Aggregator
Subsurfco LLC Falls Victim to Qilin Ransomware
Albabat Ransomware Targets Windows, Linux, and macOS via GitHub Abuse
Recent research by Trend Micro has uncovered a significant evolution in the Albabat ransomware, which now targets not only Windows but also Linux and macOS systems. This expansion highlights the increasing sophistication of ransomware groups in exploiting multiple operating systems to maximize their impact. The Albabat group has been leveraging GitHub to streamline its operations, […]
The post Albabat Ransomware Targets Windows, Linux, and macOS via GitHub Abuse appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Threat Actors Leverage Reddit to Spread AMOS and Lumma Stealers
In a recent surge of cyber threats, threat actors have been exploiting Reddit to distribute two potent malware variants: AMOS (Atomic Stealer) and Lumma Stealer. These malware types are specifically designed to target cryptocurrency traders by offering cracked versions of popular trading software, such as TradingView. The attackers engage actively with potential victims on Reddit, […]
The post Threat Actors Leverage Reddit to Spread AMOS and Lumma Stealers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Securing Your Supply Chain from Phishing Attacks
In this piece, Tass Kalfoglou, the director of our APAC Business Unit, sheds light on supply chain vulnerabilities and the need to level up domain security.
The post Securing Your Supply Chain from Phishing Attacks appeared first on Security Boulevard.
CVE-2022-38329 | Shopxian CMS 3.0.0 cross-site request forgery
CVE-2022-4448 | GiveWP Plugin up to 2.23.2 on WordPress Shortcode cross site scripting
CVE-2023-22349 | Screen Creator Advance 2 up to 0.1.1.4 Build01 Project File out-of-bounds
CVE-2022-25937 | glance up to 3.0.8 path traversal
CVE-2023-0270 | YaMaps for Plugin prior 0.6.26 on WordPress Shortcode Attribute cross site scripting
CVE-2023-0379 | Spotlight Social Feeds Plugin up to 1.4.2 on WordPress Block Option cross site scripting
CVE-2023-25719 | ConnectWise Control 19.3.25270.7185/22.8.10013.8329 ConnectWiseControl.Client.exe h code injection
CVE-2021-47185 | Linux Kernel up to 5.15.4 tty_buffer buffer overflow (Nessus ID 210815)
CVE-2024-26854 | Linux Kernel up to 6.7.9 ice_dpll_init uninitialized pointer (db29ceff3e25/9224fc86f177)
CVE-2024-26864 | Linux Kernel up to 6.1.82/6.6.22/6.7/6.7.10/6.8.1 TCP sk_nulls_del_node_init_rcu allocation of resources
CVE-2024-26896 | Linux Kernel up to 6.1.82/6.6.22/6.7.10/6.8.1 wifi wfx_set_mfp_ap memory leak
CVE-2024-26927 | Linux Kernel up to 6.1.82/6.6.22/6.7.10/6.8.1 ASoC memory corruption (Nessus ID 210815)
CVE-2024-26924 | Linux Kernel up to 6.9-rc4 Netfilter nft_pipapo_remove denial of service (3cfc9ec039af / Nessus ID 210359)
CVE-2024-26846 | Linux Kernel up to 5.10.210/5.15.149/6.1.79/6.6.18/6.7.6 nvme-fc nvme_delete_ctrl double free (Nessus ID 207773)
53% of security teams lack continuous and up-to-date visibility
Enterprises lack visibility into their own data, creating security risks that are compounding as organizations and their employees increase AI adoption, according to Bedrock Security. The majority of organizations struggle to track sensitive information across sprawling cloud environments, leaving them vulnerable to data breaches and compliance failures. The research also documents a significant shift in security roles, with nine in 10 professionals surveyed reporting their responsibilities have evolved in the past year, most notably in … More →
The post 53% of security teams lack continuous and up-to-date visibility appeared first on Help Net Security.