Cybersecurity

Category Added in a WPeMatico Campaign

Cybersecurity

New Supermicro BMC Vulnerabilities Could Expose Many Servers to Remote Attacks

Server and computer hardware giant Supermicro has released updates to address multiple vulnerabilities in Baseboard Management Controllers (BMC) IPMI firmware. The issues (tracked as CVE-2023-40284 to CVE-2023-40290) could allow remote attackers to gain root access to the BMC system, firmware supply chain security firm Binarly, which identified the bugs, explains. A special chip on server […]

Cybersecurity

GoldDigger Android Trojan Targets Banking Apps in Asia Pacific Countries

Oct 05, 2023NewsroomMobile Security / crypto A new Android banking trojan named GoldDigger has been found targeting several financial applications with an aim to siphon victims’ funds and backdoor infected devices. “The malware targets more than 50 Vietnamese banking, e-wallet and crypto wallet applications,” Group-IB said. “There are indications that this threat might be poised […]

Cybersecurity

Okta Buys Personal Password Manager Uno to Service Consumers

Identity & Access Management , Multi-factor & Risk-based Authentication , Security Operations Uno’s Design Wisdom Will Accelerate Rollout of Okta’s First-Ever Consumer Product Michael Novinson (MichaelNovinson) • October 4, 2023     Okta purchased a password manager founded by a former Google engineer and backed by Andreessen Horowitz to get a foothold in the consumer […]

Cybersecurity

CISA Warns of Active Exploitation of JetBrains and Windows Vulnerabilities

Oct 05, 2023NewsroomVulnerability / Cyber Attack The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added two security flaws to its Known Exploited Vulnerabilities (KEV) catalog due to active exploitation, while removing five bugs from the list due to lack of adequate evidence. The vulnerabilities newly added are below – CVE-2023-42793 (CVSS score: 9.8) […]

Cybersecurity

Atlassian Confluence Hit by New Actively Exploited Zero-Day – Patch Now

Oct 05, 2023NewsroomZero Day / Vulnerability Atlassian has released fixes to contain an actively exploited critical zero-day flaw impacting publicly accessible Confluence Data Center and Server instances. The vulnerability, tracked as CVE-2023-22515, is remotely exploitable and allows external attackers to create unauthorized Confluence administrator accounts and access Confluence servers. It does not impact Confluence versions […]