Security Affairs
PaperCut Zero-Day Under Active Attack: Emergency Patch Released|U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog|Cyberattack on UK Airport Operator MAG Exposes Data of 8.7 Million Customers Across Three Airports|Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback|Australian Police Charge Two Over TeamPCP Credential Theft|Meta to Pay Up to $18B Over Teen Social Media Use|CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do|OpenAI banned Russian ChatGPT accounts backing covert influence operation|CISA Red Team Fully Compromised Two Critical Infrastructure Orgs|FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure|U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog|88 ID Verification Breaches Show the Cost of Collecting Identity Data|PaperCut Zero-Day Under Active Attack: Emergency Patch Released|U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog|Cyberattack on UK Airport Operator MAG Exposes Data of 8.7 Million Customers Across Three Airports|Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback|Australian Police Charge Two Over TeamPCP Credential Theft|Meta to Pay Up to $18B Over Teen Social Media Use|CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do|OpenAI banned Russian ChatGPT accounts backing covert influence operation|CISA Red Team Fully Compromised Two Critical Infrastructure Orgs|FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure|U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog|88 ID Verification Breaches Show the Cost of Collecting Identity Data|
Advertisement

Ad Placeholder

Full Width × 90

Breaking News

Security Affairs newsletter Round 397

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs free for you in your email box. If you want to also receive for free the newsletter with the international press subscribe here. At least 4,460 vulnerable Pulse Connect Secure hosts are exposed to the Internet US HHS warns […]

newsletter

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs free for you in your email box.

If you want to also receive for free the newsletter with the international press subscribe here.

At least 4,460 vulnerable Pulse Connect Secure hosts are exposed to the Internet
US HHS warns healthcare orgs of Royal Ransomware attacks
CommonSpirit confirms data breach impacts 623K patients
Pwn2Own Toronto 2022 Day 3: Participants earned nearly $1 million
Cisco discloses high-severity flaw impacting IP Phone 7800 and 8800 Series
Experts devised a technique to bypass web application firewalls (WAF) of several vendors
Zombinder APK binding service used in multiple malware attacks
Pwn2Own Toronto 2022 Day 2: Participants earned $281K
Android app with over 5m downloads leaked user browsing history
APT37 used Internet Explorer Zero-Day in a recent campaign
New Go-based botnet Zerobot exploits dozens of flaws
Pwn2Own Toronto 2022 hacking competition. Samsung S22 hacked
Sophos fixed a critical flaw in its Sophos Firewall version 19.5
Russia’s second-largest bank VTB Bank under DDoS attack
A flaw in the connected vehicle service SiriusXM allows remote car hacking
Ransomware Toolkit Cryptonite turning into an accidental wiper
Crook sentenced to 18 months for stealing $20M in SIM swapping attack
French hospital cancels operations after a ransomware attack
Exclusive: The largest mobile malware marketplace identified by Resecurity in the Dark Web
Critical Ping bug potentially allows remote hack of FreeBSD systems
Lazarus APT uses fake cryptocurrency apps to spread AppleJeus Malware
Law enforcement agencies can extract data from thousands of cars’ infotainment systems
US DHS Cyber Safety Board will review Lapsus$ gang’s operations
New CryWiper wiper targets Russian entities masquerading as a ransomware

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

[adrotate banner=”5″]

[adrotate banner=”13″]