Friday, November 12, 2021

Iran's Lyceum Hackers Target Telecoms, ISPs in Israel, Saudi Arabia, and Africa

A state-sponsored threat actor allegedly affiliated with Iran has been linked to a series of targeted attacks aimed at internet service providers (ISPs) and telecommunication operators in Israel, Morocco, Tunisia, and Saudi Arabia, as well as a ministry of foreign affairs (MFA) in Africa, new findings reveal. The intrusions, staged by a group tracked as Lyceum, are believed to have occurred
https://thehackernews.com/2021/11/irans-lyceum-hackers-target-telecoms.html?utm_source=dlvr.it&utm_medium=blogger

Palo Alto Warns of Zero-Day Bug in Firewalls Using GlobalProtect Portal VPN

A new zero-day vulnerability has been disclosed in Palo Alto Networks GlobalProtect VPN that could be abused by an unauthenticated network-based attacker to execute arbitrary code on affected devices with root user privileges. Tracked as CVE-2021-3064 (CVSS score: 9.8), the security weakness impacts PAN-OS 8.1 versions earlier than PAN-OS 8.1.17. Massachusetts-based cybersecurity firm Randori
https://thehackernews.com/2021/11/palo-alto-warns-of-zero-day-bug-in.html?utm_source=dlvr.it&utm_medium=blogger

Researchers Discover PhoneSpy Malware Spying on South Korean Citizens

An ongoing mobile spyware campaign has been uncovered snooping on South Korean residents using a family of 23 malicious Android apps to siphon sensitive information and gain remote control of the devices. "With more than a thousand South Korean victims, the malicious group behind this invasive campaign has had access to all the data, communications, and services on their devices," Zimperium
https://thehackernews.com/2021/11/researchers-discover-phonespy-malware.html?utm_source=dlvr.it&utm_medium=blogger

13 New Flaws in Siemens Nucleus TCP/IP Stack Impact Safety-Critical Equipment

As many as 13 security vulnerabilities have been discovered in the Nucleus TCP/IP stack, a software library now maintained by Siemens and used in three billion operational technology and IoT devices that could allow for remote code execution, denial-of-service (DoS), and information leak. Collectively called "NUCLEUS:13," successful attacks abusing the flaws can "result in devices going offline
https://thehackernews.com/2021/11/13-new-flaws-in-siemens-nucleus-tcpip.html?utm_source=dlvr.it&utm_medium=blogger

14 New Security Flaws Found in BusyBox Linux Utility for Embedded Devices

Cybersecurity researchers on Tuesday disclosed 14 critical vulnerabilities in the BusyBox Linux utility that could be exploited to result in a denial-of-service (DoS) condition and, in select cases, even lead to information leaks and remote code execution. The security weaknesses, tracked from CVE-2021-42373 through CVE-2021-42386, affect multiple versions of the tool ranging from 1.16-1.33.1,
https://thehackernews.com/2021/11/14-new-security-flaws-found-in-busybox.html?utm_source=dlvr.it&utm_medium=blogger

Thursday, November 11, 2021

Trojan Source – A new method Let Hackers inject vulnerabilities into the source code

A new type of vulnerability has been identified by the security researchers of Cambridge University, Nicholas Boucher and Ross Anderson, and this vulnerability enables threat actors to insert visually deceptive malware into the source code in such a way that is semantically correct. Not only this, but at the same time, this vulnerability also modifies […] The post Trojan Source – A new method Let Hackers inject vulnerabilities into the source code appeared first on Cyber Security News.
https://cybersecuritynews.com/trojan-source/?utm_source=dlvr.it&utm_medium=blogger

The Increasing Need for Application Security During Covid-19

The Covid-19 pandemic shook businesses all over the world, unleashing massive disruption on the global economy. Trying to develop responses to the crisis almost overnight, many businesses were left exposed and vulnerable in terms of application security, and cybercriminals began to up their game with the massive increase of people working from home. According to a recent survey […] The post The Increasing Need for Application Security During Covid-19 appeared first on Cyber Security News.
https://cybersecuritynews.com/application-security-during-covid-19/?utm_source=dlvr.it&utm_medium=blogger

How to Keep Your Customer Relationship Management Software Secure

Having great customer relationship managementsoftware is absolutely essential if you are a business that is looking to plan and execute a successful marketing plan. Nonetheless, when you have so much information regarding your customers’ personal data, the difficulty can be keeping it secure. This is especially true when it comes to the rise of hackers, […] The post How to Keep Your Customer Relationship Management Software Secure appeared first on Cyber Security News.
https://cybersecuritynews.com/how-to-keep-your-customer-relationship-management-software-secure/?utm_source=dlvr.it&utm_medium=blogger

Hackers Attacking Windows Using Infostealer Malware by Mimics as Legitimate Win 10 App

A new malicious campaign has been detected recently by Rapid7’s Managed Detection and Response (MDR) team and Threat Intelligence and Detection Engineering (TIDE) team in which the hackers are targeting Windows using infostealer malware and delivering fake legitimate-looking Win 10 app. In this malicious campaign, the threat actors infect the users’ systems by using a […] The post Hackers Attacking Windows Using Infostealer Malware by Mimics as Legitimate Win 10 App appeared first on Cyber Security News.
https://cybersecuritynews.com/hackers-attacking-windows-using-infostealer-malware/?utm_source=dlvr.it&utm_medium=blogger

How Can Small Businesses Protect Against Cyber Threats?

In the modern era of working from home and agile workplaces, cyber threats are becoming more dangerous to business continuity than physical threats such as vandalism and theft. However, whilst it may seem difficult to avoid cyber threats, there are some steps you can take to stay safe in the digital landscape. Read on to […] The post How Can Small Businesses Protect Against Cyber Threats? appeared first on Cyber Security News.
https://cybersecuritynews.com/how-can-small-businesses-protect-against-cyber-threats/?utm_source=dlvr.it&utm_medium=blogger