Tag: cyber
-
Thinkware Cloud APK Vulnerability Allows Code Execution With Elevated Privileges
A critical vulnerability identified as CVE-202453614 has been discovered in the Thinkware Cloud APK version 4.3.46. This vulnerability arises from the use of a hardcoded decryption key within the application. It allows malicious actors to access sensitive data and execute arbitrary commands with elevated privileges, potentially compromising the security of users’ devices and data. The…
-
I-O DATA Routers Command Injection Vulnerabilities Actively Exploited in Attacks
I-O DATA DEVICE, INC. has announced that several critical vulnerabilities in their UD-LT1 and UD-LT1/EX routers are being actively exploited. These vulnerabilities pose significant risks to users, necessitating urgent attention and action. Below is a detailed look at each vulnerability, its potential impact, and the solutions provided. CVE-2024-45841: Incorrect Permission Assignment for Critical Resource This…
-
ChatGPT Next Web Vulnerability Let Attackers Exploit Endpoint to Perform SSRF
Researchers released a detailed report on a significant security vulnerability named CVE-2023-49785, affecting the ChatGPT Next Web, popularly known as NextChat. This vulnerability has raised concerns within the cybersecurity community due to its potential for exploitation through Server-Side Request Forgery (SSRF). NextChat is a web interface designed for large language model (LLM) services. It provides…
-
Cyber incident board’s Salt Typhoon review to begin within days, CISA leader says
First seen on therecord.media Jump to article: therecord.media/salt-typhoon-csrb-review
-
Women in cyber: Tammy Klotz’s impact (video)
Tags: cyberFirst seen on scworld.com Jump to article: www.scworld.com/news/women-in-cyber-tammy-klotzs-impact-video
-
Deloitte UK Hacked Brain Cipher Group Claim to Have Stolen 1 TB of Data
Brain Cipher has claimed to have breached Deloitte UK and exfiltrated over 1 terabyte of sensitive data. Emerging in June 2024, Brain Cipher has quickly established a reputation for its aggressive cyberattacks, with a notable incident involving According to statements released by Brain Cipher, they have exploited critical weaknesses within Deloitte UK’s cybersecurity infrastructure. The…
-
Security teams should act now to counter Chinese threat, says CISA
Tags: 5G, access, apple, at&t, attack, authentication, china, cisa, cisco, communications, control, cyber, cybersecurity, data, encryption, espionage, exploit, google, government, hacker, infrastructure, linux, microsoft, mitigation, mobile, monitoring, network, nist, password, risk, service, siem, technology, theft, threat, vpn, vulnerabilitySecurity teams and individuals across the US need to take immediate precautions to counter the surveillance threat posed by Chinese ‘Salt Typhoon’ hackers, who have burrowed deep into telecoms infrastructure, according to the US Cybersecurity and Infrastructure Security Agency (CISA).CISA issued an official alert recommending defensive measures on December 3, as federal officials briefed journalists…
-
Russian cyber company F.A.C.C.T. sells key assets to establish new firm
First seen on therecord.media Jump to article: therecord.media/russia-cyber-firm-facct-sells-assets-creating-new-firm
-
CISA, German cyber authorities warn Zyxel firewalls facing active exploitation
Attackers have targeted dozens of companies with Helldown ransomware, researchers found. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/cisa-german-zyxel-firewalls-exploitation/734581/
-
Rund um den Black Friday 2024: Cyber-Gefahren für Einzelhandel drastisch zugenommen
Tags: cyberFirst seen on datensicherheit.de Jump to article: www.datensicherheit.de/umfeld-black-friday-2024-cyber-gefahren-einzelhandel-dramatik-zunahme
-
Russian hackers hijack Pakistani hackers’ servers for their own attacks
The notorious Russian cyber-espionage group Turla is hacking other hackers, hijacking the Pakistani threat actor Storm-0156’s infrastructure to launch their own covert attacks on already compromised networks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/russian-turla-hackers-hijack-pakistani-apt-servers-for-cyber-espionage-attacks/
-
Wirral Hospital Recovery Continues One Week After Cyber Incident
Wirral University Teaching Hospital is recovering from a cybersecurity incident that occurred on November 25, with some patient services still disrupted as systems are being restored First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/wirral-hospital-recovery-continues/
-
Vorsicht vor Whatsapp-Phishing mit gespoofter Rufnummer
Cyber-Kriminelle nehmen deutschsprachige WhatsApp-Nutzer ins Visier und versuchen mit einem perfiden Trick und einem Chatbot deren Accounts zu kapern. First seen on heise.de Jump to article: www.heise.de/news/Vorsicht-vor-Whatsapp-Phishing-mit-gespoofter-Rufnummer-10188150.html
-
Nordics move to deepen cyber security cooperation
Nordic countries are increasing collaboration on cyber security amid more sophisticated and aggressive attacks First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366616450/Nordics-move-to-deepen-cyber-security-cooperation
-
Cloudflare Developer Domains Abused For Cyber Attacks
Cloudflare Pages, a popular web deployment platform, is exploited by threat actors to host phishing sites, as attackers leverage Cloudflare’s trusted infrastructure, global CDN, and free hosting to quickly set up and deploy convincing phishing sites. Automatic SSL/TLS encryption enhances the sites’ legitimacy, while custom domains and URL masking further obfuscate their malicious nature. Cloudflare’s…
-
Hackers Exploit Docker Remote API Servers To Inject Gafgyt Malware
Attackers are exploiting publicly exposed Docker Remote API servers to deploy Gafgyt malware by creating a Docker container using a legitimate >>alpine
-
Weaponized Word Documents Attacking Windows Users to Deliver NetSupport BurnsRAT
The threat actors distributed malicious JS scripts disguised as legitimate business documents, primarily in ZIP archives with names like >>Purchase request>Request for quote.
