VMware and Atlassian disclosed critical vulnerabilities today. Even though there have been no reports of misuse, administrators should update their systems as soon as possible to prevent any issues. There are two problems reported by Atlassian. The most important one is CVE-2023-22527, which is a flaw in the template system …
Read More »Flight officer ‘fled to Canada’, Biman fear of data leak
The Assistant Manager (Administration) of Biman Bangladesh Airlines Anower hosan fled to Canada without the permission of the authorities. Besides, the commercial supervisor of the company Sohan Ahmed is missing. Biman MD Shafiul Azim confirmed the matter on Tuesday (January 16). Biman’s Managing Director said, they have important software and …
Read More »Tech Giants Pay $886M Digital Taxes in Indonesia
The Indonesian government has collected Rp 13.29 trillion ($886.4 million) in digital taxes from 135 technology companies, both domestic and foreign, since 2020. Digital tax revenue has been increasing steadily, reaching Rp 731.4 billion in 2020, Rp 3.9 trillion in 2021, Rp 5.51 trillion in 2022, and Rp 3.15 trillion …
Read More »
UNDOC Report
Group reportedly link to Bangladesh Bank cyber attack still active in Asia
North Korean hackers are sharing money-laundering and underground banking networks with fraudsters and drug traffickers in Southeast Asia, according to a United Nations report published on Monday, with casinos and crypto exchanges emerging as key venues for organized crime. The United Nations Office of Drugs and Crime (UNODC) said without …
Read More »Atlassian released advisory for CVE-2023-22527
Tuesday (16 January) Atlassian released advisory for CVE-2023-22527 – RCE (Remote Code Execution) Vulnerability In Confluence Data Center and Confluence Server. A template injection vulnerability on out-of-date versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected version. Customers using an affected version …
Read More »
TrendMicro Research
CVE-2023-36025, Phemedrone Stealer exploit windows SmartScreen flaw
Cybersecurity researchers at Trend Micro discovered an exploitation of CVE-2023-36025 leading to the spread of a new type of malware called Phemedrone Stealer. Phemedrone Stealer is a malware that targets web browsers, cryptocurrency wallets, and messaging apps like Telegram, Steam, and Discord. It not only steals data, but also takes …
Read More »
Bishopfox bog
Over 178k SonicWall Firewalls are Publicly Exploitable
In a blog post BishopFox said, SonicWall next-generation firewall (NGFW) series 6 and 7 devices are affected by two unauthenticated denial-of-service vulnerabilities with the potential for remote code execution. SonicWall published advisories for CVE-2022-22274 and CVE-2023-0656 a year apart and reported that no exploitation had been observed in the wild; …
Read More »
Recorded Future Report
Security Experts Urge IT to Lock Down GitHub Services
Recorded Future, a threat intelligence firm, has cautioned that malicious actors are using GitHub services more to carry out secret cyber-attacks and has advised IT teams to act. Its new report, Flying Under the Radar: Abusing GitHub for Malicious Infrastructure, revealed the most popular GitHub services for threat actors. Between …
Read More »Microsoft lets cloud users keep personal data within Europe
Microsoft said on Thursday that it will keep all personal data of its cloud customers within the European Union instead of allowing transfers outside the EU. This is part of their ongoing efforts to comply with different privacy regulations in different places. Microsoft will store customer data from its cloud …
Read More »The US central bank suffered huge financial losses
The Federal Reserve is expecting significant losses in 2023, mainly due to higher costs. This was announced by the central bank of the United States last Friday. The interest rate was raised to reduce the money supply, causing commercial banks and other institutions to pay more interest on reserves at …
Read More »