Cybersecurity News, Insights and Analysis

cyber threat news

N-able’s incident notice says the flaw has been exploited in the wild; its release notes say that is unconfirmed. Progress Software patched the flaws in July, and exploitation requires a non-default configuration — but the release pairs a detailed write-up with a ready-to-run tool and two payloads, putting a complete attack path in public hands for the first time. Read the full recap for the week’s major developments, plus more research, attacks, and security news beyond what we covered last week.

The breach does not affect the security of the company’s hardware wallets. Sansec said all current versions are affected, including 2.4.9, and that it reproduced the full unauthenticated chain on clean Magento Open Source installations of 2.4.7, 2.4.8, and 2.4.9. A successful attack gives the attacker code execution on the store’s server and installs a persistent backdoor. Sansec, which discovered the flaw and named it StyleSmuggler , said attacks started on September 4. The company named the four programs ProManager , WinUpdate , SoftManager , and LockAppHost and published the findings on September 2 , along with a technical white paper . “The payloads are protected with javascript-obfuscator , using multiple techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers,” Check Point Research said in a technical report published last week.

Hacker group published roughly 550GB of data after MAG reportedly refused to pay a ransom demand; the group says it https://helm-engine.org/tag/data-protection gained access via exposed admin keys. The flaws could allow attackers with administrative access to a virtual machine to execute code on the host system. “We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems.” The exposure is in addition to 13,689 customers the company disclosed last month as having had their data either fully or partially exposed. Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The company’s own communications disagree on whether the flaw has already been exploited. N-able has released its fourth hotfix in five weeks for the N-central remote monitoring and management (RMM) platform, this time for a maximum-severity vulnerability that could allow remote code execution on the N-central server without authentication.

cyber threat news

Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing

cyber threat news

The activity overlaps with a threat cluster tracked under the monikers WEEVILPROXY and MeadowLocust. The counterfeit sites instruct them to download bogus installers for TradingView that lead to the deployment of the malware. Cybersecurity researchers have unpacked JSCeal , a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities. A TantoSec proof-of-concept turns an AES-CBC “padding oracle” in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July. The details of the three attacks are below – A social engineering attack that persuaded a user into executing Quick Assist as part of a tech support scam, after which a rogue ScreenConnect remote access client was d… However, once the ScreenConnect instances were installed, the cybersecurity company said it observed the clients repeatedly spawning “wscript.exe” to execute VBScripts named 1.vbs, 2.vbs, 3.vbs, and 4.vbs.

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. “A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host,” https://scriptmafia.org/tutorials/392178-consumer-privacy-and-data-protection.html Broadcom said in an alert. “Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions,” JetBrains said . As of September 6, Adobe has not published an advisory, a CVE identifier, a patch, or a workaround, and its Adobe Commerce security bulletin index lists nothing after the August 11 update. “Sansec is publishing early because stores are being compromised right now,” the company said.

  • If managing security across multiple cloud providers wasn’t hard enough, each one fails in a different way.
  • Scroll down for all the latest threat intelligence news and articles.
  • A TantoSec proof-of-concept turns an AES-CBC “padding oracle” in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July.
  • OpenAI agents made 15,000–18,000 autonomous edits to a German wiki over three months, evading moderation and echoing tactics seen in the Hugging Face breach.

Để lại một bình luận