Vulnerabilities, News
January 27, 2025
789 views 52 secs 0

SonicWall warns hackers targeting critical vulnerability in SMA 1000 series appliances

Researchers from Microsoft Threat Intelligence alerted the company to suspected threat activity. Cybersecurity Dive reports: SonicWall issued an alert Friday that a critical remote code execution vulnerability in its SMA appliances is under active exploitation by malicious hackers and urged customers to immediately update any vulnerable firmware. Researchers from Microsoft Threat Intelligence had warned SonicWall about the […]

Vulnerabilities
January 26, 2025
825 views 56 secs 0

ChatGPT API flaw could allow DDoS, prompt injection attacks

Another day, another vulnerability. CSO Online reports that a researcher discovered an OpenAI development oversight that could allow attackers to launch DDoS attacks on unsuspecting victims: OpenAI-owned ChatGPT might have a vulnerability that could allow threat actors to launch distributed denial of service (DDoS) attacks on unsuspecting targets.   According to a discovery made by German security researcher […]

Vulnerabilities, News
January 25, 2025
787 views 24 secs 0

Simple STARLINK Bug Let Hackers Control Every Connected Subaru

Security researchers gained complete control of Subaru vehicles worldwide using only basic customer information like license plates or ZIP codes Motor Illustrated reports: Security researchers discovered a critical vulnerability in Subaru‘s STARLINK connected vehicle service that allowed unauthorized access to vehicles and customer data across the United States, Canada, and Japan, according to a blog post published by […]

Vulnerabilities, Vendor News
January 24, 2025
256 views 4 secs 0

Patch now: Cisco fixes critical 9.9-rated, make-me-admin bug in Meeting Management

Another day, another critical patch. The Register reports: Cisco has pushed a patch for a critical, 9.9-rated vulnerability in its Meeting Management tool that could allow a remote, authenticated attacker with low privileges to escalate to administrator on affected devices. Cisco Meeting Management is the management software for the tech giant’s on-premises video meeting platform. […]

Vulnerabilities, Data Breach News
January 16, 2025
563 views 17 secs 0

Hacking group leaks Fortinet users’ details on dark web

Details from more than 15,000 devices exposed If you use Fortinet, Computing.co.uk has information that you need to know: Hackers calling themselves Belsen Group have leaked details of users of Fortinet firewalls on the dark web. Researcher Kevin Beaumont, who has reviewed the data dump, says he believes it to be genuine, since devices in […]

Vulnerabilities, News
January 13, 2025
255 views 52 secs 0

Researcher Uncovers AWS S3 Ransomware Vulnerabilities

As if there weren’t enough concerns with misconfigured Amazon AWS s3 buckets exposing data, now we read this: Security researchers at Rhino Security Labs have uncovered a concerning vulnerability in Amazon Web Services (AWS) S3 storage systems that could allow attackers to execute ransomware attacks against cloud-stored data.  The research demonstrates how attackers can encrypt S3 bucket […]

News, Vulnerabilities
December 30, 2024
861 views 12 secs 0

Brothel Visits Exposed In Volkswagen Location Data Leak

There are breaches and then there are really really embarrassing breaches. Jalopnik reports: Things aren’t going so great at Volkswagen right now, and while the latest scandal likely won’t rise to the level of the diesel emissions scandal, a security lapse by VW’s in-house software developer Cariad did expose the locations of about 800,000 electric vehicles to […]

Data Breach News, News, Vulnerabilities
December 10, 2024
904 views 14 secs 0

Multiple Cleo file transfer products being exploited by hackers; patch isn’t sufficient

Here we go again: threat actors are taking advantage of vulnerabilities in file transfer products. This time it is Cleo file transfer products. The Record reports: Cybersecurity researchers are warning that vulnerabilities in several file transfer products are being exploited by hackers, even after a patch was released by the developer. The vulnerability — CVE-2024-50623 — was […]

Data Breach News, News, Vulnerabilities
December 10, 2024
878 views 26 secs 0

US sanctions Chinese firm for hacking firewalls in ransomware attacks; $10 million reward for information

The U.S. Treasury Department has sanctioned Chinese cybersecurity company Sichuan Silence and one of its employees for their involvement in a series of Ragnarok ransomware attacks targeting U.S. critical infrastructure companies and many other victims worldwide in April 2020. BleepingComputer reports: According to the Department’s Office of Foreign Assets Control (OFAC), Sichuan Silence is a […]