U.S. cybersecurity agency CISA has added a new batch of 95 actively exploited flaws to its "Known Exploited Vulnerabilities Catalog."
Read: https://thehackernews.com/2022/03/cisa-adds-another-95-flaws-to-its.html
Read: https://thehackernews.com/2022/03/cisa-adds-another-95-flaws-to-its.html
👍1
Researchers warn of a new high-risk vulnerability (CVE-2022-0492) affecting the Linux kernel's cgroups feature that could potentially be abused to escape a container to execute arbitrary commands on the host.
Read details: https://thehackernews.com/2022/03/new-linux-kernel-cgroups-vulnerability.html
Read details: https://thehackernews.com/2022/03/new-linux-kernel-cgroups-vulnerability.html
Mozilla has warned hundreds of millions of Firefox users about newly discovered 0-day bugs (CVE-2022-26485, CVE-2022-26486) that are being exploited in the wild.
https://thehackernews.com/2022/03/2-new-mozilla-firefox-0-day-bugs-under.html
Update to Firefox 97.0.2, ESR 91.6.1, Android v97.3.0, Focus 97.3.0 & Thunderbird 91.6.2.
https://thehackernews.com/2022/03/2-new-mozilla-firefox-0-day-bugs-under.html
Update to Firefox 97.0.2, ESR 91.6.1, Android v97.3.0, Focus 97.3.0 & Thunderbird 91.6.2.
Ukrainian Computer Emergency Response Team (CERT-UA) warns of new phishing attacks against its citizens using compromised email accounts from Indian entities.
Read: https://thehackernews.com/2022/03/ukrainian-cert-warns-citizens-of.html
Read: https://thehackernews.com/2022/03/ukrainian-cert-warns-citizens-of.html
Newly disclosed vulnerabilities in the operating system for TerraMaster NAS devices can be chained to achieve unauthorized RCE with highest privileges.
https://thehackernews.com/2022/03/critical-bugs-in-terramaster-tos-could.html
Bugs found by Ethiopian cybersecurity firm OctagonNetworks have been patched in v4.2.30 or higher.
https://thehackernews.com/2022/03/critical-bugs-in-terramaster-tos-could.html
Bugs found by Ethiopian cybersecurity firm OctagonNetworks have been patched in v4.2.30 or higher.
Researchers have disclosed details of a now-patched Microsoft Azure automation vulnerability — dubbed AutoWarp — that could have allowed attackers unauthorized access to other Azure customer accounts.
Details: https://thehackernews.com/2022/03/microsoft-azure-autowarp-bug-could-have.html
Details: https://thehackernews.com/2022/03/microsoft-azure-autowarp-bug-could-have.html
Researchers warn of a new vulnerability (CVE-2022-0847) in the Linux kernel, dubbed "Dirty Pipe," which could allow an attacker to overwrite arbitrary data and take complete control of a system.
Details: https://thehackernews.com/2022/03/researchers-warn-of-linux-kernel-dirty.html
Details: https://thehackernews.com/2022/03/researchers-warn-of-linux-kernel-dirty.html
A series of newly discovered security vulnerabilities — dubbed "Access:7" — in PTC's Axeda software affects hundreds of thousands of ATMs, vending machines, SCADA systems, medical devices and IoT devices.
Read details: https://thehackernews.com/2022/03/critical-access7-supply-chain.html
Read details: https://thehackernews.com/2022/03/critical-access7-supply-chain.html
Samsung confirms a security breach that led to the exposure of internal company data, including the source code related to its Galaxy smartphones.
Read details: https://thehackernews.com/2022/03/samsung-confirms-data-breach-after.html
Read details: https://thehackernews.com/2022/03/samsung-confirms-data-breach-after.html
Google is officially buying cybersecurity company Mandiant in an all-cash deal approximately valued at $5.4 billion.
