In response to recent intrusions, CISA and the FBI are urging businesses and device manufacturers to eliminate OS command injection vulnerabilities at the source.
https://www.backbox.org/wp-content/uploads/2018/09/website_backbox_text_black.png00https://www.backbox.org/wp-content/uploads/2018/09/website_backbox_text_black.png2024-07-11 12:07:272024-07-11 12:07:27CISA, FBI Urge Immediate Action on OS Command Injection Vulnerabilities in Network Devices
This decision comes after a warning from the Singapore Police about phishing scams targeting bank customers. Scammers have managed to defraud individuals of over S$600,000 ($445,000) in just a few weeks.
https://www.backbox.org/wp-content/uploads/2018/09/website_backbox_text_black.png00https://www.backbox.org/wp-content/uploads/2018/09/website_backbox_text_black.png2024-07-11 12:07:262024-07-11 12:07:26Singapore to Phase Out One-Time Passwords in Banking
Huione Guarantee, an online marketplace, is reportedly being used for money laundering, particularly in “pig butchering” investment scams. Victims are tricked into investing in fake sites with high returns.
https://www.backbox.org/wp-content/uploads/2018/09/website_backbox_text_black.png00https://www.backbox.org/wp-content/uploads/2018/09/website_backbox_text_black.png2024-07-11 12:07:262024-07-11 12:07:26Huione Guarantee Exposed as a $11 Billion Marketplace for Cybercrime
The most severe flaw is an improper authorization issue (CVE-2024-6235) with a CVSS score of 9.4, allowing attackers to access sensitive information through the NetScaler Console IP.
Spanish language victims are the target of an email phishing campaign that delivers a new remote access trojan (RAT) called Poco RAT since at least February 2024.
The attacks primarily single out mining, manufacturing, hospitality, and utilities sectors, according to cybersecurity company Cofense.
“The majority of the custom code in the malware appears to be focused on anti-analysis,
https://www.backbox.org/wp-content/uploads/2018/09/website_backbox_text_black.png00https://www.backbox.org/wp-content/uploads/2018/09/website_backbox_text_black.png2024-07-11 11:06:332024-07-11 11:06:33New Poco RAT Targets Spanish-Speaking Victims in Phishing Campaign
Palo Alto Networks patched a critical vulnerability in its Expedition tool and addressed the impact of the recently disclosed BlastRADIUS vulnerability.
Poco RAT was first categorized on February 7, 2024, and has since targeted customers in multiple sectors, with Mining being the primary focus. One company was the most targeted, responsible for 67% of the total volume of campaigns.
https://www.backbox.org/wp-content/uploads/2018/09/website_backbox_text_black.png00https://www.backbox.org/wp-content/uploads/2018/09/website_backbox_text_black.png2024-07-11 11:06:322024-07-11 11:06:32New Malware Campaign Targeting Spanish Language Victims and the Mining Sector
A diverse workforce brings different perspectives, experiences, and problem-solving approaches to the table, enabling teams to identify vulnerabilities and develop more robust defense strategies.
https://www.backbox.org/wp-content/uploads/2018/09/website_backbox_text_black.png00https://www.backbox.org/wp-content/uploads/2018/09/website_backbox_text_black.png2024-07-11 11:06:322024-07-11 11:06:32Diversifying Cyber Teams to Tackle Complex Threats
Cybersecurity analyst Eugene Lim discovered the risk posed by this vulnerability, which hackers can exploit by chaining messaging APIs in browsers and extensions, bypassing security measures like the Same Origin Policy.
https://www.backbox.org/wp-content/uploads/2018/09/website_backbox_text_black.png00https://www.backbox.org/wp-content/uploads/2018/09/website_backbox_text_black.png2024-07-11 10:06:322024-07-11 10:06:32Apple needs to fix this crazy iPhone annoyance
BackBox.org offers a range of Penetration Testing services to simulate an attack on your network or application. If you are interested in our services, please contact us and we will provide you with further information as well as an initial consultation.
CISA, FBI Urge Immediate Action on OS Command Injection Vulnerabilities in Network Devices
/in General NewsIn response to recent intrusions, CISA and the FBI are urging businesses and device manufacturers to eliminate OS command injection vulnerabilities at the source.
The post CISA, FBI Urge Immediate Action on OS Command Injection Vulnerabilities in Network Devices appeared first on SecurityWeek.
SecurityWeek – Read More
Singapore to Phase Out One-Time Passwords in Banking
/in General NewsThis decision comes after a warning from the Singapore Police about phishing scams targeting bank customers. Scammers have managed to defraud individuals of over S$600,000 ($445,000) in just a few weeks.
Cyware News – Latest Cyber News – Read More
Huione Guarantee Exposed as a $11 Billion Marketplace for Cybercrime
/in General NewsHuione Guarantee, an online marketplace, is reportedly being used for money laundering, particularly in “pig butchering” investment scams. Victims are tricked into investing in fake sites with high returns.
Cyware News – Latest Cyber News – Read More
Citrix Fixed Critical and High-Severity Bugs in NetScaler Product
/in General NewsThe most severe flaw is an improper authorization issue (CVE-2024-6235) with a CVSS score of 9.4, allowing attackers to access sensitive information through the NetScaler Console IP.
Cyware News – Latest Cyber News – Read More
New Poco RAT Targets Spanish-Speaking Victims in Phishing Campaign
/in General NewsSpanish language victims are the target of an email phishing campaign that delivers a new remote access trojan (RAT) called Poco RAT since at least February 2024.
The attacks primarily single out mining, manufacturing, hospitality, and utilities sectors, according to cybersecurity company Cofense.
“The majority of the custom code in the malware appears to be focused on anti-analysis,
The Hacker News – Read More
Palo Alto Networks Addresses BlastRADIUS Vulnerability, Fixes Critical Bug in Expedition Tool
/in General NewsPalo Alto Networks patched a critical vulnerability in its Expedition tool and addressed the impact of the recently disclosed BlastRADIUS vulnerability.
The post Palo Alto Networks Addresses BlastRADIUS Vulnerability, Fixes Critical Bug in Expedition Tool appeared first on SecurityWeek.
SecurityWeek – Read More
New Malware Campaign Targeting Spanish Language Victims and the Mining Sector
/in General NewsPoco RAT was first categorized on February 7, 2024, and has since targeted customers in multiple sectors, with Mining being the primary focus. One company was the most targeted, responsible for 67% of the total volume of campaigns.
Cyware News – Latest Cyber News – Read More
Diversifying Cyber Teams to Tackle Complex Threats
/in General NewsA diverse workforce brings different perspectives, experiences, and problem-solving approaches to the table, enabling teams to identify vulnerabilities and develop more robust defense strategies.
Cyware News – Latest Cyber News – Read More
Universal Code Execution by Chaining Messages in Browser Extensions
/in General NewsCybersecurity analyst Eugene Lim discovered the risk posed by this vulnerability, which hackers can exploit by chaining messaging APIs in browsers and extensions, bypassing security measures like the Same Origin Policy.
Cyware News – Latest Cyber News – Read More
Apple needs to fix this crazy iPhone annoyance
/in General NewsI use my iPhone a lot. But one feature on the device is a massive annoyance and I seriously hope the issue is fixed in the iPhone 16.
Latest news – Read More