Security Affairs
PaperCut Zero-Day Under Active Attack: Emergency Patch Released|U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog|Cyberattack on UK Airport Operator MAG Exposes Data of 8.7 Million Customers Across Three Airports|Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback|Australian Police Charge Two Over TeamPCP Credential Theft|Meta to Pay Up to $18B Over Teen Social Media Use|CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do|OpenAI banned Russian ChatGPT accounts backing covert influence operation|CISA Red Team Fully Compromised Two Critical Infrastructure Orgs|FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure|U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog|88 ID Verification Breaches Show the Cost of Collecting Identity Data|PaperCut Zero-Day Under Active Attack: Emergency Patch Released|U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog|Cyberattack on UK Airport Operator MAG Exposes Data of 8.7 Million Customers Across Three Airports|Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback|Australian Police Charge Two Over TeamPCP Credential Theft|Meta to Pay Up to $18B Over Teen Social Media Use|CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do|OpenAI banned Russian ChatGPT accounts backing covert influence operation|CISA Red Team Fully Compromised Two Critical Infrastructure Orgs|FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure|U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog|88 ID Verification Breaches Show the Cost of Collecting Identity Data|
Advertisement

Ad Placeholder

Full Width × 90

Breaking News

Security Affairs newsletter Round 403 by Pierluigi Paganini

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs free for you in your email box. If you want to also receive for free the newsletter with the international press subscribe here. The Irish DPC fined WhatsApp €5.5M for violating GDPR Around 19,500 end-of-life Cisco routers are exposed […]

newsletter

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs free for you in your email box.

If you want to also receive for free the newsletter with the international press subscribe here.

The Irish DPC fined WhatsApp €5.5M for violating GDPR
Around 19,500 end-of-life Cisco routers are exposed to hack
T-Mobile suffered a new data breach, 37 million accounts have been compromised
PayPal notifies 34942 users of data breach over credential stuffing attack
Chinese hackers used recently patched FortiOS SSL-VPN flaw as a zero-day in October
Cisco fixes SQL Injection flaw in Unified CM
Experts released PoC exploit for critical Zoho ManageEngine RCE flaw
Critical Microsoft Azure RCE flaw impacted multiple services
Mailchimp discloses a new security breach, the second one in 6 months
US CISA adds Centos Web Panel RCE CVE-2022-44877 to its Known Exploited Vulnerabilities Catalog
Two critical flaws discovered in Git source code version control system
A couple of bugs can be chained to hack Netcomm routers
Myrocket HR platform’s data leak turns into privacy nightmare for employees 
Experts found SSRF flaws in four different Microsoft Azure services
1,000 ships impacted by a ransomware attack on maritime software supplier DNV
How to abuse GitHub Codespaces to deliver malicious content
Patch your Zoho ManageEngine instance immediately! PoC Exploit for CVE-2022-47966 will be released soon
Fortinet observed three rogue PyPI packages spreading malware
Managing Asset Risks During Healthcare M&As
Avast researchers released a free BianLian ransomware decryptor for some variants of the malware
Experts spotted a backdoor that borrows code from CIA’s Hive malware
T95 Android TV Box sold on Amazon hides sophisticated malware
Europol arrested cryptocurrency scammers that stole millions from victims
1.7 TB of data stolen from digital intelligence firm Cellebrite leaked online
Hacker stole credit cards from the website of Canada’s largest alcohol retailer LCBO

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

[adrotate banner=”5″]

[adrotate banner=”13″]