Concerning signs of escalation in tactics
Yearly Archives: 2022
See how Pentera identifies and mitigates the risk of your most exploitable exposed credentials
Graham Cluley Security News is sponsored this week by the folks at Pentera. Thanks to the great team there for their support! Leaked and stolen credentials continue to pose a critical risk to organizations globally. In fact, 65% of breaches involve leaked credentials taken from the dark web and other sources. While threat intelligence tools … Continue reading “See how Pentera identifies and mitigates the risk of your most exploitable exposed credentials”
The deepfake danger: When it wasn’t you on that Zoom call
In August, Patrick Hillman, chief communications officer of blockchain ecosystem Binance, knew something was off when he was scrolling through his full inbox and found six messages from clients about recent video calls with investors in which he had allegedly participated. “Thanks for the investment opportunity,” one of them said. “I have some concerns about your investment advice,” another wrote. Others complained the video quality wasn’t very good, and one even asked outright: “Can you confirm the Zoom call we had on Thursday was you?”
With a sinking feeling in his stomach, Hillman realized that someone had deepfaked his image and voice well enough to hold 20-minute “investment” Zoom calls trying to convince his company’s clients to turn over their Bitcoin for scammy investments. “The clients I was able to connect with shared with me links to faked LinkedIn and Telegram profiles claiming to be me inviting them to various meetings to talk about different listing opportunities. Then the criminals used a convincing-looking holograph of me in Zoom calls to try and scam several representatives of legitimate cryptocurrency projects,” he says.
US Duo Plead Guilty to $30m Forex Fraud Scheme
UK Teen Arrested on Computer Misuse Charges
postgresql-jdbc-42.2.26-1.fc35
FEDORA-2022-cdeabe1bc0
Packages in this update:
postgresql-jdbc-42.2.26-1.fc35
Update description:
Security fix for CVE-2022-31197.
firefox-105.0.1-1.fc35
FEDORA-2022-1f8312716f
Packages in this update:
firefox-105.0.1-1.fc35
Update description:
Update to latest upstream (105.0.1)
firefox-105.0.1-1.fc37
FEDORA-2022-25e330a435
Packages in this update:
firefox-105.0.1-1.fc37
Update description:
Update to latest upstream (105.0.1)
firefox-105.0.1-1.fc36
FEDORA-2022-38179cd087
Packages in this update:
firefox-105.0.1-1.fc36
Update description:
Update to latest upstream (105.0.1)
ZDI-22-1301: Measuresoft ScadaPro Server Improper Access Control Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Measuresoft ScadaPro Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.