Categoria : Security

image_pdfimage_print

Microsoft warns of a Windows-based cryptocurrency clipper that establishes a lightweight backdoor blending data exfiltration and remote code execution (RCE) capabilities. Dubbed CryptoBandits, the malware has been used in attacks since February 2026, deploying a portable Tor client on the infected systems and routing traffic through a local SOCKS5 proxy. “The clipper in this campaign ..

Leggi tutto

CISA is urging organizations to harden their internet-accessible Fortinet devices in response to a large-scale credential theft campaign that likely impacts over 86,000 firewalls and VPNs. Referred to as FortiBleed, the campaign was flagged earlier this week. SOCRadar initially warned of over 30,000 compromised Fortinet devices potentially exposing enterprise networks to hacking, and has since ..

Leggi tutto

Well hey y’all. I just got hooked up with this space to somewhat-routinely write about vulnerabilities, cybersecurity, and infosec history. I’m currently at runZero, where I’m the vice president of security research, which basically means that I spend most of my time hanging around with some incredibly bright and devoted people who are also cunning ..

Leggi tutto

Atlassian and Splunk on Wednesday announced patches for multiple vulnerabilities in their products, including critical-severity flaws. Splunk resolved a critical issue in AI Toolkit that could allow authenticated attackers with admin roles to execute arbitrary OS commands on the host the Splunk Enterprise instance runs on. “The vulnerability is possible because of an unsafe shell ..

Leggi tutto

@import url(‘https://fonts.googleapis.com/css2?family=Nunito+Sans:ital,opsz,wght@0,6..12,400;0,6..12,500;0,6..12,600;0,6..12,700;1,6..12,400;1,6..12,500;1,6..12,600;1,6..12,700&family=Nunito:ital,wght@0,400;0,500;0,600;0,700;1,400;1,500;1,600;1,700&display=swap’); @import url(‘https://fonts.googleapis.com/css2?family=Handlee&display=swap’); h3 { font-weight: bold; font-size: 18px; color: #404144; } figure { padding: 4px; margin: auto; } figcaption { color: #404144; font-family: ‘Nunito Sans’, Arial, sans-serif; font-size: 14px; padding: 10px; text-align: left; } .highlight { padding: 3%; border-top: 8px solid #207BBC; border-bottom: 3px solid #207BBC; width: 100%; font-family: ‘Nunito Sans’,Arial,sans-serif; font-size: 15px; ..

Leggi tutto

Danish pharmaceutical firm Novo Nordisk announced it faced a data breach related to clinical trials, releasing notification letters to both patients and healthcare providers (HCPs) involved. According to the statement, a threat actor gained access to a limited number of the company’s internal IT systems, which included access to certain personal data.  What Data Is Compromised? ..

Leggi tutto