βIvanti warns of new actively exploited MobileIron zero-day bug
https://www.bleepingcomputer.com/news/security/ivanti-warns-of-new-actively-exploited-mobileiron-zero-day-bug/
https://www.bleepingcomputer.com/news/security/ivanti-warns-of-new-actively-exploited-mobileiron-zero-day-bug/
BleepingComputer
Ivanti warns of new actively exploited MobileIron zero-day bug
US-based IT software company Ivanti warned customers today that a critical Sentry API authentication bypass vulnerability is being exploited in the wild.
βInterpol Arrested 14 cybercriminals and uncovered 20,674 suspicious cyber networks
https://gbhackers.com/interpol-arrested-14-cybercriminals/
https://gbhackers.com/interpol-arrested-14-cybercriminals/
GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Interpol Arrested 14 cybercriminals and 20,674 cyber networks
The recent Africa Cyber Surge II operation conducted by INTERPOL and AFRIPOL has revealed a stark reality β the surge in digital insecurity and cybercriminals threats across Africa.
βSEIKO Data Breach: BlackCat Group Claims Responsibility
https://cybersecuritynews.com/seiko-data-breach/
https://cybersecuritynews.com/seiko-data-breach/
Cyber Security News
SEIKO Data Breach: BlackCat Group Claims Responsibility
The well-known watch manufacturing company Seiko disclosed the data breach notification recently on Aug 2023, targeted by the notorious threat group BlackCat/ALPHV.
βOngoing Duo outage causes Azure Auth authentication errors
https://www.bleepingcomputer.com/news/technology/ongoing-duo-outage-causes-azure-auth-authentication-errors/
https://www.bleepingcomputer.com/news/technology/ongoing-duo-outage-causes-azure-auth-authentication-errors/
BleepingComputer
Ongoing Duo outage causes Azure Auth authentication errors
Cisco-owned multi-factor authentication (MFA) provider Duo Security is investigating an ongoing outage that has been causing authentication failures and errors starting three hours ago.
βBuilt-in authenticator in Kaspersky Password Manager | Kaspersky official blog
https://www.kaspersky.com/blog/kaspersky-password-manager-authenticator/48841/
https://www.kaspersky.com/blog/kaspersky-password-manager-authenticator/48841/
Kaspersky
Built-in authenticator in Kaspersky Password Manager
Kaspersky Password Manager now features a built-in one-time code generator for two-factor authentication in other services and applications.
βCVE-2023-38035: Ivanti Sentry API Authentication Bypass Vulnerability Being Exploited in the Wild
https://securityonline.info/cve-2023-38035-ivanti-sentry-api-authentication-bypass-vulnerability-being-exploited-in-the-wild/
https://securityonline.info/cve-2023-38035-ivanti-sentry-api-authentication-bypass-vulnerability-being-exploited-in-the-wild/
Cybersecurity News
CVE-2023-38035: Ivanti Sentry API Authentication Bypass Vulnerability Being Exploited in the Wild
With a staggering CVSS score of 9.8, the CVE-2023-38035 vulnerability pertains to the MICS Admin Portal in Ivanti MobileIron Sentry
βSneaky Amazon Google ad leads to Microsoft support scam
https://www.bleepingcomputer.com/news/security/sneaky-amazon-google-ad-leads-to-microsoft-support-scam/
https://www.bleepingcomputer.com/news/security/sneaky-amazon-google-ad-leads-to-microsoft-support-scam/
BleepingComputer
Sneaky Amazon Google ad leads to Microsoft support scam
A legitimate-looking ad for Amazon in Google search results redirects visitors to a Microsoft Defender tech support scam that locks up their browser.
βTP-Link smart bulbs can let hackers steal your WiFi password
https://www.bleepingcomputer.com/news/security/tp-link-smart-bulbs-can-let-hackers-steal-your-wifi-password/
https://www.bleepingcomputer.com/news/security/tp-link-smart-bulbs-can-let-hackers-steal-your-wifi-password/
BleepingComputer
TP-Link smart bulbs can let hackers steal your WiFi password
Researchers from Italy and the UK have discovered four vulnerabilities in the TP-Link Tapo L530E smart bulb and TP-Link's Tapo app, which could allow attackers to steal their target's WiFi password.
βJapanese Watchmaker Seiko Breached by Ransomware, Confidential Schematics Leaked
https://restoreprivacy.com/seiko-breached-by-ransomware-confidential-schematics-leaked/
https://restoreprivacy.com/seiko-breached-by-ransomware-confidential-schematics-leaked/
CyberInsider
Japanese Watchmaker Seiko Breached by Ransomware, Confidential Schematics Leaked
The Seiko Group Corporation (Seiko) has suffered a data breach resulting from a ransomware attack that has entered today its blackmail phase.
