Security Affairs

Pierluigi Paganini October 26, 2019
CVE-2019-11043 exposes Web servers using nginx and PHP-FPM to hack

asty PHP7 remote code execution bug exploited in the wild Experts warn of a remote code execution vulnerability in PHP7, tracked as CVE-2019-11043, has been exploited in attacks in the wild. A remote code execution vulnerability in PHP7, tracked as CVE-2019-11043, has been exploited in attacks in the wild. On October 22, the security expert […]

Pierluigi Paganini October 26, 2019
Unsecured ElasticSearch DB exposed data for 7.5M Adobe Creative Cloud Users

Adobe suffered an important data leak, data for 7.5 Million Adobe Creative Cloud users have been exposed online through an unsecured server. The tech giant Adobe suffered an important data leak, data belonging to 7.5 Million Adobe Creative Cloud users have been exposed online through an unsecured server. The security breach took place this month […]

Pierluigi Paganini October 26, 2019
P&G online beauty store First Aid Beauty hit by Magecart attack

A new MageCart attack made the headlines, this time hackers planted a software skimmer in the Procter & Gamble’s site First Aid Beauty website. According to Willem de Groot, a researcher at Sanguine Security, threat actors planted a MageCart software skimmer on Procter & Gamble’s site First Aid Beauty on May 5, and the malicious […]

Pierluigi Paganini October 25, 2019
DDoS Attack on Amazon Web Services caused intermittently outage

This week Amazon Web Services (AWS) suffered a major distributed denial-of-service (DDoS) attack that made it unavailable for some customers. This week, threat actors launched a massive DDoS attack against Amazon Web Services (AWS) causing the inability of some customers to access their AWS S3 buckets. Users were intermittently unable to access online services relying […]

Pierluigi Paganini October 25, 2019
Tortuga Crisis: Moonwalk, one of the biggest pirate CDNs eliminated dragging other big CDN-providers down

Group-IB has discovered that the shutdown of Moonwalk CDN (Content Delivery Network) has likely led to the closure of HDGO and Kodik CDNs. Group-IB, a Singapore-based cybersecurity company that specializes in preventing cyberattacks, has discovered that the shutdown of Moonwalk CDN (Content Delivery Network), one of the biggest pirate-powered providers of video content to Russian-speaking viewers, has likely led to the closure of HDGO and Kodik CDNs– major […]

Pierluigi Paganini October 25, 2019
Ransomware attack hit the City of Johannesburg municipality

A new ransomware attack made the headlines, this time the victim is the City of Johannesburg municipality. A ransomware attack infected systems at the City of Johannesburg municipality shutting down the website, the e-services platform, and the billing system (SAP ISU and CRM). “The City of Johannesburg reported a breach of its network on Thursday night […]

Pierluigi Paganini October 25, 2019
Spear-phishing attacks target United Nations and NGOs

Experts have uncovered an ongoing phishing campaign targeting the United Nations and NGOs, including UNICEF and UN World Food. Security firm Lookout uncovered an ongoing spear-phishing campaign aimed at NGOs, including human rights organizations such as the Red Cross, UNICEF, the UN World Food and the UN Development programs. The analysis of the server infrastructure […]

Pierluigi Paganini October 25, 2019
Google addresses High-Severity sandbox escape issues in Chrome

Google has patched three serious flaws in Chrome that can be exploited to escape the sandbox of the popular web browser. Google has addressed three serious vulnerabilities affecting its Chrome browser that can be exploited to escape the built-in sandbox. The tech giant released Chrome 77 update in September that addressed two use-after-free vulnerabilities that […]

Pierluigi Paganini October 25, 2019
Experts attribute NukeSped RAT to North Korea-Linked hackers

Experts at Fortinet analyzed NukeSped malware samples that share multiple similarities with malware associated with North Korea-linked APTs. Fortinet has analyzed the NukeSped RAT that is believed to be a malware in the arsenal of the Lazarus North-Korea linked APT group. The attribution to the Lazarus group is based on the similarities with other malware […]

Pierluigi Paganini October 24, 2019
Swedish Government grants police the use of spyware against violent crime suspects

The Sweden government is going to authorize the use of spyware on suspects’ devices to spy on their communications and track them. S The Sweden government is going to authorize law enforcement agencies into using spyware to spy on suspects’ devices, the malicious code allows agents to read encrypted communications, to track their movements, exfiltrate […]