2023

New persistent backdoor used in attacks on Barracuda ESG appliances

New persistent backdoor used in attacks on Barracuda ESG appliances 31/07/2023 at 13:32 By Helga Labus The Cybersecurity and Infrastructure Agency (CISA) has published an analysis report on the backdoors dropped by attackers exploiting CVE-2023-2868, a remote command injection vulnerability in Barracuda Email Security Gateway (ESG) appliances. Barracuda ESG zero-day exploit and backdoors In late […]

New persistent backdoor used in attacks on Barracuda ESG appliances Read More »

Second Ivanti EPMM Zero-Day Vulnerability Exploited in Targeted Attacks

Second Ivanti EPMM Zero-Day Vulnerability Exploited in Targeted Attacks 31/07/2023 at 13:31 By Eduard Kovacs Ivanti EPMM customers have been warned of CVE-2023-35081, a second zero-day vulnerability that has been exploited in targeted attacks. The post Second Ivanti EPMM Zero-Day Vulnerability Exploited in Targeted Attacks appeared first on SecurityWeek. This article is an excerpt from

Second Ivanti EPMM Zero-Day Vulnerability Exploited in Targeted Attacks Read More »

CISA Analyzes Malware Used in Barracuda ESG Attacks

CISA Analyzes Malware Used in Barracuda ESG Attacks 31/07/2023 at 13:31 By Ionut Arghire CISA has shared analysis reports on three malware families obtained from an organization hacked via a recent Barracuda ESG vulnerability. The post CISA Analyzes Malware Used in Barracuda ESG Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

CISA Analyzes Malware Used in Barracuda ESG Attacks Read More »

AVRecon Botnet Leveraging Compromised Routers to Fuel Illegal Proxy Service

AVRecon Botnet Leveraging Compromised Routers to Fuel Illegal Proxy Service 31/07/2023 at 13:02 By More details have emerged about a botnet called AVRecon, which has been observed making use of compromised small office/home office (SOHO) routers as part of a multi-year campaign active since at least May 2021. AVRecon was first disclosed by Lumen Black Lotus Labs earlier

AVRecon Botnet Leveraging Compromised Routers to Fuel Illegal Proxy Service Read More »

Fruity Trojan Uses Deceptive Software Installers to Spread Remcos RAT

Fruity Trojan Uses Deceptive Software Installers to Spread Remcos RAT 31/07/2023 at 13:02 By Threat actors are creating fake websites hosting trojanized software installers to trick unsuspecting users into downloading a downloader malware called Fruity with the goal of installing remote trojans tools like Remcos RAT. “Among the software in question are various instruments for

Fruity Trojan Uses Deceptive Software Installers to Spread Remcos RAT Read More »

Satnav for the Moon could benefit from Fibonacci’s expertise

Satnav for the Moon could benefit from Fibonacci’s expertise 31/07/2023 at 12:48 By Dan Robinson Middle Ages maths to the rescue Future satellite navigation systems intended for Earth’s Moon may be aided by a model of it developed with methods that go back to mathematician Fibonacci, who lived 800 years ago.… This article is an

Satnav for the Moon could benefit from Fibonacci’s expertise Read More »

Multiple Flaws Found in Ninja Forms Plugin Leave 800,000 Sites Vulnerable

Multiple Flaws Found in Ninja Forms Plugin Leave 800,000 Sites Vulnerable 31/07/2023 at 11:17 By Multiple security vulnerabilities have been disclosed in the Ninja Forms plugin for WordPress that could be exploited by threat actors to escalate privileges and steal sensitive data. The flaws, tracked as CVE-2023-37979, CVE-2023-38386, and CVE-2023-38393, impact versions 3.6.25 and below,

Multiple Flaws Found in Ninja Forms Plugin Leave 800,000 Sites Vulnerable Read More »

Stremio vulnerability exposes millions to RCE and data theft

Stremio vulnerability exposes millions to RCE and data theft 31/07/2023 at 11:02 By Help Net Security CyFox has recently identified a critical hijacking vulnerability in Stremio 4.4, a popular software platform for streaming movies and TV shows. With over 5 million users relying on Stremio for their entertainment needs, this vulnerability poses a significant risk

Stremio vulnerability exposes millions to RCE and data theft Read More »

