Tuesday , May 21 2024

infosecbulletin

Cisco Talos report
“CoralRaider” Targeting Financial Data Across Asia including Bangladesh

CoralRaider

Vietnamese hackers are targeting businesses in Asia to get corporate credentials and financial data to sell online. Researchers at Cisco Talos found a group of hackers, known as CoralRaider, targeting India, China, South Korea, Bangladesh, Pakistan, Indonesia, and local entities with a specific type of malware. Talos believes that the …

Read More »

India Cyber Revolution Summit 2024: April 25-26

conference

The “India Cyber Revolution Summit” will take place in New Delhi, India on April 25 and 26, 2024. TraiCon Events will host this important cybersecurity conference, bringing together over 500 industry professionals, including CISOs, CIOs, and executives involved in cybersecurity, digital transformation, and IT infrastructure. They will discuss the latest …

Read More »

CISA Releases Two Industrial Control Systems Advisories

CISA

CISA released two advisories on April 4, 2024 about security issues, vulnerabilities, and exploits for Industrial Control Systems (ICS). ICSA-24-095-01 Hitachi Energy Asset Suite 9 ICSA-24-095-02 Schweitzer Engineering Laboratories SEL CISA recommends reviewing the newly issued ICS advisory for more information and ways to address the issue.    

Read More »

New HTTP/2 Vulnerability Exposes Web Servers to DoS Attacks

http/2

The HTTP/2 protocol has a vulnerability in the CONTINUATION frame that allows for denial-of-service (DoS) attacks. Security researcher Bartek Nowotarski named this technique HTTP/2 CONTINUATION Flood and reported it to the CERT Coordination Center (CERT/CC) on January 25, 2024. “Many HTTP/2 implementations do not properly limit or sanitize the amount …

Read More »

CYBERSECURITY AND DATA PROTECTION
Serious security breach hits EU police agency

Europol

They were supposed to be under lock and key, in a secure storage room deep inside Europol’s headquarters in The Hague. But a clutch of highly sensitive files containing the personal information of top law enforcement executives went missing last summer. Europe’s law enforcement agency has been mired in a …

Read More »

BANKING, MALWARE, FINANCIAL SERVICES, RAT, JS
JSOUTPROX ATTACK FINANCIAL INSTITUTIONS IN APAC

Rat

A new version of JSOutProx has been detected by Resecurity. This version is targeting financial services and organizations in the APAC and MENA regions. JSOutProx is a sophisticated attack framework that uses both JavaScript and .NET to carry out its attacks. The malware allows for the loading of various plugins …

Read More »