German stats body says suffered possible data breach – ET CISO https://etimg.etb2bimg.com/thumb/msid-115356146,imgsize-137878,width-1200,height=765,overlay-etciso/data-breaches/german-stats-body-says-suffered-possible-data-breach.jpg Berlin, Nov 15, 2024 -Germany’s national statistics agency Destatis said Friday it had been the victim of a suspected data leak, following a media report that the organisation had been attacked by pro-Russian hackers. Destatis said in a statement it had “received indications of a possible data breach ...
Read More »Vulnerabilities & Exploits
Warning: DEEPDATA Malware Exploiting Unpatched Fortinet Flaw to Steal VPN Credentials
Warning: DEEPDATA Malware Exploiting Unpatched Fortinet Flaw to Steal VPN Credentials https://firewall.firm.in/wp-content/uploads/2024/11/lock.png A threat actor known as BrazenBamboo has exploited an unresolved security flaw in Fortinet’s FortiClient for Windows to extract VPN credentials as part of a modular framework called DEEPDATA. Volexity, which disclosed the findings Friday, said it identified the zero-day exploitation of the credential disclosure vulnerability in July ...
Read More »German stats body says suffered possible data breach – ET CISO
German stats body says suffered possible data breach – ET CISO https://etimg.etb2bimg.com/thumb/msid-115356401,imgsize-137878,width-1200,height=765,overlay-etciso/data-breaches/german-stats-body-says-suffered-possible-data-breach.jpg Berlin, Nov 15, 2024 -Germany’s national statistics agency Destatis said Friday it had been the victim of a suspected data leak, following a media report that the organisation had been attacked by pro-Russian hackers. Destatis said in a statement it had “received indications of a possible data breach ...
Read More »PAN-OS Firewall Vulnerability Under Active Exploitation – IoCs Released
PAN-OS Firewall Vulnerability Under Active Exploitation – IoCs Released https://firewall.firm.in/wp-content/uploads/2024/11/paloaltonetworks-exploit.png Nov 16, 2024Ravie LakshmananVulnerability / Network Security Palo Alto Networks has released new indicators of compromise (IoCs) a day after the network security vendor confirmed that a new zero-day vulnerability impacting its PAN-OS firewall management interface has been actively exploited in the wild. To that end, the company said it ...
Read More »Researchers Warn of Privilege Escalation Risks in Google’s Vertex AI ML Platform
Researchers Warn of Privilege Escalation Risks in Google’s Vertex AI ML Platform https://firewall.firm.in/wp-content/uploads/2024/11/ai.png Nov 15, 2024Ravie LakshmananArtificial Intelligence / Vulnerability Cybersecurity researchers have disclosed two security flaws in Google’s Vertex machine learning (ML) platform that, if successfully exploited, could allow malicious actors to escalate privileges and exfiltrate models from the cloud. “By exploiting custom job permissions, we were able to ...
Read More »Iranian Hackers Deploy WezRat Malware in Attacks Targeting Israeli Organizations
Iranian Hackers Deploy WezRat Malware in Attacks Targeting Israeli Organizations https://firewall.firm.in/wp-content/uploads/2024/11/iranian-hackers.png Nov 15, 2024Ravie LakshmananCyber Espionage / Malware Cybersecurity researchers have shed light on a new remote access trojan and information stealer used by Iranian state-sponsored actors to conduct reconnaissance of compromised endpoints and execute malicious commands. Cybersecurity company Check Point has codenamed the malware WezRat, stating it has been ...
Read More »Vietnamese Hacker Group Deploys New PXA Stealer Targeting Europe and Asia
Vietnamese Hacker Group Deploys New PXA Stealer Targeting Europe and Asia https://firewall.firm.in/wp-content/uploads/2024/11/hacking.png Nov 15, 2024Ravie LakshmananMalware / Credential Theft A Vietnamese-speaking threat actor has been linked to an information-stealing campaign targeting government and education entities in Europe and Asia with a new Python-based malware called PXA Stealer. The malware “targets victims’ sensitive information, including credentials for various online accounts, VPN ...
Read More »High-Severity Flaw in PostgreSQL Allows Hackers to Exploit Environment Variables
High-Severity Flaw in PostgreSQL Allows Hackers to Exploit Environment Variables https://firewall.firm.in/wp-content/uploads/2024/11/pistgresql.png Nov 15, 2024Ravie LakshmananVulnerability / Database Security Cybersecurity researchers have disclosed a high-severity security flaw in the PostgreSQL open-source database system that could allow unprivileged users to alter environment variables, and potentially lead to code execution or information disclosure. The vulnerability, tracked as CVE-2024-10979, carries a CVSS score of ...
Read More »New RustyAttr Malware Targets macOS Through Extended Attribute Abuse
New RustyAttr Malware Targets macOS Through Extended Attribute Abuse https://firewall.firm.in/wp-content/uploads/2024/11/gib.png Nov 14, 2024Ravie LakshmananCryptojacking / Threat Intelligence Threat actors have been found leveraging a new technique that abuses extended attributes for macOS files to smuggle a new malware called RustyAttr. The Singaporean cybersecurity company has attributed the novel activity with moderate confidence to the infamous North Korea-linked Lazarus Group, citing ...
Read More »TikTok Pixel Privacy Nightmare: A New Case Study
TikTok Pixel Privacy Nightmare: A New Case Study https://firewall.firm.in/wp-content/uploads/2024/11/tiktok.png Nov 14, 2024The Hacker NewsData Privacy / Compliance Advertising on TikTok is the obvious choice for any company trying to reach a young market, and especially so if it happens to be a travel company, with 44% of American Gen Zs saying they use the platform to plan their vacations. But ...
Read More »