MITRE revealed that nation-state actors breached its systems via Ivanti zero-days
Security Affairs
by Pierluigi Paganini
2h ago
The MITRE Corporation revealed that a nation-state actor compromised its systems in January 2024 by exploiting Ivanti VPN zero-days. In April 2024, MITRE disclosed a security breach in one of its research and prototyping networks. The security team at the organization promptly launched an investigation, logged out the threat actor, and engaged third-party forensics Incident Response teams to conduct independent analysis in collaboration with internal experts. According to the MITRE Corporation, a nation state actor breached its systems in January 2024 by chaining two Ivanti Connect Secure zero ..read more
Visit website
FBI chief says China is preparing to attack US critical infrastructure
Security Affairs
by Pierluigi Paganini
15h ago
China-linked threat actors are preparing cyber attacks against U.S. critical infrastructure warned FBI Director Christopher Wray. FBI Director Christopher Wray warned this week that China-linked threat actors are preparing an attack against U.S. critical infrastructure, Reuters reported. According to the FBI chief, the Chinese hackers are waiting “for just the right moment to deal a devastating blow.” In February, US CISA, the NSA, the FBI, along with partner Five Eyes agencies, published a joint advisory to warn that China-linked APT Volt Typhoon infiltrated a critical infrastructur ..read more
Visit website
United Nations Development Programme (UNDP) investigates data breach
Security Affairs
by Pierluigi Paganini
18h ago
The United Nations Development Programme (UNDP) has initiated an investigation into an alleged ransomware attack and the subsequent theft of data. The United Nations Development Programme (UNDP) is investigating an alleged ransomware attack that resulted in data theft. The United Nations Development Programme (UNDP) is a United Nations agency tasked with helping countries eliminate poverty and achieve sustainable economic growth and human development. The cyber attack recently targeted the IT infrastructure of the Agency in UN City, Copenhagen. On M ..read more
Visit website
FIN7 targeted a large U.S. carmaker phishing attacks
Security Affairs
by Pierluigi Paganini
1d ago
BlackBerry reported that the financially motivated group FIN7 targeted the IT department of a large U.S. carmaker with spear-phishing attacks. In late 2023, BlackBerry researchers spotted the threat actor FIN7 targeting a large US automotive manufacturer with a spear-phishing campaign. FIN7 targeted employees who worked in the company’s IT department and had higher levels of administrative rights. The attackers employed the lure of a free IP scanning tool to infect the systems with the Anunak backdoor and gain an initial foothold using living-off-the-land binaries, scripts, and libraries (lolb ..read more
Visit website
Law enforcement operation dismantled phishing-as-a-service platform LabHost
Security Affairs
by Pierluigi Paganini
1d ago
An international law enforcement operation led to the disruption of the prominent phishing-as-a-service platform LabHost. An international law enforcement operation, codenamed Nebulae and coordinated by Europol, led to the disruption of LabHost, which is one of the world’s largest phishing-as-a-service platforms. Law enforcement from 19 countries participated in the operation which resulted in the arrest of 37 individuals. The phishing-as-a-service platform was available on the clear web and has been shut down by the police. Between April 14th and April 17th, law enforcement agencies conducted ..read more
Visit website
Previously unknown Kapeka backdoor linked to Russian Sandworm APT
Security Affairs
by Pierluigi Paganini
2d ago
Russia-linked APT Sandworm employed a previously undocumented backdoor called Kapeka in attacks against Eastern Europe since 2022. WithSecure researchers identified a new backdoor named Kapeka that has been used in attacks targeting victims in Eastern Europe since at least mid-2022. The backdoor is very sophisticated, it serves as both an initial toolkit and as a backdoor for maintaining long-term access to compromised systems. The nature of the targets, low detection rate, and sophisticated malware-supported features suggest that an APT group developed it. WithSecure noticed overlaps bet ..read more
Visit website
Cisco warns of a command injection escalation flaw in its IMC. PoC publicly available
Security Affairs
by Pierluigi Paganini
2d ago
Cisco has addressed a high-severity vulnerability in its Integrated Management Controller (IMC) for which publicly available exploit code exists. Cisco has addressed a high-severity Integrated Management Controller (IMC) vulnerability and is aware of a public exploit code for this issue. The PoC exploit code allows a local attacker to escalate privileges to root. Cisco Integrated Management Controller (IMC) is a baseboard management controller (BMC) that provides embedded server management for Cisco UCS C-Series Rack Servers and Cisco UCS S-Series Storage Servers. The vulnerability, tracked as ..read more
Visit website
Linux variant of Cerber ransomware targets Atlassian servers
Security Affairs
by Pierluigi Paganini
2d ago
Threat actors are exploiting the CVE-2023-22518 flaw in Atlassian servers to deploy a Linux variant of Cerber (aka C3RB3R) ransomware. At the end of October 2023, Atlassian warned of a critical security flaw, tracked as CVE-2023-22518 (CVSS score 9.1), that affects all versions of Confluence Data Center and Server. The vulnerability is an improper authorization issue that can lead to significant data loss if exploited by an unauthenticated attacker. Cado Security Labs recently became aware that Cerber ransomware is being deployed into Confluence servers via the CV ..read more
Visit website
Ivanti fixed two critical flaws in its Avalanche MDM
Security Affairs
by Pierluigi Paganini
3d ago
Ivanti addressed two critical vulnerabilities in its Avalanche mobile device management (MDM) solution, that can lead to remote command execution. Ivanti addressed multiple flaws in its Avalanche mobile device management (MDM) solution, including two critical flaws, tracked as CVE-2024-24996 and CVE-2024-29204, that can lead to remote command execution. The MDM software allows administrators to configure, deploy, update, and maintain up to 100,000 mobile IT assets all in one system. Below is the description for the two vulnerabilities: CVE-2024-24996 (CVSS score 9.8) – A Heap overflow vulnera ..read more
Visit website
Researchers released exploit code for actively exploited Palo Alto PAN-OS bug
Security Affairs
by Pierluigi Paganini
3d ago
Researchers released an exploit code for the actively exploited vulnerability CVE-2024-3400 in Palo Alto Networks’ PAN-OS. Researchers at watchTowr Labs have released a technical analysis of the vulnerability CVE-2024-3400 in Palo Alto Networks’ PAN-OS and a proof-of-concept exploit that can be used to execute shell commands on vulnerable firewalls. CVE-2024-3400 (CVSS score of 10.0) is a critical command injection vulnerability in Palo Alto Networks PAN-OS software. An unauthenticated attacker can exploit the flaw to execute arbitrary code with root privileges on affected firewalls. This ..read more
Visit website

Follow Security Affairs on FeedSpot

Continue with Google
Continue with Apple
OR