Microsoft detailed how Russian espionage group Secret Blizzard is leveraging infrastructure of other threat actors to target the Ukrainian military with custom malware
Monthly Archives: December 2024
Sophisticated Scam Targets UAE Residents with Fake Police Fines
Fraudsters in UAE posed as Dubai Police, targeting citizens with fake fines via calls, emails and SMS
Multiple Vulnerabilities in Ivanti Cloud Services Application (CSA) Could Allow for Remote Code Execution
Multiple vulnerabilities have been discovered in Ivanti Cloud Services Application (CSA), the most severe of which could allow for remote code execution. Ivanti Endpoint Manager is a client-based unified endpoint management software. Successful exploitation of the most severe of these vulnerabilities could allow for remote code execution in the context of the system. Depending on the privileges associated with the system, an attacker could then install programs; view, change, or delete data. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.
Cyber Incident Disrupting Krispy Kreme Online Orders
Krispy Kreme said the incident is likely to materially affect operations and short-term financial performance
South Korea Takes Down Fraudulent Online Trading Network Used to Extort $6.3M
The Korean Financial Security Institute (K-FSI) disrupted a fraudulent network that made $6.3m by stealing money from fake personal trading platforms
bpftool-7.5.0-1.fc41 kernel-6.12.4-200.fc41 kernel-headers-6.12.4-200.fc41
FEDORA-2024-9fb3492511
Packages in this update:
bpftool-7.5.0-1.fc41
kernel-6.12.4-200.fc41
kernel-headers-6.12.4-200.fc41
Update description:
The 6.12.4 stable kernel rebase contains new features, additional hardware support and a number of important fixes across the tree.
bpftool-7.5.0-1.fc40 kernel-6.12.4-100.fc40 kernel-headers-6.12.4-100.fc40
FEDORA-2024-811cffc4ef
Packages in this update:
bpftool-7.5.0-1.fc40
kernel-6.12.4-100.fc40
kernel-headers-6.12.4-100.fc40
Update description:
The 6.12.4 stable kernel rebase contains new features, additional hardware support and a number of important fixes across the tree.
Microsoft Azure MFA Flaw Allowed Easy Access Bypass
Microsoft MFA flaw exposed that allowed attackers to bypass security within an hour, putting 400m Office 365 accounts at risk
USN-7150-1: Tornado vulnerabilities
It was discovered that Tornado incorrectly handled a certain redirect.
A remote attacker could possibly use this issue to redirect a user to an
arbitrary web site and conduct a phishing attack by having the user access
a specially crafted URL. This update provides the corresponding fix for
Ubuntu 22.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 18.04 LTS. (CVE-2023-28370)
It was discovered that Tornado inefficiently handled requests when parsing
cookies. An attacker could possibly use this issue to increase resource
utilization leading to a denial of service. (CVE-2024-52804)