Security Leftovers
-
US, South Korea Detail North Korea’s Social Engineering Techniques
The US and Korea are warning of North Korean social engineering attacks targeting employees of think tanks, academic and research institutions, and news media organizations.
-
High-Severity Vulnerabilities Patched in Splunk Enterprise
Splunk has resolved multiple high-severity vulnerabilities in Splunk Enterprise, including bugs in third-party packages used by the product.
-
Enzo Biochem Ransomware Attack Exposes Information of 2.5M Individuals
Enzo Biochem says the clinical test information of roughly 2.47 million individuals was exposed in a recent ransomware attack.
-
Zero-Day in MOVEit File Transfer Software Exploited to Steal Data From Organizations
A zero-day vulnerability in Progress Software’s MOVEit Transfer product has been exploited to hack organizations and steal their data.
-
New Linux Ransomware Strain BlackSuit Shows Striking Similarities to Royal [Ed: The issue VMware ESXi (proprietary), not "Linux"]
Trend Micro, which examined an x64 VMware ESXi version targeting Linux machines, said it identified an "extremely high degree of similarity" between Royal and BlackSuit.
-
Hackers Using MOVEit Flaw to Deploy Web Shells, Steal Data
An unknown threat actor began exploiting the critical SQL injection vulnerability in MOVEit Transfer on May 27 and in some cases has taken data within minutes of deploying the web shells.
Security researchers at Mandiant attribute the activity to a newly created threat cluster with unknown motivations dubbed UNC4857 that has gone after organizations across a wide range of industries based in Canada, India and the United States (see: Hackers Exploit Progress MOVEit File Transfer Vulnerability).