Avaya reseller pleads guilty to role in $88m licensing scam

Avaya reseller pleads guilty to role in $88m licensing scam 31/07/2023 at 10:02 By Simon Sharwood Comms vendor’s employee allegedly generated bogus licences and hijacked sysadmin accounts to make more A New Jersey man has plead guilty to selling pirated Avaya software licenses, allegedly generated and shopped by one of the vendor’s system administrators.… This

Avaya reseller pleads guilty to role in $88m licensing scam Read More »

‘Weird numerological coincidence’ found during work on Linux kernel 6.5

‘Weird numerological coincidence’ found during work on Linux kernel 6.5 31/07/2023 at 08:02 By Simon Sharwood It might be the only non-boring thing about the release, which has Linus Torvalds celebrating Linus Torvalds has noticed a “weird numerological coincidence” during work on version 6.5 of the Linux kernel.… This article is an excerpt from The

‘Weird numerological coincidence’ found during work on Linux kernel 6.5 Read More »

How the best CISOs leverage people and technology to become superstars

How the best CISOs leverage people and technology to become superstars 31/07/2023 at 07:47 By Help Net Security What separates superstar CISOs from the rest of the pack is that they are keenly aware of the burgeoning threat landscape and the cybersecurity skills shortage, but they don’t give in to despair. Instead, they use their

How the best CISOs leverage people and technology to become superstars Read More »

Data privacy vault: Securing sensitive data while navigating regulatory demands

Data privacy vault: Securing sensitive data while navigating regulatory demands 31/07/2023 at 07:32 By Help Net Security In this Help Net Security interview, Jean-Charles Chemin, CEO of Legapass, provides insight into the correlation between maintaining customer trust and protecting sensitive customer data. He emphasizes how a data privacy vault can reinforce customer trust by offering

Data privacy vault: Securing sensitive data while navigating regulatory demands Read More »

Relying on CVSS alone is risky for vulnerability management

Relying on CVSS alone is risky for vulnerability management 31/07/2023 at 07:05 By Help Net Security A vulnerability management strategy that relies solely on CVSS for vulnerability prioritization is proving to be insufficient at best, according to Rezilion. In fact, relying solely on a CVSS severity score to assess the risk of individual vulnerabilities was

Relying on CVSS alone is risky for vulnerability management Read More »

Open-source security challenges and complexities

Open-source security challenges and complexities 31/07/2023 at 06:31 By Help Net Security Open source refers to software or technology that is made available to the public with its source code openly accessible, editable, and distributable. In other words, the source code contains the underlying programming instructions and is freely available for anyone to view, modify,

Open-source security challenges and complexities Read More »

Indonesia blocks Musk’s X.com over its X-rated past

Indonesia blocks Musk’s X.com over its X-rated past 31/07/2023 at 06:17 By Laura Dobberstein ALSO: Japan’s government to write docs with AI; 5G boom coming; India denies infosec issues Asia In Brief  Elon Musk’s rebadged Twitter, X.com, has been blocked in Indonesia as the domain was formerly used to for websites containing content deemed unsuitable,

Indonesia blocks Musk’s X.com over its X-rated past Read More »

The race against time in ransomware attacks

The race against time in ransomware attacks 31/07/2023 at 06:02 By Help Net Security Most organizations lack strong cyber resilience strategies or data security capabilities to address threats and maintain business continuity, according to BigID. Despite both the rise in threats and the high percentage of respondents whose organizations suffered recent attacks, there hasn’t been

The race against time in ransomware attacks Read More »

Week in review: Ivanti zero-day exploited, MikroTik vulnerability could compromise 900,000 routers

Week in review: Ivanti zero-day exploited, MikroTik vulnerability could compromise 900,000 routers 30/07/2023 at 11:02 By Help Net Security Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Key factors for effective security automation In this Help Net Security interview, Oliver Rochford, Chief Futurist at Tenzir, discusses how automation

Week in review: Ivanti zero-day exploited, MikroTik vulnerability could compromise 900,000 routers Read More »

Microsoft co-founder Paul Allen’s pop artifact stash now heads to a museum

Microsoft co-founder Paul Allen’s pop artifact stash now heads to a museum 29/07/2023 at 16:19 By Brandon Vigliarolo Kurt Cobain and Jimi Hendrick’s guitars, Vader’s helmet, Captain Kirk’s chair, and more Paul Allen left more than just a tech legacy and billions of dollars behind when he died. The Microsoft co-founder amassed a sizable collection

Microsoft co-founder Paul Allen’s pop artifact stash now heads to a museum Read More »

Scroll to Top