Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Thursday, May 12, 2022

Zyxel silently fixes critical RCE vulnerability in firewall products

Threat analysts who discovered a vulnerability affecting multiple Zyxel products report that the network equipment company fixed it via a silent update pushed out two weeks ago. [...] Posted at https://sl.advdat.com/3wkVH7L

BPFdoor: Stealthy Linux malware bypasses firewalls for remote access

A recently discovered backdoor malware called BPFdoor has been stealthily targeting Linux and Solaris systems without being noticed for more than five years. [...] Posted at https://sl.advdat.com/3FGWQKZ

Microsoft: May Windows updates cause AD authentication failures

Microsoft is investigating a known issue causing authentication failures for some Windows services after installing updates released during the May 2022 Patch Tuesday. [...] Posted at https://sl.advdat.com/3FBfPGI

Wednesday, May 11, 2022

Microsoft: Windows 10 20H2 has reached end of service

Microsoft says multiple editions of Windows 10 20H2 and Windows 10 1909 have reached their end of service (EOS) on this month's Patch Tuesday, on May 10, 2022. [...] Posted at https://sl.advdat.com/3su8zHj

FBI, CISA, and NSA warn of hackers increasingly targeting MSPs

Members of the Five Eyes (FVEY) intelligence alliance today warned managed service providers (MSPs) and their customers that they're increasingly targeted by supply chain attacks. [...] Posted at https://sl.advdat.com/3w34pZd

Bitter cyberspies target South Asian govts with new malware

New activity has been observed from Bitter, an APT group focused on cyberespionage, targeting the government of Bangladesh with new malware with remote file execution capabilities. [...] Posted at https://sl.advdat.com/3w3Am3N

New IceApple exploit toolset deployed on Microsoft Exchange servers

Security researchers have found a new post-exploitation framework that they dubbed IceApple, deployed mainly on Microsoft Exchange servers across a wide geography. [...] Posted at https://sl.advdat.com/3kXlBsP

Microsoft fixes Windows Direct3D issue behind app crashes

Microsoft has addressed a known issue causing apps using Direct3D 9 to experience issues after installing April 2022 cumulative updates, including crashes and errors on systems using certain GPUs. [...] Posted at https://sl.advdat.com/3wkEriT

CISA Joins Partners to Release Advisory on Protecting MSPs and their Customers

Original release date: May 11, 2022

The cybersecurity authorities of the United Kingdom, Australia, Canada, New Zealand, and the United States have released joint Cybersecurity Advisory (CSA), Protecting Against Cyber Threats to Managed Service Providers and their Customers, to provide guidance on how to protect against malicious cyber activity targeting managed service providers (MSPs) and their customers. The CSA—created in response to reports of increased activity against MSPs and their customers—provides specific guidance for both MSPs and customers aimed at enabling transparent discussions on securing sensitive data. The CSA also provides tactical actions for MSPs and customers, including:

  • Identify and disable accounts that are no longer in use.
  • Enforce MFA on MSP accounts that access the customer environment and monitor for unexplained failed authentication.
  • Ensure MSP-customer contracts transparently identify ownership of information and communications technology (ICT) security roles and responsibilities.

CISA urges organizations to review the joint CSA and take actions to strengthen their defenses against malicious cyber activity.  

This product is provided subject to this Notification and this Privacy & Use policy.

Posted at https://sl.advdat.com/3l2n3Kq

Tuesday, May 10, 2022

Microsoft May 2022 Patch Tuesday fixes 3 zero-days, 75 flaws

Today is Microsoft's May 2022 Patch Tuesday, and with it comes fixes for three zero-day vulnerabilities, with one actively exploited, and a total of 75 flaws. [...] Posted at https://sl.advdat.com/3L0GlKT

Windows 10 KB5013942 and KB5013945 updates released

Microsoft has released Windows 10 KB5013945 and KB5013942 cumulative updates for versions 21H2, version 21H1, version 20H2, and 1909 to fix security vulnerabilities and resolve bugs. [...] Posted at https://sl.advdat.com/3w2sMGk

FluBot Android malware targets Finland in new SMS campaigns

Finland's National Cyber Security Center (NCSC-FI) has issued a warning about the FluBot Android malware infections increasing due to a new campaign that relies on SMS and MMS for distribution. [...] Posted at https://sl.advdat.com/3spMF8q

UK govt releases free tool to check for email cybersecurity risks

The United Kingdom's National Cyber Security Centre (NCSC) today released a new email security check service to help organizations easily identify vulnerabilities that could allow attackers to spoof emails or can lead to email privacy breaches. [...] Posted at https://sl.advdat.com/3M56hWX

Monday, May 9, 2022

Ukraine warns of “chemical attack” phishing pushing stealer malware

Ukraine's Computer Emergency Response Team (CERT-UA) is warning of the mass distribution of Jester Stealer malware via phishing emails using warnings of impending chemical attacks to scare recipients into opening attachments. [...] Posted at https://sl.advdat.com/3wg1AD1

Hackers are now hiding malware in Windows Event Logs

Security researchers have noticed a malicious campaign that used Windows event logs to store malware, a technique that has not been previously documented publicly for attacks in the wild. [...] Posted at https://sl.advdat.com/3FsXxHG

Costa Rica declares national emergency after Conti ransomware attacks

The Costa Rican President Rodrigo Chaves has declared a national emergency following cyber attacks from Conti ransomware group. BleepingComputer also observed Conti published most of the 672 GB dump that appears to contain data belonging to the Costa Rican government agencies. [...] Posted at https://sl.advdat.com/395VBZq

Sunday, May 8, 2022

Check your gems: RubyGems fixes unauthorized package takeover bug

The RubyGems package repository has fixed a critical vulnerability that would allow anyone to unpublish ("yank") certain Ruby packages from the repository and republish their tainted or malicious versions with the same file names and version numbers. [...] Posted at https://sl.advdat.com/3siiv6Y

Caramel credit card stealing service is growing in popularity

A credit card stealing service is growing in popularity, allowing any low-skilled threat actors an easy and automated way to get started in the world of financial fraud. [...] Posted at https://sl.advdat.com/3ynxrEH

Saturday, May 7, 2022

Fake crypto giveaways steal millions reusing Elon Musk, Dorsey videos

Fake cryptocurrency giveaways are stealing millions of dollars simply by replaying old Elon Musk and Jack Dorsey Ark Invest videos on YouTube. [...] Posted at https://sl.advdat.com/3Foo2Oq

UK sanctions Russian microprocessor makers, banning them from ARM

The UK government added 63 Russian entities to its sanction list on Wednesday. Among them are Baikal Electronics and MCST (Moscow Center of SPARC Technologies), the two most important chip makers in Russia. [...] Posted at https://sl.advdat.com/3vUCURO