The FBI and European security organizations working under Europol have seized ALPHV’s website also known as Blackcat. ALPHV ransomware has infected over 1,000 victims worldwide. Cybercrime has a popular model called ransomware-as-a-service. This model involves a group of developers who create and update ransomware. They also maintain the necessary internet …
Read More »FBI Offers Decryption Tool
Iran’s state TV said
Suspected cyberattack paralyzes 70% gas stations across Iran
Iran’s Oil Minister, Javad Owji, confirmed on Monday that a cyberattack caused a widespread disruption to petrol stations. A hacking group Iran blames Israel for claimed it caused the attack that disrupted petrol stations across the country on Monday, according to Iranian state TV and Israeli local media. ALSO READ: …
Read More »
New survey by IDC
Malaysia face doubling of ransomware incidents in 2023
In Malaysia, the cybersecurity situation is changing as organizations deal with an increase in cyber threats. A recent survey by IDC shows that phishing is the main concern, with 54% of organizations ranking it as the biggest threat. The top five risks in Malaysia are ransomware, unpatched vulnerabilities, identity theft, …
Read More »
Draft emergency plan
China to enforce 10 min response time for data breaches
China proposed a four-tier classification to respond to data security incidents, showing its concern about data leaks and hacking in the country. The plan is due to increased tensions with the United States and its allies. It follows an incident where a hacker claimed to have gotten a large amount …
Read More »
CERT-In
Warning! Govt alerts Samsung users; here’s why
The Indian government urgently asked Samsung smartphone users to update their devices due to security vulnerabilities. CERT-In issued a warning about a threat to certain Samsung devices running on Android versions 11, 12, 13, and 14. These vulnerabilities could be exploited to gain unauthorized access to sensitive data on these …
Read More »
MITRE Reveals EMB3D
MITRE reveals Critical Infrastructure Threat Model Framework
Red Balloon Security, Narf Industries, and MITRE worked together to develop the EMB3D Threat Model. This model helps us understand the risks that embedded devices face and the security measures they require. The EMB3D model is a framework that focuses on embedded devices. “It considers the specific risks presented by …
Read More »MICROSOFT PATCH TUESDAY FIXED 4 CRITICAL FLAWS
In December 2023, Microsoft released security updates for multiple products, addressing 33 vulnerabilities. The company’s vulnerabilities affect several Microsoft products, including Windows, Office, Azure, Microsoft Edge, Windows Defender, Windows DNS and DHCP server, and Microsoft Dynamic. The IT giant also addressed several Chromium issues. ALSO READ: Bypassing major EDRS using …
Read More »Sophos updated RCE fix after attacks on unsupported firewalls
Sophos had to update old firewall firmware versions due to a security vulnerability (CVE-2022-3236) after attacked by hackers. There is a code injection flaw in the User Portal and Webadmin of Sophos Firewall. This flaw allows for remote code execution. ALSO READ: Bypassing major EDRS using “POOL PARTY”, Hackers revealed …
Read More »
process injection techniques
Bypassing major EDRS using “POOL PARTY”, Hackers revealed
Researchers at cybersecurity firm SafeBreach created a new method called Pool Party. This method allows attackers to bypass EDR solutions. The researchers presented Pool Party at Black Hat Europe 2023. The experts discovered an new way to inject processes by using Windows thread pools. Researchers found eight new process injection …
Read More »APACHE FIXED CRITICAL RCE FLAW CVE-2023-50164 at STRUTS 2
The Apache Software Foundation fixed a critical file upload vulnerability in the Struts 2 open-source framework. This flaw, tracked as CVE-2023-50164, could allow remote code execution. An attacker can manipulate file upload parameters to upload a malicious file and execute code on the server. “An attacker can manipulate file upload …
Read More »
InfoSecBulletin Cybersecurity for mankind