Saturday , October 19 2024

infosecbulletin

Hackers use F5 BIG-IP malware in cyber campaign for years

hacker

In late 2023, Sygnia researchers investigated a cyber incident involving a major organization that was reportedly caused by a threat group known as ‘Velvet Ant.’ The cyberspies deployed custom malware on F5 BIG-IP appliances to gain persistent access to the internal network of the target organization and steal sensitive data. …

Read More »

Dahua Cameras 0day Vulnerability offer to sell

camera

A threat actor has announced selling a 0day vulnerability for Dahua cameras. The bad actor claimed this vulnerability supposedly works with all versions of the device. The threat actor announced the vulnerability allowed unrestricted access and control of the camera and describing it as a Remote Code Execution (RCE) exploit. …

Read More »

D-Link Routers Critical Backdoor Vulnerability Exposed

d link

Taiwan’s CERT has warned about a serious security issue with D-Link wireless routers, affecting many models. This vulnerability could let attackers on the local network access the router’s Telnet service using basic administrator credentials CVE-2024-6045 Certain D-Link router models have a hidden backdoor that was recently discovered. This flaw allows …

Read More »

338 fraudulent Olympics games ticketing websites

ticket

Proofpoint found a fake website selling tickets for the Paris 2024 Summer Olympic Games. The website, “paris24tickets[.]com,” claimed to be a secondary marketplace for sports and live event tickets. It appeared as the second sponsored search result on Google, right after the official website, when searching for “Paris 2024 tickets” …

Read More »

AWS Announced New Malware Detection Tool For S3 Buckets

aws

AWS announced new security features at its re:Inforce conference, such as identity and malware protection services. The cloud giant added passkeys to the list of supported multi-factor authentication (MFA) mechanisms for root and Identity and Access Management (IAM) users. The company also started enforcing MFA on root users, particularly AWS …

Read More »

CISA Releases Twenty Industrial Control Systems Advisories

ics

CISA released 20 advisories about Industrial Control Systems (ICS) on June 13, 2024. These advisories give important information about security issues, vulnerabilities, and exploits related to ICS. ICSA-24-165-01 Siemens Mendix Applications ICSA-24-165-02 Siemens SIMATIC S7-200 SMART Devices ICSA-24-165-03 Siemens TIA Administrator ICSA-24-165-04 Siemens ST7 ScadaConnect ICSA-24-165-05 Siemens SITOP UPS1600 ICSA-24-165-06 …

Read More »

Current web vulnerabilities in Bangladesh across vendor product line

Source: BGD e-GOV CIRT

On a report titled “Surge on Web defacement and web application related vulnerabilities targeting Bangladesh” BGD e-GOV CIRT said, web defacement attacks and the exploitation of web application vulnerabilities are a growing trend in Bangladesh. These weaknesses can be used for phishing attacks, spreading malware, and creating backdoors for continuous …

Read More »