Cybersecurity

Category Added in a WPeMatico Campaign

Cybersecurity

Grammarly says it corrected sign-in vulnerabilities after alert from cyber researchers

Popular typing assistant Grammarly said it has fixed vulnerabilities affecting user logins after being notified by a security company of the issues. The bugs affected social sign-in — when someone accesses a web service through their existing credentials for a platform like Facebook or Google — and were caused by issues with implementations of Open […]

Cybersecurity

Critical Flaw in NextGen’s Mirth Connect Could Expose Healthcare Data

Oct 26, 2023NewsroomVulnerability / Network Security Users of Mirth Connect, an open-source data integration platform from NextGen HealthCare, are being urged to update to the latest version following the discovery of an unauthenticated remote code execution vulnerability. Tracked as CVE-2023-43208, the vulnerability has been addressed in version 4.4.1 released on October 6, 2023. “This is […]

Cybersecurity

YoroTrooper: Researchers Warn of Kazakhstan’s Stealthy Cyber Espionage Group

Oct 26, 2023NewsroomEndpoint Protection / Malware A relatively new threat actor known as YoroTrooper is likely made of operators originating from Kazakhstan. The assessment, which comes from Cisco Talos, is based on their fluency in Kazakh and Russian, use of Tenge to pay for operating infrastructure, and very limited targeting of Kazakhstani entities, barring the […]

Cybersecurity

Alleged Airbnb Data Breach Exposes 1.2 Million User Records!

A significant data breach has allegedly compromised Airbnb’s security, potentially exposing the personal information of 1.2 million users. A threat actor, who goes by the name ‘Sheriff’ on the darkweb, has come forward, claiming the Airbnb data breach, which includes sensitive details such as names, email addresses, countries of residence, cities, and more. Airbnb Data […]

Cybersecurity

Act Now: VMware Releases Patch for Critical vCenter Server RCE Vulnerability

Oct 25, 2023NewsroomVulnerability / Cyber Threat VMware has released security updates to address a critical flaw in the vCenter Server that could result in remote code execution on affected systems. The issue, tracked as CVE-2023-34048 (CVSS score: 9.8), has been described as an out-of-bounds write vulnerability in the implementation of the DCE/RPC protocol. “A malicious […]

Cybersecurity

Ukraine cyber officials warn of a ‘surge’ in Smokeloader attacks on financial, government entities

Suspected Russian cybercriminals have increased their attacks against Ukrainian financial and government organizations using Smokeloader malware, according to Ukrainian cybersecurity officials. Since May of this year, the malware operators have targeted Ukrainian organizations with intense phishing attacks, primarily attempting to infiltrate their systems and steal sensitive information, according to research published Tuesday by Ukraine’s National […]