Breaking News

Security Affairs newsletter Round 369 by Pierluigi Paganini

A new round of the weekly Security Affairs newsletter arrived! Every week the best security articles from Security Affairs for free in your email box.

If you want to also receive for free the newsletter with the international press subscribe here.

Ransomware gangs are exploiting CVE-2022-26134 RCE in Atlassian Confluence servers
HID Mercury Access Controller flaws could allow to unlock Doors
Iran-linked Lyceum APT adds a new .NET DNS Backdoor to its arsenal
PACMAN, a new attack technique against Apple M1 CPUs
Threat actors exploit recently disclosed Atlassian Confluence flaw in cryptomining campaign
Experts spotted a new variant of the Cuba Ransomware with optimized infection techniques
Vice Society ransomware gang adds the Italian City of Palermo to its data leak site
Symbiote, a nearly-impossible-to-detect Linux malware
Previously undocumented Aoqin Dragon APT targets entities in Southeast Asia and Australia
New Emotet variant uses a module to steal data from Google Chrome
Tainted CCleaner Pro Cracker spreads via Black Seo campaign
0Patch released unofficial security patch for new DogWalk Windows zero-day
US dismantled and seized SSNDOB cybercrime marketplace
China-linked threat actors have breached telcos and network service providers
Black Basta ransomware now supports encrypting VMware ESXi servers
Evil Corp gang starts using LockBit Ransomware to evade sanctions
Black Basta ransomware operators leverage QBot for lateral movements
Lockbit ransomware gang claims to have hacked cybersecurity giant Mandiant
Microsoft seized 41 domains used by Iran-linked Bohrium APT
Another nation-state actor exploits Microsoft Follina to attack European and US entities
Red TIM Research discovers a Command Injection with a 9,8 score on Resi
Exclusive: Pro-Russia group ‘Cyber Spetsnaz’ is attacking government agencies
PoC exploits for Atlassian CVE-2022-26134 RCE flaw released online
Security Affairs newsletter Round 368 by Pierluigi Paganini
Hackers stole over $250,000 in Ethereum from Bored Ape Yacht Club
Atlassian rolled out fixes for Confluence zero-day actively exploited in the wild

Security Affairs is one of the finalists for the best European Cybersecurity Blogger Awards 2022 – VOTE FOR YOUR WINNERS. I ask you to vote for me again (even if you have already done it), because this vote is for the final.

Please vote for Security Affairs and Pierluigi Paganini in every category that includes them (e.g. sections “The Underdogs – Best Personal (non-commercial) Security Blog” and “The Tech Whizz – Best Technical Blog”)

To nominate, please visit: 

https://docs.google.com/forms/d/e/1FAIpQLSdNDzjvToMSq36YkIHQWwhma90SR0E9rLndflZ3Cu_gVI2Axw/viewform

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

[adrotate banner=”5″]

[adrotate banner=”13″]

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

China-linked threat actor targeted +70 orgs worldwide, SentinelOne warns

China-linked threat actor targeted over 70 global organizations, including governments and media, in cyber-espionage attacks…

3 hours ago

DOJ moves to seize $7.74M in crypto linked to North Korean IT worker scam

US seeks to seize $7.74M in crypto linked to North Korean fake IT worker schemes,…

16 hours ago

OpenAI bans ChatGPT accounts linked to Russian, Chinese cyber ops

OpenAI banned ChatGPT accounts tied to Russian and Chinese hackers using the tool for malware,…

23 hours ago

New Mirai botnet targets TBK DVRs by exploiting CVE-2024-3721

A new variant of the Mirai botnet exploits CVE-2024-3721 to target DVR systems, using a…

1 day ago

BadBox 2.0 botnet infects millions of IoT devices worldwide, FBI warns

BadBox 2.0 malware has infected millions of IoT devices globally, creating a botnet used for…

1 day ago

Over 950K weekly downloads at risk in ongoing supply chain attack on Gluestack packages

A supply chain attack hit NPM, threat actors compromised 16 popular Gluestack packages, affecting 950K+…

2 days ago