Fear, Uncertainty, Doubt (FUD) and Security
-
Mélofée: Researchers Uncover New Linux Malware Linked to Chinese APT Groups [Ed: Microsoft trying to connect malware you install to... Linux]
An unknown Chinese state-sponsored hacking group has been linked to a novel piece of malware aimed at Linux servers.
French cybersecurity firm ExaTrack, which found three samples of the previously documented malicious software that date back to early 2022, dubbed it Mélofée.
-
QNAP warns customers to patch Linux Sudo flaw in NAS devices [Ed: The problem is in QNAP devices, not "Linux"]
Taiwanese hardware vendor QNAP warns customers to secure their Linux-powered network-attached storage (NAS) devices against a high-severity Sudo privilege escalation vulnerability.
The flaw (tracked as CVE-2023-22809) was discovered by Synacktiv security researchers, who describe it as a "sudoers policy bypass in Sudo version 1.9.12p1 when using sudoedit."
-
Amnesty International uncovers new hacking campaign linked to mercenary spyware company - Amnesty International
The attack targeted Android operating system. As a result of the discovery, Google were able to release security updates protecting billions of Android, Chrome and Linux users from the exploit.
-
Malware Hunters Spot Supply Chain Attack Hitting 3CX Desktop App
CrowdStrike threat intelligence team warns about unexpected malicious activity from a legitimate, signed version of the 3CXDesktopApp.
-
OpenSSL 1.1.1 Nears End of Life: Security Updates Only Until September 2023
OpenSSL 1.1.1 will reach EoL in six months and users are instructed to either upgrade to a newer version or pay for extended support to continue receiving security patches.
-
New Wi-Fi Attack Allows Traffic Interception, Security Bypass
A group of academic researchers devised an attack that can intercept Wi-Fi traffic at the MAC layer, bypassing client isolation.
-
Google Links More iOS, Android Zero-Day Exploits to Spyware Vendors
Google has linked several zero-day vulnerabilities used last year to target Android and iOS devices to commercial spyware vendors.
-
Most Weaponized Vulnerabilities of 2022 and 5 Key Risks: Report
A new research report discusses the five most exploited vulnerabilities of 2022, and the five key risks that security teams should consider.
-
Casino Giant Crown Resorts Investigating Ransomware Group’s Data Theft Claims
Australian casino giant Crown Resorts says the Cl0p ransomware group contacted them to claim data theft in the GoAnywhere attack.