Friday , November 22 2024

infosecbulletin

Land ministry to present
2nd generation naming system “Smart Mutation” coming soon

Smart mutation

The Ministry of Lands is going to present the next (2nd) generation naming system Smart Mutation to the citizens of Bangladesh soon. Land Minister Saifuzzaman Chowdhury ordered to develop this system to facilitate mutation application more easily, quickly and safely. A demo of the ‘Smart Mutation’ system was on display …

Read More »

“Leaksmas” Event
Dark Web Expose Massive Volumes Of Leaked PII And Compromised Data

resecurity

On Christmas Eve, Resecurity protecting Fortune 100 and government agencies worldwide, noticed that multiple actors on the Dark Web were leaking a large amount of data. More than 50 million records containing personal information about consumers from different countries were leaked. The damage caused by this could potentially be worth …

Read More »

Embarking cybersecurity journey
CTF at Khulna Division, registration open

Game of riddle

Embark on a cybersecurity journey with Game of Riddles 2024, the first-ever Cyber Security Competition and Conference in Khulna Division Organized by Cyber Security Community Khulna, with technical support and co-organization by VulnSys. Join for a fusion of a cutting-edge Cyber Security Capture The Flag (CTF) Competition and an enlightening …

Read More »

Microsoft Disables MSIX App installer protocol abused in attacks

Microsoft

Microsoft disables the ms-appinstaller protocol handler by default due to its misuse by several threat actors to spread malware. “The observed threat actor activity abuses the current implementation of the ms-appinstaller protocol handler as an access vector for malware that may lead to ransomware distribution,” the Microsoft Threat Intelligence team …

Read More »

Big Defence Boost For India
India’s ISRO to launch AI enabled 50 Spy Satellites

Satellite

India’s space ambitions have grown with the announcement from the Indian Space Research Organisation (ISRO) that they plan to launch 50 satellites in the next five years. These satellites will be important for improving the country’s geo-intelligence capabilities. The satellites will form a network at different levels, allowing for monitoring …

Read More »

SonicWall Discover
Critical Zero-Day in Apache OfBiz ERP System

Apache oFBiz

A new security flaw was found in Apache OfBiz, an open-source Enterprise Resource Planning (ERP) system. This flaw could be used to get around authentication protections. The vulnerability, CVE-2023-51467, is found in the login feature and is caused by a partial fix for another serious vulnerability (CVE-2023-49070, CVSS score: 9.8) …

Read More »

CISA Finalizes Microsoft 365 Secure Configuration Baselines

microsoft 365

CISA started the SCuBA project to improve the security of email and cloud environments in the federal government. The project aims to enhance the security features of commonly used products and services and provide better visibility at the enterprise level to support our cybersecurity goals. This meant creating secure configurations …

Read More »

Daily Cybersecurity update, December 27, 2023

update

Cyberattacks and data breaches are still happening, causing harm to organizations and their confidential information. Recently, Yakult was attacked and had 95GB of stolen data leaked. LoanCare, a subsidiary of Fidelity National Financial, also had a data breach affecting over one million people. In Michigan, a healthcare firm had a …

Read More »

Warning: Poorly Secured Linux SSH Servers Under Attack for Cryptocurrency Mining

Coding

AhnLab’s Security Emergency Response Center (ASEC) studies attacks on poorly secured Linux SSH servers and shares the findings on the ASEC Blog. Attackers need to find out the IP address and SSH account details before installing malware like DDoS bot and CoinMiner. They scan for servers with the SSH service …

Read More »

Barracuda fixes new ESG zero-day exploited by hackers

Barracuda

Barracuda, fixed a zero-day bug on December 21. The bug was used by hackers known as UNC4841 to exploit Email Security Gateway (ESG) appliances. The company released additional security updates the following day for compromised ESG appliances that were attacked with SeaSpy and Saltwater malware. A security vulnerability was disclosed …

Read More »