Saturday , October 19 2024

infosecbulletin

“EchoSpoofing” Exploited Proofpoint flaw to Send Millions of Phishing Emails

diagram

A scam campaign linked to an unknown threat actor is using an email routing misconfiguration in Proofpoint’s defenses to send millions of fake emails pretending to be from companies like Best Buy, IBM, Nike, and Walt Disney. Guardio Labs named the campaign EchoSpoofing. It started in January 2024. The threat …

Read More »

Patch Now! Cisco Confirms Critical RADIUS Protocol Vulnerability

Cisco has issued a security advisory (CVE-2024-3596) in the RADIUS protocol, which is widely used for network access authentication and authorization. This vulnerability could let an attacker bypass multi-factor authentication (MFA) and gain unauthorized network access. The vulnerability is due to a problem in the MD5 Response Authenticator signature in …

Read More »

India’s central bank fines Visa for unauthorised payment transfer

visa

The Reserve Bank of India fined Visa 24.1 million rupees (nearly $288,000) for using an unauthorized payment transfer system. The central bank made this announcement on Friday (July 26). “It was discovered that the entity (Visa) had implemented a payment authentication solution without regulatory clearance from the RBI,” the central …

Read More »

New DNS Vulnerability “TuDoor” Threatens Internet Security

diagram

A new critical vulnerability in the Domain Name System (DNS) has been found. This vulnerability allows a specialized attack called “TuDoor” that can poison DNS caches, cause denial-of-service (DoS) attacks, and deplete resources, posing a significant threat to internet security. Specialists have conducted experiments that confirm the feasibility of the …

Read More »