Author: Admin

December 20, 2024Ravi LakshmananFirewall Security / Vulnerability Sophos has it patches released to address three security vulnerabilities in Sophos Firewall products that could be used to allow remote code execution and allow privileged system access under certain conditions. Of the three, two are rated critical in terms of severity. There is currently no evidence that the flaws have been exploited in the wild. The list of vulnerabilities is as follows – CVE-2024-12727 (CVSS Score: 9.8) – A SQL pre-authentication vulnerability in the email protection feature that could lead to remote code execution when certain Secure PDF eXchange (SPX) configuration is…

Read More

December 20, 2024Ravi LakshmananMalware / Supply chain attack The Rspack developers revealed that two of their npm packages, @rspack/core and @rspack/cliwere compromised in a software supply chain attack that allowed an attacker to publish malicious versions to the official cryptocurrency mining malware package registry. After discoveryversions 1.1.7 of both libraries have been removed from the npm registry. The latest secure version is 1.1.8. “They were released by an attacker who gained unauthorized access to an npm post and contain malicious scripts,” according to software security firm Socket. said in the analysis. Rspack considered as an alternative webpackoffering “a high-performance JavaScript…

Read More

December 20, 2024Ravi LakshmananVulnerability / Cyber ​​attack Fixed a critical security flaw affecting Fortinet FortiClient EMS being exploited by attackers as part of a cyber campaign that installed remote desktop software such as AnyDesk and ScreenConnect. The vulnerability in question CVE-2023-48788 (CVSS Score: 9.3), a SQL implementation flaw that allows attackers to execute unauthorized code or commands by sending specially crafted data packets. Russian cybersecurity firm Kaspersky said the October 2024 attack targeted an unnamed company’s Windows server that was exposed to the Internet and had two open ports connected to FortiClient EMS. “The targeted company uses this technology to…

Read More

December 20, 2024Ravi LakshmananCISA / Vulnerability The US Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added critical security flaw affecting BeyondTrust’s Privileged Remote Access (PRA) and Remote Support (RS) products for known vulnerabilities (KEV) catalog with reference to evidence of active exploitation in the wild. Vulnerability, tracked as CVE-2024-12356 (CVSS Score: 9.8) is a command injection flaw that could be used by an attacker to execute arbitrary commands as a site user. “BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain a command injection vulnerability that could allow an unauthenticated attacker to enter commands that execute on behalf…

Read More

December 19, 2024Ravi LakshmananMisinformation / Malware The Computer Emergency Response Team of Ukraine (CERT-UA) has opened that a threat actor it tracks as UAC-0125 is using the Cloudflare Workers service to force military personnel in the country to download malware under the guise of Army+a mobile application that was introduced by the Ministry of Defense back in August 2024 to make the armed forces paperless. Users visiting the fake Cloudflare Workers websites are prompted to download the Army+ for Windows executable file created using the Nullsoft Scriptable installer (NSIS), an open source tool used to create operating system installers. Opening…

Read More

December 19, 2024Ravi LakshmananSupply Chain / Software Security Threat actors have been observed downloading malicious typosquats of legitimate npm packages such as typescript-eslint and @types/node, which have garnered thousands of downloads in the package registry. Counterfeit versions, no @typescript_eslinter/eslint and species-nodedesigned to load a trojan and produce a stage two payload, respectively. “While typosquatting attacks are hardly new, it’s worth noting the effort nefarious contributors have put into these two libraries to pass them off as legitimate,” Sonatype’s Ax Sharma said in an analysis published Wednesday. “Furthermore, high download numbers for packages like ‘types-node’ are an indication that some developers…

Read More

December 19, 2024Ravi LakshmananMalware/botnet Juniper Networks is warning that Session Smart Router (SSR) products with default passwords are being targeted as part of a malware campaign deploying the Mirai botnet malware. The company said it is issuing the advisory after “several customers” reported anomalous behavior on their Session Smart Network (SSN) platforms on December 11, 2024. “These systems were infected with the Mirai malware and subsequently used as a source of DDOS attacks on other devices accessible through their network,” it said. said. “All affected systems used default passwords.” Miraiwhose source code was published in 2016, has spawned several variants…

Read More

December 19, 2024Ravi LakshmananPrivacy / Data Protection The Dutch data protection authority (DPA) on Wednesday fined video-on-demand streaming service Netflix 4.75 million euros ($4.93 million) for not giving consumers enough information about how it used their data during from 2018 to 2020. An investigation launched by the DPA in 2019 found that the tech giant did not make clear enough to customers in its privacy statement about what it does with the data it collects from its users. This includes email addresses, phone numbers, payment information, and information about what customers are viewing on the platform. “Furthermore, customers were not…

Read More

December 19, 2024Ravi LakshmananVulnerability / Network Security Fortinet has issued a recommendation for a a critical security flaw is now fixed which affect the Wireless LAN Manager (FortiWLM) which could lead to disclosure of sensitive information. The vulnerability, tracked as CVE-2023-34990, has a CVSS score of 9.6 out of a maximum of 10.0. “Passing a relative path (CWE-23) in FortiWLM could allow a remote, unauthenticated attacker to read sensitive files,” the company said in a statement. said in a warning issued Wednesday. However, according to A description security flaw in NIST’s National Vulnerability Database (NVD), the path traversal vulnerability could…

Read More

December 19, 2024Ravi LakshmananCloud Security / Encryption The US Cybersecurity and Infrastructure Security Agency (CISA) issued Mandatory Operational Directive (BOD) 25-01, directing federal civilian agencies to secure their cloud environments and adhere to basic configurations of Secure Cloud Business Applications (SCuBA). “Recent cyber security incidents highlight the significant risks associated with misconfigurations and weak security controls that attackers can use to gain unauthorized access, steal data, or disrupt services,” the agency notes. saidadding that the directive “will further reduce the attack surface of federal government networks.” As part of the 25-01 agency also is recommended to deploy CISA-developed automated configuration…

Read More