BleepingComputer.com

"300,000 + Fortinet firewalls vulnerable to critical FortiOS RCE bug."

Views expressed in this cybersecurity, cybercrime, and cyber espionage update are those of the reporters and correspondents.  Accessed on 03 July 2023, 1313 UTC.  Content provided by email subscription to "BleepingComputer.com."

Source:  https://www.bleepingcomputer.com/ ("BleepingComputer.com").

Please click link or scroll down to read your selections.  Thanks for joining us today.

Russ Roberts (https://www.hawaiicybersecurityjournal.net).

300,000+ Fortinet firewalls vulnerable to critical FortiOS RCE bug

  • Hundreds of thousands of FortiGate firewalls are vulnerable to a critical security issue identified as CVE-2023-27997, almost a month after Fortinet released an update that addresses the problem.

  • Twitter
     

Twitter's bot spam keeps getting worse — it's about porn this time

  • Forget crypto spam accounts, Twitter's got another problem which involves bots and accounts promoting adult content and infiltrating Direct Messages and interactions on the platform. And there doesn't seem to be an easy solution in sight.

  • Wifi
     

Snappy: A tool to detect rogue WiFi access points on open networks

  • Cybersecurity researchers have released a new tool called 'Snappy' that can help detect fake or rogue WiFi access points that attempts to steal data from unsuspecting people.

  • Black Cat BlackCat
     

BlackCat ransomware pushes Cobalt Strike via WinSCP search ads

  • The BlackCat ransomware group (aka ALPHV) is running malvertizing campaigns to lure people into fake pages that mimic the official website of the WinSCP file-transfer application for Windows but instead push malware-ridden installers.

  • Hacker disorder mental
     

The Week in Ransomware - June 30th 2023 - Mistaken Identity

  • A case of mistaken identity and further MOVEit Transfer data breaches continue dominated the ransomware news cycle this week.

  • WordPress
     

Hackers exploit zero-day in Ultimate Member WordPress plugin with 200K installs

  • Hackers exploit a zero-day privilege escalation vulnerability in the 'Ultimate Member' WordPress plugin to compromise websites by bypassing security measures and registering rogue administrator accounts.

  • Twitter
     

Twitter now forces you to sign in to view tweets

  • Starting today, Twitter is no longer accessible on web and mobile apps if you don't have an account, forcing all users to log in if they want to get access to the platform.

  • globe network map
     

New proxyjacking attacks monetize hacked SSH servers’ bandwidth

  • Attackers behind an ongoing series of proxyjacking attacks are hacking into vulnerable SSH servers exposed online to monetize them through services that pay for sharing unused Internet bandwidth.

  • Key Decryptor Unlock
     

Free Akira ransomware decryptor helps recover your files

  • Cybersecurity firm Avast has released a free decryptor for the Akira ransomware that can help victims recover their data without paying the crooks any money.

  • CISA
     

CISA issues DDoS warning after attacks hit multiple US orgs

  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned today of ongoing distributed denial-of-service (DDoS) attacks after U.S. organizations across multiple industry sectors were hit.

  • LockBit
     

TSMC denies LockBit hack as ransomware gang demands $70 million

  • Chipmaking giant TSMC (Taiwan Semiconductor Manufacturing Company) denied being hacked after the LockBit ransomware gang demanded $70 million not to release stolen data.

  • YouTube
     

YouTube tests restricting ad blocker users to 3 video views

  • YouTube is currently running what it describes as a "small experiment globally," warning users to toggle off their ad blockers and avoid being limited to only three video views.

  • North Korea hacker
     

New EarlyRAT malware linked to North Korean Andariel hacking group

  • Security analysts have discovered a previously undocumented remote access trojan (RAT) named 'EarlyRAT,' used by Andariel, a sub-group of the Lazarus North Korean state-sponsored hacking group.

  • Windows 11
     

Microsoft rolls out early Windows Copilot preview to Insiders

  • Microsoft announced today that an early preview of its AI-powered Windows Copilot personal assistant is rolling out to Insiders in the Windows 11 Dev Channel.

  • List
     

MITRE releases new list of top 25 most dangerous software bugs

  • MITRE shared today this year's list of the top 25 most dangerous weaknesses plaguing software during the previous two years.

VIEW MORE

Comments

Popular posts from this blog

The Cyberwire Daily Briefing

BleepingComputer.com

SecurityWeek Briefing