Security Leftovers
-
In Other News: Healthcare Product Flaws, Free Email Security Testing, New Attack Techniques
Weekly cybersecurity news roundup that provides a summary of noteworthy stories that might have slipped under the radar for the week of July 3, 2023.
-
Vulnerabilities in PiiGAB Product Could Expose Industrial Organizations to Attacks
Potentially serious vulnerabilities discovered by researchers in a PiiGAB product could expose industrial organizations to remote hacker attacks.
-
Top Suspect in 2015 Ashley Madison Hack Committed Suicide in 2014
When the marital infidelity website AshleyMadison.com learned in July 2015 that hackers were threatening to publish data stolen from 37 million users, the company’s then-CEO Noel Biderman was quick to point the finger at an unnamed former contractor. But as a new documentary series on Hulu reveals [SPOILER ALERT!], there was just one problem with that theory: Their top suspect had killed himself more than a year before the hackers began publishing stolen user data.
-
After Zero-Day Attacks, MOVEit Turns to Security Service Packs
Facing ransomware zero-days, Progress Software will release regular service packs to help customers mitigate critical security flaws.
-
Iranian Cyberspies Target US-Based Think Tank With New macOS Malware
In May 2023, Iran-linked cyberespionage group Charming Kitten targeted a US-based think tank with new macOS malware.
-
OWASP SwSec 5D Tool Provides SDLC Maturity Ratings, Aids Software Supply Chain
SwSec 5D framework aims to provide a roadmap for secure software development, and its use would help improve security in the software supply chain.
-
Critical Linux Kernel StackRot Bug Fixed
Exploit code will soon become available for a critical vulnerability in the Linux kernel that a security researcher discovered and reported in mid-June. Dubbed StackRot (CVE-2023-3269), this bug impacts the Linux kernel 6.1 through 6.4. The data structure for managing virtual memory spaces in the Linux kernel handles a particular memory management function in a manner that results in use-after-free-by-RCU (UAFBR) issues. The security researcher who discovered StackRot, Ruihan Li, describes the exploit for StackRot as likely the first to successfully exploit a UAFBR bug.
-
Actively Exploited WebKitGTK Code Execution Vuln Fixed
A type confusion issue that may have been actively exploited has been identified in the WebKitGTK web engine (CVE-2023-32439). With a low attack complexity and a high confidentiality, integrity and availability impact, this vulnerability has received a National Vulnerability Database severity rating of High.
-
Two Apps Hosted on Google Play Caught Sending User Data to Chinese Servers
Two applications hosted on Google Play, with over 1.5 million combined downloads, were caught sending user data to servers in China.
-
Security Firm Finds Over 130k Internet-Exposed Photovoltaic Diagnostics Systems
Cyble has discovered more than 130,000 Photovoltaic monitoring and diagnostic solutions exposed to the internet.
-
Former Contractor Employee Charged for Hacking California Water Treatment Facility
Former contractor employee charged with hacking for accessing the systems of a water treatment facility in California to delete critical software.