Off we go again!
Move files and wipe old devices with this PC transfer kit bundle deal
This three-program PC transfer kit offers peace of mind with every device for $25.49 with code TRANSFER30 at checkout. But act fast, because this coupon is only good through the end of April 11th.
- April 07, 2023
- 07:18 AM
- 1
Flipper Zero banned by Amazon for being a ‘card skimming device’
Amazon has banned the sale of the Flipper Zero portable multi-tool for pen-testers as it no longer allows its sale on the platform after tagging it as a card-skimming device.
- April 07, 2023
- 05:01 AM
- 1
Breached shutdown sparks migration to ARES data leak forums
"A threat group called ARES is gaining notoriety on the cybercrime scene by selling and leaking databases stolen from corporations and public authorities.
The actor emerged on Telegram in late 2021 and has been associated with the RansomHouse ransomware operation and the data leak platform, KelvinSecurity, and the network access group Adrastea.
ARES Group manages its own site with database leaks and a forum, which may fill the void left by the now defunct Breached forum. . " READ MORE
UK criminal records office confirms cyber incident behind portal issues
The UK's Criminal Records Office (ACRO) has finally confirmed, after weeks of delaying issuing a statement, that online portal issues experienced since January 17 resulted from what it described as a "cyber security incident."
- April 06, 2023
- 03:38 PM
- 0
CISA orders agencies to patch Backup Exec bugs used by ransomware gang
- April 7, 2023
- 05:07 PM
- 0
"On Friday, U.S. Cybersecurity and Infrastructure Security Agency (CISA) increased by five its list of security issues that threat actors have used in attacks, three of them in Veritas Backup Exec exploited to deploy ransomware.
One of the vulnerabilities was exploited as zero-day as part of an exploit chain that targeted Samsung’s web browser and another that allows attackers to increase privileges on Windows machines.
Initial access in ransomware attack
Of the five vulnerabilities that CISA added to the catalog of Known Exploited Vulnerabilities (KEV) today, only one was rated critical, an issue in Veritas’ data protection software tracked as CVE-2021-27877 that allows remote access and command execution with elevated privileges.
A report earlier this week from cybersecurity firm Mandiant informs that CVE-2021-27877 was used by an affiliate of the ALPHV/BlackCat ransomware operation to gain initial access to a target network.
The other two flaws (CVE-2021-27876, CVE-2021-27878) impacting Veritas Backup Exec were also leveraged in the attack, enabling the intruder to access arbitrary files and execute arbitrary commands on the system.
It is worth noting that Veritas patched all three vulnerabilities in March 2021 and that thousands of Backup Exec instances are currently reachable over the public web.
Exploit chain delivers spyware
The zero-day vulnerability leveraged against Samsung’s web browser is tracked as CVE-2023-26083 and affects the Mali GPU driver from Arm.
Part of an exploit chain that delivered commercial spyware in a campaign discovered in December 2022 by Google's Threat Analysis Group (TAG), the security issue is an information leak that allows exposing sensitive kernel metadata.
In a previous KEV update at the end of March, CISA included in the catalog the other vulnerabilities leveraged in the exploit chain, some of which were zero-days at the time of the attack.
✓ The fifth vulnerability CISA added to KEV is identified as CVE-2019-1388. It impacts the Microsoft Windows Certificate Dialog and has been used in attacks to run processes with elevated privileges on a previously compromised machine.
Federal agencies in the U.S. have until April 28 to check if their systems are impacted by the newly added vulnerabilities and to apply the necessary updates.
As part of the binding operational directive (BOD 22-01) from November 2021, Federal Civilian Executive Branch Agencies (FCEB) agencies have to check and fix their networks for all bugs included in the KEV catalog, which currently has 911 entries.
Even if KEV is mainly aimed at federal agencies, it is strongly recommended that private companies all over the world treat with priority the vulnerabilities in the catalog.
-
Microsoft PowerToys adds Windows Registry preview feature
Microsoft PowerToys, a set of free utilities for Windows 10 users, has introduced a new feature allowing users to preview registry file contents before importing them.
- April 09, 2023
- 04:45 PM
- 0
-
All Dutch govt networks to use RPKI to prevent BGP hijacking
The Dutch government will adopt the RPKI (Resource Public Key Infrastructure) standard on all its systems before the end of 2024 to upgrade the security of its internet routing.
- April 09, 2023
- 11:21 AM
- 0
-
Get started in ethical hacking with this super-sized training bundle deal
Whether you're in charge of an enterprise system or simply looking for a new challenge in IT, ethical hacking is a rapidly growing field. These 18 courses offer multiple ways to get started for $45.99, 98% off the $3284 MSRP.
- April 09, 2023
- 08:14 AM
- 0
-
Breached shutdown sparks migration to ARES data leak forums
A threat group called ARES is gaining notoriety on the cybercrime scene by selling and leaking databases stolen from corporations and public authorities.
- April 08, 2023
- 12:17 PM
- 0
-
Western Digital struggles to fix massive My Cloud outage, offers workaround
On Friday, five days into a massive outage impacting its cloud services, Western Digital finally provided customers with a workaround to access their files.
- April 08, 2023
- 11:08 AM
- 0
-
No comments:
Post a Comment