Tuesday , December 24 2024

infosecbulletin

BCSI call for team CERT to Defend Bangladesh’s Cyberspace

BCSI

Bangladesh Cyber Security Intelligence (BCSI) has launched a Community-driven Emergency Response Team to defend the nation’s digital assets in response to recent floods and cyberattacks from a neighboring country. This team will be on the front lines, protecting Bangladesh during this critical time and ensuring that any future threats to …

Read More »

NPDC fined Fidelity Bank ₦555.8 Million

keyboard

Nigeria’s National Data Protection Commission (NDPC) fined Fidelity Bank ₦555.8 million for breaking customer data protection laws. Punch reported that Olatunji said the top bank violated Nigeria’s Data Protection Act and Regulation, resulting in a large fine of 0.1% of the bank’s 2023 revenue. Commissioner emphasized the importance of following …

Read More »

Azure Kubernetes Services at Risk: “WireServing” Threat Uncover

coding

Mandiant has found a new vulnerability in Azure Kubernetes Services (AKS) called “WireServing.” This flaw could have let attackers increase their privileges in a compromised cluster and access sensitive credentials without authorization. Kubernetes is a complex platform known for security challenges. A vulnerability in AKS clusters using “Azure CNI” and …

Read More »

Microsoft requires MFA for access to admin portals starting in October

microsoft

Microsoft warned Entra global admins to enable multi-factor authentication (MFA) for their tenants by October 15 to prevent users from losing access to admin portals. This is part of Redmond’s Secure Future Initiative. It aims to protect Azure accounts from phishing and hijacking attempts by requiring mandatory MFA for all …

Read More »

Ransomware attack on Indian payment system linked to Jenkins bug

Payment

Researchers found that recently the ransomware attack on the digital payment system used by many of India’s banks started with a vulnerability in Jenkins, an open-source automation system for software developers. Juniper Networks recently published a study on the abuse of CVE-2024-23897, a vulnerability in Jenkins Command Line Interface. The …

Read More »