Security News > 2023 > June

The downside of frenemies
2023-06-01 16:43

Webinar Popular DevOps tools are great when it comes to helping developers optimize digital infrastructure, but there's a potential downside - the hidden risks they can contain which may compromise your supply chain. The problem is that tools such as Puppet, Chef, Ansible, and other developer solutions can quickly take those security risks into the heart of your internal software base.

Russia says US hacked thousands of iPhones in iOS zero-click attacks
2023-06-01 16:11

Russian cybersecurity firm Kaspersky says some iPhones on its network were hacked using an iOS vulnerability that installed malware via iMessage zero-click exploits. Kaspersky says the campaign started in 2019 and reports the attacks are still ongoing.

Evasive QBot Malware Leverages Short-lived Residential IPs for Dynamic Attacks
2023-06-01 16:11

An analysis of the "Evasive and tenacious" malware known as QBot has revealed that 25% of its command-and-control servers are merely active for a single day. What's more, 50% of the servers don't remain active for more than a week, indicating the use of an adaptable and dynamic C2 infrastructure, Lumen Black Lotus Labs said in a report shared with The Hacker News.

How to determine exactly what personal information Microsoft Edge knows about you
2023-06-01 16:03

Determine exactly what personal information Microsoft Edge knows about you. Depending on how long you have been using Microsoft Edge, especially if you are using the syncing feature that shares data across all your Microsoft account-related computers, the list of stored personal information on this page could be extensive.

Checklist: Network and systems security
2023-06-01 16:00

Cybersecurity demands and the stakes of failing to properly secure systems and networks are high. While every organization's specific security needs form a unique and complex blend of interconnected requirements, numerous security fundamentals almost always apply to each of these groups.

Google triples rewards for Chrome sandbox escape chain exploits
2023-06-01 16:00

Google announced today that bug bounty hunters who report sandbox escape chain exploits targeting its Chrome web browser are now eligible for triple the standard reward until December 1st, 2023. "The full chain exploit must result in a Chrome browser sandbox escape, with a demonstration of attacker control / code execution outside of the sandbox. The exploit scenario must be fully remote and the exploit able to be used by a remote attacker," Google explains.

New Zero-Click Hack Targets iOS Users with Stealthy Root-Privilege Malware
2023-06-01 15:14

A previously unknown advanced persistent threat is targeting iOS devices as part of a sophisticated and long-running mobile campaign dubbed Operation Triangulation that began in 2019. "The targets are infected using zero-click exploits via the iMessage platform, and the malware runs with root privileges, gaining complete control over the device and user data," Kaspersky said.

Critical zero-day vulnerability in MOVEit Transfer exploited by attackers!
2023-06-01 15:10

A critical zero-day vulnerability in Progress Software's enterprise managed file transfer solution MOVEit Transfer is being exploited by attackers to grab corporate data. " could lead to escalated privileges and potential unauthorized access to the environment," the company warned on Wednesday, and advised customers to take action to protect their MOVEit Transfer environment, "While our team produces a patch."

Unmasking XE Group: Experts Reveal Identity of Suspected Cybercrime Kingpin
2023-06-01 14:55

Cybersecurity researchers have unmasked the identity of one of the individuals who is believed to be associated with the e-crime actor known as XE Group. According to Menlo Security, which pieced together the information from different online sources, "Nguyen Huu Tai, who also goes by the names Joe Nguyen and Thanh Nguyen, has the strongest likelihood of being involved with the XE Group."

New MOVEit Transfer zero-day mass-exploited in data theft attacks
2023-06-01 14:47

Hackers are actively exploiting a zero-day vulnerability in the MOVEit Transfer file transfer software to steal data from organizations. MOVEit Transfer is a managed file transfer solution developed by Ipswitch, a subsidiary of US-based Progress Software Corporation, that allows the enterprise to securely transfer files between business partners and customers using SFTP, SCP, and HTTP-based uploads.