CISA Forced to Take Two Systems Offline Last Month After Ivanti Compromise

The breach was limited to two systems, the Infrastructure Protection (IP) Gateway and the Chemical Security Assessment Tool (CSAT), which house critical information about U.S. infrastructure interdependency and private sector chemical security plans.

Cyware News – Latest Cyber News – ​Read More

Possibly Exploited Fortinet Flaw Impacts Many Systems, but No Signs of Mass Attacks

150,000 systems possibly impacted by the recent Fortinet vulnerability ​​CVE-2024-21762, but there is still no evidence of widespread exploitation. 

The post Possibly Exploited Fortinet Flaw Impacts Many Systems, but No Signs of Mass Attacks appeared first on SecurityWeek.

SecurityWeek – ​Read More

Magnet Goblin Delivers Linux Malware Using One-Day Vulnerabilities

The financially motivated threat actor Magnet Goblin is targeting one-day vulnerabilities to deploy Nerbian malware on Linux systems.

The post Magnet Goblin Delivers Linux Malware Using One-Day Vulnerabilities appeared first on SecurityWeek.

SecurityWeek – ​Read More

New Golang-based Planet Stealer Emerges in Underground Forums

Planet Stealer is a Go-based information-stealing trojan that targets sensitive information from victim hosts. The trojan’s capabilities include browser information theft, cryptocurrency wallet theft, and sandbox evasion.

Cyware News – Latest Cyber News – ​Read More

Zama’s Homomorphic Encryption Tech Lands it $73M on a Valuation of Nearly $400M

Zama, a Paris-based startup, has raised $73 million in a Series A funding round to develop and commercialize homomorphic encryption technology for blockchain transactions and AI data exchange.

Cyware News – Latest Cyber News – ​Read More

Critical Fortinet Flaw May Impact 150,000 Exposed Devices

Approximately 150,000 Fortinet FortiOS and FortiProxy secure web gateway systems are vulnerable to CVE-2024-21762, a critical security issue that allows code execution without authentication.

Cyware News – Latest Cyber News – ​Read More

Lithuania Warns China Has Ramped up Espionage Campaigns

The opening of Taiwan’s Representative Office in Lithuania has prompted China to increase its focus on gathering information about the country’s internal affairs and political landscape.

Cyware News – Latest Cyber News – ​Read More

Japan Blames North Korea for PyPI Supply Chain Cyberattack

Open-source software ecosystem compromise leaves developers in Asia and around the globe at risk.

darkreading – ​Read More

Magnet Goblin Hacker Group Leveraging 1-Day Exploits to Deploy Nerbian RAT

A financially motivated threat actor called Magnet Goblin is swiftly adopting one-day security vulnerabilities into its arsenal in order to opportunistically breach edge devices and public-facing services and deploy malware on compromised hosts.
“Threat actor group Magnet Goblin’s hallmark is its ability to swiftly leverage newly disclosed vulnerabilities, particularly targeting

The Hacker News – ​Read More

Proof-of-Concept Exploit Released for Progress Software OpenEdge Vulnerability

Technical specifics and a proof-of-concept (PoC) exploit have been made available for a recently disclosed critical security flaw in Progress Software OpenEdge Authentication Gateway and AdminServer, which could be potentially exploited to bypass authentication protections.
Tracked as CVE-2024-1403, the vulnerability has a maximum severity rating of 10.0 on the CVSS scoring system. It

The Hacker News – ​Read More