Have just published description for a new #0day#vulnerability in Versa Networks Director. It's quite frustrating when security solutions vendors do not have mature vulnerability disclosure policy in place :(
https://t.co/t9ExiEDHxb
Hard-coded credentials #vulnerability in #SolarWinds Web Help Desk allows RCE. Vendor has released a fixed version 12.8.3 HF2. Patch ASAP.
https://t.co/cHN8GXcgf6
Dovecot has released 2 security advisories to address DoS vulnerabilities when parsing email headers. The vulnerabilities are addressed in version 2.3.21.1.
The vulnerabilities can be triggered by a remote actor by sending specially crafted email messages.
https://t.co/vAMwcmDm8J
https://t.co/LvqUrZRvlU
A North Korea-linked threat actor known as Moonstone Sleet has been detected pushing malicious npm packages to the JavaScript package registry
#MoonstoneSleet#DatadogSecurityLabs#APT
https://t.co/XpR7VI4yHg
Singapore authorities have recovered over $40 million defrauded in a business email compromise (BEC) scam
#Interpol#BEC#cyberfraud
https://t.co/f4akyppAGv
South Korea's intelligence community has released joint cybersecurity advisory to warn about the increasing cyber threats posed by North Korean hacking groups
#Kimsuky#Andariel#APT
https://t.co/vBdZPE2Qpx
A recent investigation has uncovered that software essential to the operation of Britain's nuclear submarines was developed by engineers based in Russia and Belarus
#UK#software#Russiaisaterroriststate
https://t.co/pinwTxtgaZ
A new cyber espionage campaign by the the China-linked state-sponsored threat actor tracked as APT41 has been observed targeting a Taiwanese government-affiliated research institute with ShadowPad and Cobalt Strike
#CiscoTalos#APT41#APT
https://t.co/hweKZCgdJX
The US and German authorities have seized the domain of online crypto wallet Cryptonator, an unlicensed money service business (MSB) that processed over $235 million in funds obtained through cybercrime
#Cryptonator#cybercrime
https://t.co/e1QT9DtBpC
The China-linked threat actor StormBamboo, compromised an internet service provider (ISP) to push malicious software updates to target enterprises
#Volexity#StormBamboo#APT
https://t.co/k5ozA22cGx
In brief: ‘Sitting Ducks’ domain hijacking attack puts at risk over a million domains, the UK shuts down Russian Coms fraud platform, and more
#cybersecurity#APT
https://t.co/tDvXAeDWE0
A Chinese nation-state threat actor has been observed leveraging the LODEINFO and NOOPDOOR malware families to steal sensitive information from Japanese organizations
#Cybereason#CuckooSpear#APT10#APT
https://t.co/ygsX9BMvMv
A new malicious campaign has been observed exploiting malicious Android apps to steal users' SMS messages since at least February 2022, as part of a large-scale operation
#Zimperium#Android#malware
https://t.co/iUR6btu5hM
DigiCert has announced the revocation of approximately 0.4% of its customer base's SSL/TLS certificates following the discovery of a flaw in its domain control verification process
#DigiCert
https://t.co/aaTMrjKSSy
The UK's ICO said that the Electoral Commission was compromised in August 2021 due to its failure to patch its on-premise Microsoft Exchange Server against the ProxyShell flaws
#APT31#APT#securitybreach
https://t.co/QJy1YTfUGF
Threat actors are targeting SMBs in Poland with phishing campaigns delivering a number of malware families such as Agent Tesla, Formbook, and Remcos RAT
#ESET#malware
https://t.co/Z1morCX35S
A recently patched vulnerability in VMware ESXi hypervisors is being actively exploited by threat actors to gain access to target networks and deploy ransomware
#Microsoft#ransomware
https://t.co/KhmyZGAigl
The nation-state threat actor SideWinder is now targeting ports and maritime facilities in the Mediterranean Sea and Indian Ocean, according to a new report from BlackBerry
#SideWinder#APT#BlackBerryResearchandIntelligenceTeam
https://t.co/ImJSxBQsz0
Cryptocurrency exchange Gemini has disclosed a security breach resulting in the compromise of personal and banking information of thousands of its customers
#Gemini#cryptoexchange#databreach
https://t.co/xfp9Xbo2Vk
A security weakness in Google Workspace allowed hackers to bypass the email verification required to create accounts to impersonate domain holders across various third-party services
#GoogleWorkspace