Warning: DEEPDATA Malware Exploiting Unpatched Fortinet Flaw to Steal VPN Credentials https://firewall.firm.in/wp-content/uploads/2024/11/lock.png A threat actor known as BrazenBamboo has exploited an unresolved security flaw in Fortinet’s FortiClient for Windows to extract VPN credentials as part of a modular framework called DEEPDATA. Volexity, which disclosed the findings Friday, said it identified the zero-day exploitation of the credential disclosure vulnerability in July ...
Read More »Author Archives: firewallfirmadmin
US greatest threat to space security: Chinese defence ministry – ET CISO
US greatest threat to space security: Chinese defence ministry – ET CISO https://etimg.etb2bimg.com/thumb/msid-115356238,imgsize-5998,width-1200,height=765,overlay-etciso/cybercrime-fraud/us-greatest-threat-to-space-security-chinese-defence-ministry.jpg Beijing, Facts have proven that the United States is the greatest threat to space security and the biggest instigator of the space arms race, a Chinese defence ministry spokesperson said on Friday. Zhang Xiaogang, spokesperson for China’s Ministry of National Defence, made the remarks in response to ...
Read More »German stats body says suffered possible data breach – ET CISO
German stats body says suffered possible data breach – ET CISO https://etimg.etb2bimg.com/thumb/msid-115356401,imgsize-137878,width-1200,height=765,overlay-etciso/data-breaches/german-stats-body-says-suffered-possible-data-breach.jpg Berlin, Nov 15, 2024 -Germany’s national statistics agency Destatis said Friday it had been the victim of a suspected data leak, following a media report that the organisation had been attacked by pro-Russian hackers. Destatis said in a statement it had “received indications of a possible data breach ...
Read More »PAN-OS Firewall Vulnerability Under Active Exploitation – IoCs Released
PAN-OS Firewall Vulnerability Under Active Exploitation – IoCs Released https://firewall.firm.in/wp-content/uploads/2024/11/paloaltonetworks-exploit.png Nov 16, 2024Ravie LakshmananVulnerability / Network Security Palo Alto Networks has released new indicators of compromise (IoCs) a day after the network security vendor confirmed that a new zero-day vulnerability impacting its PAN-OS firewall management interface has been actively exploited in the wild. To that end, the company said it ...
Read More »T-Mobile hacked in massive Chinese breach of telecom networks: Report – ET CISO
T-Mobile hacked in massive Chinese breach of telecom networks: Report – ET CISO https://etimg.etb2bimg.com/thumb/msid-115356410,imgsize-199428,width-1200,height=765,overlay-etciso/data-breaches/t-mobile-hacked-in-massive-chinese-breach-of-telecom-networks-report.jpg T-Mobile’s network was among the systems hacked in a damaging Chinese cyber-espionage operation that gained entry into multiple U.S. and international telecommunications companies, The Wall Street Journal reported on Friday citing people familiar with the matter. Hackers linked to a Chinese intelligence agency were able to ...
Read More »Researchers Warn of Privilege Escalation Risks in Google’s Vertex AI ML Platform
Researchers Warn of Privilege Escalation Risks in Google’s Vertex AI ML Platform https://firewall.firm.in/wp-content/uploads/2024/11/ai.png Nov 15, 2024Ravie LakshmananArtificial Intelligence / Vulnerability Cybersecurity researchers have disclosed two security flaws in Google’s Vertex machine learning (ML) platform that, if successfully exploited, could allow malicious actors to escalate privileges and exfiltrate models from the cloud. “By exploiting custom job permissions, we were able to ...
Read More »Telangana Cyber Security Bureau arrests 165 cybercriminals in 6 months – ET CISO
Telangana Cyber Security Bureau arrests 165 cybercriminals in 6 months – ET CISO https://etimg.etb2bimg.com/thumb/msid-115166897,imgsize-5128,width-1200,height=765,overlay-etciso/cybercrime-fraud/telangana-cyber-security-bureau-arrests-165-cybercriminals-in-6-months.jpg Hyderabad, Telangana Cyber Security Bureau (TGCSB) has arrested 165 cyber criminals from across the country during the last six months. TGSCB director Shikha Goel said on Sunday that these cyber criminals were involved in 76 cases registered at seven cybercrime police stations in the state. In ...
Read More »Iranian Hackers Deploy WezRat Malware in Attacks Targeting Israeli Organizations
Iranian Hackers Deploy WezRat Malware in Attacks Targeting Israeli Organizations https://firewall.firm.in/wp-content/uploads/2024/11/iranian-hackers.png Nov 15, 2024Ravie LakshmananCyber Espionage / Malware Cybersecurity researchers have shed light on a new remote access trojan and information stealer used by Iranian state-sponsored actors to conduct reconnaissance of compromised endpoints and execute malicious commands. Cybersecurity company Check Point has codenamed the malware WezRat, stating it has been ...
Read More »Meeting Modern Security Demands: The evolution of security integrators into hybrid solution providers – ET CISO
Meeting Modern Security Demands: The evolution of security integrators into hybrid solution providers – ET CISO https://etimg.etb2bimg.com/thumb/msid-115169950,imgsize-11204,width-1200,height=765,overlay-etciso/next-gen-tech/meeting-modern-security-demands-the-evolution-of-security-integrators-into-hybrid-solution-providers.jpg The security industry’s evolution from traditional models to hybrid, technology-driven solutions underscore the need for a comprehensive approach. As technological advancements continue at an unprecedented pace and security threats grow increasingly complex, the security industry finds itself at a critical crossroads. Traditional, isolated ...
Read More »Vietnamese Hacker Group Deploys New PXA Stealer Targeting Europe and Asia
Vietnamese Hacker Group Deploys New PXA Stealer Targeting Europe and Asia https://firewall.firm.in/wp-content/uploads/2024/11/hacking.png Nov 15, 2024Ravie LakshmananMalware / Credential Theft A Vietnamese-speaking threat actor has been linked to an information-stealing campaign targeting government and education entities in Europe and Asia with a new Python-based malware called PXA Stealer. The malware “targets victims’ sensitive information, including credentials for various online accounts, VPN ...
Read More »