Updates
- Another Critical Unauthenticated SQLi Flaw Discovered in MOVEit Transfer Software
- Google Releases Android Patch Update for 3 Actively Exploited Vulnerabilities
- Cisco warns of a flaw in Nexus 9000 series switches that allows modifying encrypted traffic
- Critical TootRoot bug lets attackers hijack Mastodon servers
Threats
- Solar monitoring systems exposed: Secure your devices
- Security Firm Finds Over 130k Internet-Exposed Photovoltaic Diagnostics Systems
- 3 Critical RCE Bugs Threaten Industrial Solar Panels
- Photovoltaik-Monitoring: Sicherheitslücken in Solarview werden angegriffen
- Over 130,000 solar energy monitoring systems exposed online
- Researchers Uncover New Linux Kernel 'StackRot' Privilege Escalation Vulnerability
- Node.js Users Beware: Manifest Confusion Attack Opens Door to Malware
- Vishing Goes High-Tech: New 'Letscall' Malware Employs Voice Traffic Routing
- Beware of the Growing Scourge of Job Recruitment Scams
- New ‘Big Head’ ransomware displays fake Windows update alert
- New tool exploits Microsoft Teams bug to send malware to users
- StackRot, a new Linux Kernel privilege escalation vulnerability
- Phishing-Angriffe auf mobile Geräte nehmen erschreckende Ausmaße an
Incidents
- Chinese Hackers Use HTML Smuggling to Infiltrate European Ministries with PlugX
- Former Contractor Employee Charged for Hacking California Water Treatment Facility
- Nickelodeon investigates breach after leak of 'decades old’ data
- Chinese hackers target European embassies with HTML smuggling technique
- JumpCloud resets admin API keys amid ‘ongoing incident’
- Bangladesh government website leaked data of millions of citizens
- Datenleck bei Deutscher Bank und Postbank
Cyber Crime
- BreachForums replacement emerges as robust forum for criminal hackers to trade their spoils
- Police arrest suspect linked to notorius OPERA1ER cybercrime gang
Malware
- Iranian Hackers' Sophisticated Malware Targets Windows and macOS Users
- Evasive Meduza Stealer Targets 19 Password Managers and 76 Crypto Wallets
- BlackCat ransomware pushes Cobalt Strike via WinSCP search ads