New OpenSSH Vulnerability Could Lead to RCE as Root on Linux Systems post, juli 1, 2024 OpenSSH maintainers have released security updates to contain a critical security flaw that could result in unauthenticated remote code execution with root privileges in glibc-based Linux systems. The vulnerability has been assigned the CVE identifier CVE-2024-6387. It resides in the OpenSSH server component, also known as sshd, which is designed to… Continue Reading
TeamViewer Credits Network Segmentation for Rebuffing APT29 Attack post, juni 28, 2024juli 3, 2025 Despite warnings from Health-ISAC and the NCC Group, the remote access software maker says defense-in-depth kept customers’ data safe from Midnight Blizzard. In public statements on June 27 (reiterated today), the German maker of remote desktop software said, “[W]e keep all servers, networks, and accounts strictly separate to help prevent unauthorized access… Continue Reading
Chinese Cyberspies Employ Ransomware in Attacks for Diversion post, juni 27, 2024juli 3, 2025 Cyberespionage groups have been using ransomware as a tactic to make attack attribution more challenging, distract defenders, or for a financial reward as a secondary goal to data theft. A joint report from SentinelLabs and Recorded Future analysts presents the case of ChamelGang, a suspected Chinese advanced persistent threat (APT) that… Continue Reading
Most critical open source projects not using memory safe code post, juni 26, 2024juni 27, 2024 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published research looking into 172 key open-source projects and whether they are susceptible to memory flaws. The report, cosigned by CISA, the Federal Bureau of Investigation (FBI), as well as Australian (ASD, ACSC) and Canadian organizations (CCCS), is a follow-up to the… Continue Reading
China-Linked Cyber-Espionage Teams Target Asian Telecoms post, juni 25, 2024februari 24, 2025 In the latest breaches, threat groups compromised telecommunications firms in at least two Asian nations, installing backdoors and possibly eavesdropping or pre-positioning for a future attack. At least three cyber-espionage groups have compromised telecommunications operators in multiple countries in the Asia-Pacific region, placing backdoors inside the communications providers’ networks, stealing… Continue Reading
Chinese Cyber Espionage Targets Telecom Operators in Asia Since 2021 post, juni 20, 2024februari 24, 2025 Cyber espionage groups associated with China have been linked to a long-running campaign that has infiltrated several telecom operators located in a single Asian country at least since 2021. “The attackers placed backdoors on the networks of targeted companies and also attempted to steal credentials,” the Symantec Threat Hunter Team,… Continue Reading
Phoenix UEFI vulnerability impacts hundreds of Intel PC models post, juni 20, 2024juni 21, 2024 A newly discovered vulnerability in Phoenix SecureCore UEFI firmware tracked as CVE-2024-0762 impacts devices running numerous Intel CPUs, with Lenovo already releasing new firmware updates to resolve the flaw. The vulnerability, dubbed ‘UEFICANHAZBUFFEROVERFLOW,’ is a buffer overflow bug in the firmware’s Trusted Platform Module (TPM) configuration that could be exploited… Continue Reading
Hamas Hackers Sling Stealthy Spyware Across Egypt, Palestine post, juni 17, 2024juli 3, 2025 Hamas-linked advanced persistent threat (APT) group Arid Viper has been observed using Android spyware AridSpy dating back to 2022. Now, for the first time, researchers have provided a full analysis of the malware’s previously mysterious later stages. Continue Reading
PoC Exploit Emerges for Critical RCE Bug in Ivanti Endpoint Manager post, juni 13, 2024juni 14, 2024 A new month, a new high-risk Ivanti bug for attackers to exploit — this time, an SQL injection issue in its centralized endpoint manager. Researchers have developed a proof-of-concept (PoC) exploit for a critical vulnerability in Ivanti Endpoint Manager that was recently disclosed — potentially setting the stage for mass… Continue Reading
Rockwell’s ICS Directive Comes As Critical Infrastructure Risk Peaks post, juni 13, 2024februari 24, 2025 Critical infrastructure is facing increasingly disruptive threats to physical processes, while thousands of devices are online with weak authentication and riddled with exploitable bugs. Continue Reading