βnoir: attack surface detector from source code
https://securityonline.info/noir-attack-surface-detector-from-source-code/
https://securityonline.info/noir-attack-surface-detector-from-source-code/
βCISA warns of critical Adobe ColdFusion flaw (CVE-2023-26359) exploited in the wild
https://securityonline.info/cisa-warns-of-critical-adobe-coldfusion-flaw-cve-2023-26359-exploited-in-the-wild/
https://securityonline.info/cisa-warns-of-critical-adobe-coldfusion-flaw-cve-2023-26359-exploited-in-the-wild/
Cybersecurity News
CISA warns of critical Adobe ColdFusion flaw (CVE-2023-26359) exploited in the wild
The CVE-2023-26359 vulnerability with a CVSS score of 9.8 is caused by the deserialization of untrusted data.
βWordPress custom field plugin bug (CVE-2023-40068) exposes 1M sites to XSS attacks
https://securityonline.info/wordpress-custom-field-plugin-bug-cve-2023-40068-exposes-1m-sites-to-xss-attacks/
https://securityonline.info/wordpress-custom-field-plugin-bug-cve-2023-40068-exposes-1m-sites-to-xss-attacks/
Cybersecurity News
WordPress custom field plugin bug (CVE-2023-40068) exposes 1M sites to XSS attacks
CVE-2023-40068 is a stored XSS vulnerability specifically affecting ACFβs admin screens tied with post type and taxonomy labels
βopenappsec: machine learning security engine to prevents threats against Web Application & APIs
https://securityonline.info/openappsec-machine-learning-security-engine-to-prevents-threats-against-web-application-apis/
https://securityonline.info/openappsec-machine-learning-security-engine-to-prevents-threats-against-web-application-apis/
βNew HiatusRAT campaign targets Taiwan and U.S. military procurement system
https://securityaffairs.com/149723/intelligence/hiatusrat-campaign-taiwan-us.html
https://securityaffairs.com/149723/intelligence/hiatusrat-campaign-taiwan-us.html
Security Affairs
New HiatusRAT campaign targets Taiwan and U.S. military procurement system
HiatusRAT malware operators resurfaced with a new wave of attacks targeting Taiwan-based organizations and a U.S. military procurement system
βBlackCat ransomware group claims the hack of Seiko network
https://securityaffairs.com/149734/cyber-crime/blackcat-alphv-ransomware-group-seiko.html
https://securityaffairs.com/149734/cyber-crime/blackcat-alphv-ransomware-group-seiko.html
Security Affairs
BlackCat ransomware group claims the hack of Seiko network
The BlackCat/ALPHV ransomware group claims to have hacked the Japanese maker of watches Seiko and added the company to its data leak site.
βDotRunpeX Malware Injector Widely Delivers Known Malware Families to Attack Windows
https://gbhackers.com/dotrunpex-malware/
https://gbhackers.com/dotrunpex-malware/
GBHackers Security | #1 Globally Trusted Cyber Security News Platform
DotRunpeX Injector Widely Delivers Known Malware Families to Attack Windows
DotRunpeX is one of the new and stealthiest .NET injectors that employs the "Process Hollowing" method, through which this malware distributes a diverse range of other malware strains.
βIvanti fixed a new critical Sentry API authentication bypass flaw
https://securityaffairs.com/149739/hacking/ivanti-sentry-api-flaw.html
https://securityaffairs.com/149739/hacking/ivanti-sentry-api-flaw.html
Security Affairs
Ivanti fixed a new critical Sentry API authentication bypass flaw
Ivanti warned customers of a new critical Sentry API authentication bypass vulnerability tracked as CVE-2023-38035.
βTesla Data Breach β 75,000+ Users Information Details Exposed
https://cybersecuritynews.com/tesla-data-breach/
https://cybersecuritynews.com/tesla-data-breach/
Cyber Security News
Tesla Data Breach β 75,000+ Users Information Details Exposed
Recently, Tesla reported a data breach that exposed more than 75,000 users' information. It's the result of an "insider wrongdoing."
βA cyber attack hit the Australian software provider Energy One
https://securityaffairs.com/149746/hacking/cyber-attack-hit-energy-one.html
https://securityaffairs.com/149746/hacking/cyber-attack-hit-energy-one.html
Security Affairs
A cyber attack hit the Australian software provider Energy One
Energy One announced it was hit by a cyberattack last week that affected certain corporate systems in Australia and the UK.
βCISA adds critical Adobe ColdFusion flaw to its Known Exploited Vulnerabilities catalog
https://securityaffairs.com/149754/security/cisa-adds-critical-adobe-coldfusion-flaw-to-its-known-exploited-vulnerabilities-catalog.html
https://securityaffairs.com/149754/security/cisa-adds-critical-adobe-coldfusion-flaw-to-its-known-exploited-vulnerabilities-catalog.html
Security Affairs
CISA adds critical Adobe ColdFusion flaw to its Known Exploited Vulnerabilities catalog
US CISA added critical vulnerability CVE-2023-26359 in Citrix ShareFile to its Known Exploited Vulnerabilities catalog.
βSnatch gang claims the hack of the Department of Defence South Africa
https://securityaffairs.com/149760/cyber-crime/snatch-ransomware-department-of-defence-south-africa.html
https://securityaffairs.com/149760/cyber-crime/snatch-ransomware-department-of-defence-south-africa.html
Security Affairs
Snatch gang claims the hack of the Department of Defence South Africa
Snatch gang claims the hack of the Department of Defence South Africa and added the military organization to its leak site.