Wednesday , April 2 2025

infosecbulletin

Researchers Unveil Massive Quad7 Botnet Targeting Microsoft 365

diagram

Sekoia.io and Intrinsec analyzed the Quad7 (7777) botnet, which uses TCP port 7777 on infected routers to carry out brute-force attacks on Microsoft 365 accounts. Attacks were detected on 0.11% of monitored accounts. Key insights highlighted by researchers: Botnet Evolution: Quad7 has been active for a long time and continues …

Read More »

CISA added two security flaws to its KEV catalog

CISA

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two security flaws to its Known Exploited Vulnerabilities (KEV) catalog based on evidence of active exploitation. The vulnerabilities are listed below – CVE-2012-4792 (CVSS score: 9.3) – Microsoft Internet Explorer Use-After-Free Vulnerability CVE-2024-39891 (CVSS score: 5.3) – Twilio Authy Information Disclosure …

Read More »

Cisco SSM On-Prem bug allows change any user’s password

CISCO

CISCO fixed a vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem). The vulnerability could allow an attacker without authentication to change the password of any user, even administrative users. The problem is caused by not implementing the password-change process correctly. An attacker could take advantage …

Read More »

Nacsa investigates
Malaysia Telco U Mobile Four Million user data allegedly Breached

u mobile

Malyasian National Cyber Security Agency (Nacsa) is investigating a possible data breach that exposed the data of four million U Mobile subscribers. The data, which claimed to contain personal information like names, addresses, MyKad numbers, andThe data, which may include personal information like names, addresses, MyKad numbers, and mobile phone …

Read More »

(CVE-2024-37381)
Ivanti Patches SQLi Vulnerability in Endpoint Management Software

ivanti

Ivanti fixed a SQL Injection vulnerability in its Endpoint Management software. This vulnerability, designated as CVE-2024-37381, could have allowed authenticated attackers on the same network to run any code on affected systems. The EPM software is used in many industries to manage different device platforms such as Windows, macOS, Chrome …

Read More »

CERT-In Flags Critical Vulnerabilities in Adobe, IBM WebSphere, and Joomla

vulnarabilities

The Indian Computer Emergency Response Team (CERT-In) has warned Adobe users about a high-risk cybersecurity issue. Adobe recently found serious security problems in various versions of their software, including Adobe Premiere Pro, Adobe InDesign, and Adobe Bridge. CERT-In classifies the vulnerabilities as “HIGH” severity and advises users to act quickly …

Read More »

Hacker transfer 16.5 Crore from India’s Nainital bank’s Noida branch

Thana

A massive cyber heist has hit at India’s Nainital Bank’s Noida branch, where over ₹16 crore was stolen after hackers accessed the servers and transferred the money to 89 different accounts. Cybercriminals hacked the bank’s RTGS channel by stealing the manager’s login details and stole ₹16.5 crore from June 16 …

Read More »