Security Affairs newsletter Round 439 by Pierluigi Paganini – International edition

Pierluigi Paganini October 01, 2023

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free for you in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.

ALPHV/BlackCat ransomware gang hacked the hotel chain Motel One
FBI warns of dual ransomware attacks
Progress Software fixed two critical severity flaws in WS_FTP Server
Child abuse site taken down, organized child exploitation crime suspected – exclusive
A still unpatched zero-day RCE impacts more than 3.5M Exim servers
Chinese threat actors stole around 60,000 emails from US State Department in Microsoft breach
Misconfigured WBSC server leaks thousands of passports
CISA adds JBoss RichFaces Framework flaw to its Known Exploited Vulnerabilities catalog
Cisco urges to patch actively exploited IOS zero-day CVE-2023-20109
Dark Angels Team ransomware group hit Johnson Controls
GOOGLE FIXED THE FIFTH CHROME ZERO-DAY OF 2023
Russian zero-day broker is willing to pay $20M for zero-day exploits for iPhones and Android devices
China-linked APT BlackTech was spotted hiding in Cisco router firmware
Watch out! CVE-2023-5129 in libwebp library affects millions applications
DarkBeam leaks billions of email and password combinations
‘Ransomed.vc’ in the Spotlight – What is Known About the Ransomware Group Targeting Sony and NTT Docomo
Top 5 Problems Solved by Data Lineage
Threat actors claim the hack of Sony, and the company investigates
Canadian Flair Airlines left user data leaking for months
The Rhysida ransomware group hit the Kuwait Ministry of Finance
BORN Ontario data breach impacted 3.4 million newborns and pregnancy care patients
Xenomorph malware is back after months of hiatus and expands the list of targets
Smishing Triad Stretches Its Tentacles into the United Arab Emirates
Crooks stole $200 million worth of assets from Mixin Network
A phishing campaign targets Ukrainian military entities with drone manual lures
Alert! Patch your TeamCity instance to avoid server hack
Is Gelsemium APT behind a targeted attack in Southeast Asian Government?
Nigerian National pleads guilty to participating in a millionaire BEC scheme
New variant of BBTok Trojan targets users of +40 banks in LATAM
Deadglyph, a very sophisticated and unknown backdoor targets the Middle East
Alphv group claims the hack of Clarion, a global manufacturer of audio and video equipment for cars
National Student Clearinghouse data breach impacted approximately 900 US schools

Cybercrime

  

  

  

  

      

Malware

  

    

Hacking

CVE-2023-34040 Spring Kafka Deserialization Remote Code Execution

    

  

   

Using silent SMS to localize LTE users 

  

Intelligence and Information Warfare

  

  

 

How Russian government-controlled hacking groups shift their tactics, objectives and capabilities — report  

      

Cybersecurity

  

  

  

  

Follow me on Twitter:  and  and Mastodon

(SecurityAffairs – hacking, newsletter)



you might also like

leave a comment