-
Leveraging Wazuh for Zero Trust security
- November 5, 2024
- Posted by: claudia
- Categories:
No CommentsZero Trust security revolutionizes organizational security by eliminating implicit trust. It focuses on continuous validation of user access and real-time monitoring of devices, addressing cyber threats and improving compliance, especially for remote work environments.
-
Synology Urges Patch for Critical Zero-Click RCE Flaw Affecting Millions of NAS Devices
- November 5, 2024
- Posted by: claudia
- Categories:
A critical security flaw, tracked as CVE-2024-10443 and dubbed RISK:STATION, affects Synology’s DiskStation and BeePhotos devices, enabling remote code execution. Demonstrated at Pwn2Own Ireland, this zero-click vulnerability could expose millions of users to data theft and malware.
-
Canadian Suspect Arrested Over Snowflake Data Breach and Extortion Attacks
- November 5, 2024
- Posted by: claudia
- Categories:
Canadian law enforcement has arrested Alexander “Connor” Moucka, suspected of multiple hacks linked to a breach of the Snowflake data platform earlier this year. The arrest follows a U.S. request, and while specific charges are unclear, the investigation highlights serious cyber threats.
-
Malware Campaign Uses Ethereum Smart Contracts to Control npm Typosquat Packages
- November 5, 2024
- Posted by: claudia
- Categories:
An ongoing attack is targeting npm developers with typosquat packages to deploy cross-platform malware. Utilizing Ethereum smart contracts for command-and-control server addresses, over 287 malicious packages have already been published, complicating detection efforts.
-
Google Warns of Actively Exploited CVE-2024-43093 Vulnerability in Android System
- November 5, 2024
- Posted by: claudia
- Categories:
Google has issued a warning about a privilege escalation vulnerability in Android (CVE-2024-43093), which is actively being exploited. This flaw allows unauthorized access to sensitive directories. Additionally, CVE-2024-43047, a vulnerability in Qualcomm chipsets, is also under exploitation.
-
Critical Flaws in Ollama AI Framework Could Enable DoS, Model Theft, and Poisoning
- November 4, 2024
- Posted by: claudia
- Categories:
Cybersecurity researchers revealed six vulnerabilities in the Ollama AI framework, allowing attackers to perform actions like denial-of-service and model theft. Notably, two unpatched issues could enable model poisoning and theft via specific API endpoints. Users are advised to filter endpoint exposure.
-
CISA Warns of Active Exploitation of Microsoft SharePoint Vulnerability (CVE-2024-38094)
- November 4, 2024
- Posted by: claudia
- Categories:
A high-severity flaw in Microsoft SharePoint, tracked as CVE-2024-38094 (CVSS score: 7.2), has been added to CISA’s Known Exploited Vulnerabilities catalog. This deserialization vulnerability allows authenticated attackers to inject arbitrary code, risking remote code execution.
-
A Shake-up in Identity Security Is Looming Large
- November 4, 2024
- Posted by: claudia
- Categories:
Identity security is increasingly vital amid recent breaches affecting major companies like Microsoft and Cloudflare. Organizations are called to rethink their approach to identity security, moving beyond mere access management to a broader strategic framework that ensures robust protection.
-
New Grandoreiro Banking Malware Variants Emerge with Advanced Tactics to Evade Detection
- November 4, 2024
- Posted by: claudia
- Categories:
New variants of the Grandoreiro banking malware adopt advanced tactics to bypass anti-fraud measures. Despite arrests in the gang, malicious software continues evolving, employing techniques like domain generation algorithms and mouse tracking to target users globally.
-
Fortinet Warns of Critical Vulnerability in FortiManager Under Active Exploitation
- November 4, 2024
- Posted by: claudia
- Categories:
Fortinet confirmed a critical flaw in FortiManager (CVE-2024-47575) that allows unauthenticated remote code execution via crafted requests. The vulnerability, scoring 9.8 on the CVSS, affects multiple versions of FortiManager and could lead to significant data exfiltration, prompting urgent patches.
Contact us at the Consulting WP office nearest to you or submit a business inquiry online.