Critical GitLab Bug Lets Attackers Run Pipelines as Any User

A critical vulnerability has been discovered in certain versions of GitLab Community and Enterprise Edition products. This vulnerability allows an attacker to run pipelines as any user.

Cyware News – Latest Cyber News – ​Read More

Examining Water Sigbin’s Infection Routine Leading to an XMRig Cryptominer

A sophisticated multi-stage malware campaign by the threat actor “Water Sigbin” (also known as the 8220 Gang) exploits Oracle WebLogic vulnerabilities to deliver a cryptocurrency miner called XMRig.

Cyware News – Latest Cyber News – ​Read More

MerkSpy: Exploiting CVE-2021-40444 to Infiltrate Systems

MerkSpy is designed to covertly monitor user activities, capture sensitive information like keystrokes and Chrome login credentials, and exfiltrate the data to the attacker’s server.

Cyware News – Latest Cyber News – ​Read More

The Mount Kisco Surgery Center LLC d/b/a The Ambulatory Surgery Center of Westchester – Notice of Data Security Incident

Post Content

darkreading – ​Read More

TeamViewer Credits Network Segmentation for Rebuffing APT29 Attack

Despite warnings from Health-ISAC and the NCC Group, the remote access software maker says defense-in-depth kept customers’ data safe from Midnight Blizzard.

darkreading – ​Read More

CISO Corner: The NYSE & the SEC; Ransomware Negotiation Tips

Our collection of the most relevant reporting and industry perspectives for those guiding cybersecurity strategies and focused on SecOps.

darkreading – ​Read More

Critical GitLab Bug Threatens Software Development Pipelines

The company is urging users running vulnerable versions to patch CVE-2024-5655 immediately, to avoid CI/CD malfeasance.

darkreading – ​Read More

TeamViewer Confirms Security Breach by Russian Midnight Blizzard

TeamViewer reassures users after a security breach targeted an employee account. The company claims no customer data was…

Hackread – Latest Cybersecurity, Tech, Crypto & Hacking News – ​Read More