Security News > 2024 > August

Litespeed Cache bug exposes millions of WordPress sites to takeover attacks
2024-08-21 17:22

A critical vulnerability in the LiteSpeed Cache WordPress plugin can let attackers take over millions of websites after creating rogue admin accounts. [...]

Microsoft Patches Critical Copilot Studio Vulnerability Exposing Sensitive Data
2024-08-21 16:15

Cybersecurity researchers have disclosed a critical security flaw impacting Microsoft's Copilot Studio that could be exploited to access sensitive information. "An authenticated attacker can bypass Server-Side Request Forgery protection in Microsoft Copilot Studio to leak sensitive information over a network," Microsoft said in an advisory released on August 6, 2024.

Phrack hacker zine publishes new edition after three years
2024-08-21 15:45

Phrack #71 has been released online and is available to read for free. This issue is the first to be released since 2021, marking a new chapter in the influential online magazine's history. [...]

More than 3 in 4 Tech Leaders Worry About SaaS Security Threats, New Survey Reveals
2024-08-21 15:38

A new study finds that these threats remain top of mind for 78% of U.S. technology leaders as more SaaS apps find their way into the enterprise. Although enterprises have been prioritizing data privacy and security, their continued reliance on SaaS and cloud offerings means they remain at risk, according to the The SaaS Disruption Report: Security & Data by Onymos and Enterprise Strategy Group.

North Korean Hackers Deploy New MoonPeak Trojan in Cyber Campaign
2024-08-21 15:37

A new remote access trojan called MoonPeak has been discovered as being used by a state-sponsored North Korean threat activity cluster as part of a new campaign. Cisco Talos attributed the...

Russia tells citizens to switch off home surveillance because the Ukrainians are coming
2024-08-21 15:01

Forget about your love life too, no dating apps until the war is over Russia's Ministry of Internal Affairs is warning residents of under-siege regions to switch off home surveillance systems and...

GitHub Enterprise Server vulnerable to critical auth bypass flaw
2024-08-21 14:15

A critical vulnerability affecting multiple versions of GitHub Enterprise Server could be exploited to bypass authentication and enable an attacker to gain administrator privileges on the machine. [...]

Story of an Undercover CIA Agent who Penetrated Al Qaeda
2024-08-21 13:56

Rolling Stone has a long investigative story about a CIA agent who spent years posing as an Islamic radical. Unrelated, but also in the "Real life spies" file: a fake Sudanese diving resort run by Mossad. Tags: al Qaeda, CIA, espionage, undercover.

PostgreSQL databases under attack
2024-08-21 13:10

Poorly protected PostgreSQL databases running on Linux machines are being compromised by cryptojacking attackers. Internet-exposed PostgreSQL databases are a favorite target of opportunistic cryptojacking groups and, occasionally, extortionists.

It's Time To Untangle the SaaS Ball of Yarn
2024-08-21 11:11

It's no great revelation to say that SaaS applications have changed the way we operate, both in our personal and professional lives. We routinely rely on cloud-based and remote applications to...