Read: https://thehackernews.com/2022/03/google-buys-cybersecurity-firm-mandiant.html
Read: https://thehackernews.com/2022/03/google-buys-cybersecurity-firm-mandiant.html
Google warns that Russian and Belarusian hackers are targeting Ukraine and European allies through phishing attacks.
Read details: https://thehackernews.com/2022/03/google-russian-hackers-target.html
Read details: https://thehackernews.com/2022/03/google-russian-hackers-target.html
👍1
Researchers have discovered 16 new high-severity vulnerabilities in UEFI firmware affecting millions of HP devices, including laptops, desktops, PoS systems and edge computing nodes.
Read details: https://thehackernews.com/2022/03/new-16-high-severity-uefi-firmware.html
Read details: https://thehackernews.com/2022/03/new-16-high-severity-uefi-firmware.html
Researchers have uncovered 3 critical vulnerabilities in the Pascom Cloud Phone System (CPS) that could be combined to achieve full pre-authenticated remote code execution of affected systems.
Details: https://thehackernews.com/2022/03/critical-rce-bugs-found-in-pascom-cloud.html
Details: https://thehackernews.com/2022/03/critical-rce-bugs-found-in-pascom-cloud.html
Cybersecurity researchers at Mandiant have revealed that China-backed APT41 hacker group compromised at least 6 state government networks in the United States between May 2021 and February 2022.
Read details: https://thehackernews.com/2022/03/chinese-apt41-hackers-broke-into-at.html
Read details: https://thehackernews.com/2022/03/chinese-apt41-hackers-broke-into-at.html
Patch Tuesday, March 2022: In addition to Microsoft, Adobe, and Google, the following major software vendors have also released patches to fix various security vulnerabilities:
—Cisco
—Citrix
—HP
—Intel
—Juniper Networks
—Linux distributions
— Mozilla Firefox and ESR
—SAP
—Schneider Electric, and
—Siemens
https://thehackernews.com/2022/03/critical-security-patches-issued-by.html
—Cisco
—Citrix
—HP
—Intel
—Juniper Networks
—Linux distributions
— Mozilla Firefox and ESR
—SAP
—Schneider Electric, and
—Siemens
https://thehackernews.com/2022/03/critical-security-patches-issued-by.html
👍1
⭐Experts have discovered 3 new critical flaws in APC Smart UPS that could let attackers remotely hack devices or manipulate ⚡ power of millions of enterprise devices to physically 💥 damage them or other 🖨️💻 assets connected to them.
Details: https://thehackernews.com/2022/03/critical-bugs-could-let-attackers.html
Details: https://thehackernews.com/2022/03/critical-bugs-could-let-attackers.html
⚡Hackers abusing Mitel devices to launch high-impact DDoS attacks with a record-breaking amplification ratio of 4,294,967,296 to 1.
Read details: https://thehackernews.com/2022/03/hackers-abuse-mitel-devices-to-amplify.html
Read details: https://thehackernews.com/2022/03/hackers-abuse-mitel-devices-to-amplify.html
Emotet botnet malware has infected over 100,000 computers since its latest resurgence in November 2021, and the number is steadily increasing.
Read details: https://thehackernews.com/2022/03/emotet-botnets-latest-resurgence.html
Read details: https://thehackernews.com/2022/03/emotet-botnets-latest-resurgence.html
22-year-old Ukrainian hacker allegedly linked to Sodinokibi/REvil ransomware gang has been extradited to the United States and put on trial for his role in carrying out #cyberattacks on several companies, including Kaseya.
Read details: https://thehackernews.com/2022/03/ukrainian-hacker-linked-to-revil.html
Read details: https://thehackernews.com/2022/03/ukrainian-hacker-linked-to-revil.html
New Branch History Injection (BHI) technique to exploit the Spectre v2 vulnerability allows attackers to bypass existing hardware mitigations in Intel, AMD, and Arm processors and leak sensitive information from host memory.
Details: https://thehackernews.com/2022/03/new-exploit-bypasses-existing-spectre.html
Details: https://thehackernews.com/2022/03/new-exploit-bypasses-existing-spectre.html