Infosec News

InfoSec News 20230626

  • Publicado: Seg, 26/06/2023 - 12:23

Top News


  • Trojanized Super Mario game used to install Windows malware

"A trojanized installer for the popular Super Mario 3: Mario Forever game for Windows has been infecting unsuspecting players with multiple malware infections.
Super Mario 3: Mario Forever is a free-to-play remake of the classic Nintendo game developed by Buziol Games and released for the Windows platform in 2003.

InfoSec News 20230623

  • Publicado: Sex, 23/06/2023 - 13:33

Top News


  • More than a million GitHub repositories potentially vulnerable to RepoJacking

"A study conducted by Aqua researchers revealed that millions of GitHub repositories are potentially vulnerable to RepoJacking.
In the RepoJacking attack, attackers claim the old username of a repository after the legitimate creator changed the username, then publish a rogue repository with the same name to trick users into downloading its content."

InfoSec News 20230622

  • Publicado: Qui, 22/06/2023 - 14:50

Top News


  • Apple fixes zero-days used to deploy Triangulation spyware via iMessage

"Apple addressed three new zero-day vulnerabilities exploited in attacks installing Triangulation spyware on iPhones via iMessage zero-click exploits.
"Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7," the company says when describing Kernel and WebKit vulnerabilities tracked as CVE-2023-32434 and CVE-2023-32435.

InfoSec News 20230621

  • Publicado: Qua, 21/06/2023 - 11:30

Top News


  • VMware warns of critical vRealize flaw exploited in attacks

"VMware updated a security advisory published two weeks ago to warn customers that a now-patched critical vulnerability allowing remote code execution is being actively exploited in attacks.
"VMware has confirmed that exploitation of CVE-2023-20887 has occurred in the wild," the company said today.

InfoSec News 20230620

  • Publicado: Ter, 20/06/2023 - 13:07

Top News


  • Infostealer malware have stolen 101,000 ChatGPT accounts

"​More than 101,000 ChatGPT user accounts have been stolen by information-stealing malware over the past year, according to dark web marketplace data.
Cyberintelligence firm Group-IB reports having identified over a hundred thousand info-stealer logs on various underground websites containing ChatGPT accounts, with the peak observed in May 2023, when threat actors posted 26,800 new ChatGPT credential pairs.

InfoSec News 20230619

  • Publicado: Seg, 19/06/2023 - 13:01

Top News


  • Microsoft confirms Azure, Outlook outages caused by DDoS attacks

"Microsoft has confirmed that recent outages to Azure, Outlook, and OneDrive web portals resulted from Layer 7 DDoS attacks against the company's services.
The attacks are being attributed to a threat actor tracked by Microsoft as Storm-1359, who calls themselves Anonymous Sudan.
The outages occurred at the beginning of June, with Outlook.com's web portal targeted on June 7th, OneDrive on June 8th, and the Microsoft Azure Portal on June 9th.

InfoSec News 20230616

  • Publicado: Sex, 16/06/2023 - 14:44

Top News


  • MOVEit Transfer customers warned of new flaw as PoC info surfaces

"Progress warned MOVEit Transfer customers to restrict all HTTP access to their environments after info on a new SQL injection (SQLi) vulnerability was shared online today.
A patch addressing this new critical security bug is not yet available, but one is currently being tested and will be released "shortly," according to the company.

InfoSec News 20230615

  • Publicado: Qui, 15/06/2023 - 13:41

Top News


  • Amazon cloud services back up after big outage hits thousands of users

"Amazon.com said cloud services offered by its unit, Amazon Web Services (AWS), were restored after a big disruption on Tuesday affected websites of the New York Metropolitan Transportation Authority and the Boston Globe among others.
Several hours after Downdetector.com started showing reports of outages, Amazon said, "the issue has been resolved and all AWS Services are operating normally."

InfoSec News 20230614

  • Publicado: Qua, 14/06/2023 - 14:32

Top News


  • Fake zero-day PoC exploits on GitHub push Windows, Linux malware

"Hackers are impersonating cybersecurity researchers on Twitter and GitHub to publish fake proof-of-concept exploits for zero-day vulnerabilities that infect Windows and Linux with malware."

Link

TLP1 : Green

InfoSec News 20230612

  • Publicado: Seg, 12/06/2023 - 14:17

Top News


  • Critical RCE Flaw Discovered in Fortinet FortiGate Firewalls - Patch Now!

"Fortinet has released patches to address a critical security flaw in its FortiGate firewalls that could be abused by a threat actor to achieve remote code execution.

The vulnerability, tracked as CVE-2023-27997, is "reachable pre-authentication, on every SSL VPN appliance," Lexfo Security researcher Charles Fol, who discovered and reported the flaw, said in a tweet over the weekend."

Páginas