Android, Linux, Apple Devices Exposed to Bluetooth Keystroke Injection Attacks

December 8, 2023 at 06:42AM A Bluetooth vulnerability enables attackers to bypass authentication and perform keystroke injection on Android, Linux, and Apple devices. Meeting Takeaways: 1. A security vulnerability has been identified that affects Android, Linux, and Apple devices pertaining to Bluetooth connections. 2. This vulnerability allows attackers to execute a Bluetooth authentication bypass. 3. … Read more

‘HeadCrab’ Malware Variants Commandeer Thousands of Servers

December 7, 2023 at 01:57PM A new version of HeadCrab malware targets Redis servers for cryptomining and further attacks, with over 1,100 additional infections reported by Aqua Security. The malware now has enhanced ability to hide its presence, and its sole user, Ice9, has interacted with researchers via a built-in “mini blog.” Security enhancements in … Read more

Patch Now: Critical Atlassian Bugs Endanger Enterprise Apps

December 6, 2023 at 06:00PM Atlassian has patched four critical vulnerabilities (CVE-2022-1471, CVE-2023-22522, CVE-2023-22523, CVE-2023-22524) with CVSS scores up to 9.8, affecting various platforms with risks of remote code execution (RCE). These follow a series of bugs in their widely-used collaboration tools, with prior exploits prompting urgent updates. Meeting Takeaways: 1. Atlassian has encountered four … Read more

Holiday Hackers: How to Safeguard Your Service Desk

December 5, 2023 at 12:07PM During holidays, cyberattacks on e-commerce rise, targeting customer-rich environments and understaffed service desks. Attackers exploit high-risk events like password resets, using social engineering and ransomware. Companies lack proper response plans and may pay ransoms. Secure verification via Specops Software and staff training can mitigate risks. (Sponsored content by Specops Software.) … Read more

Iranian Hackers Exploit PLCs in Attack on Water Authority in U.S.

November 29, 2023 at 08:12AM CISA is tackling a cyber attack on Pennsylvania’s Municipal Water Authority by the Iranian-affiliated Cyber Av3ngers, who exploited Unitronics PLCs. The water facility is now manual with no drinking water risk. CISA advises strengthened cybersecurity, while Cyber Av3ngers continues targeting critical infrastructure. Meeting Takeaways: Cyber Attack on Municipal Water Authority … Read more

Long Beach, California turns off IT systems after cyberattack

November 16, 2023 at 05:25PM Long Beach, California, has suffered a cyberattack, leading to the shutdown of portions of their IT network. The city detected the attack and began taking systems offline immediately to prevent further spread. Systems are expected to be offline for several days while the incident is investigated. It is unclear what … Read more