Broadcom has fixed a serious VMware vCenter Server vulnerability that allows attackers to execute remote code on unpatched servers through network packets. vCenter Server is the main management hub for VMware’s vSphere suite, enabling administrators to oversee and monitor virtualized infrastructure. The vulnerability (CVE-2024-38812) identified by TZL security researchers at …
Read More »Cybercriminal now misuse Microsoft Azure tool to steal data
Ransomware groups like BianLian and Rhysida use Microsoft’s Azure Storage Explorer and AzCopy to steal data from hacked networks and store it in Azure Blob storage. Storage Explorer is a GUI tool for managing Microsoft Azure, while AzCopy is a command-line tool for large data transfers to and from Azure …
Read More »Apple warns users to install iOS 18 to Fix 33 iPhone Vulnerabilities
Apple has released iOS 18, the latest update for iPhones and iPads. Along with new features, it mainly focuses on fixing security vulnerabilities. Apple’s iOS 18 has addressed 33 major security vulnerabilities that could have endangered millions of iPhone users. Without these fixes, hackers could have accessed personal data, controlled …
Read More »CISA adds windows and whatsUp Gold vuls to its KEV
CISA has warned Microsoft Windows MSHTML Platform Spoofing Vulnerability and Progress WhatsUp Gold SQL Injection Vulnerability actively exploited security flaws, adding them to its Known Exploited Vulnerabilities catalog, and is urging swift action from federal agencies and global organizations. CVE-2024-43461: Microsoft Windows MSHTML Platform Spoofing Vulnerability (CVSS 8.8) Microsoft‘s MSHTML …
Read More »
Petroleum and Fuel Industry
FleetPanda exposes Nearly One Million Documents
Cybersecurity researcher Jeremiah Fowler found a non-password-protected database with 780,000 records from FleetPanda, a tech provider for dispatch management. The database included invoices, driver applications, and images of licenses and background checks containing personal identifiable information (PII). A non-password-protected database held 780,191 documents, totaling 193 GB. The exposed files included …
Read More »DESCO faces cyber attack: Customers Data Breach
A recent dark web scan revealed that customer data from Dhaka Electric Supply Company Limited (DESCO) has been exposed. The breach affects 110,856 users and includes sensitive information like Customer Number, Name, Email, Address, and Mobile Number. The exposure of this data on the dark web poses several risks like: …
Read More »Alert! Google Fixes GCP Composer Flaw
Tenable Research found and fixed a remote code execution (RCE) vulnerability, called CloudImposer, in Google Cloud Platform (GCP). This flaw could have let attackers hijack a pre-installed software dependency in Google Cloud Composer. Additionally, Tenable identified concerning guidance in GCP documentation that customers should note. The Hacker News reported, quoted …
Read More »CTF in Bangladesh: Unveiling Challenges, Opportunities and remedies
In this article, we won’t dive too deep into the technical aspects of Capture The Flag (CTF) competitions. Instead, we will skim the surface of this wonderful side of the cyber world and highlight the amazing community that Bangladesh has been building over the years. We will get to know …
Read More »
Bitdefender blog post
Medusa target Fortinet flaw (CVE-2023-48788) for Ransomware Attacks
A recent Bitdefender report reveals that Medusa is still actively attacking and has created a notable presence on both the dark web and surface web, making it a ransomware group to monitor. Medusa stands out from other ransomware groups by maintaining a name-and-shame blog on the surface web, where it …
Read More »Ivanti alerts ongoing exploitation of recently patched CAV
Ivanti warned that a recently fixed security flaw in its Cloud Service Appliance (CSA) is being actively exploited. CVE-2024-8190 is a high-severity vulnerability (CVSS score: 7.2) that can enable remote code execution in specific situations. “An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and …
Read More »