A new sophisticated scam is targeting Gmail users, using artificial intelligence to manipulate them into giving away account access. This “super realistic AI scam call” includes fake recovery notifications, spoofed phone numbers, and convincing AI voices to trick users. The scam usually starts with an unexpected Gmail account recovery notification …
Read More »Gmail Scam Alert
RansomHub Targets Bangladeshi Confidence Group
RansomHub targets Bangladeshi Confidence group of companies limited. The rapidly growing RansomHub ransomware group set time to release the data. The time remaining 4 days to release while publishing the report. According to the RansomHub ransomware group post, they are going to publish 350GB of confidence group data after the …
Read More »Hackers using ChatGPT create malware, OpenAI confirm
OpenAI has neutralized over 20 malicious cyber operations using its AI chatbot, ChatGPT, for creating malware, spreading misinformation, avoiding detection, and spear-phishing. The report confirms that since the start of the year, generative AI tools are being used to improve offensive cyber operations. OpenAI’s latest report reveals that Chinese and …
Read More »TrackMan exposes nearly 32 Million Records
Nearly 32 million records and about 110 TB of data from Trackman users were left exposed online. This database included user names, email addresses, device information, IP addresses, and security tokens. Security researcher Jeremiah Fowler discovered the vulnerability and reported it to Website Planet, noting that the database lacked password …
Read More »
CISA WARNS
CISA Warns of F5 BIG-IP Cookie Exploitation for Network Reconnaissance
CISA has issued a warning about a vulnerability in unencrypted persistent cookies in the F5 BIG-IP Local Traffic Manager (LTM) module. This issue poses a risk for organizations using F5 BIG-IP, as it can be exploited by cybercriminals. CISA warns that cybercriminals are using unencrypted persistent cookies to discover details …
Read More »CVE-2024-9164: GitLab Users Urged to Update Now
GitLab, a premier platform for DevOps and continuous integration/continuous delivery has rolled out essential security updates in versions 17.4.2, 17.3.5 and 17.2.9 for both community Edition (CE) and enterprises edition (EE). These updates tackles several important vulnerabilities, notably a critical severity flaw (CVE: 2024-9164) that could enable attackers to execute …
Read More »CISA Warns of Critical Fortinet Flaw as Palo Alto and Cisco Issue Urgent Patches
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical security flaw impacting Fortinet products to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2024-23113 (CVSS score: 9.8), relates to cases of remote code execution that affects FortiOS, FortiPAM, FortiProxy, …
Read More »Palo Alto Networks issues fix for security flaws, Including CVE-2024-9463
Palo Alto Networks released a security advisory (PAN-SA-2024-0010) about several high-severity vulnerabilities in its Expedition migration tool, with CVSS scores between 7.0 and 9.9. Exploiting these flaws could allow attackers to take over firewall admin accounts and access sensitive information like usernames, cleartext passwords, and API keys for PAN-OS firewalls. …
Read More »Microsoft October 2024 Patch: 5 Zero-Days, 118 flaw
In its recent Patch Tuesday release, Microsoft fixed 118 vulnerabilities, including five zero-day flaws, two of which are currently being exploited. The updates affect multiple Microsoft products, such as Windows, Office, Azure, .NET, and Visual Studio. Zero-Day Vulnerabilities: Among the five zero-day vulnerabilities patched, two were actively exploited in the …
Read More »
BD CIRT alert
Lumma C2 malware attack Bangladeshi several websites
The Cyber Threat Intelligence (CTI) Unit at BGD e-GOV CIRT has discovered a malware campaign involving the Lumma Stealer family. They’ve found that various types of stealer malware are being spread using similar methods. CIRT is monitoring stealer malware campaigns and has found malware that steals sensitive information. Recently, the …
Read More »