Security News > 2024 > October

China-Linked CeranaKeeper Targeting Southeast Asia with Data Exfiltration
2024-10-02 15:21

A previously undocumented threat actor called CeranaKeeper has been linked to a string of data exfiltration attacks targeting Southeast Asia. Slovak cybersecurity firm ESET, which observed...

Fake Job Applications Deliver Dangerous More_eggs Malware to HR Professionals
2024-10-02 15:08

A spear-phishing email campaign has been observed targeting recruiters with a JavaScript backdoor called More_eggs, indicating persistent efforts to single out the sector under the guise of fake...

CISA: Network switch RCE flaw impacts critical infrastructure
2024-10-02 15:02

U.S. cybersecurity agency CISA is warning about two critical vulnerabilities that allow authentication bypass and remote code execution in Optigo Networks ONS-S8 Aggregation Switch products used...

Critical Zimbra RCE flaw exploited to backdoor servers using emails
2024-10-02 14:15

Hackers are actively exploiting a recently disclosed RCE vulnerability in Zimbra email servers that can be triggered simply by sending specially crafted emails to the SMTP server. [...]

Alert: Over 700,000 DrayTek Routers Exposed to Hacking via 14 New Vulnerabilities
2024-10-02 13:00

A little over a dozen new security vulnerabilities have been discovered in residential and enterprise routers manufactured by DrayTek that could be exploited to take over susceptible devices....

DrayTek fixed critical flaws in over 700,000 exposed routers
2024-10-02 13:00

DrayTek has released security updates for multiple router models to address 14 vulnerabilities of varying severity, including a remote code execution flaw that received the maximum CVSS score of 10. [...]

Microsoft blocks Windows 11 24H2 on some Intel PCs over BSOD issues
2024-10-02 12:34

​Microsoft is blocking Windows 24H2 upgrades on systems with incompatible Intel Smart Sound Technology (SST) audio drivers due to blue screen of death (BSOD) issues. [...]

NIST's security flaw database still backlogged with 17K+ unprocessed bugs. Not great
2024-10-02 12:31

Logjam 'hurting infosec processes world over' one expert tells us as US body blows its own Sept deadline NIST has made some progress clearing its backlog of security vulnerability reports to...

Obsidian Security Warns of Rising SaaS Threats to Enterprises
2024-10-02 12:15

A company representative warned that many organisations still misunderstand the SaaS shared responsibility model.

Alert: Adobe Commerce and Magento Stores Under Attack from CosmicSting Exploit
2024-10-02 12:13

Cybersecurity researchers have disclosed that 5% of all Adobe Commerce and Magento stores have been hacked by malicious actors by exploiting a security vulnerability dubbed CosmicSting. Tracked as...