE, install updates asapSecurity Affairs

Fortinet addressed a critical remote command execution vulnerability, tracked as CVE-2023-33299, affecting FortiNAC solution. FortiNAC is a network access control…

More than a million GitHub repositories potentially vulnerable to RepoJackingSecurity Affairs
23
Jun
2023

More than a million GitHub repositories potentially vulnerable to RepoJackingSecurity Affairs

Researchers reported that millions of GitHub repositories are likely vulnerable to an attack called RepoJacking. A study conducted by Aqua…

New Mirai botnet targets tens of flaws in popular IoT devicesSecurity Affairs
22
Jun
2023

New Mirai botnet targets tens of flaws in popular IoT devicesSecurity Affairs

Since March 2023, Unit 42 researchers have observed a variant of the Mirai botnet spreading by targeting tens of flaws…

Researchers released a PoC exploit for CVE-2023-20178 flaw in Cisco AnyConnect SecureSecurity Affairs
22
Jun
2023

Researchers released a PoC exploit for CVE-2023-20178 flaw in Cisco AnyConnect SecureSecurity Affairs

The proof-of-concept (PoC) exploit code for high-severity vulnerability (CVE-2023-20178) in Cisco AnyConnect Secure was published online. A security researcher has…

UK regulator Ofcom hacked with a MOVEit zero-daySecurity Affairs
22
Jun
2023

Norton parent firm Gen Digital, was victim of a MOVEit ransomware attackSecurity Affairs

Norton parent firm, Gen Digital, was the victim of a ransomware attack that exploited the recently disclosed MOVEit zero-day vulnerability….

Apple fixed actively exploited zero-day flaws in iOS,macOS,& SafariSecurity Affairs
22
Jun
2023

Apple fixed actively exploited zero-day flaws in iOS,macOS,& SafariSecurity Affairs

Apple rolled out security updates to address actively exploited zero-day flaws in iOS, iPadOS, macOS, watchOS, and Safari. Apple addressed…

Analyzing the TriangleDB implant used in Operation TriangulationSecurity Affairs
22
Jun
2023

Analyzing the TriangleDB implant used in Operation TriangulationSecurity Affairs

Kaspersky provided more details about Operation Triangulation, including the exploitation chain and the implant used by the threat actors. Kaspersky…

APT28 hacked Roundcube email servers of Ukrainian entitiesSecurity Affairs
21
Jun
2023

APT28 hacked Roundcube email servers of Ukrainian entitiesSecurity Affairs

Russia-linked APT28 group hacked into Roundcube email servers belonging to multiple Ukrainian organizations. A joint investigation conducted by Ukraine’s Computer…