Security Leftovers
-
Mass Ransomware Attack
A vulnerability in a popular data transfer tool has resulted in a mass ransomware attack:
TechCrunch has learned of dozens of organizations that used the affected GoAnywhere file transfer software at the time of the ransomware attack, suggesting more victims are likely to come forward.
However, while the number of victims of the mass-hack is widening, the known impact is murky at best.
-
Stealthy hacks show advancements in China’s cyberespionage operations, researchers say
Hacker groups linked to China have demonstrated the growing ability to infiltrate systems and remain hidden while they steal data.
-
CISA, NSA Issue Guidance for IAM Administrators
New CISA and NSA guidance includes recommended best practices for identity and access management (IAM) administrators.
-
Cisco Patches High-Severity Vulnerabilities in IOS Software
Cisco’s semiannual security updates for IOS and IOS XE software resolve high-severity DoS, command injection, and privilege escalation vulnerabilities.
-
‘Nexus’ Android Trojan Targets 450 Financial Applications
Promoted as a MaaS, the Nexus Android trojan targets 450 financial applications for account takeover.
-
Dole Says Employee Information Compromised in Ransomware Attack
Dole has admitted in an SEC filing that its investigation into the recent ransomware attack found that the hackers had accessed employee information.
-
Microsoft booster: Apple macOS, Microsoft Windows 11, Ubuntu Desktop Hacked During $1 Million Hacking Spree
What might happen if some of the world's most proficient hackers targeted some of the biggest tech names at the same time? That's what we are finding out as the Pwn2Own Vancouver 2023 hacking competition kicked off yesterday, and some tech titans fell to some serious zero-day security exploit action. Over the course of just this one day, 22 March, Apple macOS, Microsoft Windows 11, Microsoft SharePoint, Ubuntu Desktop, Tesla Gateway, Adobe Reader, and Oracle VirtualBox all fell at the hands of these elite hackers.
-
Microsoft Teams, Virtualbox, Tesla zero-days exploited at Pwn2Own