article thumbnail

Cellebrite ‘s forensics tool affected by arbitrary code execution issue

Security Affairs

Cellebrite mobile forensics tool Ufed contains multiple flaws that allow arbitrary code execution on the device, SIGNAL creator warns. Cellebrite develops forensics tools for law enforcement and intelligence agencies that allow automating physically extracting and indexing data from mobile devices. ” concludes the expert.

article thumbnail

Russian APT Gamaredon uses USB worm LitterDrifter against Ukraine

Security Affairs

The Gamaredon APT group continues to carry out attacks against entities in Ukraine, including security services, military, and government organizations. If present, the current execution could simply be a scheduled execution triggered by the persistence mechanisms.”

Military 118
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Catches of the Month: Phishing Scams for March 2022

IT Governance

The Ukrainian government and its military were targeted by DDoS (distributed denial-of-service) attacks, while a pro-Ukrainian group attacked the Belarusian railway system with ransomware after discovering that it was being used by Russia to transport tanks and weapons. Beware of remote access takeover scams.

Phishing 144
article thumbnail

MI5 chief warns of Chinese cyber espionage reached an unprecedented scale

Security Affairs

“And we know that authoritarian states are laser-focused on the opportunities that these technologies may present for them.” The BBC reported the case of an acquisition of a sensitive UK tech company involved in UK military supply chains. ” reported BBC.

Military 133
article thumbnail

Cryptic Rumblings Ahead of First 2020 Patch Tuesday

Krebs on Security

is slated to release a software update on Tuesday to fix an extraordinarily serious security vulnerability in a core cryptographic component present in all versions of Windows. Sources tell KrebsOnSecurity that Microsoft Corp. Those sources say Microsoft has quietly shipped a patch for the bug to branches of the U.S.

Military 265
article thumbnail

UK emphasises cyber security in new foreign policy strategy

IT Governance

A central part of this review is the NCF (National Cyber Force), which uses “offensive cyber tools” to detect, disrupt and deter adversaries. This is in line with what little we know about the tools at the NCF’s disposal. National Cyber Force. Formed in 2020, the NCF is a partnership between the Ministry of Defence and GCHQ.

Security 124
article thumbnail

Iran-linked Lyceum APT adds a new.NET DNS Backdoor to its arsenal

Security Affairs

The DNS backdoor borrows the code from an open-source tool named DIG.net , it was used to perform “DNS hijacking.” The attack chain observed by the researchers starts with spear-phishing messages using weaponized Word document disguised as a news report related to military affairs in Iran. “The dropped binary is a .NET

IT 144