-
Liverpool Children’s Hospital Confirms Cyber-Attack
Alder Hey Children’s NHS Foundation Trust said a single attack compromised the systems of three NHS entities First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/liverpool-children-hospital/
-
Prognosen für die Cyber-Bedrohungen 2025
Tags: cyberJedes Jahr, wenn wir uns dem Ende des letzten Quartals nähern, ist es wichtig, über die Trends, Taktiken und Techniken nachzudenken, die die Cyber-Bedrohungen während des Jahres dominiert haben. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/prognosen-fuer-die-cyber-bedrohungen-2025
-
From Phishing to Passwords: How Azercell is Educating Seniors About Cyber Threats
Azercell, the leading mobile operator in Azerbaijan, is offering cybersecurity training to its customers, particularly the elderly. As part of its ongoing efforts, Azercell cybersecurity training for residents of a social service institution for the elderly. The training aimed to equip this senior generation with the knowledge and tools necessary to understand digital life and…
-
Virtual Event Today: Cyber AI Automation Summit
SecurityWeek’s Cyber AI Automation Summit takes place on December 4th, as a fully immersive online experience. The post Virtual Event Today: Cyber AI & Automation Summit appeared first on SecurityWeek. First seen on securityweek.com Jump to article: www.securityweek.com/virtual-event-today-cyber-ai-automation-summit-2/
-
New TLDs Such as .shop, .top and .xyz Leveraged by Phishers
Phishing attacks have surged nearly 40% in the year ending August 2024, with a significant portion of this increase linked to new generic top-level domains (gTLDs) like .shop, .top, and .xyz. These domains, known for their minimal registration requirements and low costs, have become attractive to cybercriminals, according to new research by Interisle Consulting. This…
-
Australia, Canada, New Zealand, and the U.S. warn of PRC-linked cyber espionage targeting telecom networks
Australia, Canada, New Zealand, and the U.S. warn of PRC-linked cyber espionage targeting telecom networks in a joint advisory. Australia, Canada, New Zealand, and the U.S. issued a joint advisory to warn of People’s Republic of China (PRC)-linked cyber espionage targeting telecom networks. >>The Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Federal…
-
Preis allein ist nicht entscheidend – So kommen Sie an Ihren besten Cyber-Versicherungsschutz
Tags: cyberFirst seen on security-insider.de Jump to article: www.security-insider.de/cyberversicherung-kmu-risiken-vorteile-a-5a926fc7e6b7853512bffb9e07d8f96e/
-
Veeam stellt neue Enterprise-Funktionalitäten und Microsoft Entra ID-Schutz vor
Die neueste Version bietet neue Tools zur Stärkung der Cyber-Resilienz, verbessertes Reporting durch Generative KI, vollständigen Schutz für Nutanix AHV und Zugang zu Veeam Data Cloud Vault v2 First seen on infopoint-security.de Jump to article: www.infopoint-security.de/veeam-stellt-neue-enterprise-funktionalitaeten-und-microsoft-entra-id-schutz-vor/a39139/
-
Google Chrome Security Update, Patch for High-severity Vulnerability
Google has released a significant security update for its Chrome browser, aiming to address several vulnerabilities and enhance user safety. The Stable channel has been updated to version 131.0.6778.108/.109 for Windows, and Mac, and version 131.0.6778.108 for Linux. These updates will be gradually rolled out to users over the coming days and weeks. According to…
-
Progress WhatsUp Gold RCE Vulnerability PoC Exploit Released
A registry overwrite remote code execution (RCE) vulnerability has been identified in NmAPI.exe, part of the WhatsUp Gold network monitoring software. This vulnerability, present in versions before 24.0.1, allows an unauthenticated remote attacker to execute arbitrary code on affected systems, posing significant security risks. Vulnerability Details The vulnerability lies within NmAPI.exe, a Windows Communication Foundation…

