Daily NCSC-FI news followup 2020-06-03

Critical SAP ASE Flaws Allow Complete Control of Databases

threatpost.com/critical-sap-ase-flaws-complete-control-databases/156239/ If exploited, the most severe flaws could give unprivileged users complete control of databases and in some cases even underlying operating systems – The most severe vulnerability, CVE-2020-6248, has a CVSS score of 9.1 out of 10. See also:

wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=545396222. And also:

www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/system-takeover-through-new-sap-ase-vulnerabilities/

Vulnerability Spotlight: Two vulnerabilities in Zoom could lead to code execution

blog.talosintelligence.com/2020/06/vuln-spotlight-zoom-code-execution-june-2020.html An exploitable path traversal vulnerability exists in the Zoom Client version 4.6.10 processes messages including animated GIFs. In order to trigger this vulnerability, an attacker needs to send a specially crafted message to a target user or a group. See also:

talosintelligence.com/vulnerability_reports/TALOS-2020-1055. And also:

talosintelligence.com/vulnerability_reports/TALOS-2020-1056

Large-scale attack tries to steal configuration files from WordPress sites

www.zdnet.com/article/large-scale-attack-tries-to-steal-configuration-files-from-wordpress-sites/ Hackers have launched a massive campaign against WordPress websites over the past weekend, attacking old vulnerabilities in unpatched plugins to download configuration files from WordPress sites. Campaign accounted for 75% of all attempted exploits of plugin and theme vulnerabilities across the WordPress ecosystem

Ransomware gang says it breached one of NASA’s IT contractors

www.zdnet.com/article/ransomware-gang-says-it-breached-one-of-nasas-it-contractors/ DopplePaymer ransomware gang claims to have breached DMI, a major US IT and cybersecurity provider, and one of NASA IT contractors. In a blog post published today, the DopplePaymer ransomware gang said it successfully breached the network of Digital Management Inc. (DMI), a Maryland-based company that provides managed IT and cyber-security services on demand.

European Cyber Security Challenge 2020 – Event Date Change

www.enisa.europa.eu/news/enisa-news/european-cyber-security-challenge-2020-dates-changed The ECSC Steering Committee together with the Austrian national planners and the support of the European Agency for Cybersecurity decided to change the dates of the European Cyber Security Challenge 2020 Finals, scheduled to take place in Vienna this November. More information: europeancybersecuritychallenge.eu/

Pidä varasi: Lidl-huijaus kerää suomalaisten yhteystietoja

www.is.fi/digitoday/tietoturva/art-2000006528702.html Facebookissa näytetään suomalaisille Lidlin nimissä tehtyä huijausta, jonka varjolla ihmisiltä kalastellaan yhteystietoja.

You might be interested in …

Daily NCSC-FI news followup 2020-11-18

Hackers are actively probing millions of WordPress sites www.bleepingcomputer.com/news/security/hackers-are-actively-probing-millions-of-wordpress-sites/ Unknown threat actors are scanning for WordPress websites with Epsilon Framework themes installed on over 150, 000 sites and vulnerable to Function Injection attacks that could lead to full site takeovers. Hacking group exploits ZeroLogon in automotive, industrial attack wave www.zdnet.com/article/cicada-hacking-group-exploits-zerologon-launches-new-backdoor-in-automotive-industry-attack-wave/ The active cyberattack is thought […]

Read More

Daily NCSC-FI news followup 2019-11-16

Holiday Shoppers Beware: 100K Malicious Sites Found Posing as Well-Known Retailers threatpost.com/holiday-shoppers-malicious-sites-posing-retailers/150326/ As the holiday season looms, cybercrooks are going after shoppers with more than 100,000 lookalike domains mimicking legitimate retailers.. To that point, Venafi researchers uncovered the copycat phishing sites, which use trusted, valid TLS certificates (60 percent of them are free certificates from […]

Read More

Daily NCSC-FI news followup 2021-02-20

Safety Certification Giant UL Has Been Hit By Ransomware www.forbes.com/sites/leemathews/2021/02/19/safety-certification-giant-ul-has-been-hit-by-ransomware/ UL, which you may know better as Underwriters Laboratories, has overcome countless obstacles in its 127-year run as the world’s leading safety testing authority. Now they’re facing down a true 21st century menace: ransomware. Lisäksi: www.bleepingcomputer.com/news/security/underwriters-laboratories-ul-certification-giant-hit-by-ransomware/ Recently fixed Windows zero-day actively exploited since mid-2020 www.bleepingcomputer.com/news/security/recently-fixed-windows-zero-day-actively-exploited-since-mid-2020/ […]

Read More

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.