Microsoft’s threat intelligence team has reported that ransomware groups are exploiting a critical vulnerability in VMware’s ESXi hypervisors. This allows them to gain full administrative access to systems that are joined to a domain. The flaw labeled CVE-2024-37085 with a severity score of 6.8 has been used by ransomware groups …
Read More »Fiber optic networks ‘sabotaged’ in France: Telecom networks hit
Several fiber optic networks in France were sabotaged shortly after arson attacks disrupted high-speed train services during the Olympics opening ceremony. Cables for telecom operators in six areas of France were intentionally cut earlier today, according to the police. French authorities arrested an activist from an ultra-left-wing movement at an …
Read More »“EchoSpoofing” Exploited Proofpoint flaw to Send Millions of Phishing Emails
A scam campaign linked to an unknown threat actor is using an email routing misconfiguration in Proofpoint’s defenses to send millions of fake emails pretending to be from companies like Best Buy, IBM, Nike, and Walt Disney. Guardio Labs named the campaign EchoSpoofing. It started in January 2024. The threat …
Read More »VPN Surge 5016% in Bangladesh Amid Violent Protests
VPN usage in Bangladesh has surged due to violent protests and government-imposed internet restrictions. In Bangladesh, there was a conflict for quota in the government jobs taking place on July 15 and resulted in many students getting hurt and at least five people being killed. The police tried to stop …
Read More »Patch Now! Cisco Confirms Critical RADIUS Protocol Vulnerability
Cisco has issued a security advisory (CVE-2024-3596) in the RADIUS protocol, which is widely used for network access authentication and authorization. This vulnerability could let an attacker bypass multi-factor authentication (MFA) and gain unauthorized network access. The vulnerability is due to a problem in the MD5 Response Authenticator signature in …
Read More »India’s central bank fines Visa for unauthorised payment transfer
The Reserve Bank of India fined Visa 24.1 million rupees (nearly $288,000) for using an unauthorized payment transfer system. The central bank made this announcement on Friday (July 26). “It was discovered that the entity (Visa) had implemented a payment authentication solution without regulatory clearance from the RBI,” the central …
Read More »EU 109 Banks, Cyber Stress Test; “room for improvement”
Stress test gauged how banks would respond to and recover from severe but plausible cybersecurity incident 109 banks tested, of which 28 underwent more extensive testing Results to feed into ECB’s 2024 Supervisory Review and Evaluation Process The European Central Bank (ECB) is set to conduct its first thematic stress …
Read More »Risk of cyber attack, DSE, CSE website not accessible
Risk of cyber attack, the country’s main stock market Dhaka Stock Exchange (DSE) and Chittagong stock exchange (CSE) website is closed. It is reported that it is not possible to access the DSE website as the website has been closed since Friday (July 26) morning. Acting Managing Director (MD) of …
Read More »Google fixes Chrome Password Manager bug hiding credentials
Google fixed a bug in Chrome’s Password Manager that caused user credentials to vanish temporarily. A problem with Google Chrome’s Password Manager caused an 18-hour outage on Wednesday. This affected users who use the tool to save and automatically fill in their passwords. Many users said they couldn’t find their …
Read More »India Confirms BSNL’s Data Breach, formed committee to investigate
India’s Communications Minister Chandra Sekhar Pemmasani confirmed a breach at the state-owned telecom operator BSNL on May 20 during a session in the Lok Sabha on July 24. The Minister provided this information in a written response to a question from Congress MP Amar Singh. CERT-In, India’s national agency for …
Read More »