+44 (0)203 88 020 88

Menu

Search

cyber security news

Critical Atlassian Bitbucket Vulnerability

A critical vulnerability has been identified in multiple versions of Atlassian’s Bitbucket Server and Bitbucket Data Center. A recent advisory released by Bitbucket Support explains that all versions after 6.10.17, including 7.0.0 and later, have been affected by this flaw. However, this vulnerability is not present in Atlassian Cloud sites, so users who access Bitbucket […]

Critical Atlassian Bitbucket Vulnerability Read More »

NOBELIUM’s Backdoor Malware: MagicWeb

Microsoft’s Threat Intelligence Center (MSTIC) have recently discovered a new malware capability that NOBELIUM are using called MagicWeb. Highly active threat actor NOBELIUM are known for targeting organisations across Europe, Central Asia, and the USA. First detected in 2020, they use unique malware that is usually tailored to their current target. The MagicWeb malware is

NOBELIUM’s Backdoor Malware: MagicWeb Read More »

GitLab Patch Critical Remote Code Execution Flaw

GitLab have published a critical security release this week to notify their users about an update that contains important security fixes. Versions 15.3.1, 15.2.3, and 15.1.5 were released for GitLab Community Edition (CE) and Enterprise Edition (EE), in order to patch a remote code execution (RCE) vulnerability. GitLab is used as a DevOps platform for

GitLab Patch Critical Remote Code Execution Flaw Read More »

Palo Alto Networks Exploited in DoS Attacks

A denial-of-service vulnerability was identified this month in Palo Alto Networks PAN-OS software. This week, the Cybersecurity and Infrastructure Agency (CISA), a branch of the US government, have added this vulnerability to their list of known exploited vulnerabilities. Tracked as CVE-2022-0028, this flaw affects the URL filtering policy in multiple versions of PAN-OS running on

Palo Alto Networks Exploited in DoS Attacks Read More »

VMware Patch Critical Authentication Bypass Flaw

VMware released a critical security advisory this week to warn users of security vulnerabilities that have been found in a variety of their systems. VMware Workspace ONE Access, Access Connector, Identity Manager, Identity Manager Connector, and vRealize Automation products have all received security patches to deal with these vulnerabilities. VMware advise all users that it

VMware Patch Critical Authentication Bypass Flaw Read More »

Critical Confluence Vulnerability Exploited in the Wild

A vulnerability in Atlassian’s Questions for Confluence app has been found that includes hardcoded credentials that remote attackers can exploit to access the Confluence Server or Confluence Data Center it is hosted on. The versions of Questions for Confluence with this vulnerability unpatched are 2.7.34, 2.7.35, and 3.0.2. Atlassian have released a security advisory rating

Critical Confluence Vulnerability Exploited in the Wild Read More »

Microsoft Exchange Servers Open to Backdoor Hack

Microsoft have warned customers of a form of attack capable of targeting unpatched Microsoft Exchange servers. The attacks taking place in the first 5 months of this year saw threat actors using Internet Information Services (IIS) extension modules to: access their victim’s email mailboxes, execute commands remotely, harvest credentials from within the system memory, steal

Microsoft Exchange Servers Open to Backdoor Hack Read More »

New Backdoor Linux Malware ‘Lightning Framework’

A new, previously undetected, Linux malware known as ‘Lightning Framework’ can be used as a backdoor to install rootkits in infected devices via Secure Shell (SSH). A report released by Intezer this week calls this malware “Swiss Army Knife-like” due to its wide range of capabilities, and ability to use techniques to avoid detection and

New Backdoor Linux Malware ‘Lightning Framework’ Read More »

0

No products in the basket.

No products in the basket.