Europe Confirms Record €4.1B Penalty Against Google for Android Practices|U.S. CISA adds a Microsoft SharePoint Server flaw to its Known Exploited Vulnerabilities catalog|430,000 FortiGate Devices Exposed in FortiBleed Ransomware Link|Adobe fixed multiple maximum-severity flaws in ColdFusion and Campaign Classic|Alleged Scattered Spider Hacker Extradited to U.S. to Face Cybercrime Charges|Oracle E-Business Suite Flaw Under Active Attack, 950 Systems Exposed|Azure CLI Targeted in LSHIY Password Spray Campaign Across 64 Orgs|CISA Warns BlueHammer Flaw Is Now Exploited in Ransomware Attacks|RustDuck: The Botnet That’s Still Small but Engineering Like It Plans to Grow|GuardFall Flaw Hits 10 of 11 Popular Open-Source AI Agents|XSS.is, The Forum That Ran the Ransomware Supply Chain Is Down. The Market Isn’t|U.S. CISA adds SimpleHelp flaw to its Known Exploited Vulnerabilities catalog|Europe Confirms Record €4.1B Penalty Against Google for Android Practices|U.S. CISA adds a Microsoft SharePoint Server flaw to its Known Exploited Vulnerabilities catalog|430,000 FortiGate Devices Exposed in FortiBleed Ransomware Link|Adobe fixed multiple maximum-severity flaws in ColdFusion and Campaign Classic|Alleged Scattered Spider Hacker Extradited to U.S. to Face Cybercrime Charges|Oracle E-Business Suite Flaw Under Active Attack, 950 Systems Exposed|Azure CLI Targeted in LSHIY Password Spray Campaign Across 64 Orgs|CISA Warns BlueHammer Flaw Is Now Exploited in Ransomware Attacks|RustDuck: The Botnet That’s Still Small but Engineering Like It Plans to Grow|GuardFall Flaw Hits 10 of 11 Popular Open-Source AI Agents|XSS.is, The Forum That Ran the Ransomware Supply Chain Is Down. The Market Isn’t|U.S. CISA adds SimpleHelp flaw to its Known Exploited Vulnerabilities catalog|
Advertisement

Ad Placeholder

Full Width × 90

Breaking News

Security Affairs newsletter Round 158 – News of the week

A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. Let me inform you that my new book, “Digging in the Deep Web” is online Kindle Edition Paper Copy Once again thank you! ·      ATMJackpot, a new strain of ATM Malware discovered by experts ·      Auth0 authentication […]

newsletter

A new round of the weekly SecurityAffairs newsletter arrived!

The best news of the week with Security Affairs.

Let me inform you that my new book, “Digging in the Deep Web” is online

Kindle Edition

Paper Copy

Digging The Deep Web

Once again thank you!

·      ATMJackpot, a new strain of ATM Malware discovered by experts
·      Auth0 authentication bypass issue exposed enterprises to hack
·      Experts spotted a campaign spreading a new Agent Tesla Spyware variant
·      Crooks distribute malware masquerade as fake software updates and use NetSupport RAT
·      Sodexo Filmology data breach – Users need cancel their credit cards
·      Verge Cryptocurrency suffered a cyber attack, dev team responded with an Hard Fork
·      Vigilante hackers strike Russia and Iran Networks exploiting Cisco CVE-2018-0171 flaw
·      Booby-trapped Office docs build with ThreadKit trigger CVE-2018-4878 flaw
·      Linux open source utility Beep is affected by several vulnerabilitues
·      Public services at the Caribbean island Sint Maarten shut down by a cyber attack
·      SirenJack flaw in Emergency Alert Systems could be exploited to trigger false alarms
·      Top VEVO Music videos Including ‘Despacito defaced by hackers
·      Adobe April Security Bulletin Tuesday fixed 4 critical flaws in Flash
·      AMD and Microsoft release microcode and operating system updates against Spectre flaw
·      Microsoft April Patch Tuesday – Update your system now to avoid being hacked by visiting a site
·      APT33 devised a code injection technique dubbed Early Bird to evade detection by anti-malware tools
·      CVE-2018-0950 flaw in Microsoft Outlook could be exploited to steal Windows Passwords
·      Researchers discovered several flaws that expose electrical substations to hack
·      SAP April 2018 Security Patch Day address critical flaws in web browser controls in SAP Business Client
·      $3.3 Million stolen from main Coinsecure Bitcoin wallet
·      Experts uncovered a proxy botnet composed of over 65,000 routers exposed via UPnP protocol
·      Experts warn threat actors are scanning the web for Drupal installs vulnerable to Drupalgeddon2
·      Uber agrees to new FTC settlement over 2016 data breach
·      When the Russian Malware coder Gatsoev is praised by the Russian head of Information Department of the Ministry of Education and Science of North Ossetia
·      Are your Android devices updated? Researchers say maybe no
·      Great Western Railway asks users to reset passwords due to a security breach
·      Malware researcher have dismantled the EITest Network composed of 52,000

 

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(Security Affairs – Newsletter)

[adrotate banner=”5″]

[adrotate banner=”13″]