Remove 02
article thumbnail

Hackers exploit 3-years old flaw to wipe Western Digital devices

Security Affairs

WD is investigating the mysterious wave of attacks launched and speculates that attackers have been exploiting a known vulnerability, tracked as CVE-2018-18472 , to wipe the devices. Please check yours and see what happened.” ” Some of the users were able to recover the wiped files using a tool named PhotoRec. .”

Security 101
article thumbnail

02-16-18

Info Source

DIR 2-16-2018.

40
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

EnemyBot malware adds new exploits to target CMS servers and Android devices

Security Affairs

The first version of the bot exploits tens of known vulnerabilities including: CVE-2020-17456 vulnerability affecting SEOWON INTECH SLC-130 and SLR-120S routers; CVE-2018-10823 flaw an older D-Link routers (DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, DWR-111 through 1.01).

CMS 142
article thumbnail

Millions of devices could be hacked exploiting flaws targeted by tools stolen from FireEye

Security Affairs

91541, 91534 CVE-2014-1812 05/13/2014 Microsoft Windows Group Policy Preferences Password Elevation of Privilege Vulnerability (KB2962486) 9 91148, 90951 CVE-2020-0688 02/11/2020 Microsoft Exchange Server Security Update for February 2020 8.8 110306 CVE-2018-8581 11/13/2018 Microsoft Exchange Server Elevation of Privilege Vulnerability 7.4

Passwords 113
article thumbnail

Cisco WebEx Meetings affected by a new elevation of privilege flaw

Security Affairs

According to SecureAuth, that flaw is a “bypass to avoid the new controls” implemented by Cisco after addressing a DLL hijacking issue tracked as CVE-2018-15442. Below the timeline for the vulnerability: 2018-12-04: SecureAuth sent an initial notification to the Cisco PSIRT including a draft advisory. Pierluigi Paganini.

article thumbnail

Predictions for 2018 – This is where the magic happens!

CGI

Predictions for 2018 – This is where the magic happens! Wed, 02/21/2018 - 03:49. Now, much like data analytics, I will pivot from reactive to predictive mode and make some forecasts for 2018. Here are a few other trend predictions for 2018: It is decidedly so … blockchain will continue with its hype.

article thumbnail

Apr 10 – Apr 16 Ukraine – Russia the silent cyber conflict

Security Affairs

Threat actors are targeting Ukrainian government organizations with exploits for XSS vulnerabilities in Zimbra Collaboration Suite (CVE-2018-6882). Mar 27 – Apr 02 Ukraine – Russia the silent cyber conflict. April 15 – Threat actors use Zimbra exploits to target Ukrainian organizations.