A hacker changed the code of five plugins on WordPress.org to add harmful PHP scripts that make new admin accounts on websites using the plugins. The Wordfence Threat Intelligence team found the attack yesterday, but the injections happened between June 21 and June 22, last week. Wordfence found a breach …
Read More »CISA issued two advisories for industrial control systems
CISA released two advisories about Industrial Control Systems (ICS) on June 25, 2024. The advisories contain important information about security issues, vulnerabilities, and exploits related to ICS. ICSA-24-177-01 ABB Ability System 800xA: Successful exploitation of these vulnerabilities could cause services to crash and restart. ICSA-24-177-02 PTC Creo Elements/Direct License Server: …
Read More »CISA confirms hackers possibly access CSAT January incident
CISA warns that its Chemical Security Assessment Tool (CSAT) was hacked in January. Hackers used a webshell on the Ivanti device, which may have exposed important security assessments and plans. In March, The Record revealed that CISA had a breach after the Ivanti device was exploited, leading to two systems …
Read More »LockBit Claims 33 TB of US Federal Reserve Data
LockBit claimed that it breached Federal Reserve Board (Federalreserve.gov), the central banking system of the United States and exfiltrated 33 TB of sensitive data, including “Americans’ banking secrets.” “The group announced to release the stolen data on 25 June, 2024 20:27:10 UTC.” According to the post by the LockBit ransomware …
Read More »Indonesia’s National data center compromised, $8M ransom demand
Cyber attack compromised Indonesia’s national data center, causing trouble with immigration checks at airports. Attacker demanded an $8 million ransom, Reuters reported. The attack caused problems for government services, especially at airports, with long lines at immigration desks. The communications ministry said that automated passport machines are now working. Minister …
Read More »ESET Issues Security Patch for Privilege Escalation Flaw
ESET Issued security patch for privilege escalation flaw in its Windows security products. This flaw, called CVE-2024-2003 (CVSS 7.3), was found by the Zero Day Initiative (ZDI). It could have let attackers gain access to important files and folders without permission. The vulnerability exploited ESET’s file operations while restoring quarantined …
Read More »Hacker offer zero-day RCE exploit of Atlassian Jira for Sale
A threat offer to sell a zero-day exploit for Atlassian’s Jira in a underground forum. This exploit can be used on the latest version of Jira desktop app and Jira integrated with Confluence. According to the offer, It does not require any login credentials and can also work with Okta …
Read More »US bans Kaspersky software over Russia ties
The US plans to ban the sale of Kaspersky antivirus software due to its alleged ties to the Kremlin. Gina Raimondo, the US Commerce Secretary, said that Moscow’s control over the company was a big threat to US infrastructure and services. She said that the US was compelled to take …
Read More »China-linked spies target Asian Telcos since 2021
A group believed to be linked to China has hacked multiple telecom operators in an Asian country since 2021, according to the Symantec Threat Hunter Team. The attackers used tools linked to Chinese spying groups. They installed several backdoors on targeted companies’ networks to steal passwords. “The attacks have been …
Read More »Azad selected expert reviewer for CISA Review Manual 28th Edition
Certified Information Systems Auditor (CISA) is a globally recognized professional certification for information systems audit, control, and security. It’s offered by ISACA (Information Systems Audit and Control Association). CISA holders demonstrate expertise in assessing an organization’s IT controls and processes to identify and manage risks. The CISA Review Manual, 28th …
Read More »