Security News > 2024 > April

Week in review: Palo Alto Networks firewalls under attack, Microsoft patches two exploited zero-days
2024-04-14 08:00

Palo Alto Networks firewalls under attack, hotfixes incoming!Attackers are exploiting a command injection vulnerability affecting Palo Alto Networks' firewalls, the company has warned, and urged customers to implement temporary mitigations and get in touch to check whether their devices have been compromised. It can handle almost anything, and someone once called it the kitchen sink of PKI. Microsoft patches two actively exploited zero-daysOn this April 2024 Patch Tuesday, Microsoft has fixed a record 147 CVE-numbered vulnerabilities, including CVE-2024-29988, a vulnerability that Microsoft hasn't marked as exploited, but Peter Girnus, senior threat researcher with Trend Micro's Zero Day Initiative, has found being leveraged by attackers in the wild.

Ex-Security Engineer Jailed 3 Years for $12.3 Million Crypto Exchange Thefts
2024-04-13 14:25

A former security engineer has been sentenced to three years in prison in the U.S. for charges relating to hacking two decentralized cryptocurrency exchanges in July 2022 and stealing over $12.3...

Firebird RAT creator and seller arrested in the U.S. and Australia
2024-04-13 14:17

A joint police operation between the Australian Federal Police and the FBI has led to the arrest and charging of two individuals who are believed to be behind the development and distribution of the "Firebird" remote access trojan, later rebranded as "Hive.". The Australian Federal Police alleges that the Australian developed and sold the RAT on a dedicated hacking forum, enabling other users who paid for the tool to remotely access victims' computers and perform unauthorized activity.

Hacker claims Giant Tiger data breach, leaks 2.8M records online
2024-04-13 14:00

Canadian retail chain Giant Tiger disclosed a data breach in March 2024.A threat actor has now publicly claimed responsibility for the data breach and leaked 2.8 million records on a hacker forum that they claim are of Giant Tiger customers.

U.S. Treasury Hamas Spokesperson for Cyber Influence Operations
2024-04-13 13:58

The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) on Friday announced sanctions against an official associated with Hamas for his involvement in cyber influence operations....

Palo Alto Networks zero-day exploited since March to backdoor firewalls
2024-04-13 12:35

Suspected state-sponsored hackers have been exploiting a zero-day vulnerability in Palo Alto Networks firewalls tracked as CVE-2024-3400 since March 26, using the compromised devices to breach internal networks, steal data and credentials. Palo Alto Networks warned yesterday that hackers were actively exploiting an unauthenticated remote code execution vulnerability in its PAN-OS firewall software and that patches would be available on April 14.

UK flooded with forged stamps despite using barcodes — to prevent just that
2024-04-13 09:05

Royal Mail, the British postal and courier service began switching all snail mail stamps to barcoded stamps last year. As Royal Mail transitioned towards barcoded stamps last year, the public had until the end of July 2023 to swap out their old paper stamps with ones carrying a 2D data matrix barcode at no cost.

#UK
Hackers Deploy Python Backdoor in Palo Alto Zero-Day Attack
2024-04-13 08:25

Threat actors have been exploiting the newly disclosed zero-day flaw in Palo Alto Networks PAN-OS software dating back to March 26, 2024, nearly three weeks before it came to light yesterday. The...

Zero-day exploited right now in Palo Alto Networks' GlobalProtect gateways
2024-04-12 22:43

Your profile can be used to present content that appears more relevant based on your possible interests, such as by adapting the order in which content is shown to you, so that it is even easier for you to find content that matches your interests. Content presented to you on this service can be based on your content personalisation profiles, which can reflect your activity on this or other services, possible interests and personal aspects.

Friday Squid Blogging: The Awfulness of Squid Fishing Boats
2024-04-12 21:08

Baleen whales, including humpbacks, right whales and blue whales, have evolved a unique larynx that allows them to produce super low-frequency sounds which can travel huge distances. Toothed whales which include sperm whales, dolphins, porpoises and orcas, are the among loudest animals on Earth and use ultra-fast clicks for echolocation, to "See" their world, as well as soft burst pulses and whistles to communicate.