Remove 11
article thumbnail

Talos experts found 11 flaws in Schneider Electric Modicon Controllers

Security Affairs

Talos experts discovered 11 security flaws affecting some models of Schneider Electric’s Modicon programmable logic controllers. Talos blog post also includes SNORT rules to detect exploitation attempts. Copyright (C) 2014-2015 Media.net Advertising FZ-LLC All Rights Reserved -->. Pierluigi Paganini.

article thumbnail

Threat actors are actively exploiting Zerologon flaw, Microsoft warns

Security Affairs

. “Microsoft has received a small number of reports from customers and others about continued activity exploiting a vulnerability affecting the Netlogon protocol ( CVE-2020-1472 ) which was previously addressed in security updates starting on August 11, 2020.” Pierluigi Paganini. SecurityAffairs – hacking, Windows).

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Experts linked multiple ransomware strains North Korea-backed APT38 group

Security Affairs

APT38 appears to be a North Korea-linked group separate from the infamous Lazarus group, it has been active since at least 2014 and it has been observed targeting over 16 organizations across 11 countries. are part of more organized attacks,” concludes the blog. “We suspect the ransomware families [.] Pierluigi Paganini.

article thumbnail

EnemyBot malware adds new exploits to target CMS servers and Android devices

Security Affairs

CVE Number Affected devices CVE-2021-44228, CVE-2021-45046 Log4J RCE CVE-2022-1388 F5 BIG IP RCE No CVE (vulnerability published on 2022-02) Adobe ColdFusion 11 RCE CVE-2020-7961 Liferay Portal – Java Unmarshalling via JSONWS RCE No CVE (vulnerability published on 2022-04) PHP Scriptcase 9.7 LFI CVE-2018-16763 Fuel CMS 1.4.1

CMS 141
article thumbnail

The Week in Cyber Security and Data Privacy: 16–22 October 2023

IT Governance

Welcome to a new series of weekly blog posts rounding up the biggest and most interesting news stories. At the end of each month, these incidents – and any others that we find – will be used to inform our monthly analysis of data breaches and cyber attacks. Records breached: Around 700 records. Records breached: Unknown.

article thumbnail

TroyStealer – A new info stealer targeting Portuguese Internet users

Security Affairs

Threat name: TroyStealer.exe MD5: DAB6194F16CEFDB400E3FB6C11A76861 SHA1: C76A9FB1A2AE927BF9C950338BE5B391FED29CD7 Imphash: F34D5F2D4577ED6D9CEEC516C1F5A744 Created: Thu Jun 11 19:53:24 2020. He is also a founding member at CSIRT.UBI and Editor-in-Chief of the security computer blog seguranca-informatica.pt.

Passwords 108
article thumbnail

Holes in Linux Kernel Could Pose Problems for Red Hat, Ubuntu, Other Distros

eSecurity Planet

The two flaws – CVE-2021-33909 and CVE-2021-33910, respectively – were disclosed by vulnerability management vendor Qualys in a pair of blogs that outlined the threat to Linux OSes from such companies Red Hat, Ubuntu, Debian and Fedora. The vulnerability was introduced in systemd v220 in April 2015. Severe Potential’.

Metadata 145